The Compliance Officer will be familiar with risk management comfortable leading internal risk assessments and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks.
The candidate will be allowed to work remotely but will need to be onsite at short notice. There is a mandatory three week training onsite at the beginning of the engagement. Once all staff return to site the candidate will need to work onsite full time. The NC HIEA Compliance Officer will ensure that operations follow all relevant state and federal requirements for securely transacting health information via the HIE Network NC HealthConnex. The Compliance Officer will be familiar with risk management comfortable leading internal risk assessments and possess knowledge of HIPAA and NIST privacy and security requirements for health information networks. This position will work closely with the NC HIEA leadership team DIT legal counsel and DIT Privacy Team and DIT Security and Risk Management Team to ensure continual improvement of the NC HIEA s security and risk profile.
Responsibilities
- Assist with the development and implementation of a compliance program for the NC HIEA that includes preparation for HITRUST certification
- Create sound internal controls and monitor adherence to them
- Draft and revise policies
- Proactively audit processes practices and documents to identify weaknesses
- Evaluate activities to assess compliance risk
- Collaborate with external auditors and DIT Security Team when needed
- Set plans to manage a crisis or compliance violation
- Educate and train employees on regulations and industry practices
- Address employee concerns or questions on compliance
- Keep abreast of industry standards and business goals
Requirements
Proven experience as a Compliance Officer
Experience in risk management
Knowledge of HIPAA and NIST requirements
Familiarity with industry practices and professional standards
Excellent communication skills
Integrity And professional ethics
Attention To detail
Required/Desired Skills
Skill | Required /Desired | Amount | of Experience |
---|
Knowledge of privacy laws (state and federal such as HIPAA (preferred) PCI CJIS); proven risk management experience. | Required | 3 | Years |
Experience in creation of risk management strategies and policy development to handle data breaches and other incidents. | Required | 3 | Years |
Knowledge of NIST controls and experience with completing/conducting assessments; written and verbal communication. | Required | 3 | Years |
Strong conflict management skills in order to work with senior management to ensure security and data protection rules and regulations are in place. | Required | 3 | Years |
Knowledge of cybersecurity and privacy principles | Required | 3 | Years |
Ability to determine whether a security incident violates a privacy principle or legal standard requiring specific legal action. | Required | 3 | Years |
Ability to work across departments and business units to implement organization s privacy principles and programs. | Required | 3 | Years |
Ability to develop update and/or maintain standard operating procedures (SOPs). | Required | 3 | Years |
Ability to develop clear directions and instructional materials. | Required | 3 | Years |
Questions
No. | Question |
---|
Question1 | Absences greater than two weeks MUST be approved by CAI management in advance and contact information must be provided to CAI so that the resource can be reached during his or her absence. The Client has the right to dismiss the resource if he or she does not return to work by the agreed upon date. Do you accept this requirement |
Question2 | The candidate will be allowed to work remotely but will need to be onsite at short notice. There is a mandatory three week training onsite at the beginning of the engagement. Once all staff return to site the candidate will need to work onsite full time. Do you accept this requirement |
Question3 | Please list candidates email address |
Question4 | Please indicate how soon this candidate is available to start work. Vendors are encouraged to submit candidates that are available for the duration of the assignment. |
Question5 | Vendor must disclose to the agency if the candidate will be subcontracted at the time of submission. Do you accept this requirement |
Question6 | Vendor must notify the agency if any portion of the requirements listed in this task order is to be outsourced to other countries. Do you accept this requirement |
Question7 | Candidates submitted above the rate of will not be considered. Do you accept this requirement |
Question8 | Payment for all approved hours will be paid at the straight hourly rate regardless of the total hours worked by the engaged resource. It is the responsibility of the supplier to adhere to any applicable compensation laws including payment for overtime hours. Do you accept this requirement |
Question9 | Please confirm you have thoroughly validated and attest to the accuracy of the credentials listed throughout this candidates VectorVMS profile and resume pursuant to Section 5.2.5 of ITS009440. Do you confirm |
Question10 | Please list the city and state where the candidate is currently located. |
Employment Type
Full Time
Disclaimer:
Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via
contact us page.