Director of Compliance
Job description
About the role
The Director of Compliance owns the design, oversight, and continuous evaluation of Commure's enterprise-wide corporate compliance program. This role operates at the intersection of healthcare regulation and Health IT platform integrity, ensuring that our AI Operating System serves patients and providers within a legally sound and ethically robust framework. The hire will act as an independent voice, translating complex regulatory landscapes into actionable policies and controls that protect the company and support innovation. They will embed compliance thinking into daily product, engineering, and operational decisions rather than treating it as a retrospective checkpoint. If you are driven by high consequence problem solving and believe that integrity is a competitive advantage in healthcare, this position offers direct impact on a mission-critical scale. You will be measured by the strength of the control environment, the reduction in regulatory risk, and the trust earned with internal and external stakeholders.
Key facts
What you'll do
- Know, understand, and champion Commure's mission, vision, and values through leadership behaviors, practices, and decisions.
- Chair the Corporate Compliance Committee, ensuring regular meetings with appropriate cross-functional representation from Legal, Human Resources, Engineering, Product, Security, and Sales.
- Develop, implement, and maintain policies, procedures, and controls for the compliance program to prevent and detect illegal, unethical, or improper conduct, with a strong focus on Health IT-specific risks.
- Conduct regular, comprehensive risk assessments to identify potential areas of compliance vulnerability, including those related to HIPAA/HITECH, data security, the Anti-Kickback Statute, Stark Law, information blocking, and FDA regulations for Software as a Medical Device (SaMD).
- Develop, implement, and track corrective action plans to resolve compliance issues, providing guidance to prevent future occurrences.
- Establish and execute an annual compliance work plan based on risk assessment results, including targeted auditing and monitoring activities.
- Develop and report on key compliance metrics and data analytics to senior leadership and the Audit Committee of the Board, detecting potential fraud, waste, abuse, and other aberrant patterns.
- Direct and oversee the creation and delivery of effective compliance training and educational materials for all employees, executives, board members, and key vendors, focusing on the real-world application of compliance principles to Commure's business model.
- Manage and promote effective lines of communication, including the company's compliance hotline, ensuring a safe and anonymous channel for reporting concerns.
- Monitor the performance and effectiveness of the compliance program on an ongoing basis and implement continuous improvements.
- Maintain expert knowledge of the evolving healthcare regulatory landscape and advise the company on the potential impact of new laws and regulations.
- Liaise with senior management to ensure a strong "tone at the top," integrate compliance activities into business operations, and evaluate the compliance-related performance of employees.
Requirements
- Bachelor's degree required; Juris Doctorate (JD) or relevant Master's degree (e.g., MBA, MHA) is strongly preferred.
- Certification in Healthcare Compliance (CHC) or similar compliance certification is highly desirable.
- Minimum of 7 years of progressively responsible compliance, legal, or risk management experience, with at least 3 years focused on Health IT, healthcare services, or a heavily regulated environment.
- Demonstrated expertise with core healthcare regulations, including but not limited to HIPAA, HITECH, the Anti-Kickback Statute, Stark Law, and information blocking rules.
- Prior experience implementing and maintaining enterprise compliance programs, including policy development, risk assessments, control monitoring, and audit support.
- Strong understanding of data privacy and security frameworks, such as NIST, ISO 27001, or SOC 2, particularly as they apply to protected health information.
- Familiarity with FDA oversight of Software as a Medical Device (SaMD) and related quality system regulations is required.
- Proven ability to work independently with high integrity, manage multiple priorities, and communicate effectively with executive leadership and cross-functional teams.
Nice to have
- Experience in a Health IT company building AI-enabled platforms is preferred.
- Knowledge of emerging state-level privacy and data security regulations as they apply to health information.
- Understanding of revenue cycle management processes and compliance risks within RCM workflows.
Practical notes
- Full-time onsite role in Mountain View, California.
- No relocation support is provided.
- Candidates must be authorized to work in the United States without sponsorship at this time.
- The start date will align with business needs and will be coordinated with the successful candidate.
- Travel is not required for this role.
- This position does not offer visa sponsorship.