What are the responsibilities and job description for the Director of Compliance & Privacy Officer position at WellMed Optum Florida?
Director of Compliance & Privacy Officer
Location: Tampa, Florida (Hybrid)
Reports To: General Counsel, Compliance Officer & Chief Legal Officer
Position Summary
Seeking a Director of Compliance and Privacy Officer to manage the organization's day-to-day compliance operations and serve as the designated HIPAA Privacy Officer. This role does not serve as the organization's Compliance Officer. The Compliance Officer function is held by the General Counsel. This individual will execute and operationalize the compliance program under the direction of the Compliance Officer, managing regulatory risk across a 94-location primary care organization operating in the Medicare Advantage and value-based care space, with a dotted-line reporting relationship to the Board's Compliance Committee.
Key Responsibilities
Compliance Program Operations
- Execute and operationalize the compliance program consistent with OIG guidance, CMS requirements under 42 CFR 422.503, and the Federal Sentencing Guidelines, under the direction of the Compliance Officer
- Serve as the day-to-day compliance lead across all clinical and operational locations
- Develop and enforce compliance policies and procedures, including the Code of Conduct, FWA (fraud, waste, and abuse) protocols, and reporting mechanisms
- Manage the compliance hotline and investigate reports of potential violations, including conducting root cause analyses and recommending corrective actions to the Compliance Officer
- Lead internal monitoring and auditing activities to identify compliance risks before they become enforcement actions
- Prepare compliance reports for the Compliance Officer's presentation to the Board Compliance Committee and senior leadership on a quarterly basis
Privacy & HIPAA
- Serve as the organization's designated HIPAA Privacy Officer responsible for the privacy program across all covered entities
- Develop and maintain HIPAA policies, Notice of Privacy Practices, and Business Associate Agreement templates and tracking
- Oversee breach risk assessments, breach notifications, and OCR reporting obligations
- Manage patient rights requests (access, amendment, restriction, accounting of disclosures)
- Conduct and oversee periodic HIPAA risk assessments and coordinate remediation efforts
- Monitor and advise on state privacy laws, including Florida's health information privacy requirements
Regulatory & Government Programs
- Ensure compliance with CMS MA program requirements, including marketing, enrollment, grievances and appeals, and ODAG (Organization Determinations, Appeals, and Grievances)
- Oversee exclusion screening processes (OIG LEIE, SAM.gov, Florida AHCA) for employees, providers, and vendors
- Support CMS audit readiness, including RADV, program audits, and compliance program effectiveness reviews
- Monitor regulatory changes from CMS, OIG, AHCA, and other relevant agencies and translate them into operational action items
- Coordinate with the Compliance Officer and legal team on government investigations, subpoenas, and voluntary self-disclosures
Training & Culture
- Develop and deliver annual and ad hoc compliance and privacy training programs across all locations
- Manage the organization's Learning Management System (LMS) for compliance training tracking and documentation
- Foster a culture of compliance and ethical behavior through visible leadership, communication, and accessibility to frontline staff
Team & Vendor Management
- Build and manage the compliance team, including oversight of the HIM (Health Information Management) function and coordination with the Risk Manager and Licensing Specialist
- Evaluate, select, and manage compliance technology vendors (exclusion screening, incident reporting, policy management)
- Manage relationships with external compliance consultants and auditors as needed
Required Qualifications
- Bachelor's degree required; J.D., Master's in Health Administration, Public Health, or related field preferred
- Minimum 7 years of healthcare compliance experience, with at least 3 years in a leadership or director-level role
- Direct experience with Medicare Advantage, managed care, or value-based care compliance programs
- Deep working knowledge of HIPAA Privacy and Security Rules, including breach notification requirements
- Demonstrated experience building or significantly enhancing a compliance program (not just maintaining an inherited one)
- Fluency in federal healthcare fraud and abuse laws: False Claims Act, Anti-Kickback Statute, Stark Law, and applicable safe harbors and exceptions
- Strong investigation and analytical skills with the ability to manage sensitive matters with discretion
- Ability to communicate complex regulatory requirements in plain language to clinical and operational staff
Preferred Qualifications
- Certified in Healthcare Compliance (CHC) through HCCA
- Certified in Healthcare Privacy Compliance (CHPC) or CIPP/US designation
- In-house experience at a health plan, MSO, large provider group, or health system
- Experience with Florida-specific regulatory bodies: AHCA, OIR, DOH, and Florida Medicaid managed care
- Familiarity with D-SNP programs and dual-eligible compliance requirements
- Experience implementing or managing compliance technology platforms (Healthicity, Relias, SAI360, Compliance 360)
- Experience with Ethico or similar ethics and compliance hotline/case management platforms
- Proficiency with AI-powered compliance and legal tools