Director of Privacy and ROI
VIA Health Partners · Charlotte, NC · 4 wk ago
ManagementFull-time
Essential Functions
- Lead the organization’s HIPAA privacy program through policy and procedure development, risk assessments, audits, and training in coordination with leadership and HIPAA Security Officer.
- Manage all HIPAA patient rights, safeguards, and regulatory allowances, including patient access requests, amendment requests, accounting of disclosure issues, and disclosure disputes, escalating to leadership, legal where interpretation of law or organizational risk is involved.
- Oversee all disclosures and manage ROI procedures across all branches and service lines, including reviewing and validating documentation supporting authority to request, receive, or authorize disclosure of PHI.
- Act as Subject Matter Expert for all related legal documentation such as HCPOA, guardianships, executorship, letters of administration, and other personal representative documentation as covered under HIPAA or applicable state law.
- Maintain complete, audit-ready documentation of all requests, legal basis for disclosure, approvals, denials, redactions, deadlines, and final release actions, including accounting disclosures, patient access processes, and documentation of investigations and program activity.
- Partner with Compliance, HIM, CIO, Security, Clinical Software, IT and Operations to support policy administration, risk reduction, and technology modernization, including review of AI-enabled or automated workflows that may affect PHI, disclosure practices, or documentation integrity.
- Ensure lawful release practices, authorization sufficiency, representative documentation, and documentation retention requirements are upheld by partnering with branch level leadership, Business Office Managers, social workers, and HIM for development of SOPs for identified low risk, high volume requests for letters, forms containing PHI and requiring authorization.
- Support policy administration, risk reduction, and technology modernization, including review of AI-enabled or automated workflows that may affect PHI, disclosure practices, or documentation integrity.
- Oversee privacy impact, AI-related risk, and process controls around digital tools, especially when PHI or clinical documentation is involved.
- Coordinate with branch level leadership, Business Office Managers, social workers, and HIM for development of SOPs for identified low risk, high volume requests for letters, forms containing PHI and requiring authorization.
- Ensure all medical record retention, storage, and destruction and all associated documentation are handled appropriately.
Qualifications
- Minimum Qualifications: Bachelor’s degree in Health Information Management, Healthcare Administration, Public Health, Business, Legal Studies, or related field; minimum of 5 years or progressively responsible experience in at least one of the following: privacy/compliance operations, release of information, HIM, healthcare paralegal work or healthcare regulatory operations; working knowledge of HIPAA Privacy Rule, personal representative standards, and healthcare record confidentiality requirements; experience using EHR/EMR systems, document management systems, disclosure logs, and Microsoft Office tools.
- Prior experience in healthcare legal operations, record subpoena processing, privacy operations, and legal document review; Hospice, palliative, home health, or post-acute experience preferred.
- Preferred Certification: healthcare privacy/HIPAA/HIM compliance (HPOC, CHPS, CHPSE, RHIT, RHIA, CHC, CHPC).