Position Summary
The Compliance and Privacy Program Lead serves as the day-to-day owner of Detego Health's compliance and privacy program. This role is responsible for designing, implementing, operating, measuring, and continually improving compliance and privacy processes across the organization in a healthcare third party administrator environment.
The immediate first-year priority is reliable privacy operations and a working investigations and corrective action process, including individual rights request handling, privacy incident and breach response, and compliance investigation intake through closure. The metrics, monitoring, training, and audit readiness scope build from that foundation as the program matures.
The successful candidate will lead privacy and compliance investigations, support regulatory readiness, maintain program documentation and evidence, coordinate corrective actions, manage privacy and compliance reporting, and work closely with Legal, Security, Enterprise Risk, Operations, Cost Containment, Human Resources, vendors, and business stakeholders.
This is a hands-on operational role. Success is measured by whether compliance and privacy processes function effectively, risks are identified and addressed, investigations are completed, regulatory obligations are met, and leadership has clear visibility into program performance. The candidate must be able to identify risk, make practical recommendations, escalate material concerns, and operate with limited supervision.
Scope of the Role
This role owns the day-to-day operation of Detego Health's compliance and privacy program. The position partners closely with Enterprise Risk, Security, Third Party Risk Management, Human Resources, Legal, Operations, and Payment Integrity to ensure compliance and privacy requirements are effectively implemented across the organization.
What You Own
Privacy Compliance
- HIPAA Privacy Rule compliance
- HIPAA Breach Notification Rule compliance
- State privacy law monitoring and implementation
- Privacy risk assessments
- Privacy investigations
- Breach analysis and documentation
- Privacy training and awareness
- Privacy metrics and reporting
Compliance Program Operations
- Compliance monitoring activities
- Compliance investigations
- Regulatory issue tracking
- Corrective action management
- Compliance training
- Compliance program documentation
- Policy and procedure governance
- Compliance intake channel, including a confidential reporting mechanism, and the associated case handling
- Compliance risk assessments and mitigation planning
- Compliance program effectiveness assessments
- Compliance metrics and reporting
Healthcare TPA Regulatory Support
- Support state third party administrator licensing and filing obligations in coordination with Legal and the contracts function
- Support compliance activities associated with ERISA, plan administration, and client specific requirements where privacy or regulatory obligations intersect business operations
- Support prompt pay, claims handling, appeals, and grievance compliance requirements in coordination with Operations and Payment Integrity
- Support compliance reviews associated with sanctions screening processes as assigned
- Track client and payer driven compliance obligations flowing from administered plans
Program Governance
- Compliance and privacy dashboards
- Key performance indicators and key risk indicators
- Executive reporting
- Audit evidence repositories
- Program maturity improvements
Vendor Compliance Coordination
- Privacy and compliance reviews of vendors, in coordination with Third Party Risk Management, where Third Party Risk Management owns the vendor risk assessment and lifecycle and this role owns the privacy and compliance determination within it
- Business Associate Agreement coordination
- Compliance requirement reviews
- Contractual compliance obligation tracking
Key Responsibilities
Compliance and Privacy Investigations
- Conduct, document, and manage compliance and privacy investigations from intake through closure
- Conduct investigations arising from confidential reporting channels, policy violations, regulatory concerns, and compliance matters
- Escalate to and coordinate with Legal when a matter carries litigation, privilege, or material regulatory exposure, and conduct legal directed investigations under that direction
- Perform root cause analysis
- Track corrective actions to completion
- Maintain investigation files and supporting evidence
Privacy Program Operations
- Operate privacy processes for individual rights requests, privacy concerns, incident response, breach analysis, and documentation
- Maintain the Record of Processing Activities and related data inventories as living artifacts that match actual business operations
- Conduct privacy assessments for new processes, technologies, vendors, and AI related use cases, including PHI use, minimum necessary, retention, transparency, and human oversight
Compliance Program Operations
- Monitor compliance obligations and regulatory requirements
- Assist departments in implementing compliance controls and corrective actions
- Support compliance reviews and targeted monitoring activities
- Conduct and document periodic compliance risk assessments and assist in the development of mitigation plans
- Conduct periodic compliance and privacy program effectiveness assessments and recommend improvements
- Operate the compliance intake channel and manage resulting cases to closure
Training and Awareness
- Develop and deliver compliance and privacy education programs
- Maintain new hire and annual training requirements
- Develop awareness materials, guidance documents, FAQs, alerts, and compliance communications
Governance, Metrics, and Reporting
- Establish and maintain compliance and privacy metrics
- Develop dashboards and leadership reporting
- Track investigation trends, corrective actions, training completion, privacy incidents, compliance concerns, policy acknowledgments, and other program indicators
- Present findings and recommendations to leadership
Audit and Regulatory Readiness
- Maintain organized evidence repositories
- Support HIPAA, SOC 2, URAC, client audits, and regulatory reviews
- Coordinate document requests and responses
What Success Looks Like
First 90 Days
- Compliance and privacy investigation workflows are documented and operating
- A corrective action tracking process is established
- The privacy incident response workflow is functioning and any appropriate team member can trigger and follow it
- A defined compliance intake channel is stood up and operating
- Reporting requirements are defined
- Existing policies and procedures have been assessed
Within Six Months
- Compliance and privacy metrics are reported on a recurring basis
- Investigations and corrective actions are tracked through closure
- Privacy and compliance processes operate consistently without executive intervention
- The Record of Processing Activities reflects current data flows
- Leadership has visibility into program performance, trends, and risks
- Evidence repositories support audit readiness
Required Qualifications
- Five or more years of healthcare compliance, privacy, investigations, audit, regulatory affairs, risk, or related experience
- Strong knowledge of the HIPAA Privacy Rule, the HIPAA Breach Notification Rule, and healthcare regulatory compliance
- Experience conducting investigations and managing corrective actions through to closure
- Experience developing and operating compliance or privacy programs, processes, or controls, not only drafting policy
- Experience creating metrics, dashboards, reports, or compliance monitoring activities
- Strong written and verbal communication skills
- Ability to operate independently, escalate clearly, and influence stakeholders across the organization
Preferred Qualifications
- CHC or CHPC strongly preferred on the compliance side
- CIPP/US strongly preferred on the privacy side
- CIPM, CCEP, or a similar certification is a plus
- A candidate without a certification should offset it with a demonstrable operating track record and be willing to obtain a relevant certification within 12 months
- Healthcare TPA, health plan, managed care, or healthcare services experience
- Experience with SharePoint, Power Automate, Vanta, BitSight, or similar governance tools
The Kind of Person Who Thrives Here
You are an operator/a self-starter. You would rather have a process running, measured, and improving than a perfect policy no one follows. You are comfortable owning an investigation or a privacy incident from first report to closure, and you keep records clean enough to support leadership review, audit review, client diligence, or regulatory scrutiny.
You are direct, practical, and organized. You work across Legal, Security, Enterprise Risk, Operations, Payment Integrity, Human Resources, vendors, and business owners without creating unnecessary friction, while still protecting the program and escalating risk when it matters.
Equal Opportunity Statement
Detego Health is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Pay: $110,000.00 - $125,000.00 per year
Benefits:
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Life insurance
- Paid time off
- Vision insurance
Work Location: In person