Privacy Officer
![]() | |
![]() United States, Nebraska, Lincoln | |
![]() | |
GENERAL SUMMARY: Responsible for the direction and oversight of organizational matters governing privacy and confidentiality of patient, employee, student, provider and business information. Ensures organizational compliance with applicable statutory and regulatory requirements pertaining to the subject of privacy. Frequently interacts with patients, employees, leaders, medical staff, vendors, service providers, consultants, contractors, attorneys and regulators. Serves as Bryan Health's designated "Privacy Officer" required under the Federal Health Insurance and Portability and Accountability Act (HIPAA) 164.530 (a). Supports all Bryan Health entity's privacy activities. PRINCIPAL JOB FUNCTIONS: 1. *Commits to the mission, vision, beliefs and consistently demonstrates our core values. 2. *Directs the compliance and oversight of confidentiality and privacy-related policies, procedures, and guidelines; serves as the primary point of contact for privacy-related matters within Bryan Health. 3. *Establishes and chairs the appropriate governance and advisory teams to identify and maintain policies and procedures for information management and privacy across the organization. 4. *Develops structure and processes to maintain compliance with HIPAA and Health Information for Economic and Clinical Health Act (HITECH) regulations and requirements for security and privacy as they relate to the organization and its contractual relationships. 5. *Works closely with other Bryan Health leadership and department personnel to maintain privacy, confidentiality and compliance throughout the organization. 6. *Communicates awareness and understanding of privacy practices throughout Bryan Health. Guides the development of education and training processes to include assisting department leaders in establishing and maintaining local processes. 7. *Develops a process for reporting and investigating potential confidentiality and privacy violations and facilitates performance improvement initiatives regarding these subjects. 8. *Collaborates with the IT Team to lead the evaluation and recommendation of new technologies and counter measures against threats to privacy and confidentiality and safe, reliable information management functions. 9. Provides assistance to affiliates as directed by the Corporate Compliance Office. 10. Participates with national or regional organizations that promulgate, recommend and/or enforce guidelines and standards regarding information security, confidentiality and privacy, especially as it pertains to the organization. 11. Maintains professional growth and development through seminars, workshops, and professional affiliations to keep abreast of latest trends in field of expertise. 12. Participates in meetings, committees and department projects as assigned. 13. Performs other related projects and duties as assigned. (Essential Job functions are marked with an asterisk "*". Refer to the Job Description Guide for the definition of essential and non-essential job functions.) Attach Addendum for positions with slightly different roles or work-specific differences as needed. REQUIRED KNOWLEDGE, SKILLS AND ABILITIES: 1. Knowledge of local, state and federal regulations concerning privacy and confidentiality, including an in-depth knowledge of HIPAA, HITECH and other privacy regulations. 2. Knowledge of computer software applications relevant to work functions. 3. Knowledge of healthcare financial, clinical and ancillary processes and their associated applications. 4. Ability to communicate effectively both verbally and in writing. 5. Ability to perform crucial conversations with desired outcomes. 6. Ability to effectively interact with patients, employees, leaders, medical staff, vendors, service providers, consultants, contractors, attorneys and regulators. 7. Ability to solve problems and engage independent critical thinking skills. 8. Ability to maintain confidentiality relevant to sensitive information. 9. Ability to analyze problems, identify needs and priorities and implement effective work strategies. 10. Ability to maintain regular and punctual attendance. EDUCATION AND EXPERIENCE: Bachelor's degree in healthcare, health information management, information technology, legal or business required. Five (5) years progressive experience in privacy or related experience required. Experience conducting privacy audits and investigations required. Strong understanding of healthcare operations and privacy processes required. OTHER CREDENTIALS / CERTIFICATIONS: Certification in healthcare privacy is highly desirable and required within two (2) years of hire. PHYSICAL REQUIREMENTS: (Physical Requirements are based on federal criteria and assigned by Human Resources upon review of the Principal Job Functions.) (DOT)-Characterized as sedentary work requiring exertion up to 10 pounds of force occasionally and/or a negligible amount of force frequently to lift, carry, push, pull, or otherwise move objects, including the human body. Under the Nebraska Radiation Control Act governing the Gamma Knife, employees in this job description are required to be deemed trustworthy and reliable. The information required includes identity verification, a background check, employment and education history. |