Job Requirements Supports and is committed to operating an effective Corporate Compliance and Privacy Program. Works under general direction to perform ongoing activities related to developing, implementing, maintaining, and adhering to policies and procedures in compliance with federal, state, and local laws and regulations. Under general supervision, works closely with key stakeholders to implement elements of the Corporate Compliance and Privacy Program to ensure compliance with existing and new federal and state laws and regulations affecting the University of Maryland Medical System (UMMS). Responsibilities include representing assigned policy and procedure development areas, performing privacy and compliance risk assessments, education and training, and auditing and monitoring. Responsible for facilitating the development and maintenance of the Compliance and Privacy Work Plan. Works collectively with hospital management and other personnel to ensure that Corporate Compliance and Privacy Program initiatives are implemented across UMMS.
The following statements describe the general nature and level of work being performed by people assignedย
to this classification.ย They are not to be construed as an exhaustive list of all job duties performed byย
personnel so classified.ย
- Accountable for the Compliance Program at Member Organizations (MOs).ย Directs assignedย MO-specific risk assessments related to HIPAA and privacy compliance. Conducts riskย assessment analysis identifying high, medium, and low risks. Works with UMMS System andย Physician Compliance Leadership to compile Executive reports on Member Organizations'ย aggregate risk assessment findings and recommendations. Communicates risks to both technicalย and non-technical stakeholders.ย
- Lead assigned Member Organization Privacy Monitoring Program and ensure ongoing monitoringย of inappropriate/unauthorized access and disclosures through the use of electronic recordย monitoring applications and features (e.g., Protenus, Break-the-Glass, etc.) and data lossย prevention applications in accordance with the Health Information Technology for Economic andย Clinical Health Act and HIPAA Privacy Rule. Perform trend analyses.ย Prepare summary reportsย for Executive Leadership on privacy monitoring activities.ย
- Serves as an expert resource in interpreting and providing guidance to departmentalย representatives on developing policies specific to their departmental needs.ย ย
- Oversees development and dissemination of compliance policies and procedures.ย
- Leads the development and approves use of monitoring and auditing tools for assigned areas.ย ย Reviews reporting to ensure adherence to compliance and privacy.ย Recommends actions based onย self-monitoring results to ensure that programs and procedures follow regulatory requirements.ย ย
- Directs local compliance and privacy auditing and monitoring activities.ย Reviews findings asย required for compliance with various regulatory guidelines.ย ย Identifies and escalates issues toย executive leadership.ย Ensure compliance monitoring reports are updated.ย
- Accountable for assuring timely completion of all management action plans resulting fromย compliance-related findings by internal audit for assigned MOs.ย
- Provides ongoing compliance and privacy education including regular training sessions andย special topic training.ย ย
- Develops activities to foster compliance and privacy awareness through various modes ofย publicity (publications, newsletters, fairs, Intranet, etc.).ย
- Maintains local systems to solicit, evaluate and respond to complaints, problems, and issuesย through all means of communication. Coordinates and oversees investigations, responses toย violations, and corrective actions for reports of alleged fraud and noncompliance.ย
- Ensures all escalated complaints for supported MOs are are resolved timely and satisfactorily.ย
- Based on investigation report findings, reviews recommendations and approves adjustmentsย necessary for achieving set objectives.ย
- Utilizes IT systems/tools in managing and coordinating data investigations.ย
- Participates in UMMS and Member Organizations' Compliance Committees as the leadย compliance and privacy representative. Sets compliance committee agenda. Chairs the assignedย Member Organization quarterly compliance committee and ensures the meeting packet isย complete and submitted to stakeholders within five calendar days before the meeting.ย
- Monitors and keeps up-to-date with laws, regulations, standards, and guidelines.ย Communicatesย and distributes information relating to updates to the appropriate stakeholders.ย
- Prepares reports to meet the needs of local and Corporate executive leadership and the Audit andย Compliance Committee of the Board of Directors.ย
- Collaborates with the Director, Physician and Ambulatory Network for pertinent physician-relatedย matters.ย
- Perform other duties as assigned.ย
Work Experience Required
- Bachelor's degree or an equivalent combination of education and experience is required. Master's degree preferred.
- Ten 10 years of related compliance and privacy experience with a background in healthcare regulatory issues, including general familiarity with hospital billing, is required. Four (4) years of experience in healthcare or regulatory fields is preferred.
- Certified in Healthcare Compliance or other professional compliance certification (or achieve certification by 12 months from hire date.)
- Experience and working knowledge of Corporate Compliance, Audit, Legal, Privacy, or Information Security. Experience with case investigations management and compliance hotline management preferred.ย ย
Employment Type: FULL_TIME