16 open roles
Director of Risk and Compliance
$82k to $120k
Job description
Job title Director of Risk and Compliance Reports to Chief Operations Officer Status Exempt (Salaried $82,000 - $120,000) Position Overview: The Director of Risk and Compliance is responsible for developing, implementing, and monitoring the risk management and compliance program of the organization. This role involves working closely with executive leadership and employees to identify potential risks, ensuring compliance with regulatory requirements, and fostering a culture of ethical behavior and risk awareness across the organization.
The Director serves as a key organizational resource for risk-based decision-making, helping leaders and employees understand potential exposure, evaluate the likelihood and impact of adverse events, establish appropriate controls, and develop strategies to reduce or manage risk. The Director is expected to recognize emerging risks, connect individual incidents or concerns to broader organizational trends, and translate risk information into actionable recommendations for executive leadership and the Board of Directors.
The Director reports to the Chief Operations Officer (COO) and will also provide regular updates or correspondence to the Chief Executive Officer, executive leadership, committees, and Board of Directors. The Director serves as the HIPAA Privacy Officer and leads the annual Federal Tort Claim Act application process. The Director is responsible for overseeing the development, implementation, and monitoring of risk management strategies related to health information management.
This role ensures that the organization complies with legal and regulatory requirements, protects the integrity and confidentiality of patient data, and mitigates risks associated with the management of health information. The position directly supervises the health information and medical records (HIMS) department.
Duties and Responsibilities
Risk Management: Develop and implement a comprehensive risk management strategy aligned with the organization's strategic plan and goals, including business, clinical care, patient safety, facility, and operational risks. Establish a consistent framework for identifying, assessing, prioritizing, mitigating, monitoring, and reporting organizational risks.
Provide risk-based recommendations to leadership regarding the prioritization and escalation of significant risks based on likelihood, severity, impact, and organizational exposure. Collaborate with leaders and employees to conduct regular risk assessments and audits to identify areas of potential exposure and emerging risks.
Collaborate with clinical leaders and employees to assess and mitigate risks related to patient safety and quality of care. Establish risk mitigation plans and monitor their effectiveness. Establish and maintain processes for reporting, investigating, escalating, and managing adverse events, patient safety concerns, incidents, and near misses.
Evaluate incidents and near misses for immediate risk, potential systemic risk, and opportunities for improvement. Develop and maintain organizational crisis, emergency preparedness, and business continuity plans. Lead the organization's response to significant risk events, emergencies, and incidents, with a focus on patient safety and continuity of operations.
Lead or coordinate response to data breaches, privacy incidents, and other health information risks. Conduct root cause analyses to identify contributing factors, systemic risks, and opportunities for improvement. Develop and monitor corrective and preventive actions to mitigate risk and prevent recurrence. Monitor claims, complaints, incidents, and adverse events for trends and opportunities to reduce organizational and patient safety risk.
Monitor and coordinate the management of claims, potential claims, and litigation-related risks in collaboration with appropriate internal and external resources. Monitor incident trends and emerging risks and use findings to strengthen policies, processes, and risk mitigation strategies Facilitate regular reporting to executive leadership, applicable committees, and the Board of Directors regarding significant risks, trends, mitigation strategies, and areas requiring leadership attention.
Risk Management in Health Information Management: Develop and implement risk management strategies specifically related to health information management. Identify, assess, and mitigate risks related to the collection, storage, processing, use, disclosure, retention, and sharing of patient health information. Establish and maintain controls to mitigate risks and ensure the security and confidentiality of health information.
Evaluate risks associated with health information systems, workflows, vendors, technology, access controls, data sharing, and information disclosure. Monitor and evaluate the effectiveness of risk management strategies and adjust as necessary. Lead or coordinate responses to significant health information incidents, including privacy or security incidents and potential data breaches.
Compliance Oversight: Serve as the HIPAA Privacy Officer. Ensure the organization complies with all relevant laws, regulations, and industry standards. Ensure that health information management practices comply with relevant healthcare regulations, including HIPAA, HITECH, HRSA, CMS, and other federal and state laws. Serve as the lead for the Federal Tort Claims Act (FTCA) risk management annual application.
Develop and maintain compliance policies and procedures. Assess and monitor risks associated with vendors, contractors, business associates, and other third parties, including contractual, regulatory, privacy, security, and operational risks. Monitor changes in laws and regulations that could impact on the organization and update policies accordingly.
Conduct regular compliance audits and investigations. Provide training and education for employees on compliance-related topics. Monitor the Peer Review policy and procedures in collaboration with clinical leaders. Manage and respond to regulatory inquiries, inspections, and site visits as applicable. Policy Development: Develop and implement policies and procedures that promote ethical behavior, regulatory compliance, patient safety, and effective risk management.
Develop, implement, and maintain policies and procedures related to health information management, patient safety, incident response, and risk mitigation. Ensure policies and procedures are effectively communicated and supported through appropriate training and education. Oversee employee adherence to the organization's policies and procedures.
Evaluate the effectiveness of internal controls and recommend modifications when controls are insufficient or risks change. Risk, Compliance, and Quality Improvement: Continuously evaluate the effectiveness of the organization's risk management and compliance programs. Establish meaningful performance indicators and measures to monitor risk, compliance, patient safety, incident management, and HIMS performance.
Analyze data and trends to identify emerging risks and opportunities for improvement. Use data, incident trends, audit findings, claims, complaints, and other information to prioritize risk management activities. Monitor completion and effectiveness of corrective action plans. Identify opportunities to strengthen internal controls, processes, communication, and accountability.
Stay current on emerging risks, regulatory developments, industry standards, and best practices in healthcare risk management, compliance, patient safety, and health information management. Health Information Management (HIMS) Management: Directly supervise and provide leadership to the HIMS department. Ensure HIMS operations incorporate appropriate risk management, compliance, privacy, security, and information governance practices.
Provide guidance and support to HIMS staff regarding regulatory requirements, risk identification, documentation, privacy, disclosure, and information management. Monitor HIMS processes for potential compliance, operational, patient safety, and information-related risks. Establish appropriate controls and monitoring processes to reduce risk associated with medical records and health information.
Collaborate with IT, Legal, Compliance resources, and external vendors or consultants to address risks involving health information. Ensure HIMS performance measures and risk indicators are monitored and reported appropriately.
Qualifications
Bachelor’s degree in Healthcare Administration, Public Health, Business Administration, Nursing, Risk Management, Quality Management, Law, or a related field; or equivalent combination of education, certification, and relevant experience (e.g., Certified Risk Manager (CRM), Certified Compliance & Ethics Professional (CCEP), etc.)
Healthcare risk management, compliance, or patient safety certification preferred (e.g., Certified Professional in Healthcare Risk Management [CPHRM], Certified Risk Manager [CRM], Certified Professional in Healthcare Quality [CPHQ], Certified Compliance & Ethics Professional [CCEP], or comparable certification). Minimum of 5–7 years of progressive experience in healthcare risk management, patient safety, quality, compliance, or a related healthcare leadership function, including at least 3 years in a management or leadership role.
Demonstrated experience in healthcare risk management, patient safety, incident/event management, risk assessment, and development of strategies to prevent patient harm and organizational loss. Strong knowledge of applicable healthcare regulatory and legal requirements, including HRSA, HIPAA, FTCA, CMS, OSHA, and applicable federal and state requirements.
In-depth knowledge of enterprise risk management principles and the ability to identify, assess, prioritize, mitigate, monitor, and communicate clinical, operational, financial, regulatory, facility, and patient safety risks. Demonstrated knowledge and experience with incident/event reporting, investigation, root cause analysis, corrective and preventive action (CAPA), risk assessments, and patient safety improvement methodologies.
Working knowledge of professional liability, medical malpractice, claims management, insurance, FTCA, and strategies for reducing organizational and patient safety risk. Knowledge of healthcare accreditation and regulatory standards and the ability to interpret requirements and translate them into practical organizational processes and controls.
Strong analytical, organizational, critical-thinking, problem-solving, and communication skills, with the ability to evaluate complex situations, identify risks, and make sound recommendations. Demonstrated ability to collaborate effectively with clinical, operational, quality, compliance, HR, finance, IT, and executive leadership to identify and mitigate risk and improve patient safety.
High ethical standards, sound professional judgment, and the ability to maintain confidentiality and appropriately handle sensitive information. Patient-centered and service-oriented approach that promotes the safety, satisfaction, dignity, and well-being of patients, families, employees, and those we are called to serve.
Ability to remain calm and exercise sound judgment in high-pressure or sensitive situations, including adverse events, complaints, investigations, and regulatory matters. Strong computer skills and proficiency with Microsoft Office and systems used for risk, quality, compliance, incident reporting, and data analysis. Demonstrated initiative, accountability, flexibility, attention to detail, and ability to work independently while contributing effectively to a collaborative team environment.
Maintains regular and predictable attendance. Physical Requirements & Working Conditions: Moves equipment weighing up to 50 pounds. Moves throughout the building to meet with employees, patients, or visitors. Must be able to remain in a stationary position during shift. Ability to read, write, and speak English. Frequent communication with patients about their experience at the health center.
Must be able to exchange accurate information in these situations. Operate a computer and other office equipment, such as tablets, scanners, printers, and phones. Adhere to process protocol or procedures. This role requires movement throughout the building day or multiple locations during the day. This role may be exposed to infections and contagious diseases.
This role is subject to interruptions. This role requires management of personnel and procedures in a high stress & high paced environment. This role completes tasks that are performed in close physical proximity to other people. This role requires working indoors in environmentally controlled conditions. Details: Schedule: Full-time exempt.
Hours Mon-Friday 8:00AM-5:00PM (as needed) (average 40 hours/week) Office Location: Heartland at Panda Pediatrics Schedule may be altered by supervisor(s) as needed to allow for completion of expected duties of the position. Work from home eligibility – up to 10% FT in a calendar year.
Description copied from Heartland Community Health Center's careers page. Read the full posting before you apply.
More jobs at Heartland Community Health Center
Pediatric Psychiatric Registered Nurse (RN)
Heartland Community Health Center· Lawrence, KS· $64k – $85kRegistered Dental Hygienist (Part-Time)
Heartland Community Health Center· Lawrence, KS· $84k – $110kRegistered Dental Hygienist (Full-Time)
Heartland Community Health Center· Lawrence, KS· $84k – $110kDental Assistant
Heartland Community Health Center· Lawrence, KS· $37k – $52kReferral Coordinator
Heartland Community Health Center· Lawrence, KS· $40k – $52k