monitors and reports on adherence to role-based access controls
performs regular internal audits to ensure data integrity and privacy
engage in and respond to third-party audit requests
exhibit a professional attitude, communication style, and presence
conduct routine audits reviewing and assessing compliance with departmental policies and procedures on data migration, EPCS, system access
provide requested reports and documentation as required and coordinating with IA SOX to respond to any findings
configure compliance reports highlighting findings, recommendations and areas of concern
administer investigations into potential compliance violations or breaches, gathers evidence, conducts interviews, and prepares reports on the findings
monitor disaster recovery exercises tracking scheduling compliance and completion
serve as a bridge between Epic technical teams and Internal Audit
coordinate meetings to review findings and deficiencies with teams and assist in remediation plans
draft, prepare and disseminate education on identified compliance violations with minimal manager supervision
manage smaller projects with multiple teams and participates in multi-disciplined project teams
maintain documentation for routine audits, compliance reports and Audit Board requests
monitor clinical and technical team adherence to policies and procedures
analyze internal controls, policies and procedures, identify weaknesses and recommend improvements
collaborate with Epic Security group to ensure all Epic certifications are up to date for Epic analysts with EMR access
monitor planning and testing of downtime and disaster recovery procedures
leverage ServiceNow for incident management review and change control compliance
Requirements
3 years of experience in healthcare IT
Demonstrated experience with EMR software, including audit reporting, and change control processes using tools like Data Courier, Content Management and Analytics Catalog
self-directed learning, multi-tasking, organizational, communication, and IT project management skills
Some experience specifically supporting Epic environments
Demonstrated experience with Epic software, including audit reporting and change control processes using tools like Data Courier, Content Management and Analytics Catalog
Relevant Epic certifications (e.g., Data Courier, Bridges) are often preferred
ITIL certification is also a common preference
Certified Information Systems Security Professional (CISSP) preferred
Degree in Information Technology, Computer Science, or a related field; or comparable industry and vendor-provided Certifications