Jobs · Legal

Senior Director of Compliance & Privacy

Nema Health · United States · 1 mo ago
RemoteRemoteLegal$180k–$200k/yrFull-time

About the role

The Senior Director of Compliance & Privacy will lead and scale Nema’s compliance, privacy, regulatory, audit, and risk management functions across the organization. This role will oversee compliance operations related to clinical care delivery, patient privacy, therapist practices, documentation standards, regulatory readiness, organizational policy governance, and healthcare security oversight.

Responsibilities

  • Lead the development, implementation, and ongoing oversight of Nema’s compliance and privacy programs across all clinical and operational functions.
  • Ensure organizational adherence to applicable federal, state, and local healthcare regulations, payer requirements, licensing standards, privacy laws, and internal policies.
  • Maintain accurate records of audits, findings, investigations, corrective actions, and compliance activities.
  • Develop and maintain scalable compliance systems, workflows, policies, SOPs, and governance processes.
  • Partner cross-functionally with Clinical, Operations, Legal, People, and Product teams to operationalize compliance and privacy requirements across the organization.
  • Oversee all privacy-related functions, including HIPAA compliance, patient confidentiality practices, and protected health information (PHI) safeguards.
  • Develop and maintain privacy policies, procedures, training programs, and incident response protocols.
  • Lead investigations and management of privacy incidents, breaches, and related corrective action plans.
  • Ensure appropriate access controls, documentation standards, and operational safeguards are maintained across clinical and technical systems.
  • Support Business Associate Agreement (BAA) processes and privacy-related vendor reviews as needed.
  • Coordinate preparation activities, documentation reviews, corrective action plans, and follow-up initiatives related to regulatory or accreditation processes.
  • Partner with leadership to ensure continuous readiness and sustained compliance across clinical operations and corporate functions.

Requirements

  • Bachelor’s degree in healthcare administration, public health, nursing, behavioral health, business, law, or related field required; advanced degree preferred.
  • Minimum 5 years of progressive healthcare compliance, privacy, audit, risk management, or regulatory experience, with at least 2 years in a leadership role.
  • Strong working knowledge of HIPAA, healthcare privacy regulations, clinical documentation standards, patient rights, incident reporting, and licensure requirements.
  • Familiarity with healthcare security frameworks, HIPAA Security Rule requirements, vendor risk management, and cross-functional collaboration with security and IT teams.
  • Experience managing audits, investigations, incident reporting systems, complaints/grievances, privacy incidents, and corrective action planning.
  • Strong understanding of behavioral healthcare operations and compliance considerations within clinical environments.
  • Exceptional organizational, analytical, communication, and problem-solving skills.
  • Ability to manage sensitive and confidential information with discretion and professionalism.
  • Strong operational mindset with the ability to build scalable systems and processes.
  • Mission-driven and committed to high-quality, patient-centered care.
  • Certification in healthcare compliance or privacy (e.g., CHC, CHPC, CHPS, CIPP).
  • Experience supporting behavioral health accreditation or regulatory readiness initiatives.
  • Experience partnering with security leadership, CISOs, or external security vendors in healthcare or digital health environments.
  • Experience with compliance reporting systems, privacy monitoring frameworks, and quality dashboards.
  • Experience supporting remote or distributed healthcare organizations.

Similar jobs