Blue Cross and Blue Shield Association logo

Privacy Program Specialist, Consultant

    Highlights

    Requires a solid understanding of state and federal privacy laws, including HIPAA/HITECH, CMIA, and privacy-related consumer protections laws, such as the Telephone Consumer Protection Act (TCPA), as well as knowledge of Department of Health Care Services (DHCS) privacy requirements for Medi-Cal Managed Care Health Plans and Centers for Medicare or Medi-Cal and Medicaid (CMS) Medicare or Medi-Cal Managed Care Plans. The Privacy Program ensures that Blue Shield and its affiliated covered entities, including Blue Shield of California Promise Health Plan, are in compliance with state and federal privacy laws and regulations, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and California's Confidentiality of Medical Information Act (CMIA).

    Numbers & Facts

    LocationOakland, CA
    IndustryInsurance
    Company Size2,000 to 2,499 employees
    Websitehttps://www.bcbs.com/about-us/careers

    Description

    Your Role

    The Privacy Office is responsible for development, implementation, and oversight of Blue Shield's Privacy Program. The Privacy Program ensures that Blue Shield and its affiliated covered entities, including Blue Shield of California Promise Health Plan, are in compliance with state and federal privacy laws and regulations, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and California's Confidentiality of Medical Information Act (CMIA). The Privacy Program Specialist, Consultant reports to the Privacy Office Sr. Manager and plays an essential role in advancing and enforcing Blue Shield's Privacy Program.

    Your Knowledge and Experience

    Required

    • Requires a bachelor's degree or High School Diploma/GED and 4 years of additional relevant experience in lieu of a degree
    • Requires 7 years of prior relevant experience
    • Requires prior experience in healthcare privacy, cybersecurity incident management, investigative services, or another related field
    • Requires a solid understanding of state and federal privacy laws, including HIPAA/HITECH, CMIA, and privacy-related consumer protections laws, such as the Telephone Consumer Protection Act (TCPA), as well as knowledge of Department of Health Care Services (DHCS) privacy requirements for Medi-Cal Managed Care Health Plans and Centers for Medicare or Medi-Cal and Medicaid (CMS) Medicare or Medi-Cal Managed Care Plans
    • Requires excellent organizational skills and strong independent judgment, problem-solving, critical and analytical thinking skills, including an exceptional "moral compass" and work ethic
    • Requires ability to work collaboratively in a team, perform duties with minimal supervision, multi-task, and to deliver a quality work product in a highly regulated, demanding, and constantly changing corporate environment
    • Requires proficiency in Microsoft Word, Access, Excel, PowerPoint, and Outlook

    Preferred

    • Possesses extensive experience in directly handling investigations
    • Privacy healthcare-related experience that includes a familiarity with Privacy Impact Assessments and Data Protection Impact Assessments; auditing and monitoring; investigating, managing, and reporting privacy incidents; health information management
    • CIPP/US Certification or HCCA CHPC Certification
    • Experience and knowledge of compliance or privacy incident management software

    Hybrid

    This role requires employees to be in-office based on our hybrid workplace model, balancing purposeful in-person collaboration with flexibility. For most teams, this means coming into the office two days each week.

    Employees living more than 50 miles from an office location will work with their manager to determine in-office time based on business need.

    Your Work

    In this role, you will:

    • Be responsible for the oversight of Blue Shield''s compliance with state and federal privacy laws, including the privacy component of HIPAA and HITECH
    • The majority of this role involves leading assigned privacy investigations, timely and accurately document case files, direct investigations into root cause analysis, address mitigation, and work with impacted business units to develop and complete corrective action for remediation and to minimize risk of recurrence
    • Consult with internal clients to review and provide privacy guidance about proposed projects and initiatives and serve as a privacy subject matter expert
    • Respond to privacy-related requests and inquiries
    • Develop and assist with the implementation of workforce privacy training programs, privacy policies, desk-level procedures, resource guides, job aids, and other educational tools
    • Act as a liaison with regulatory enforcement agencies to address technical assistance letters, investigation compliance reviews, audits, and other related reviews
    • Assist, evaluate, and determine appropriateness of ad hoc requests from internal clients to disclose protected health information (PHI) to third parties and/or to allow third parties access to, or use of, Blue Shield PHI
    • Perform other duties as assigned

    Your Work

    In this role, you will:

    • Be responsible for the oversight of Blue Shield''s compliance with state and federal privacy laws, including the privacy component of HIPAA and HITECH
    • The majority of this role involves leading assigned privacy investigations, timely and accurately document case files, direct investigations into root cause analysis, address mitigation, and work with impacted business units to develop and complete corrective action for remediation and to minimize risk of recurrence
    • Consult with internal clients to review and provide privacy guidance about proposed projects and initiatives and serve as a privacy subject matter expert
    • Respond to privacy-related requests and inquiries
    • Develop and assist with the implementation of workforce privacy training programs, privacy policies, desk-level procedures, resource guides, job aids, and other educational tools
    • Act as a liaison with regulatory enforcement agencies to address technical assistance letters, investigation compliance reviews, audits, and other related reviews
    • Assist, evaluate, and determine appropriateness of ad hoc requests from internal clients to disclose protected health information (PHI) to third parties and/or to allow third parties access to, or use of, Blue Shield PHI
    • Perform other duties as assigned

    About Company

    At the Blue Cross and Blue Shield Association (BCBSA), we provide business strategy, technical support and consulting expertise to 36 Blue Cross and Blue Shield companies across the nation, employing more than 1,000 of the best strategic thinkers in the industry. We are a Brand manager that sets quality control standards for the 36 independent companies that use the Blue Cross and Blue Shield Brands, and we serve as a trade association that represents these Blue companies. It is through our involvement that the Blues companies share a united vision and strategy while also benefiting from the local strength of all member companies.

    Similar Jobs

    See more jobs