Chief Compliance Officer & Chief Privacy Officer / Job Req 990161477
16 hours ago
Alameda
Hybrid Applicants must be a California resident as of their first day of employment and must reside within a 120-mile radius of the Alliance's office in Alameda, CA. Principal Responsibilities The Chief Compliance Officer & Chief Privacy Officer (CCO/CPO) is responsible for the development, implementation, and oversight of all activities related to the Alliance's adherence to the laws, regulations and policies that govern its business, with specific emphasis on Medicare, Medi-Cal, and commercial programs. The CCO/CPO leads the organization's Enterprise Risk Management (ERM) program following ISO 31000 and COSO frameworks to identify, assess, and mitigate risks across the enterprise. The CCO/CPO is responsible for the identification and organization of information and resources related to compliance requirements and policies; for the communication and training on the importance of compliance in general; and for the development of policies, procedures and standards related to the compliance program. The CCO/CPO reports to the Chief Executive Officer (CEO) and the Board of Governors. Compliance Program & Enterprise Risk Management • Update, implement, document, and maintain the Alliance's compliance program, updating annually to ensure accessibility, compliance with applicable laws, and continuity., • Develop, implement, and oversee the ERM program following ISO 31000 and COSO principles, establishing a systematic approach to identifying, analyzing, and managing risks across the organization., • Develop and execute a Medicare-specific compliance work plan that adheres to CMS requirements, including risk assessments, monitoring, and auditing., • Develop an annual work plan in cooperation with the Compliance Committee that provides ongoing development and implementation of the compliance program across all lines of business., • Establish and maintain an enterprise risk register that identifies, categorizes, and prioritizes risks in alignment with ISO or COSO integrated framework., • Facilitate regular enterprise risk assessments using established ISO methodologies and prepare reports on the organization's risk profile., • Set Compliance Committee agendas and develop reports of Compliance Committee findings and actions on a routine basis., • Chair the Enterprise Risk Management Committee and coordinate cross-functional risk management activities., • Coordinate resources to ensure the ongoing effectiveness of the compliance program., • Present periodic reports and an annual evaluation on the operation of the compliance program and ERM activities to the Board of Governors and senior management, including an annual work plan that identifies areas of risk with specific attention to Medicare program risk areas., • Hire and manage compliance department staff, including specialized Medicare compliance personnel and risk management professionals., • Manage the compliance department's administrative duties, including supervising support staff, organizing and maintaining compliance files, and preparing necessary reports on activities., • Represent the Alliance as the primary contact for federal, state, and regulatory bodies on compliance matters, preparing information, organizing materials, and overseeing all filings, compliance audits, and site visits for applicable agencies., • Coordinate with department directors, managers, legal counsel and the Human Resource Department as necessary for the execution of the compliance program and ERM initiatives., • Coordinate with the Chief Security Officer on matters involving privacy and security breaches, investigations, and reporting. Policies, Procedures and Standards • In a timely fashion, update and distribute applicable policy and procedures with current compliance information, along with notification and/or training on the effect or implication of such policy or procedure on the Alliance or on a particular department., • Develop and maintain the ERM policy and framework in accordance with ISO 31000 and COSO ERM principles., • Establish risk appetite statements and risk tolerance thresholds for key risk categories in partnership with executive leadership and the Board., • Ensure alignment between Medicare, Medi-Cal, and commercial program compliance activities and requirements., • Implement standardized risk assessment methodologies across the organization following ISO principles., • Identify, assess, and report on areas of risk for the Alliance and with the appropriate staff of various departments and develop policies and procedures to ensure compliance with federal, state, and local laws, with specific attention to Medicare regulations and CMS guidance. Education and Training • Assist internal departments in establishing, maintaining, and updating programs to educate and train managers and other employees regarding applicable state and federal compliance requirements, including HIPAA, and to regularly monitor compliance with those requirements., • Monitor and identify state and federal regulatory changes that impact the Alliance, and provide education in conjunction with senior management to employees, agents and contractors on implementing necessary policy or process changes to comply with all applicable regulations and contracts., • Develop, implement, and maintain appropriate training and education for Alliance employees, the Board of Governors, providers and members regarding the compliance plan and the Alliance's commitment to compliance., • Develop and deliver enterprise risk management training for employees at all levels, with specialized training for risk owners and senior leadership., • Develop and implement specialized Medicare compliance training for staff, leadership, and board members, including fraud, waste, and abuse prevention. Effective Lines of Communication • In coordination with the Human Resources Department, develop and communicate a confidential process and an open-door policy for all employees to seek guidance on compliance questions or concerns and to report suspected violations of the Company Code of Conduct, its policies and procedures, and/or violation of law or regulations., • Establish and maintain communication channels for reporting enterprise risks, near-misses, and risk incidents., • Ensure employees are informed of the Alliance's non-retaliation policy and collaborate with HR to implement it appropriately., • Maintain and operate the compliance hotline and other mechanisms to receive reports of alleged compliance violations, including potential Medicare fraud, waste, and abuse., • Formalize and monitor a system to enable employees to report non-compliance without fear of retribution, ensuring the system is adequately publicized and investigations are promptly conducted., • Communicate the compliance program's code of conduct, policies, and procedures in a practical manner to all employees through regular training and education programs., • Communicate responses/actions to compliance reports to senior managers, the compliance committee, and the Board of Governors., • Lead coordination with HIPAA, privacy, and security risk assessment activities., • Establish productive working relationships with all Alliance departments and employees to facilitate operation of the compliance program, including education, training, compliance, auditing, and reporting., • Escalate privacy and regulatory matters to the CEO in a timely manner. Enforcing Standards • Coordinate with HR to ensure compliance objectives are incorporated into hiring, evaluation, investigation, and discipline practices., • Publicize the consequences of non-compliance by educating employees on disciplinary actions that may be taken, up to and including termination., • Formalize and monitor a system to enable employees to report non-compliance without fear of retribution, ensuring prompt investigation and response., • Establish and maintain key risk indicators (KRIs) and key performance indicators (KPIs) for monitoring risk management effectiveness., • Implement a consistent methodology for tracking and reporting on risk treatment plans and their effectiveness. Monitor, Track and Audit • Assist departments in compliance identifying, prioritizing, and undertaking monitoring and auditing activities in line with the annual compliance work plan., • Lead in the coordination with applicable departments and agencies to develop audit procedures and conduct internal and external audits., • Oversee Medicare program audits, including readiness for CMS program audits and responses to audit findings., • Conduct regular enterprise-wide risk assessments using COSO and ISO methodologies to identify emerging risks and evaluate control effectiveness., • Develop and ensure internal controls are capable of preventing and detecting significant instances or patterns of illegal, unethical, or improper conduct., • Assist department managers in establishing routine audit and reporting procedures according to compliance requirements; in the event of non-compliance, work with managers to establish corrective action plans and follow up until compliance is restored., • Conduct routine reviews of the OIG's "List of Excluded Individuals/Entities" to determine if employees, third parties, or providers have been excluded from federal health care programs., • Direct Medicare data validation activities to ensure accuracy of data submitted to CMS., • Develop and maintain risk control matrices that document key risks and associated controls across the organization., • Conduct control effectiveness testing and facilitate control self-assessments in alignment with COSO principles. Investigation and Corrective Action • Coordinate with legal counsel, conducting or authorizing and overseeing investigations of matters requiring investigation under the compliance program., • Develop detailed corrective action plans that clearly identify the corrective action steps required, timeframes, and individuals responsible., • Work with the appropriate department director or manager to coordinate implementation of corrective action plans., • Implement a structured risk response process that includes risk acceptance, mitigation, transfer, or avoidance strategies in accordance with ISO 31000., • Coordinate with senior management and legal counsel to communicate with all federal, state, and regulatory bodies on issues of compliance, including reporting of compliance audits, fraud or abuse, patient privacy, grievances, and other non-compliance issues., • Ensure timely self-reporting of identified Medicare compliance issues to CMS as required., • Monitor the implementation and effectiveness of risk mitigation activities through established metrics and reporting mechanisms. Essential Functions of the Job • Update, develop, implement, document, and maintain an organization-wide compliance program as necessary., • Update, develop, implement, and maintain organizational policies, procedures, and standards., • Coordinate and initiate internal audits., • Provide compliance education and training to staff., • Monitor, track, and audit the compliance program, identify risks, and ensure departmental compliance on an ongoing basis., • Initiate investigations and corrective action plans. Physical Requirements • Constant and close visual work at desk or computer., • Constant sitting and working at desk., • Constant data entry using keyboard and/or mouse., • Frequent use of telephone headset., • Frequent verbal and written communication with staff and other business associates by telephone, correspondence, or in person., • Frequent lifting of folders and various other objects weighing between 0 and 30 lbs., • Frequent walking and standing., • Occasional driving of automobiles. Number of Employees Supervised: 3–5 Minimum Qualifications Education or Training Equivalent To: • Bachelor's degree required., • Master's degree with emphasis in business, health administration, or related field preferred., • Medicare compliance certification (CHC, CCEP, or similar) preferred., • Enterprise Risk Management certification (CRMA, CRISC, or similar) preferred. Minimum Years of Additional Related Experience: • Twelve (12) years' experience in federal and/or state regulatory compliance., • Five (5) years in compliance and/or risk management roles at the management level in managed health care or insurance industry., • Twelve (12) years' health plan management experience., • Experience with Medicare Advantage and/or Part D program compliance preferred., • Experience implementing, overseeing or managing ERM programs following ISO 31000 or COSO frameworks preferred. Special Qualifications (Skills, Abilities, License) • Specialized training in federal regulatory compliance and/or corporate risk., • Demonstrated knowledge of ISO 31000 risk management principles and ISO or COSO Enterprise Risk Management Framework., • Experience in using managed care concepts within the public sector health delivery systems. Excellent oral and written communication skills, with emphasis on effective education, training and reporting., • Inquisitive and analytical problem solver with initiative and ability to work independently., • Excellent interpersonal skills and ability to perform effectively with members of different departments as a team., • Ability to effectively present and represent the Alliance's interests externally with regulators., • Excellent computer analysis and research skills., • Ability to read, analyze and interpret professional journals, technical procedures, governmental regulations and legal documents., • Ability to understand and discuss detail, but also to develop and manage high-level plans and strategies., • Strong influencing skills and perseverance in investigation., • Demonstrates high integrity and excellent judgment., • Proven ability to maintain an effective professional liaison with a Board of Governors., • Extensive experience with public assistance programs and public agencies., • Experience with various computer system software, including Windows, Microsoft Word, Excel, Outlook and PowerPoint. Salary Range: $305,697.60 – $458,556.80 annually The Alliance is an equal opportunity employer and makes all employment decisions on the basis of merit and business necessity. We strive to have the best-qualified person in every job. The Alliance prohibits unlawful discrimination against any employee or applicant for employment based on race, color, religious creed, sex, gender, transgender status, age, sexual orientation, national origin, ethnicity, citizenship, ancestry, religion, marital status, familial status, status as a victim of domestic violence, assault or stalking, military service/veteran status, physical or mental disability, genetic information, medical condition, employees requesting accommodation of a disability or religious belief, political affiliation or activities, or any other status protected by federal, state, or local laws. #J-18808-Ljbffr