waypointjobs

Paycom

Compliance and Privacy Program Lead

omaha, NE

Check who can apply and the requirements below before continuing.

This job is closed

Applications are no longer available for this announcement. Explore current related opportunities below.

Job description

Position SummaryThe Compliance and Privacy Program Lead serves as the day-to-day owner of Detego Health's compliance and privacy program. This role is responsible for designing, implementing, operating, measuring, and continually improving compliance and privacy processes across the organization in a healthcare third party administrator environment.The immediate first-year priority is reliable privacy operations and a working investigations and corrective action process, including individual rights request handling, privacy incident and breach response, and compliance investigation intake through closure. The metrics, monitoring, training, and audit readiness scope build from that foundation as the program matures.The successful candidate will lead privacy and compliance investigations, support regulatory readiness, maintain program documentation and evidence, coordinate corrective actions, manage privacy and compliance reporting, and work closely with Legal, Security, Enterprise Risk, Operations, Cost Containment, Human Resources, vendors, and business stakeholders.This is a hands-on operational role. Success is measured by whether compliance and privacy processes function effectively, risks are identified and addressed, investigations are completed, regulatory obligations are met, and leadership has clear visibility into program performance. The candidate must be able to identify risk, make practical recommendations, escalate material concerns, and operate with limited supervision.Key ResponsibilitiesCompliance and Privacy InvestigationsConduct, document, and manage compliance and privacy investigations from intake through closureConduct investigations arising from confidential reporting channels, policy violations, regulatory concerns, and compliance mattersEscalate to and coordinate with Legal when a matter carries litigation, privilege, or material regulatory exposure, and conduct legal directed investigations under that directionPerform root cause analysisTrack corrective actions to completionMaintain investigation files and supporting evidencePrivacy Program OperationsOperate privacy processes for individual rights requests, privacy concerns, incident response, breach analysis, and documentationMaintain the Record of Processing Activities and related data inventories as living artifacts that match actual business operationsConduct privacy assessments for new processes, technologies, vendors, and AI related use cases, including PHI use, minimum necessary, retention, transparency, and human oversightCompliance Program OperationsMonitor compliance obligations and regulatory requirementsAssist departments in implementing compliance controls and corrective actionsSupport compliance reviews and targeted monitoring activitiesConduct and document periodic compliance risk assessments and assist in the development of mitigation plansConduct periodic compliance and privacy program effectiveness assessments and recommend improvementsOperate the compliance intake channel and manage resulting cases to closureTraining and AwarenessDevelop and deliver compliance and privacy education programsMaintain new hire and annual training requirementsDevelop awareness materials, guidance documents, FAQs, alerts, and compliance communicationsGovernance, Metrics, and ReportingEstablish and maintain compliance and privacy metricsDevelop dashboards and leadership reportingTrack investigation trends, corrective actions, training completion, privacy incidents, compliance concerns, policy acknowledgments, and other program indicatorsPresent findings and recommendations to leadershipAudit and Regulatory ReadinessMaintain organized evidence repositoriesSupport HIPAA, SOC 2, URAC, client audits, and regulatory reviewsCoordinate document requests and responsesEmployee Acknowledgment and DisclaimerI acknowledge that I have received, reviewed, and understand this Job Description. I understand that this document is intended to describe the general nature, essential functions, responsibilities, qualifications, and expectations of the position.I recognize that this Job Description is not intended to be a comprehensive list of all duties, responsibilities, or qualifications associated with the role. The Company reserves the right to modify, assign, or remove job duties and responsibilities at any time to meet business needs.I understand that this Job Description does not constitute a contract of employment, express or implied, and does not alter the at-will nature of my employment. Employment may be terminated by either the employee or the Company at any time, with or without notice, and with or without cause, subject to applicable law.My signature below acknowledges that I have reviewed and understand the contents of this Job Description and have had the opportunity to ask questions regarding my role and responsibilities.My signature does not certify that I am able to perform every duty listed in this Job Description; rather, it acknowledges my understanding of the position's responsibilities and expectations, which may be performed with or without reasonable accommodation, as applicable.Employee Name: ______________________________________Employee Signature: ___________________________________Date: ________________________________________________Five or more years of healthcare compliance, privacy, investigations, audit, regulatory affairs, risk, or related experienceStrong knowledge of the HIPAA Privacy Rule, the HIPAA Breach Notification Rule, and healthcare regulatory complianceExperience conducting investigations and managing corrective actions through to closureExperience developing and operating compliance or privacy programs, processes, or controls, not only drafting policyExperience creating metrics, dashboards, reports, or compliance monitoring activitiesStrong written and verbal communication skillsAbility to operate independently, escalate clearly, and influence stakeholders across the organizationCHC or CHPC strongly preferred on the compliance sideCIPP/US strongly preferred on the privacy sideCIPM, CCEP, or a similar certification is a plusA candidate without a certification should offset it with a demonstrable operating track record and be willing to obtain a relevant certification within 12 monthsHealthcare TPA, health plan, managed care, or healthcare services experienceExperience with SharePoint, Power Automate, Vanta, BitSight, or similar governance tools

#J-18808-Ljbffr

Worksite address

omaha, NE, 68197, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Explore related searches

Current related jobs