Compliance, HIPAA, and Risk Management Officer

About RiverPeak Health

RiverPeak Health is a locally owned, locally governed nonprofit organization dedicated to restoring access to high-quality care in Fremont County, Wyoming. Our new hospital and clinic, currently under construction in Riverton, reflect years of community vision, volunteer leadership, and collaboration to bring essential medical services back to the region and ensure patients can receive excellent care close to home.

Guided by a local governing board and supported through an affiliation with Billings Clinic, RiverPeak Health is building a sustainable, community-centered healthcare organization designed to serve the long-term needs of the area. As we prepare to open, we are building a team committed to shaping a culture centered on patients, teamwork, and community service.

Department: Compliance / Risk Management

Reports to: Chief Executive Officer (CEO)

Employment Type: Full-Time

Location: This position requires regular on-site presence and may require occasional after-hours availability in response to privacy incidents, regulatory matters, or urgent organizational risk events.

Position Summary

The Compliance, HIPAA, and Risk Management Officer is responsible for developing, implementing, and overseeing the organization’s compliance, privacy, HIPAA, and risk management programs. This position ensures the organization operates in accordance with applicable federal and state laws, regulations, accreditation standards, contractual requirements, and internal policies.

The Compliance, HIPAA & Risk Management Officer serves as a key resource for leadership, management, and employees on regulatory compliance, privacy and security requirements, organizational risk, and ethical business practices. The position leads efforts to identify and mitigate compliance and operational risks, protect the privacy and security of protected health information (PHI), investigate potential violations, and promote a culture of accountability and continuous improvement.

Essential Responsibilities

Compliance Program Oversight

  • Develop, implement, maintain, and monitor the organization’s comprehensive compliance program.

  • Ensure policies and procedures reflect applicable federal and state laws, regulations, contractual obligations, and industry standards.

  • Conduct regular compliance assessments, audits, and monitoring activities to identify potential areas of noncompliance.

  • Develop corrective action plans and track remediation efforts through completion.

  • Provide compliance guidance and consultation to executives, managers, and employees.

  • Maintain compliance with documentation, reports, audit findings, and corrective action records.

  • Monitor regulatory and legislative changes and communicate relevant requirements to leadership and affected departments.

  • Coordinate internal and external compliance audits, surveys, and regulatory reviews.

  • Promote a culture of ethical conduct, accountability, transparency, and regulatory compliance.

HIPAA Privacy & Security

  • Serve as the organization’s designated HIPAA Privacy Officer and/or Security Officer, as assigned.

  • Oversee compliance with the HIPAA Privacy, Security, and Breach Notification Rules and applicable state privacy laws.

  • Develop, maintain, and periodically review HIPAA policies, procedures, and safeguards.

  • Oversee processes for access, use, disclosure, retention, and disposal of PHI.

  • Coordinate investigation and response to suspected privacy or security incidents and potential breaches.

  • Maintain appropriate documentation related to privacy incidents, investigations, risk assessments, and breach determinations.

  • Coordinate required breach notifications and regulatory reporting in collaboration with leadership and legal counsel.

  • Conduct or coordinate HIPAA privacy and security risk assessments and ensure identified risks are addressed.

  • Partner with Information Technology and Information Security to evaluate administrative, physical, and technical safeguards protecting PHI.

  • Ensure appropriate workforce training and education regarding HIPAA and privacy requirements.

  • Monitor compliance with Business Associate Agreements and other privacy-related contractual requirements.

  • Serve as a resource for employees and leadership regarding HIPAA questions, privacy concerns, and permissible uses and disclosures of PHI.

Risk Management

  • Lead the organization’s enterprise risk management program and risk identification process.

  • Identify, assess, prioritize, and monitor legal, regulatory, operational, clinical, financial, technology, privacy, security, and reputational risks.

  • Maintain an enterprise risk register and establish appropriate risk mitigation strategies.

  • Work with department leaders to develop and monitor risk mitigation and corrective action plans.

  • Conduct risk assessments related to new services, vendors, technology, processes, facilities, and organizational changes.

  • Monitor key risk indicators and provide regular reports and recommendations to executive leadership.

  • Coordinate risk management activities with insurance, legal, compliance, quality, information security, and operational teams.

  • Assist with incident reporting, investigation, root-cause analysis, and corrective action when appropriate.

  • Identify trends and emerging risks and recommend proactive measures to reduce organizational exposure.

Auditing, Investigations, & Reporting

  • Establish and execute an annual compliance and auditing work plan based on organizational risk.

  • Conduct or coordinate audits, reviews, and investigations involving compliance, HIPAA, privacy, billing, documentation, conflicts of interest, and other regulatory concerns.

  • Receive, document, and investigate reports of suspected compliance violations or unethical conduct.

  • Maintain appropriate confidentiality throughout investigations.

  • Escalate significant compliance, privacy, security, or risk issues to executive leadership, legal counsel, and/or the appropriate governing committee.

  • Prepare regular reports for senior leadership and the Board or Compliance Committee regarding compliance activities, significant risks, investigations, and corrective actions.

  • Maintain appropriate records demonstrating the effectiveness of the compliance program.

Education & Training

  • Develop and coordinate annual compliance and HIPAA training programs.

  • Provide orientation and ongoing education regarding compliance, privacy, security, ethics, and risk management.

  • Develop educational materials and communications addressing regulatory changes and emerging risks.

  • Promote employee awareness of reporting mechanisms and non-retaliation protections.

  • Evaluate training effectiveness and make improvements as needed.

Policy & Program Development

  • Develop, review, and update compliance, HIPAA, privacy, security, and risk management policies.

  • Establish processes to ensure policies are communicated effectively and consistently implemented.

  • Periodically evaluate the effectiveness of compliance and risk management programs and recommend improvements.

  • Collaborate with Human Resources, Legal, IT, Quality, Finance, Clinical Operations, and other departments on policies and processes affecting compliance and risk.

Supervisory Responsibilities

  • Provide direct supervision of Compliance Specialists, Privacy Analysts, and related staff as assigned.

Minimum Qualifications

Required

  • Bachelor’s degree in healthcare administration, business administration, health information management, compliance, risk management, or related field.

  • 5+ years of experience in healthcare compliance, HIPAA/privacy, risk management, healthcare administration, auditing, or related field.

  • Strong knowledge of HIPAA Privacy, Security, and Breach Notification requirements.

  • Experience conducting compliance audits, risk assessments, investigations, and corrective action planning.

  • Strong understanding of healthcare regulatory requirements and privacy principles.

  • Excellent written, verbal, analytical, and organizational skills.

  • Ability to handle confidential and sensitive information with discretion.

  • Demonstrated ability to work independently while collaborating effectively with executive leadership and multidisciplinary teams.

Preferred

  • Master’s degree in healthcare administration, business, law, public health, or related discipline.

  • Experience with organizational risk management.

  • Experience working with healthcare regulatory agencies, accreditation organizations, or external auditors.

  • Experience developing and maintaining HIPAA Privacy and Security programs.

  • Familiarity with healthcare information systems, cybersecurity risks, and third-party/vendor risk management.

  • Required within 12 months of hire:  

    • Certified in Healthcare Compliance (CHC)

    • Certified in Healthcare Privacy Compliance (CHP) or Certified in Healthcare Privacy and Security (CHPS)

Core Competencies

  • Regulatory and healthcare compliance

  • HIPAA privacy and security

  • Enterprise risk management

  • Auditing and monitoring

  • Investigation and problem-solving

  • Policy development

  • Regulatory interpretation

  • Risk assessment and mitigation

  • Incident and breach response

  • Data privacy and information security

  • Executive communication

  • Ethics and professional judgment

  • Change management

  • Cross-functional leadership

Key Performance Indicators

Success in this position may be measured by:

  • Effectiveness and maturity of the organization’s compliance program.

  • Completion of the annual compliance audit and monitoring plan.

  • Timely identification, investigation, and resolution of compliance concerns.

  • Reduction and mitigation of identified organizational risks.

  • Timely completion of corrective action plans.

  • HIPAA training and compliance rates.

  • Timeliness and effectiveness of privacy/security incident response.

  • Completion and remediation of HIPAA and enterprise risk assessments.

  • Regulatory and accreditation survey performance.

  • Effectiveness of compliance reporting to executive leadership and the Board.

  • Demonstrated improvement in organizational compliance and risk culture.

Physical Requirements

Must be able to sit, stand, walk, use a computer, communicate effectively, and occasionally lift up to 20 pounds. Reasonable accommodations may be provided to qualified individuals with disabilities.

General Statement

This job description is intended to describe the general nature and level of work performed by employees in this position. It is not intended to be an exhaustive list of all duties, responsibilities, qualifications, or working conditions. Employees may be required to perform other job-related duties as assigned. RiverPeak Health reserves the right to modify job duties, responsibilities, and requirements based on organizational needs, patient care requirements, operational demands, and changes in federal, state, or local laws and regulations.

As a condition of employment, applicants must successfully complete all required pre-employment screenings applicable to the position, which may include a criminal background check, fingerprint-based criminal history check, Office of Inspector General (OIG) exclusion screening, applicable state abuse, neglect, and exploitation registry checks, and a pre-employment drug screening. Applicants who do not meet the employment eligibility requirements based on the results of these screenings may be disqualified from employment, to the extent permitted by applicable law.

RiverPeak Health participates in E-Verify. We will provide the Social Security Administration, and if necessary, the Department of Homeland Security, with information from each new employee's Form I-9 to confirm work authorization. Please note that we do not use this information to pre-screen job applicants.

 RiverPeak Health is an Equal Opportunity Employer and actively supports the ADA and reasonably accommodates qualified applicants with disabilities.