Compliance Specialist

MCRA, an IQVIA business

BLOOMINGTON (MN)

On-site

USD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

MCRA, an IQVIA business, partners with an emerging MedTech startup to hire a Compliance Specialist who will oversee HIPAA privacy and security governance, DMEPOS compliance, and information security policy. This role acts as Privacy Officer and Security Officer of record, coordinating with external vendors and CHAP accreditation readiness.

You will build and maintain frameworks, lead risk assessments, and manage the compliance platform while collaborating with leadership to align regulatory

Qualifications

  • 2+ years in healthcare compliance, DMEPOS, or health information privacy.
  • Bachelor's degree or higher in healthcare administration, business, or a related field.
  • Working knowledge of Medicare DMEPOS billing rules, CMS coverage policy.
  • HIPAA Privacy and Security Rule expertise, including Privacy Officer or equivalent.
  • Experience drafting and owning compliance policies, procedures, and training programs.
  • Familiarity with HCP interaction compliance and anti-kickback principles.
  • Strong organizational, documentation, and project coordination skills.
  • Ability to work independently in a small-company environment.

Responsibilities

  • Own and maintain the DMEPOS compliance program across licensing and billing.
  • Monitor CMS, OIG, and MAC guidance and translate to procedures.
  • Lead CHAP accreditation obligations and renewal readiness.
  • Coordinate multi-state DME licensing, registrations, and renewals.
  • Develop and deliver compliance training for operations teams.
  • Lead internal compliance audits and remediation documentation.
  • Maintain policies for interactions with healthcare professionals and entities.
  • Oversee the compliance technology platform and vendor due diligence.
  • Collaborate with leadership on risk, priorities, and governance.
  • Prepare compliance reports for internal and external stakeholders.

Skills

Strong organizational skills
Excellent written and verbal comms

Education

Bachelor's degree or higher in healthcare administration, business, or related field

Tools

Vanta
Drata
Secureframe

Job description

Notice: MCRA’s Talent Solutions division works to unite top talent with opportunities on our clients’ teams. This posting is not for a position directly at MCRA, but rather for a position with an MCRA client that our team is helping to recruit and fill.

MCRA Talent Solutions is proud to partner with an emerging MedTech startup advancing technologies in the Neuro AI space to hire a Compliance Specialist that will oversee the regulatory compliance program, HIPAA privacy and security governance, and information security policy, building and maintaining the frameworks, policies, audit readiness, and operational workflows needed for the company to operate as a compliant Medicare DMEPOS supplier and responsible steward of protected health information. This role also serves as the Privacy Officer and Security Officer of record, focusing on policy and governance rather than hands‑on IT or cybersecurity engineering, while coordinating with external IT and cybersecurity vendors, managing the compliance technology platform, and leading CHAP accreditation readiness.

Responsibilities
  • Own and maintain DMEPOS compliance program, including Medicare coverage and billing policies, ABN processes, same/similar checks, and supplier standards under 42 CFR Part 424.
  • Monitor CMS, OIG, and MAC guidance for policy changes affecting DME suppliers; translate updates into internal procedures and staff training.
  • Lead CHAP accreditation obligations, including self‑assessments, corrective action plans, and renewal readiness.
  • Own multi‑state DME licensing compliance; coordinate renewals, foreign entity registrations, Secretary of State filings, annual reports, and tax registrations with external vendors
  • Maintain organized records of all licenses, registrations, compliance filings, and supporting documentation.
  • Develop and deliver compliance training for operational staff, including billing, intake, and customer‑facing teams.
  • Lead internal compliance auditing, incident tracking, and corrective action documentation.
  • Own compliance policies and documentation for interactions with healthcare professionals (HCPs), clinics, hospitals, and healthcare organizations.
  • Maintain and enforce policies covering HCP interactions, educational and training activities, marketing and promotional compliance, transparency reporting, and business conduct standards.
  • Coordinate compliance reviews and documentation for HCP‑related engagements and referral arrangements.
  • Work with leadership and outside counsel on anti‑kickback and Stark Law compliance review for distributor, referral partner, and vendor arrangements.
  • Lead compliance training and awareness programs for employees interacting with HCPs and healthcare organizations.
  • Serve as Privacy Officer and Security Officer of record.
  • Own the HIPAA Privacy and Security Rule compliance program: policies, risk assessments, workforce training, and breach response procedures.
  • Lead and document annual HIPAA security risk analyses; drive remediation of identified gaps.
  • Maintain and manage Business Associate Agreements with clearinghouses, software platforms, and other covered partners.
  • Own information security policy suite (access control, acceptable use, incident response, data retention) in alignment with HIPAA Security Rule requirements, coordinating with IT and external cybersecurity vendors on implementation.
  • Support review of security‑relevant vendor contracts and data processing addenda in coordination with leadership and outside counsel.
  • Administer and maintain the compliance and GRC technology platform (Vanta or equivalent); coordinate vendor due diligence, audit readiness, and remediation tracking.
  • Collaborate with executive leadership on compliance priorities, operational risk, and organizational initiatives.
  • Build scalable compliance processes suited to a growing DMEPOS operation.
  • Prepare compliance reports, summaries, and documentation for internal and external stakeholders.
  • Coordinate with legal, quality, operations, finance, and external consultants as needed.
Qualifications
Required
  • 2+ years in healthcare compliance, DMEPOS operations, or health information privacy.
  • Bachelor's degree or higher in healthcare administration, business, or a related field required
  • Working knowledge of Medicare DMEPOS billing rules, supplier standards, and CMS coverage policy.
  • Demonstrated HIPAA Privacy and Security Rule expertise, including experience as Privacy Officer or Security Officer of record (or functional equivalent).
  • Experience drafting and owning compliance policies, procedures, and training programs.
  • Familiarity with HCP interaction compliance, anti‑kickback principles, and promotional compliance in a healthcare setting.
  • Strong organizational, documentation, and project coordination skills.
  • Ability to manage multiple compliance workflows and deadlines simultaneously.
  • Strong written and verbal communication skills.
  • Comfort operating independently in a small‑company environment with limited administrative support.
Preferred
  • CHC (Certified in Healthcare Compliance), CHPC, or equivalent credential.
  • Experience with CHAP or The Joint Commission DME accreditation standards.
  • Hands‑on experience with a GRC or compliance automation platform (Vanta, Drata, Secureframe, or similar).
  • Familiarity with HCPCS code policy, Medicare Advantage billing, or DMEPOS competitive bidding.
  • Exposure to SOC 2, NIST Cybersecurity Framework, or ISO 27001 in a healthcare or medtech context.
  • Experience supporting audits, accreditation activities, or regulatory inspections.
  • Additional certifications a plus: Security+, HCISPP, CISA, or CISSP.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privacy & HIPAA Compliance Lead (DMEPOS)
Privacy & HIPAA Compliance Lead (DMEPOS)

MCRA, an IQVIA business • BLOOMINGTON (MN)

On-site
USD 90,000 - 130,000
Compliance Manager
Compliance Manager

Southeastern Retina Associates • Knoxville (TN)

On-site
USD 90,000 - 120,000
Compliance Manager
Compliance Manager

Dozee • Dallas (TX)

On-site
USD 80,000 - 100,000
Compliance & Integrity Director
Compliance & Integrity Director

ChenMed • United States

On-site
USD 150,000 - 195,000
Healthcare Compliance Officer
Healthcare Compliance Officer

TalentLNX • Northern (KY)

Hybrid
USD 115,000 - 145,000
Compliance Manager
Compliance Manager

UpDoc, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Sr. Director, Compliance and Privacy
Sr. Director, Compliance and Privacy

American Health Partners • Franklin (TN)

On-site
USD 150,000 - 210,000
Compliance and Privacy Director
Compliance and Privacy Director

Nashville Public Radio • New York (NY)

On-site
USD 100,000 - 150,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (Roth 401k)
Flexible PTO Policy
+1
Compliance Manager
Compliance Manager

CharterCARE of Rhode Island • Providence (RI)

On-site
USD 90,000 - 140,000
Medical Compliance Auditor
Medical Compliance Auditor

DaMar Staffing • United States

On-site
USD 85,000 - 110,000