Skip to content
OpenLoopOpenLoopUnited States

Senior Director, Compliance & Regulatory Affairs

Leads the end-to-end healthcare compliance program for a multi-state telehealth company, including OIG framework oversight, HIPAA privacy and security, investigations, policy governance, and regulatory readiness. Requires 12+ years in healthcare compliance or health law and experience managing compliance teams.

Salary not listed
Remote12+ YOELegal

About the role

Responsibilities

  • Design and oversee all seven elements of an effective, documented OIG compliance program.
  • Serve as the designated compliance officer for regulators, payors, and auditors.
  • Own written standards, compliance training and education, and program oversight.
  • Manage the policy and SOP lifecycle, including authoring, versioning, attestation, and retirement across subsidiaries.
  • Maintain the governance framework and map policies to OIG and CMS controls.
  • Own HIPAA Privacy and Security programs, including breach response from detection through notification and documentation.
  • Serve as or directly support the GDPR Data Protection Officer function.
  • Oversee hotline and investigation programs, including intake, triage, root-cause analysis, corrective action, and self-disclosure workflows.
  • Own exclusion and sanction screening, conflict-of-interest administration, and Stark Law and non-monetary compensation tracking.
  • Design and maintain compliance training across the workforce and clinician network, with direct ownership of OIG Element 3.
  • Manage the healthcare investigations, policy and governance, exclusion and sanction screening, and HIPAA and privacy compliance teams.
  • Oversee conflict-of-interest and Stark Law/non-monetary compensation functions.
  • Prepare board and leadership reporting on program status, risk posture, and open corrective actions.

Requirements

  • 12+ years of experience in healthcare compliance or health law.
  • End-to-end ownership of a healthcare compliance program.
  • Deep working knowledge of the OIG Seven Elements framework.
  • Ownership experience for HIPAA Privacy and Security programs.
  • Experience managing and developing a compliance team in a multi-state, technology-forward healthcare or pharmacy-adjacent environment.
  • Executive presence, sound judgment, and ability to serve as the responsible executive in regulator-facing documentation.
  • Ability to influence across Legal, Product, Security, and Clinical teams.
  • High integrity and a collaborative, low-ego working style.

Nice-to-haves

  • GDPR experience.
  • CHC, CHPC, CCEP, or equivalent compliance credential.

Compensation and Benefits

Salaried employees are eligible for:

  • Medical, dental, and vision plans
  • Flexible Spending Accounts and Health Savings Accounts
  • Flexible paid time off
  • 401(k) with company match
  • Life insurance
  • Pet insurance

Skills

healthcare compliancehealth lawoig seven elementsHIPAAGDPRcms controlsprivacydata securitybreach responsestark lawconflict of interestregulatory auditspolicy governancesanctions screeningcompliance training

Similar roles

Legal jobs
Redpanda Data

Director of Legal

Redpanda DataAustin, TX

Leads commercial transactions and builds scalable contracting infrastructure while advising the company on privacy, AI regulation, compliance, and broader legal risks. Requires a JD, state bar membership, and at least five years of technology-focused legal experience.

250k – 265k/yrHybrid8+ YOELegal
Anthropic

M&A Tax Director

AnthropicSan Francisco, CA

Leads tax workstreams across acquisitions, reorganizations, investments, and infrastructure transactions, advising Corporate Development, Legal, and Finance. Requires a JD or CPA and substantial transactional tax experience, with preferred depth in M&A, REITs, joint ventures, and technology or data center transactions.

230k – 300k/yrHybrid8+ YOELegal
Okta

Director, Corporate Counsel

OktaBellevue, WA +3

Lead and develop a global privacy legal team at Okta, providing expert guidance on data protection compliance, incident response, policy development, and contract negotiations for a high-growth SaaS company. Requires 10+ years legal experience including 5+ in privacy, JD, and team leadership.

240k – 330k/yrHybrid10+ YOELegal
Gauntlet

Head of Compliance

GauntletUnited States

The Head of Compliance will build and operate Gauntlet’s company-wide compliance program, covering policies, controls, monitoring, registrations, examinations, and risk advisory. The role requires broad, hands-on compliance experience and strong judgment in a growing traditional and onchain financial business.

Salary not listedRemote8+ YOELegal
AKASA

Director, Compliance & AI Governance

AKASASouth San Francisco, CA

Leads AKASA’s healthcare compliance and AI governance programs, owning HITRUST, SOC 2, HIPAA, audit readiness, policy management, and customer trust activities. The role requires 8+ years in security compliance, GRC, or risk management and hands-on experience with automation and emerging AI governance frameworks.

150k – 185k/yrHybrid8+ YOELegal