Your Role
The Privacy Office is responsible for development, implementation, and oversight of Blue Shield’s Privacy Program. The Privacy Program ensures that Blue Shield and its affiliated covered entities, including Blue Shield of California Promise Health Plan, are in compliance with state and federal privacy laws and regulations, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and California’s Confidentiality of Medical Information Act (CMIA). The Privacy Program Specialist, Consultant reports to the Privacy Office Sr. Manager and plays an essential role in advancing and enforcing Blue Shield’s Privacy Program.Your Work
In this role, you will:
Be responsible for the oversight of Blue Shield's compliance with state and federal privacy laws, including the privacy component of HIPAA and HITECHRespond to privacy complaints and incidents reported to the Privacy Office, lead assigned privacy investigations, timely and accurately document case files, direct investigations into root cause analysis, address mitigation, and work with impacted business units to develop and complete corrective action for remediation and to minimize risk of recurrenceConsult with internal clients to review and provide privacy guidance about proposed projects and initiativesand serve as a privacy subject matter expertRespond to privacy-related requestsand inquiriesDevelop and assist with the implementation of workforce privacy training programs, privacy policies, desk-level procedures, resource guides, job aids, and other educational toolsAct as a liaison with regulatory enforcement agencies to address technical assistance letters, investigation compliance reviews, audits, and other related reviewsAssist, evaluate, and determine appropriateness of ad hoc requests from internal clients to disclose protected health information (PHI) to third parties and/or to allow third parties access to, or use of, Blue Shield PHIYour Knowledge and Experience
Requires a bachelor's degree or equivalent experienceRequires at least 7 years of prior relevant experienceRequires prior experience in healthcare privacy, cybersecurity incident management, investigative services, or another related fieldRequires a solid understanding of state and federal privacy laws, including HIPAA/HITECH, CMIA, and privacy-related consumer protections laws, such as the Telephone Consumer Protection Act (TCPA), as well as knowledge of Department of Health Care Services (DHCS) privacy requirements for Medi-Cal Managed Care Health Plans and Centers for Medicare or Medi-Cal and Medicaid (CMS) Medicare or Medi-Cal Managed Care PlansExcellent organizational skills and strong independent judgment, problem-solving, critical and analytical thinking skills, including an exceptional “moral compass” and work ethicAbility to work collaboratively in a team, perform duties with minimal supervision, multi-task, and to deliver a quality work product in a highly regulated, demanding, and constantly changing corporate environmentProficient in Microsoft Word, Access, Excel, PowerPoint, and OutlookPrivacy healthcare-related experience that includes a familiarity with Privacy Impact Assessments and Data Protection Impact Assessments; auditing and monitoring; investigating, managing, and reporting privacy incidents; health information managementCIPP/US Certification or HCCA CHPC CertificationpreferredExperience and knowledge of compliance or privacy incident management software