Privacy and Compliance Officer; Repost
Listed on 2026-01-12
-
Healthcare
Privacy and Compliance Officer (Repost)
4 days ago Be among the first 25 applicants
Department Information
This position is open to current Colorado residents only.
Please note:
This recruitment may be used to fill multiple vacancies.
CDHSCareers
Most State of Colorado employees are eligible for a great benefit package! Please see the Supplemental Information section below for details!
Description Of Job
8-5 Monday through Friday
at least one in-person meeting per month. This is subject to change due to the BHA’s needs.
These working arrangements are subject to change.
This position is responsible for overseeing the BHA’s Privacy and Compliance areas. The purpose of the position is to enhance and protect the BHA’s vision, mission, and values by providing risk-based and objective assurance, advice, and insight to individual Offices within the BHA in regard to compliance with state and federal laws and regulations, as well as BHA policies and procedures, that govern privacy and other compliance areas.
This position administers a BHA-wide Privacy program that targets BHA divisions/office staff, business associates and trading partners (Example: OIT, HCPF, COAG, outside vendors stakeholders), and is designed so that staff are knowledgeable of BHA and legal requirements for protecting the privacy of confidential information and for instituting policies, procedures, forms and other materials that support this effort via training and enforcement.
Of The Position
- Provides technical assistance in establishing data protection policies and behaviors of staff and management throughout the organization, including interactions with other local, State, and federal agencies.
- Provides technical expertise regarding the BHA's implementation of HIPAA and other privacy/data protection/information legislation within the State and on a local level.
- Develops and maintains BHA privacy policies, procedures, and tools consistent with state and federal privacy statutes.
- Reviews and monitors (sometimes in conjunction with the Attorney General’s Office, OSC, Contracting Division, etc.) BHA business associate, data protection, security agreements for completeness and compliance with State and federal statutes and internal policy.
- Coordinates and works closely with BHA staff to improve compliance throughout the BHA.
- Reports to the U.S. Department of Health and Human Services Secretary concerning agency's level of compliance with standards and legislation mandates.
- Maintains logs and documentation of findings within the BHA as well as with division/office business associates, including compliance and non-compliance issues, along with recommendations for remediation and/or mitigation of non-compliance issues.
- Serves as point person in responding to breaches, specifically proper response, overseeing notifications, when appropriate, and communicating with the Attorney General’s office and the U.S. Department of Health and Human Services, as appropriate.
- Creates and conducts educational and ongoing awareness programs for the BHA workforce, including Divisional HIPAA liaisons as identified by Division Directors. Provides initial and ongoing training for all staff on privacy requirements based on State and federal laws that protect health information. Provides updated training as necessary based on changes in laws and/or BHA policies.
- Monitors to assure that employees complete required training. Answers employee questions. Evaluates current business practices to determine level of staff understanding and adjust training efforts to meet the needs of staff. Updates training modules as new are disseminated.
- Attends BHA and outside training offerings in order to keep current with the latest requirements and to share agency experiences that have enhanced the privacy program with other agencies.
- Regularly communicates with programs, BHA employees, and other agencies to ensure awareness and compliance with the latest information on BHA policies and procedures and state and federal law; potential vulnerabilities and risks; best practices in safeguarding protected information; and continually reinforcing the importance of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).