Director of Compliance
commureUSAFull Time3w ago
NLPAISecurityComplianceSaaSSalesLegalHROperationsSupportRevenueExecutive
Job description
Director of Compliance at commure.
About the role
Commure is building an AI operating system for the healthcare sector to improve how care is delivered and documented. As the Director of Compliance, you will lead the corporate compliance program and ensure the organization meets all legal and regulatory standards. You will report to the Chief Legal Officer with a dotted line to the Board of Directors to maintain objective oversight of company operations.
Key facts
What you'll do
- Chair the Corporate Compliance Committee with members from Legal, HR, Engineering, Product, Security, and Sales.
- Create and maintain internal controls and policies to prevent unethical or illegal conduct within the Health IT environment.
- Perform risk assessments covering HIPAA, HITECH, Anti-Kickback Statute, Stark Law, information blocking, and FDA SaMD regulations.
- Design and execute an annual work plan that includes auditing and monitoring.
- Track and report compliance metrics to the Board and senior leadership to identify fraud, waste, or abuse.
- Manage the company compliance hotline and provide training materials for staff, executives, and vendors.
- Advise leadership on changes to the healthcare regulatory landscape.
Requirements
- Bachelor degree required.
- Minimum of 6 to 10 years of experience in healthcare regulatory and compliance roles.
- Leadership experience within a SaaS, Health IT, or medical device organization.
- Deep knowledge of HIPAA, HITECH, Anti-Kickback Statute, and federal or state privacy laws like CCPA and CPRA.
- Ability to manage compliance programs and develop training initiatives.
- Strong communication skills to explain regulatory concepts to diverse internal teams.
Nice to have
- Juris Doctorate or a Master degree such as an MBA or MHA.
- Certification in Healthcare Compliance (CHC).
- Experience with FDA regulations for digital health tools and ONC Cures Act Final Rule requirements.
Skills & tools
- Healthcare regulatory compliance
- Risk assessment and auditing
- Policy development
- Data privacy law
- Information security policy adherence
Practical notes
- Official communication will only originate from email addresses ending in @commure.com.
- Employees must adhere to information security policies and report potential risks to the security office.
- Annual attestation to security requirements is mandatory.