Compliance and Risk Specialist

METROPOLITAN PEDIATRICS LLCPortland, OR
$68,640 - $85,800Onsite

About The Position

The Compliance and Risk Specialist is responsible for monitoring organizational compliance with applicable governmental regulations related to the Administrative Simplification elements of the Health Insurance Portability and Accountability Act of 1996 (a.k.a. HIPAA). They will research available resources and coordinate implementation of this highly specialized and technical information with various clinical, administrative and support departments. A significant responsibility will include the coordination of the organization’s implementation of all HIPAA standards and practices. In addition, the Compliance and Risk Specialist will support clinical and security risk management within the organization.

Requirements

  • Bachelor's degree or equivalent work experience in a relevant field or industry preferred.
  • Certification from the International Compliance Association, AAPC, or another recognized compliance group required or ability to obtain certification within the first 90 days of hire.
  • CHC, CHPC, or CPCO preferred.
  • 1+ years of relevant work experience preferred.
  • Strong communication, presentation, and organizational skills.

Responsibilities

  • Monitor changes in HIPAA and related federal/state regulations.
  • Develop, update, and maintain HIPAA privacy and security policies, including our organizational Compliance Plan, ensuring alignment with current laws, regulations, and statutes.
  • Conduct assessments to identify vulnerabilities in handling protected health information (PHI).
  • Maintain knowledge and relationship with key third-party risk support organizations to understand and complete any documentation of clinical incidents or potential at-risk situations.
  • Collaborate with our IT teams and leaders to ensure completion of any identified security risk findings.
  • Collaborate with clinical and administrative teams to develop and optimize compliance, privacy, and security processes while promoting an understanding of the intricacies of regulatory requirements.
  • Stay up to date with HIPAA regulations and laws to ensure our organization minimizes risk through proper processes and workflows.
  • Build and maintain relationships with key third-party compliance team members, security personnel, and any legal counsel we might need.
  • Oversee HIPAA training for staff, including onboarding, periodic refreshers, and targeted training for high-risk departments.
  • Ensure employees understand their obligations under HIPAA and know how to respond to privacy/security incidents.
  • Provide education to staff and providers on best privacy and compliance practices, such as phishing awareness, workstation security, MyHealth proxy policy, and other privacy or security issues.
  • Maintain records of compliance and risk related committees including any activities, training, or policy updates.
  • Prepare reports for internal audits, external regulators, or risk committees.
  • Coordinate with clinical, administrative, IT, legal, and finance departments to implement HIPAA-compliant processes.
  • Work with information systems to ensure technical safeguards (e.g., encryption, access controls) meet HIPAA Security Rule requirements.
  • Develop and manage processes for patient access, amendment requests, accounting of disclosures, and restrictions on PHI use.
  • Serve as a resource for affiliates or other entities when compliance or risk questions arise.
  • Investigate all potential privacy or security breach events, coordinate and document findings and present this information to Compliance team members for outcomes and decisions.
  • Organize and summarize incident reports and report out summaries to applicable teams such as the Compliance team and the Peer Review committee.
  • Coordinate breach notifications and remediation efforts in compliance with HIPAA requirements.
  • Analyze, monitor, report and follow up on identified trends in incidents.
  • Always maintain confidentiality of sensitive patient and organizational information.
  • Display high standards of office conduct.
  • Actively participate in team development and collaborative processes.
  • Punctual, regular, timely, and dependable attendance.
  • Flexible with capacity to work in a fast-paced and changing environment.

Benefits

  • sign on bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service