Job Description
General Summary
Investigate privacy incidents, develop, implement, and monitor privacy policies, procedures and processes. Assist with managing and monitoring privacy work and auditing plans to ensure compliance with applicable federal and state laws, rules and regulations. Work collaboratively with UMMS member organizations (e.g., hospitals) management and other staff to ensure Privacy Program initiatives are implemented across UMMS. Work is performed under limited supervision. Direct report to the Manager, Privacy & Data Protection.
Principal Responsibilities and Tasks
The following elements are intended to provide a comprehensive overview and level of work performed by the individual assigned to this job description. The elements are not an exhaustive list of all job duties the assigned individual may be requested to perform.
- Serve as a resource to UMMS Corporate, member organizations, and Regional Compliance teams for privacy-related issues.
- Serve as an information and support resource to the organization regarding privacy related issues.
- May serve in a lead capacity for investigating and resolving privacy matters in collaboration with internal and external key stakeholders and member organizations and manage breach determinations and notification processes under the Health Insurance Portability and Accountability Act (HIPAA) and applicable state privacy laws.
- May be asked to conduct root cause analysis, facilitate management action plan completion and assist with implementation.
- Facilitate prompt responses to complaints, privacy inquiries and investigation requests received from regulatory agencies (e.g., Department of Health and Human Services Office for Civil Rights and Health and Human Services (HHS), and Office of Attorney General).
- May be assigned to prepare draft responses to regulatory inquiries, including gather supporting documentation, collaborating with key stakeholders to gather facts and/or investigate complaints, and facilitate development of related management action plans.
- Prepare and submit federal and state privacy breach reports as assigned by the Manager or Director, Privacy & Data Protection.
- Stay abreast of applicable federal and state laws, rules and regulations that govern privacy.
- Assist with tracking of current, revised, and new federal and state privacy laws. Provide status reports to Compliance leadership pertaining to regulations and their potential impact on UMMS.
- Develop and manage project plans designed to comply with regulatory changes and collaborate with key stakeholders and member organizations on regulatory change implementation, socialization and education.
- Conduct audits/reviews and perform analysis to ensure compliance with applicable federal and state laws, rules, regulations and UMMS policies and procedures.
- Support creation and completion of the annual Privacy Audit and Monitoring Plan.
- Develop auditing tools and toolkits.
- Collaborate with member organizations to implement audit and monitor activities.
- Perform quality assurance reviews and provide recommendations.
- Develop, prepare, and present audit and monitoring outcome reports with recommendations for improvement and remediation to CCBEG leadership.
- Review the investigation and breach risk assessment work of member organizations and Compliance Analysts.
- Mentor and guide Compliance Analysts on Privacy Program related issues.
- Assist with developing, updating, and implementing privacy policies and procedures.
- Monitor privacy data and trends to detect systemic issues, deficiencies and/or areas for further investigation and provide recommendations for operational changes and corrective action.
- Develop HIPAA hints and privacy awareness communication and education materials in collaboration with the Director, Privacy & Data Protection, Manager, Privacy & Data Protection, and the Program Manager, Compliance Training & Education.
- Prepare reports for the Vice President of Compliance Operations in collaboration with the Director, Privacy & Data Protection, Manager, Privacy & Data Protection, UMMS Executive Management, and the Audit and Compliance Committee of the Board of Directors.
- Perform other duties as assigned.