This role is responsible for providing strategic direction and oversight for the organization's corporate compliance and privacy programs. It ensures alignment with evolving healthcare regulations, industry standards, and internal policies. As a key advisor to executive leadership, the Board of Directors, and governance committees, the role fosters a culture of ethics, accountability, and transparency across the enterprise. This role will serve as the designated Privacy Official, responsible for the development and implementation of policies and procedures, personnel training, and processes to investigate and respond to complaints regarding impermissible uses or disclosures of PHI and related policy violations. Has full ownership of HIPAA compliance for BCBSA.
The position leads a team of compliance and privacy professionals, driving continuous improvement and operational excellence. It plays a critical role in risk mitigation, regulatory readiness, and the development of policies and practices that safeguard patient and organizational data.
Responsibilities include but are not limited to:
Government Programs Compliance
• Serve as BCBSA’s Medicare Compliance Official for purposes of complying with Medicare Compliance obligations.
• Serve as the subject matter expert for Medicare Part D and other government programs compliance.
• Build and oversee the operations of government programs compliance programs, as necessary
• Support and oversee the operations of Compliance Committee(s), and report findings to leadership and through appropriate BCBSA governance Committee(s).
Corporate Compliance Oversight
• Serve as BCBSA's Compliance Official
• Provide leadership and operational oversight for BCBSA's Compliance and Ethics Program, including the Code of Business Conduct and annual reporting to leadership and the Board.
• Address compliance issues in collaboration with internal stakeholders.
Privacy Program Leadership
• Serve as BCBSA’s Privacy Official for purposes of HIPAA compliance
• Oversee the organization’s Privacy Program, including HIPAA and GDPR compliance.
• Lead cross-functional efforts to investigate and resolve privacy incidents.
Team Leadership
• Lead and develop a high-performing compliance and privacy team, fostering professional growth and a positive, inclusive work environment.
Systemwide Engagement
• Promote best practices and coordinate incident response efforts across the system.
Training & Education
• Oversee compliance and ethics training programs for Blue Plan Compliance leaders.
The posting range for this position is:
173,400.00 - 251,400.00Required Education, Certifications and Experience:
Education
- Required BS or equivalent work experience
- Preferred MS in Law; Business Administration; or equivalents
Experience
- Required 12+ Years Experience in the healthcare industry with demonstrated knowledge of regulatory, privacy (HIPAA), and compliance and ethics issues
Knowledge Skills and Abilities
- Proven ability to lead teams, drive organizational change, and influence cross-functional initiatives in complex environments.
- Deep understanding of healthcare compliance, privacy program administration, and data security technologies, including HIPAA and GDPR.
- Strong capability to assess regulatory and operational risks and develop effective mitigation strategies.
- Excellent analytical skills with sound business judgment, creativity, and initiative to solve complex problems.
- Advanced interpersonal and communication skills, including experience facilitating training and presenting to executive leadership and governance bodies.
- Ability to build and maintain credible relationships with internal and external stakeholders, including senior executives and board members.
- Skilled in strategic project planning and execution, with the ability to remain composed and tactful under pressure.
- Competent in Microsoft Office applications and other relevant compliance and privacy tools.
- Understanding of data security technologies and privacy program administration
- Preferred: Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.
Certifications & Licenses
- Preferred: Licensed Attorney (varies by state) - Various
- Preferred: Professional, Academy for Health Care Management (PAHM) - AHIP
- Preferred: Certified Information Privacy Professional (CIPP) - IAPP
Extra Posting Information:
- Minimum twelve years' experience in the healthcare business arena with demonstrated knowledge of current regulatory and compliance and ethics issues, including knowledge of and experience working with Centers for Medicare and Medicaid Services/Medicare compliance requirements.
- Experience managing privacy programs subject to healthcare laws and regulations, including HIPAA
- Must have at least one year of experience managing privacy programs subject to healthcare laws and regulations, and a proven track record of leading and implementing regulatory compliance initiatives.
- Direct experience with CMS/Medicare compliance requirements is required.
- Proven record in leading and implementing regulatory compliance programs
#LI_HYBRID
The posted salary range is the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the hiring range and this hiring range may also be modified in the future. A candidate’s position within the hiring range may be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, relevant experience, skills, seniority, performance, shift, travel requirements, and business or organizational needs. This job is also eligible for annual bonus incentive pay.
We offer a comprehensive package of benefits including paid time off, 11 holidays, medical/dental/vision insurance, generous 401(k) matching, lifestyle spending account and many other benefits to eligible employees.
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.
Blue Cross Blue Shield Association Chicago, Illinois, USA Office
225 North Michigan Avenue, Chicago, IL, United States, 60601
Blue Cross Blue Shield Association Downers Grove, Illinois, USA Office
Downers Grove, United States
Similar Jobs
What you need to know about the Chicago Tech Scene
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory


