Knoxville Hospital and Clinics strive to be your healthcare destination, building on compassion and innovation. We are committed to faithfully providing exceptional healthcare. The values we hold true are Teamwork, Innovation, Compassion, Integrity, Service, and People-Centered.
The Compliance, Risk, and Privacy Manager is responsible for the development, implementation, maintenance, and continuous improvement of Knoxville Hospital & Clinics’ compliance, privacy, risk management, and regulatory readiness programs. This position serves as the organization’s HIPAA Privacy Officer and provides enterprise risk management activities, compliance auditing and monitoring, regulatory preparedness, and continuous survey readiness.
The Compliance, Risk, and Privacy Manager collaborates with leadership, medical staff, department directors, and the Board of Trustees to ensure compliance with federal and state laws, Critical Access Hospital Conditions of Participation, Iowa Department of Inspections, Appeals, and Licensing requirements, HIPAA regulations, accreditation standards, and organizational policies. The position reports to the Chief Operating Officer and maintains independent access to senior leadership and the Board when necessary to fulfill compliance responsibilities.
Essential Functions
- Possesses proven oral and written communication skills.
- Knowledgeable in the use of Microsoft Word, Excel, and PowerPoint.
- Maintains an effective working relationship with internal and external customers.
- Serves as a role model with regard to the organization’s culture of safety and standards of behavior.
- Possesses high moral and ethical character. Independent, objective, detail-oriented, and analytical.
- Identifies learning needs and provide educational sessions for all hospital personnel in the areas of compliance, privacy, risk management, patient safety, and regulatory survey preparedness.
- Facilitates implementation of evidence-based practices.
- Ensures that policies, procedures, and plans for the compliance, risk, privacy, and accreditation programs are current and remain relevant.
- Participates in internal and external projects associated with compliance, risk, privacy, and accreditation.
- Facilitates hospital and medical staff committees, as assigned.
- Maintains direct access to the Chief Operating Officer, Chief Executive Officer, Compliance Committee, and Board of Trustees to report significant compliance, privacy, regulatory, or risk concerns when necessary.
- Ensures ongoing compliance with accreditation standards associated with medical errors and patient safety.
- Maintains and revises policies, procedures, and practices for the general operation of the compliance program and its related activities to help prevent illegal, unethical or improper hospital conduct.
- Oversees compliance reporting systems, including hotline activities, investigations, and follow-up actions. Collaborates with leadership regarding identified concerns, corrective actions, and regulatory reporting obligations.
- Serves as in-house counsel for senior management regarding compliance uncertainties.
- Coordinates compliance risk assessments and annual compliance work plans.
- Knowledgeable in healthcare risk management and patient safety standards and initiatives.
- Performs risk assessment, prevention, identification, and control activities.
- Maintains Incident/Occurrence reporting system. Follows up on individual incident reports as needed. Provides aggregate reports to appropriate people and committees.
- Actively participates in the investigation and evaluation of hospital claims or potential claims, and other activities related to the legal system.
- Directs the investigation and evaluation of hospital claims.
- Knowledgeable and experienced in information privacy laws, access, release of information and release control activities.
- Responds promptly to detected HIPAA privacy offenses, coordinating with appropriate department managers the timely development and implementation of corrective action plans and the reporting of findings to appropriate individuals- including any necessary governmental reporting.
- Maintains current knowledge of applicable federal and state privacy laws and accreditation standards to ensure organizational adaptation and compliance.
- Coordinates accreditation standards throughout the hospital. Compiles information for credentialing requests.
- Maintains continuous survey readiness through tracers, mock surveys, document reviews, rounding, and staff education.
- Tracks regulatory findings, develops corrective action plans, and monitors completion and sustainability of corrective actions.
- Assist in the coordination and compliance of currently received grants
- Coordinate the application of new grants and work with administration on meeting necessary requirements for future grants
Job Requirements
Required Qualifications
- Bachelor’s degree in healthcare administration, nursing, business administration, health information management, public health, healthcare compliance, or related field.
- Minimum three years of progressively responsible experience in healthcare compliance, regulatory affairs, risk management, privacy, quality, patient safety, or related healthcare leadership role.
- Working knowledge of Critical Access Hospital Conditions of Participation.
- Working knowledge of Iowa healthcare regulatory requirements.
- Knowledge of HIPAA Privacy Rule, healthcare compliance programs, risk management principles, and healthcare regulations.
- Demonstrated experience conducting investigations, audits, risk assessments, and regulatory preparedness activities.
- Completes all annual competency training and maintain license and/or certification
This is a Full-time position and is eligible for benefits for medical, dental, vision, flexible spending accounts, retirement plan with company match of up to 6%, accrued hours for vacation and sick time, paid holidays, and company benefits for employee life, employee AD&D, short term and long-term disability.
