| Title | Healthcare Compliance Manager |
|---|---|
| Department | Compliance / Privacy / Legal |
| Reports to | [Chief Compliance Officer / Privacy Officer / General Counsel] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Healthcare Compliance Manager leads [Company]'s healthcare compliance program, ensuring the organization meets its obligations under HIPAA, HITECH, federal healthcare program rules, and other applicable regulations. This role owns policy, training, auditing and monitoring, investigations, and the relationship with regulators and enforcement bodies.
Working across privacy, security, clinical, billing, and legal teams, the Healthcare Compliance Manager protects patient information, guards against fraud, waste, and abuse, and builds a strong compliance culture. The role balances regulatory rigor with the realities of care delivery and operations.
This is a hands-on leadership role for a compliance professional who knows healthcare regulation and can operationalize it across a complex organization.
Key responsibilities
Compliance program management
- Operate the compliance program around the seven elements outlined in OIG guidance.
- Maintain compliance policies, standards, and the code of conduct.
- Run the compliance risk assessment and work plan.
- Report program status to leadership and the compliance committee.
HIPAA privacy and security
Oversee HIPAA privacy and security compliance across the organization. Coordinate with the Privacy and Security Officers where those roles are separate.
- Maintain privacy policies and Notice of Privacy Practices.
- Support safeguards for protected health information (PHI).
- Manage patient rights requests and privacy complaints.
- Coordinate breach assessment and notification.
Auditing and monitoring
Design and run auditing and monitoring across billing, coding, privacy, and high-risk areas. Track exceptions, root causes, and corrective action.
Fraud, waste, and abuse
- Support compliance with federal healthcare program rules.
- Help guard against fraud, waste, and abuse.
- Coordinate exclusion and sanction screening.
- Advise on arrangements that raise regulatory concern.
Investigations and corrective action
Investigate compliance concerns, hotline reports, and potential violations. Document findings, drive corrective action, and manage disclosures where required.
Training and culture
Deliver compliance and privacy training, promote the hotline and non-retaliation policy, and build a culture where staff raise concerns.
Required qualifications
- Bachelor's degree in Healthcare Administration, Business, Nursing, Law, or a related discipline. Advanced degree a plus.
- 6 to 10 years of healthcare compliance, privacy, or regulatory experience.
- Strong knowledge of HIPAA, HITECH, and federal healthcare program requirements.
- Experience running auditing, monitoring, or investigation processes.
- Familiarity with OIG compliance program guidance and the seven elements.
- Demonstrated ability to advise clinical and operational leaders.
Preferred certifications
One or more of: CHC, CCEP, CHPC, CHRC, or equivalent healthcare compliance certification.
Technical knowledge
Healthcare compliance program management, HIPAA privacy and security, breach assessment and notification, auditing and monitoring, fraud, waste, and abuse controls, exclusion screening, investigations, corrective action, and compliance training.
Essential competencies
Sound judgment, discretion, clear communication, stakeholder influence across clinical and operational teams, program management, and the ability to translate regulation into practical guidance.
Success measures: first 12 months
- Refresh the compliance risk assessment and annual work plan.
- Update core compliance and HIPAA privacy policies.
- Stand up or strengthen the auditing and monitoring calendar.
- Close open corrective action items and prior findings.
- Deliver baseline compliance and privacy training.
- Strengthen the hotline, intake, and investigation process.
- Confirm exclusion and sanction screening is current.
- Improve compliance reporting to leadership and the committee.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in healthcare compliance and privacy rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Healthcare Compliance Manager do?
A Healthcare Compliance Manager runs an organization's healthcare compliance program. They own policy, training, auditing and monitoring, and investigations, oversee HIPAA privacy and security, and help guard against fraud, waste, and abuse in federal healthcare programs.
What qualifications and certifications does a Healthcare Compliance Manager need?
Most bring 6 to 10 years of healthcare compliance or privacy experience plus a bachelor's degree. Common certifications include CHC, CCEP, and CHPC, with CHRC for those focused on research compliance.
What frameworks does a Healthcare Compliance Manager use?
Common references include HIPAA and HITECH, the HHS Privacy and Security Rules, OIG Compliance Program Guidance and its seven elements, and applicable federal healthcare program rules under Title 42.
What are the seven elements of an effective compliance program?
OIG guidance describes seven elements: written policies and standards, a compliance officer and committee, training and education, effective lines of communication, auditing and monitoring, enforcement and discipline, and prompt response and corrective action.