MHBE is accepting applications for an Administrative Program Manager I/Compliance and Privacy Manager.
The Maryland Health Benefit Exchange is responsible for the administration of Maryland Health Connection, the State's health insurance marketplace, under the Patient Protection and Affordable Care Act of 2010 (ACA).
MHBE works with the Maryland Department of Health, Maryland Insurance Administration, Department of Human Services, and stakeholders statewide.
Our Vision: High-quality, affordable health coverage for all Marylanders.
Mission Statement: We improve the health and well-being of Marylanders by connecting them with high-quality, affordable health coverage through innovation, technology, and customer service.
Values: Diverse & Inclusive, Innovative, Collaborative, Ethical
19
Baltimore City, Maryland
Under the direction of MHBE’s Director of Compliance and Privacy, the
Compliance and Privacy Manager is responsible for assisting with the implementation and maintenance of all facets of MHBE’s Compliance and Privacy programs including, but are not limited to, auditing and monitoring activities (departmental and business partner assessments by MHBE and State and Federal assessments of MHBE); overseeing the review and update of agency-wide policies and procedures; recording, investigating and resolving Fraud, Waste and Abuse (FWA) concerns; overseeing the agency-wide record retention procedure; collaborating across departments in negotiating / finalizing Non-Exchange Entity Agreements (NEEAs), Data Use Agreements (DUAs) and Memorandum of Understandings (MOUs), and maintaining a repository for NEEAs and DUAs; leading and coordinating privacy incident reporting, investigations, mitigations, breach risk analysis and corrective actions; performing Privacy Impact Assessments and self-assessment of compliance with Acceptable Risk Controls for ACA, Medicaid and Partner Entities (ARC-AMPE); preparing requested reports related to Compliance and Privacy by collecting, analyzing and summarizing data obtained through investigations, work plan submissions and other activities; developing and updating the annual compliance and privacy training; maintaining current knowledge of applicable laws and regulations pertaining to Compliance and Privacy; maintaining timely communication with the Director of Compliance and Privacy on concerns that have been reported and/or observed; and maintaining effective communications with MHBE stakeholders (internally and externally) while consistently demonstrating a high standard of conduct, ethics and objectivity.
The Compliance and Privacy Manager may also lead special projects assigned by the Director of Compliance and Privacy.
- Assist in the development and implementation of MHBE’s Compliance and Privacy programs by incorporating corrective actions and new requirements into Audit Control Plan, Privacy Program Plan and Privacy Notice.
- Collaborate with the Director of Compliance and Privacy in conducting annual internal reviews of MHBE departments and assist with preparation, coordination and completion of external audits of MHBE as mandated by Centers for Consumer Information and Insurance Oversight (CCIIO), Centers for Medicaid and Medicare Services (CMS), the Internal Revenue Service, and the Maryland Office of Legislative Audits.
- Additionally, collaborate with IT Security, and other departments, to complete the annual Privacy Impact Assessment (PIA) and Privacy Self-assessments. As a part of the PIA, assist in performing annual and ongoing Personally Identifiable Information Inventory assessments, in collaboration with IT Security, to ensure PII inventory is complete and maintained so as to minimize access to, use of, and disclosure of consumer PII (inputs and outputs) to only that amount which is required for individuals to complete their job functions, within and across the Exchange.
- Assist with the development, distribution, implementation and tracking of privacy and compliance training materials, forms and documents, and assist departments across the agency for review, update, renewal and dissemination of departmental policies and procedures.
- Actively lead and coordinate privacy incident reporting, investigations, risk mitigation, breach analyses, breach notifications, and corrective action plans for internal and external stakeholders, along with properly documenting records in the incident management system, keeping the logging current and reporting incident statistics as needed.
- Prepare requested reports by collecting, analyzing and summarizing relevant information obtained through investigations, work plan submissions and other privacy and compliance activities.
- Collaborate in the development, tracking and maintenance, as applicable, of all official records regarding due diligence and compliance for MHBE Non-Exchange Entities Agreements (NEEAs) / Data Use Agreements (DUAs) / Memorandum of Understanding (with focus on Compliance and Privacy requirements) with contractors, State agencies, and other entities to meet Medicaid, CHIP and other state and federal benefit programs and privacy compliance.
- Coordinate with IT personnel in the design, development, and/or implementation of privacy requirements, checklists and/or tools to be used in new applications regarding uses or disclosures of personally identifiable information.
- Lead, develop and coordinate implementation of Compliance and Privacy related corrective action plans ensuring proactive reviews of pending regulations and their integration into the Plans.
- Be a resource for staff and management in compliance and privacy related matters through meetings, discussions, and formal training.
- Maintain timely communication with the Director of Compliance and Privacy regarding compliance and privacy concerns that have been reported and/or observed.
- Maintain current knowledge of applicable federal and state compliance and privacy laws and accreditation standards.
- Effectively interact and communicate with MHBE stakeholders while consistently demonstrating a high standard of conduct, ethics, objectivity, judgment, independence and discretion.
- Other duties as assigned.
Bachelor's degree in any discipline from an accredited college or university; and
Compliance: 2-5 years of verifiable experience in compliance (such as creating and updating policies & procedures and experience creating and managing work plans with a strong attention to detail); recording, investigating, tracking and resolving cases; and audit experience (such as coordinating, conducting, overseeing or supporting an audit); and/or
Privacy: 2-5 years of verifiable experience in Data Privacy. One year of this experience must have involved one or more of the following: supervision, overseeing and coordinating the general operations of a unit, applying rules and regulations, or exercising responsibility for the development of tasks related to a privacy program such as policies or procedures.
Clear and concise articulation in verbal and written communications and active listening with messages tailored to the audience; and proficiency in Microsoft Office (Word, Excel, and PowerPoint)
Candidates may substitute U.S. Armed Forces military service experience as a commissioned or non commissioned officer involving staff work related to the administration of rules, regulations, policy, procedures and processes, or overseeing or coordinating unit operations or functioning as a staff assistant to a higher ranking commissioned officer on a year-for-year basis for the required education and experience.
Preferred Qualifications
A Masters Degree in healthcare or business administration or Juris of Doctor (JD).
Certification in Privacy or Healthcare Compliance (CIPP, CIPM, CIPT and/or related certifications a plus).
A. Compliance:
- Demonstrated ability to engage with a high degree of self-direction in analyzing issues,developing plans to resolve the issues, and implementing the resolution
- Must be able to manage multiple priorities and projects with tight deadlines
- Experience with preparing technical and non-technical reports, presenting findings, conducting investigations, reviewing and analyzing documentation, and managing cases
- Outstanding interactive and leadership skills, and the ability to function in a team environment
- Strong understanding of federal, state, and local regulatory processes and Knowledge of current healthcare and ethics laws/regulations (e.g. The Patient Protection andAffordable Care Act (ACA), 45 CFR 155 Privacy and IT Security, 45 CFR 155 ExchangeEstablishment Standards, ARC-AMPE, Md. Code Ann., State Gov't §§ 15-101 - Ethics Law)
B. Privacy:
- Experience in developing, implementing, monitoring and/or improving a Privacy Program such as:
- Developing data use agreements
- Monitoring compliance with privacy regulations
- Overseeing privacy incident management
- Overseeing and coordinating the general operations of a unit
- Applying rules and regulations
- Exercising responsibility for the development of policies or procedures
- 2+ years of experience with data inventory documentation, privacy impact assessments, and data mapping
Preference will be given to applicants who possess these preferred qualification(s). Include clear and specific information on your application regarding your qualifications.
Please note that the candidate selected for hire will be subject to the successful completion of a pre-hire background check.
Please make sure that you provide sufficient information on your application to show that you meet the qualifications for this recruitment.
All information concerning your qualifications must be submitted by the closing date. We will not consider information submitted after this date.
Successful candidates will be ranked as Best Qualified, Better Qualified, or Qualified and placed on the eligible (employment) list for at least one year.
Candidates selected for interview may be required to provide a writing sample for review and evaluation as part of the competitive recruitment process.
STATE OF MARYLAND BENEFITS
Resumes will not be accepted in lieu of completing the online or paper application.
Applications must be received no later than the close of business on the closing date.
As an equal opportunity employer, Maryland is committed to recruiting, retaining, and promoting employees who are reflective of the State's diversity.
People with disabilities and bilingual candidates are encouraged to apply.
We thank you our veterans for their service to our country and encourage them to apply.
Appropriate accommodations for individuals with disabilities are available upon request by calling MD TTY Relay Service.
This employer participates in E-Verify and will provide the Federal government with your Form 1-9 information to confirm that you are authorized to work in the U.S.
Employers can only use E-Verify once you have accepted a job offer and completed the Form 1-9.
If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact the Department of Homeland Security (OHS) or Social Security Administration (SSA) so you can begin to resolve the issues before the employer can take any employment action against you.
For education obtained outside the U.S., a copy of the equivalent American education as determined by a foreign credential evaluation service must be provided prior to hire.
For questions regarding this recruitment, please contact the DBM Recruitment and Examination Division at
[email protected] or 410-767-4850, MD TTY Relay Service 1-800-735-2258.