The Senior Privacy Specialist conducts, coordinates and oversees privacy investigations, analyzes automated system access reports, and reviews and responds to reports and inquiries to the Office of Compliance and Integrity. R esponsibilities include but are not limited to the following:
- Responsible for the intake, tracking, investigating, resolving, and documentation of all privacy inquiries, and complaints/investigations. Maintains all investigation notes and files in a contemporaneous, organized manner within the OCI incident reporting database. Strives to close all investigations and respond to all routine inquiries within OCI department standards and industry benchmarks. Escalates urgent issues to OCI leadership when necessary.
- Ensures the consistency and integrity of all risk analyses performed with respect to the HIPAA Breach Notification Rule in determining whether there is greater than a low probability of compromise in the event of an impermissible use of disclosure of protected health information. Drafts breach notification letters for review by HHC Privacy Officer.
- Audits access to protected health information (PHI) and personal information (PI) and recommends appropriate action necessary as a result of audit activities.
- Collaborates with key stakeholders in the development, drafting, and revision of training and education materials, policies and procedures, issuance of position papers, memos and documentation to disseminate applicable privacy requirements.
- Responsible for ensuring all required metric reporting goals are met by privacy specialists and in collaboration with others in the OCI department. This includes completion of privacy safeguard evaluations.
- Responsible for conducting privacy risk assessments, routine privacy monitoring, and privacy compliance reviews.
- Collaborates with leadership, key departments, and committees/structures to ensure the implementation, maintenance, enforcement, and an update of appropriate documentation (e.g. NPP, authorization forms, investigation forms, etc.) as needed in compliance with Federal laws, state laws and relevant accreditation standards.
- Maintain current knowledge of applicable federal and state laws and other regulations and accreditation standards, and monitor privacy standards and changes in regulations to ensure organizational adaptation and compliance.
Qualifications:Education: - Bachelor's degree required
- MBA, MHA, JD with major coursework in business administration, health care administration, or law preferred.
Experience: - A minimum of three (3) years of health care privacy experience, preferably in a large healthcare system setting or in a consulting capacity.
Licensure, Certification, Registration - Privacy or health information certifications (e.g., CIPP, CHPC, RHIA, RHIT) preferred (will be required to obtain a privacy certification within 180 days)