§ 30.242 DUTIES OF THE PRIVACY OFFICER.
   The Privacy Officer shall:
   (A)   Oversee all ongoing activities related to the development, implementation, maintenance of, and adherence to the Village of Schiller Park policies and procedures covering the privacy of, and access to, patient health information in compliance with federal and state laws.
   (B)   Train all Village employees in regards to the privacy policies and procedures and maintain documentation of all training so provided.
   (C)   Put administrative, technical and physical safeguards into practice in order to protect the privacy of protected health information to avoid intentional and unintentional prohibited uses and/or disclosures.
   (D)   Establish a process for employees to make complaints about the privacy policies and procedures, and to report alleged violations and a mechanism for the documentation of reports and/or complaints.
   (E)   Provide development guidance and assist in the identification, implementation, and maintenance of information concerning the privacy policies and procedures of the Village in coordination with the Village Manager/Comptroller and the Corporation Counsel.
   (F)   Work with the Village Manager/Comptroller to establish a Privacy Oversight Committee and serve in a leadership capacity for the Privacy Oversight Committee's activities.
   (G)   Perform initial and periodic information privacy risk assessments and conduct related ongoing compliance monitoring activities in coordination wits the Village's other compliance and operational assessment functions.
   (H)   Work with the Corporation Counsel and other Village officials, departments and committees to ensure the Village has and maintains appropriate privacy and confidentiality consent, authorization forms, and information notices and materials reflecting current Village practices and requirements.
   (I)   Oversee, direct, deliver, or ensure delivery of initial and privacy training and orientation to all employees, volunteers, medical and professional staff, contractors, alliances, business associates, and other appropriate third parties.
   (J)   Participate in the development, implemen- tation, and ongoing compliance monitoring of all business associate agreements, to ensure all privacy concerns, requirements, and responsibilities are addressed.
   (K)   Establish a mechanism to track access to protected health information, within the purview of the Village and as required by law, and to allow qualified individuals to review or receive a report on such activity.
   (L)   Oversee patient rights to inspect, amend, and restrict access to protected health information when appropriate.
   (M)   Establish and administer a process for receiving, documenting, tracking, investigating, and taking action on all complaints concerning Village privacy policies and procedures in coordination and collaboration with other similar functions and, when necessary, legal counsel.
   (N)   Ensure compliance with privacy practices and consistent application of sanctions for failure to comply with privacy policies for all individuals in the Village of Schiller Park workforce, extended workforce, and for all business associates, in cooperation with the Village Human Resources, information security officer, administration, and legal counsel as applicable.
   (O)   Initiate, facilitate and promote activities to foster information privacy awareness within the Village and related entities.
   (P)   Serve as a member of, or liaison to, the Village of Schiller Park Privacy Oversight Committee, should one exist and also serve as the information privacy liaison for users of clinical and administrative systems.
   (Q)   Review all system-related information security plans throughout the Village government network to ensure alignment between security and privacy practices, and act as a liaison to the information systems department.
   (R)   Work with all Village personnel involved with any aspect of release of protected health information, to ensure full coordination and cooperation under Village policies and procedures and legal requirements.
   (S)   Maintain current knowledge of applicable federal and state privacy laws and accreditation standards, monitor advancements in information privacy technologies to ensure Village adaptation and compliance.
   (T)   Serve as information privacy consultant to the Village for all Village departments and entities.
   (U)   Cooperate with the Office of Civil Rights, other legal entities, and Village officers in any compliance review or investigations.
   (V)   Work with Village administration, its Corporation Counsel and other related parties to represent the information privacy interests of the Village when federal or state government adopt or amend privacy legislation, regulation, or standards.
(Ord. 03-2393, passed 2-11-03)