The Compliance Associate II, Privacy plays a key role in protecting patient privacy and supporting Northwestern Medicine's compliance program. This position is responsible for investigating privacy-related concerns, conducting risk assessments and audits, identifying potential compliance issues, and partnering with stakeholders across the organization to promote adherence to HIPAA and other regulatory requirements. Through analysis, education, and collaboration, this role helps strengthen the organization's culture of compliance and safeguard patient information.Responsibilities:Maintain current knowledge of federal, state, and local laws, regulations, and industry standards impacting healthcare compliance and privacy; assess organizational impact and provide guidance regarding new or revised requirements.Receive, investigate, document, resolve, and report all incoming compliance-related concerns, with a focus on HIPAA patient privacy.Manage compliance concerns reported via the Compliance Hotline, email, and phone, including intake, triage, investigation, and resolution.Conduct privacy assessments, including HIPAA risk assessments, by collecting, analyzing, and reporting relevant information to evaluate risks, identify root causes of reported or identified issues, and determine appropriate mitigation and escalation actions.Design and conduct audits of electronic health record (EHR) access; analyze results and identify potential inappropriate access, use, or disclosure of protected health information.Assist departments in developing and monitoring corrective action plans to address identified compliance and privacy issues.Track, monitor, and maintain privacy incidents, investigations, and inquiries within departmental databases and case management systems.Respond to queries or allegations and appropriately refer matters to Human Resources, Risk Management, the Office of General Counsel, or other departments, as necessary.Collaborate with cross-functional stakeholders to promote and maintain compliance with privacy and data protection requirements.Coordinate privacy related audits, reviews and, when necessary, investigations (in conjunction with the Corporate Compliance Manager) in response to CMS, OIG, and/or other regulatory bodies or organizational needs.Provide guidance on privacy-related matters and supporting the development of compliance education, training materials, policies, and procedures.Assist with the development, implementation, and monitoring of the annual Compliance Work Plan.Participate in process improvement initiatives designed to strengthen compliance and privacy program effectiveness.Provide data reporting and analysis of privacy program activities for internal and executive reporting. Provides administrative support to the department and coordinates with other departments and activities, as needed.Perform other duties as assigned.