Chief Financial Officer & Human Resources
Role Overview
The Chief Financial Officer (CFO) is a senior executive responsible for the financial stewardship of the
organization and, in this structure, for the human resources function. The role is shared across the MedSuite
group of companies rather than held separately by each company.
The human resources half of the role carries direct compliance significance. Workforce screening, training
records, personnel files and the administration of disciplinary sanctions are all controls named in the HIPAA
Security Rule administrative safeguards, and all sit with this function. Where a policy or procedure assigns a
duty to “Human Resources,” it means this shared function.
Key Responsibilities
Financial Stewardship
- Own financial planning, budgeting, forecasting and reporting across the group.
- Maintain the integrity of financial records and the controls that protect them.
- Ensure funding decisions for security and compliance sit above the roles being funded, so that risk can be escalated without conflict of interest.
- Oversee financial aspects of vendor and third-party arrangements, including business associate relationships.
Workforce Administration
- Own the hiring, onboarding, transfer and departure processes for the workforce.
- Maintain personnel files as the authoritative record of employment, including role designations where a policy requires one to be filed.
- Operate the group HR system of record and ensure workforce data held in it is accurate and current.
- Ensure departure notification reaches the security function in time for access to be terminated within the period the policies require.
Workforce Screening and Clearance
- Conduct background verification appropriate to the level of access a position requires, before hire.
- Maintain the record of what was verified, so that screening can be evidenced rather than asserted.
- Support periodic re-evaluation of workforce members where the role or its access changes.
Training and Awareness Records
- Deliver the group security and privacy awareness program and maintain completion records as the system of record.
- Ensure new workforce members complete required training within the period stated in policy.
- Produce training completion evidence on request for audits, assessments and regulatory inquiries.
Sanctions and Investigations
- Determine and apply disciplinary sanctions for policy violations, on the basis of investigation findings provided by the security function.
- Apply the disciplinary sanctions matrix consistently across the workforce.
- Record disciplinary action in the personnel file, and consult Legal Counsel where a matter may carry legal or regulatory consequence.
Separation of duties: the function that investigates a violation does not decide the penalty. Investigations
are conducted by the Information System Security Officer; sanctions are determined by this function on the basis
of those findings.
Qualifications
- Senior financial leadership experience, preferably in a regulated industry.
- Working knowledge of employment law and of the workforce controls required by HIPAA and applicable state law.
- Experience operating an HR system of record and producing evidence from it for audit.
- Bachelor’s degree in Accounting, Finance, Business Administration or a related field; professional certification such as CPA preferred.
Key Competencies
- Stewardship: Accountability for both financial assets and workforce records.
- Discretion: Handling personnel and disciplinary matters with appropriate confidentiality.
- Consistency: Applying screening, training and sanctions uniformly, so that controls are defensible.
- Evidence Discipline: Maintaining records that can be produced on request, in a form an assessor can rely on.
- Collaboration: Working with the security, compliance and privacy functions where duties are shared.