Overview
This role is for a General Counsel & Chief Compliance and Privacy Officer within the senior leadership team. The position reports to the General Counsel of the organization and its affiliate groups. It is an exempt status role.
The organization is a national third-party administrator specializing in self-funded health plan solutions with over 44 years of industry experience. It serves clients across diverse industries by providing customized health plan strategies that manage costs and risks while enhancing the health insurance experience for members.
Responsibilities
- Lead the development, implementation, and ongoing monitoring of legal, compliance, and privacy programs.
- Analyze requests for disclosure of protected health information (PHI) from clients, vendors, and third parties; issue and negotiate privacy-related agreements such as Business Associate Agreements and Non-Disclosure Agreements; maintain an agreement database.
- Develop, review, update, and maintain privacy-focused policies, procedures, processes, and programs; stay current on applicable privacy laws and regulations; advise the organization on legal and regulatory privacy requirements.
- Develop, review, update, and maintain compliance-focused policies, procedures, processes, and programs to meet accreditation standards; maintain knowledge of relevant laws, regulations, and accreditation requirements; advise on compliance adherence.
- Manage the creation and delivery of legal, compliance, and privacy training programs; update training materials; provide specialized education to mitigate legal, privacy, compliance, and accreditation risks.
- Establish and chair a Compliance Oversight Committee; provide regular reports on privacy and compliance initiatives to senior management; recommend improvements to policies and programs to mitigate risk.
- Coordinate and review all legal workflows involving external counsel, including collaboration with Human Resources; manage outside counsel relationships and billing.
- Conduct or participate in annual privacy, security, and compliance risk analyses and ongoing monitoring.
- Participate in internal and external audits related to privacy, security, accreditation, and compliance; oversee corrective action implementation.
- Receive, track, document, investigate, and take action on reports of potential privacy or compliance incidents or complaints; manage incident reporting as required by legal, accreditation, or contractual obligations.
- Review, draft, and negotiate all contractual agreements.
- Serve as a key advisor on internal legal, compliance, accreditation, and privacy matters.
- Perform additional duties and projects requiring legal, compliance, accreditation, or privacy expertise as assigned by senior leadership.
Requirements
Education
- Bachelor’s degree and Juris Doctor (JD) required.
- Certifications such as CIPP, CIPM, CHC, or CHPC are a plus.
Licensure
- Admission to the Bar in one or more states where the organization operates.
Experience
- Minimum of 7 years of experience in healthcare privacy, legal, and compliance matters.
- Experience with Utilization Review Accreditation Commission matters is a plus.
- Experience with Service Organization Controls (SOC) reporting and audits is a plus.
Skills and Attributes
- Resilient, collaborative, flexible, and innovative.
Working Environment and Physical Demands
- Moderate noise level.
- Occasional lifting or moving of up to 20 pounds.
- Vision requirements include close, distance, peripheral vision, depth perception, and ability to adjust focus.
- Regularly required to sit, walk, speak, or hear.
- Frequently required to use hands, feel or handle items, and reach with hands and arms.
- Occasionally required to stand.
Reasonable Accommodation
Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.
Equal Employment Opportunity
The organization is an equal opportunity employer committed to diversity and inclusion.