ADMINISTRATIVE PROGRAM MANAGER I Compliance and Privacy Manager
MHBE (Maryland Health Benefit Exchange) administers Maryland Health Connection, the state’s health insurance marketplace under the Affordable Care Act. We partner with the Maryland Department of Health, Maryland Insurance Administration, Department of Human Services, and stakeholders statewide to provide high-quality, affordable health coverage for all Marylanders.
About the role
Under the direction of MHBE’s Director of Compliance and Privacy, the Compliance and Privacy Manager assists in implementing and maintaining all facets of MHBE’s Compliance and Privacy programs. This includes auditing and monitoring activities, policy and procedure updates, fraud/waste/abuse investigations, record retention, contract negotiations, privacy incident management, and compliance reporting. The role also involves leading special projects as assigned.
Responsibilities
- Assist in developing and implementing MHBE’s Compliance and Privacy programs, incorporating corrective actions and new requirements into the Audit Control Plan, Privacy Program Plan, and Privacy Notice.
- Collaborate with the Director of Compliance and Privacy on annual internal reviews of MHBE departments and assist with preparation, coordination, and completion of external audits mandated by CCIIO, CMS, IRS, and the Maryland Office of Legislative Audits.
- Collaborate with IT Security and other departments to complete annual Privacy Impact Assessments (PIA) and Privacy Self-assessments, including Personally Identifiable Information (PII) Inventory assessments.
- Assist in developing, distributing, implementing, and tracking privacy and compliance training materials, forms, and documents, and support departments in reviewing, updating, and renewing policies and procedures.
- Lead and coordinate privacy incident reporting, investigations, risk mitigation, breach analyses, breach notifications, and corrective action plans for internal and external stakeholders, documenting records in the incident management system.
- Prepare reports by collecting, analyzing, and summarizing information from investigations, work plan submissions, and other compliance activities.
- Collaborate in the development, tracking, and maintenance of official records for Non-Exchange Entity Agreements (NEEAs), Data Use Agreements (DUAs), and Memorandum of Understandings (MOUs), focusing on compliance and privacy requirements.
- Coordinate with IT personnel to design, develop, and implement privacy requirements, checklists, and tools for new applications involving PII.
- Lead, develop, and coordinate implementation of Compliance and Privacy-related corrective action plans, ensuring proactive reviews of pending regulations.
- Serve as a resource for staff and management on compliance and privacy matters through meetings, discussions, and formal training.
- Maintain timely communication with the Director of Compliance and Privacy regarding reported or observed concerns.
- Stay current with applicable federal and state compliance and privacy laws and accreditation standards.
- Interact and communicate effectively with MHBE stakeholders while demonstrating high standards of conduct, ethics, objectivity, judgment, independence, and discretion.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree in any discipline from an accredited college or university.
- 2–5 years of verifiable experience in compliance (e.g., creating/updating policies, managing work plans, conducting audits) or 2–5 years of verifiable experience in data privacy.
- At least one year of experience in one or more of the following: supervision, overseeing unit operations, applying rules/regulations, or developing privacy-related policies/procedures.
- Clear and concise verbal and written communication skills, with the ability to tailor messages to the audience.
- Proficiency in Microsoft Office (Word, Excel, PowerPoint).
Candidates may substitute U.S. Armed Forces military service experience as a commissioned or non-commissioned officer involving staff work related to rules, regulations, policy, procedures, or unit operations on a year-for-year basis for the required education and experience.
Qualifications
- Master’s degree in healthcare or business administration or Juris Doctor (JD).
- Certification in Privacy or Healthcare Compliance (e.g., CIPP, CIPM, CIPT).
- Demonstrated ability to analyze issues, develop resolution plans, and implement solutions with a high degree of self-direction.
- Experience managing multiple priorities and projects with tight deadlines.
- Experience preparing technical/non-technical reports, presenting findings, conducting investigations, reviewing documentation, and managing cases.
- Strong interactive and leadership skills, with the ability to function in a team environment.
- Knowledge of federal, state, and local regulatory processes and healthcare/ethics laws (e.g., ACA, 45 CFR 155, ARC-AMPE, Maryland Ethics Law).
- Experience in developing, implementing, monitoring, or improving a Privacy Program, including data use agreements, compliance monitoring, and privacy incident management.
- 2+ years of experience with data inventory documentation, privacy impact assessments, and data mapping.
Benefits
This position offers the benefits package provided by the State of Maryland.
Note: The selected candidate will be subject to a pre-hire background check. Applications must include sufficient detail to demonstrate qualifications by the closing date. Successful candidates may be required to provide a writing sample as part of the interview process.