Principal Analyst Clinical Risk Management
Mayo Clinic is seeking an experienced healthcare professional to join the newly established Rochester Clinical Risk Management team as a Principal Risk Analyst. This is a unique opportunity to help build a strategic program advancing patient safety, transparency, organizational learning, and enterprise risk management at one of the world's leading healthcare organizations.
Reporting to the Senior Manager of Clinical Risk Management, the Principal Risk Analyst serves as a senior clinical risk expert who proactively identifies, assesses, and mitigates the clinical, operational, regulatory, financial, legal, and reputational risks associated with patient care. This includes leading the organization's response to complex patient care events, supporting communication and resolution efforts, guiding event review and mitigation activities, and advancing systems, processes, and education that strengthen safety, accountability, and trust.
Key Responsibilities
• Partner with physicians, administrators, patient safety professionals, legal counsel, accreditation leaders, and operational teams to manage complex matters involving patient care events.
• Support patient-centered communication and caregiver support following patient care events, in alignment with Mayo Clinic's Communication and Resolution approach.
• Apply a broad healthcare risk management lens across the five ASHRM/CPHRM domains: Clinical/Patient Safety, Risk Financing, Legal and Regulatory, Health Care Operations, and Claims and Litigation.
• Identify emerging risk trends and support claims-informed organizational learning.
• Partner with insurance and risk financing colleagues when clinical events carry financial or coverage implications.
• Translate complex clinical events into practical mitigation strategies, education, and system-level improvements.
A professional with deep clinical, operational, regulatory, or risk management expertise, sound judgment, and exceptional communication skills is desired. The successful candidate demonstrates the ability to assess risk, build trusted relationships, navigate sensitive situations, facilitate difficult conversations, and support leaders and care teams through challenging events — developing practical solutions that balance patient-centered care with organizational priorities while strengthening organizational resilience.
In addition, Principal Risk Analyst responsibilities may include:
Receives direction and reports to the Director or Senior Manager in the Risk Department (RD). Works in partnership with other department members as well as various physicians, administrative colleagues, and committees. Will collaborate with a wide range of Mayo Clinic departments including, but not limited to: Office of Information Security, Legal, Health Information Management and Human Resources. Interacts, supports and consults with individuals within Mayo Clinic and outside Mayo Clinic including external business partners, government agencies, and organizations.
The incumbent will lead risk business operations, special projects, investigations, legal litigation, mitigation development, non-employee access and end user awareness/education. Incumbent will provide guidance to the RD unit for day-to-day operational support, including project management. Incumbent will demonstrate leadership and represent the RD on project teams, committees, strike teams and workgroups. Job Duties and Responsibilities: Supports and develops RD initiatives. Responsible for the design of enterprise business operations, including operational growth and development. Leads multi-disciplinary workgroups and projects.
Responsible for development of policies and procedures to support the organization's risk tolerance. Gathers and organizes information from a cross-functional investigative team. Works directly with Legal and Human Resources on high risk internal and external investigations. Works directly with Legal and External Counsel on policy, regulatory and/or litigation matters (using eDiscovery protocols). Completes documentation to support findings including legal reports, SBARs, and executive summaries. Responsible for peer review of work unit documentation. Develops and presents Risk training(s) geared towards Mayo Clinic Leadership. Has extensive experience in regulatory compliance and investigations that includes:
• Deep subject matter expertise in relevant compliance laws and regulations such as privacy compliance, investigations, revenue cycle compliance, device manufacturing compliance, general compliance, conflict of interest;
• Understanding of and ability to apply the Seven Elements of an Effective Compliance Program;
• Ability to carry out audits, assessments and investigations; and
• Ability to use relevant compliance tools including GRC software, monitoring tools, and issue management software.
Ability to follow and apply holds and execute proper preservation of evidence and chain of custody protocols. Depending on role this may include the ability to follow proper computer forensic evidence handling, advanced knowledge of data preservation, acquisition of computing and storage devices either fixed or mobile and more technical forensic investigation.
Must have technical and nontechnical communication skills (verbal and written), analytical aptitude and project management skills. Demonstrates high level integrity and ability to use discretion and maintain confidential information. Other functions and projects as assigned. Some travel may be required to other Mayo Clinic Sites and/or training conferences.
Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.
This is a hybrid position and incumbent must live within 100 miles of the Rochester, MN campus.
Bachelor’s degree and 9 years’ experience in business analysis, insider threat, information security, compliance, privacy, risk management, information science, business administration, health or science-related fields OR Master’s degree and 6 years’ experience in business analysis, insider threat, information security, compliance, privacy, risk management, information science, business administration, health or science-related fields. JD or Masters degree preferred. Certified as CHC, CHPC, CCEP, CISSP, CISM, CITPM or relevant equivalent certification; or will obtain certification within 2 years of hire.
Preferred Qualifications
Certified Professional in Health Care Risk Management (CPHRM)
Certified in Healthcare Risk Management (CHRM)