Summary/objective
The Compliance/Privacy Officer is responsible for the oversight, maintenance, and implementation of OnPoint’s Corporate Compliance program.
Pay Rate/Benefits Package
Pay range starting at $70,428.80 up to $97,198.40 - placement above minimum salary is based on experience.
OnPoint Benefits:
Benefits effective date of hire:
Employer Paid benefits:
Essential functions
- Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.
- Serve as Compliance and Privacy Officer and will develop and maintain policies and procedures relative to compliance and privacy.
- Maintain a strategic and comprehensive privacy program to minimize risk and ensure the confidentiality of protected health information (PHI) across all media types.
- Establishes, in collaboration with the Security Officer, a process to log, investigate, and report inappropriate access, use, or disclosure of PHI and monitor.
- Maintains current knowledge of applicable federal and state compliance and privacy laws and accreditation standards.
- Monitor OnPoint’s various sources for compliance complaints such as helpline, incident management reporting system, emails, etc. and respond to internal/external complaints of fraud, waste, or abuse and other violations or wrongdoing according to the compliance plan and policy requirements.
- Ensures investigation are conducted and completed as timely as possible.
- Collaborate and work closely with the Security Officer to ensure alignment between security and privacy compliance programs including policies, practices, and investigations.
- Report to and/or attend Board Executive Committee meetings and/or Board of Directors meeting at least quarterly and as directed by the CEO or warranted by Compliance responsibilities.
- Ensures periodic information privacy risk assessment/analysis, mitigation, and remediation.
- Coordinates with other relevant entity components (e.g., as applicable, Internal Audit, Risk, Quality, IT) to develop work plans for reviewing, monitoring, and auditing compliance risks.
- Ensures ongoing privacy monitoring activities in coordination with the organization’s other compliance and operational assessment functions.
- Ensures organization’s personnel and contractors complete training on compliance, privacy, and confidentiality.
- Works cooperatively with the Information Management Director and/or Recipient Rights Director and other applicable organization units in overseeing patient rights to inspect, amend, and restrict access to PHI when appropriate.
- Ensures all required breach determination, notification, and reporting processes under HIPAA and applicable rules and regulations are completed.
- Establish and administer a process for investigating and acting on privacy and security complaints.
- Works with HR to ensure consistent application of sanctions for compliance and privacy violations.
- Works with Network Manager to ensure consistent application of sanctions for compliance and privacy violations.
- Works with Recipient Rights Director to ensure consumer rights in terms of privacy and confidentiality are upheld and that reported violations are investigated, mitigated, recommend corrective action, and monitored as necessary.
- Initiates, facilitates, and promotes activities to foster information privacy awareness within the organization and related entities.
- Participate in monthly LRE Compliance Regional Operations Advisory Team (ROAT) and keep Chief Executive Officer (CEO), and others as appropriate, informed and up-to-date on compliance ROAT activities.
- Function as the conduit between the regional PIHP and OnPoint for all matters related to compliance and privacy.
- Update and maintain OnPoint’s Compliance plan and policies as needed to assure congruence with applicable internal and external requirements.
- Cooperate with external authorities (e.g., US Office for Civil Rights, state regulators) involved in reviews or investigations.
- Performs other duties as assigned.
Competencies
- Knowledgeable in Patient/Client privacy: Laws and regulations that are in place to protect privacy.
- Knowledgeable in Quality care: Laws and regulations are in place to ensure quality care.
- Knowledgeable in Healthcare integrity: Laws and regulations are in place to maintain the integrity of healthcare.
- Knowledgeable in Healthcare billing: Ensure claims, billing, and coding are accurate and in line with regulatory and audit requirements.
- Computers. Various software programs and applications, including Microsoft Office and Electronic Medical Records (EMR's). Office equipment including but not limited to fax machine, scanner, copy machine, calculator, printers, etc.
- Maintains consistent and regular attendance. Schedules time-off in advance.
- Encourages and supports co-workers.
- Maintains a positive outlook and strives to see the opportunity in all situations.
- Active participation in problem solving and continuous improvement activities.
- Effectively communicates with others and maintains a respectful and positive outlook at all times.
- Provides appropriate self, peer and 360 feedback to support the review process.
Supervisory responsibilities
Core Values
- Integrity
- Inclusivity
- Honor
- Equality
- Humility
- Innovation
- Teamwork
- Cultural Competence
Environment (Work, Physical, Travel)
- Work Environment – Environments can vary. Office environment. Travel by automobile to other locations within and outside of the County may be required.
- Physical Demands – Generally, performs sedentary work but must have the ability to lift up to 35 pounds. Occasional bending, stooping, kneeling, lifting. Ability to sit for extended periods of time.
Required education and experience
- Bachelor’s degree in a health and human services field plus 5 years of direct experience in compliance as a direct employee of a healthcare system or government public health agency, or 10 years of equivalent education and experience.
- CHC (Certified in Healthcare Compliance) and CHPC (Certified in Healthcare Privacy Compliance) certification or commitment to achieve certification within first year of employment.
- Strong investigative, problem solving, and analytical skills.
- Must possess excellent written and verbal communication skills.
- Must be familiar with state and federal regulations.
- Must be self-motivated and able to work independently.
Preferred education and experience
- Master’s degree in human services, Public or Health Administration preferred.
- 5 years of progressively responsible Compliance experience as a direct employee of a CMHSP.
- Lived experiences with mental illness/developmental disabilities/co-occurring disorders/substance use disorders.
Additional eligibility requirements
- Must possess a valid driver’s license, registration and proof of automobile insurance when operating County vehicles or operating personal vehicles in performance of job duties at any time. May provide own transportation for job related use, including transporting of individuals served, to and from meetings and activities at varying work locations throughout Allegan County.
Work authorization/security clearance requirements
- In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
EEO statement
OnPoint is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetic information, protected veteran status, sexual orientation, gender identity or expression, pregnancy, height, weight or marital status, or any other characteristic protected by federal, state or local laws.