The Director of Compliance, Risk Management & Regulatory Affairs provides operational leadership for Sandhills Medical Foundation's corporate compliance, enterprise risk management, and regulatory affairs programs. Reporting to the Vice President of Compliance & Continuous Improvement, this position oversees the daily implementation, monitoring, and continuous improvement of the organization's compliance infrastructure to ensure adherence to HRSA Health Center Program requirements, FTCA, HIPAA, CMS, federal and state regulations, and organizational policies.
The Director serves as the operational lead for regulatory readiness, compliance investigations, enterprise risk management, medical record compliance auditing, policy governance, incident management, and corrective action monitoring while fostering a culture of ethics, accountability, and continuous organizational readiness.
Essential Responsibilities
Corporate Compliance
Manage the day-to-day Corporate Compliance Program.
Implement and monitor the Corporate Compliance Plan and annual Work Plan.
Coordinate Compliance Committee activities and maintain compliance documentation.
Monitor corrective action plans and develop executive compliance dashboards.
Promote ethical business practices and regulatory accountability.
Regulatory Affairs & HRSA Compliance
Coordinate organizational compliance with HRSA Health Center Program requirements.
Administer HRSA Electronic Handbooks (EHB), compliance documentation, and evidence management.
Lead Operational Site Visit (OSV) readiness and maintain year-round survey preparedness.
Coordinate FTCA deeming, Change in Scope requests, grant compliance activities, and other HRSA regulatory submissions.
Enterprise Risk Management
Administer the Enterprise Risk Management Program.
Conduct organizational risk assessments and maintain the risk register.
Lead Root Cause Analyses (RCA), Failure Mode and Effects Analyses (FMEA), and mitigation planning.
Support emergency preparedness, business continuity, and insurance risk activities.
HIPAA Privacy & Compliance
Serve as the operational lead for the Privacy Program.
Coordinate privacy investigations, breach response, privacy audits, and required notifications.
Collaborate with Information Technology to support HIPAA Privacy and Security compliance.
Develop and deliver privacy education and awareness programs.
Incident Management & Investigations
Oversee the organizational incident reporting program.
Coordinate compliance investigations and maintain confidential investigative records.
Analyze trends, develop corrective action plans, and report significant findings to leadership.
Promote Just Culture principles and patient safety initiatives.
Medical Record Compliance
Coordinate annual medical record compliance audits.
Evaluate documentation quality, coding integrity, and regulatory compliance.
Monitor audit findings, provide education, and support documentation improvement initiatives.
Policy Governance
Maintain the organizational policy management process.
Coordinate policy development, annual reviews, approvals, and version control.
Ensure policies remain compliant with applicable regulatory and accreditation standards.
Education & Leadership
Develop and coordinate annual compliance education, including HIPAA, Fraud, Waste & Abuse, Corporate Compliance, and regulatory updates.
Provide leadership to compliance staff, establish departmental goals and KPIs, and prepare reports for executive leadership and the Board.
Collaborate across departments to strengthen organizational compliance and regulatory readiness.
Education
Bachelor’s degree in healthcare administration, Nursing, Public Health, Business Administration, Healthcare Compliance, Risk Management, or related field required.
Master's degree preferred.
Experience
5–7 years of progressive healthcare leadership experience.
3–5 years in healthcare compliance, risk management, regulatory affairs, or quality.
Experience in an FQHC or community health center strongly preferred.
Experience with:
HRSA Health Center Program Compliance
FTCA Deeming
HRSA Electronic Handbooks (EHB)
Operational Site Visits (OSV)
HIPAA Privacy & Security
Enterprise Risk Management
Medical Record Auditing
Incident Management
Internal Investigations
Policy Development
Grant Compliance
Knowledge & Skills
Strong knowledge of:
HRSA Health Center Program Requirements
FTCA
HIPAA Privacy & Security
CMS regulations
OSHA standards
Federal healthcare fraud and abuse laws
Enterprise Risk Management
Internal auditing principles
Healthcare accreditation standards
Root Cause Analysis (RCA) and FMEA
Performance Improvement methodologies
Ability to:
Interpret healthcare regulations.
Conduct investigations and compliance audits.
Develop policies and corrective action plans.
Present findings to executive leadership and the Board.
Lead cross-functional teams while managing multiple priorities.
Maintain confidentiality and exercise sound professional judgment.
Preferred Certifications
Certified in Healthcare Compliance (CHC)
Certified Professional in Healthcare Risk Management (CPHRM)
Certified Professional in Healthcare Quality (CPHQ)
Certified HIPAA Professional (CHP)
Lean Six Sigma Green Belt or Black Belt
Physical Requirements
Ability to work in office and clinical environments.
Occasional travel between Sandhills Medical locations.
Ability to conduct on-site audits, investigations, and regulatory reviews.
Ability to lift up to 25 pounds occasionally.