Join Our Team!
At Hill Physicians Medical Group, we're shaping the healthcare of the future : actively managed care that prevents disease, supports those with chronic conditions and anticipates the needs of our members.
Hill Physicians has much to offer prospective employees. We're regularly recognized as one of the "Best Places to Work in the Bay Area" and have been recognized as one of the "Healthiest Places to Work in the Bay Area." When you join our team, you're making a great choice for your professional career and your personal satisfaction.
We value and respect your race, ethnicity, gender identity, sexual orientation, age, religion, disabilities, experiences, perspectives, and other attributes. Our celebration of diversity and foundation of inclusion allows us to leverage our differences and capitalize on our similarities to better serve our communities. We do it because it's right!
Job Description
The Manager of Compliance and Privacy Program assists with the Compliance and Privacy Program Elements. The Manager provides support to the Compliance Officer gathering and maintaining information for the required elements of a compliance and privacy program and maintains timely and accurate internal and external compliance communications. Assume primary responsibility for the intake of Compliance FWA and Privacy incident reports including initial investigation, completion of risk assessment, response, reporting, escalation, and documentation of matters. Additionally, maintain clear and concise detail-level supporting documentation of departmental projects and corporate projects that impact the department in an orderly fashion. The Manager works with the Compliance Officer to verify that appropriate resources are allocated to complete projects on time and achieve service levels. The Manager assists staff with representing Compliance in cross-functional projects or Health Plan audits, Regulatory Templates / Letters, participating in meetings with other departments on Compliance and Privacy matters.
Essential Responsibilities
Corporate Compliance and Privacy Program
- Assist the Compliance / Privacy Officer with the Corporate Compliance and Privacy Program Elements.
- Maintain and update Compliance and Privacy Toolsincluding SAI360, SharePoint, databases, Excel workbooks, files, and foldersand prepare reports as required. Serve as the system administrator for SAI360, ensuring awareness of updates and the maintenance of the Policy, Privacy, and Compliance Modules. Provide support for the Audit and COI Modules as necessary. Keep Compliance Officer informed timely.
- Conduct a comprehensive review of Compliance and Privacy policies and procedures at least annually to ensure they remain current and aligned with regulatory requirements. Report to Compliance Officer all changes promptly.
- Promptly update, review, and maintain compliance and privacy playbooks and training materials. Report to Compliance Officer all changes promptly.
- Develop, update, manage, and coordinate the preparation of materials for Compliance and Privacy Program Committees and meetings, including agendas, data analysis reports, presentations, and minutes. Promptly gather and communicate essential information regarding Compliance or Privacy requirements to the Compliance Officer.
- Perform comprehensive research on complex questions to identify relevant regulatory or contractual obligations and promptly present the findings to the Compliance Officer.
- Collaborating with the Compliance / Privacy Officer and team lead coordinating project activities, identifying, documenting, and executing specific action items required for the effective implementation of process improvement initiatives. Design thorough test cases and scenarios to conduct testing and detect defects. Anticipate potential issues and develop alternative solutions while delivering timely updates to the Compliance Officer. Regularly review and monitor the issues log to confirm resolution of outstanding matters, reporting status to the Compliance Officer prior to solution deployment. Provide backup support to the team when necessary.
- Keep the Compliance / Privacy Office Project List up to date with all ongoing departmental projects. The list should include information such as the intended audience, project goals, project leader and team members, detailed next steps with deadlines, responsible personnel, and the completion date. Update this list before or after status meetings to reflect the latest status and upcoming actions. Present during Monday Morning weekly Team meeting.
- Promptly notify the Compliance or Privacy Officer of any potential compliance or privacy incidents to ensure proper coordination and remediation.
- Perform other Compliance or Privacy activities as assigned.
Compliance
Assumes primary responsibility for the initial screening, prompt investigation, and triage of FWA and other Compliance matters for PriMed, Hill Physicians Medical Group, Inc., their affiliates, and related parties. Conducts, coordinates and manages thorough investigations encompassing data collection, analysis, interviews, and report preparation. Report all potential incidents and resolution steps to be completed to Compliance / Privacy Officer immediately.Conduct, coordinate, and manage investigations of potential FWA or compliance incidents, including but not limited to monitoring and performing tasks for the Compliance Hotline and Compliance incident emails, using the GRC SAI360 Compliance Incident Management Tool. Perform tasks such as intake of report, categorization of internal folder systems, investigation, risk assessment, response, reporting, escalation, documentation, tracking. Keep Compliance / Privacy Officer informed timely.Perform comprehensive research, analysis, and evaluation of changes to applicable statutes, rules, regulations, and compliance standards pertaining to federal and state Compliance, Privacy, and Breach Notification requirements utilizing government sources, professional compliance organizations, and relevant industry literature. Prepare timely updates, reports, training documents, and detailed summaries that articulate the implications of both newly enacted and existing compliance obligations, ensuring they are available for review by the Compliance / Privacy Officer timely.Supervise, train staff, and perform investigations of potential FWA or compliance incidents. Processes include but not limited to monitoring and performing tasks for the Hotline and Compliance emails, utilization and maintaining the GRC SAI360 Compliance Incident Management Tool, initial intake of report, categorization / organization of internal folder systems, investigation of incident, completion of a risk assessment, response, reporting, escalation, documentation, tracking, trending, and reporting.Demonstrate proficiency in compliance delegation tasks and facilitate cross-training among team members. Diligently monitor assigned email days to ensure proper acknowledgments, effective handovers, and precise logging within SAI360.Perform assigned tasks for health plan delegation audits or government agency audits, including gather case files, policies and procedures, attestations, questionnaires, and other material as requested.Perform all Compliance assignments and requests timely and accurately utilizing HPMG Tools. Assists with coverage and perform other compliance duties as assigned.Privacy
Assumes primary responsibility for the initial screening, prompt investigation, and triage of HIPAA / HITECH and other Privacy matters for PriMed, Hill Physicians Medical Group, Inc., their affiliates, and related parties. Conducts, coordinates and manages thorough investigations encompassing data collection, analysis, interviews, and report preparation, as well as all required breach determination and notification processes under HIPAA and applicable state breach rules and requirements. Report all potential incidents and resolution steps to be completed to Compliance / Privacy Officer immediately.Conduct, coordinate, and manage privacy investigation activities with team members, including detailed logs of all allegations, information related to affected parties, investigation details, risk assessments, as well as all required breach determination and notification processes under HIPAA and applicable state breach rules and requirements. Report all potential incidents and resolution steps to be completed to Compliance / Privacy Officer immediately.Supervise, train staff, and perform investigations of potential privacy incidents. Processes include but not limited to monitoring and performing tasks for the Hotline and Privacy emails, utilization and maintaining the GRC SAI360 Privacy Incident Management Tool, initial intake of report, categorization / organization of internal folder systems, investigation of incident, completion of a risk assessment, response, reporting, escalation, documentation, tracking, trending, and reporting.Prepares, implements, maintains, and updates Privacy and Breach Notification policies and associated documentation; requests regular reviews from subject matter experts and informs stakeholders of any policy revisions. Develops and manages tracking systems to document compliance with relevant privacy and breach notification standards. Ensures the Compliance / Privacy Officer is kept promptly informed.Perform privacy program QA to ensure compliance with appropriate laws, regulations, and policy standards, and reviews areas previously audited to confirm proper corrective action or recommendation(s) have been implemented. Develop recommendations for improvement based on findings and conduct related ongoing privacy rule compliance monitoring activities in coordination with the organization's other compliance and operational assessment functions.Monitors patterns of inappropriate use and / or disclosure of Protected Health Information, and establishes an ongoing process to track / trend, investigate, and report inappropriate access and disclosure of Protected Health Information immediately to the Compliance / Privacy Officer.Collaborates with the Security team to ensure alignment between security and privacy compliance programs including policies, practices, investigations, and acts as a liaison to the Security team.On a continuous basis, develop training materials, identify target audiences, and deliver education and training to foster awareness and understanding of and promoting adherence to state and federal Privacy and Breach Notification requirements.Addresses privacy and breach notification inquiries. Handles privacy-related questions, comments, and complaints. Notifies Compliance Officer promptly.Assesses risk and plans for long range privacy and confidentiality compliance. Drafts all-staff communications to reinforce privacy best practices.