VP, Chief Compliance Officer

Boston Medical Center (BMC)

Boston (MA)

On-site

USD 321,000 - 370,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Boston Medical Center Health System is seeking a Vice President & Chief Compliance Officer to lead and evolve the enterprise compliance and privacy program across our hospitals, Health Plan, and Physician Organizations. The role reports to the Senior Vice President, General Counsel, and interfaces with the CEO and Board committees.

The position drives risk assessment, monitoring, and corrective actions, ensuring adherence to federal and state healthcare laws, privacy protections, and

Qualifications

  • Bachelor’s degree in business, healthcare administration, law, public health, or a related field.
  • At least twelve (12) years of progressively responsible healthcare compliance, privacy, legal, regulatory, audit, or related experience, including experience leading a compliance program in a complex healthcare organization.
  • Graduate degree in law, business administration, healthcare administration, public health, or related discipline preferred.

Responsibilities

  • Establishes, leads, and continuously improves the Health System’s enterprise compliance and privacy program to prevent, detect, and address conduct inconsistent with laws, regulations, policies, and ethical standards.
  • Leads the enterprise compliance risk assessment and annual compliance work-planning process with monitoring, auditing, data analysis, and testing activities.
  • Directs the intake, triage, investigation, escalation, documentation, and resolution of reported compliance and privacy concerns in coordination with Legal, HR, Internal Audit, and IT.
  • Provides enterprise oversight of healthcare regulatory compliance and privacy activities including HIPAA Privacy, Security, and Breach Notification requirements.
  • Develops and oversees enterprise education, communication, and policy-management programs to promote a culture of integrity and non-retaliation.
  • Oversees compliance due diligence and monitoring related to third parties, transactions, and business arrangements.

Skills

Leadership
Healthcare compliance
HIPAA/privacy
Risk assessment
Investigations
Governance
Regulatory knowledge

Education

Bachelor’s degree in business/healthcare/related field

Job description

The Vice President & Chief Compliance Officer provides strategic and independent leadership for Boston Medical Center Health System’s compliance and privacy programs across Boston Medical Center hospitals, Health Plan, and Physician Organizations. The position designs, implements, evaluates, and continuously improves an effective enterprise compliance program that identifies, prevents, detects, investigates, and remediates potential violations of law, regulation, policy, and ethical standards. Reporting to the Senior Vice President, General Counsel, the Vice President & Chief Compliance Officer leads the Health System’s compliance and privacy staff and has direct and unrestricted access to the Chief Executive Officer, senior leadership, and the Audit and Compliance Committee of the Board regarding significant compliance matters.

Essential Responsibilities / Duties

Establishes, leads, and continuously improves the Health System’s enterprise compliance and privacy program to prevent, detect, and address conduct inconsistent with applicable laws, regulations, contractual requirements, ethical standards, and Health System policies. Maintains the independence, authority, visibility, and resources necessary to administer an effective compliance program, working directly with senior leadership, and the Audit and Compliance Committee of the Board. Chairs the Hospital Compliance Oversight Committee; participates in WellSense Health Plan, Boston University Medical Group, and other compliance or governance committees; and provides regular reports to the Boards of Trustees, Audit and Compliance Committee, General Counsel, and senior leadership regarding compliance priorities, significant matters, emerging risks, and corrective actions. (20% of time)

Leads the enterprise compliance risk assessment and annual compliance work-planning process to identify and prioritize regulatory, billing, privacy, operational, financial, and business-conduct risks. Oversees risk-based monitoring, auditing, data analysis, and testing activities; develops key compliance indicators; evaluates trends, audit findings, training completion, reporting activity, and corrective‑action status; and uses results to assess program effectiveness and implement continuous improvements. (20% of time)

Directs the intake, triage, investigation, escalation, documentation, and resolution of reported compliance and privacy concerns in coordination with Legal, Human Resources, Internal Audit, Information Security, and other functions, as appropriate. Maintains confidential reporting channels, promotes good‑faith reporting without fear of retaliation, evaluates substantiated concerns for root causes, and ensures timely and sustainable corrective‑action plans are implemented and monitored. Advises senior management regarding appropriate remediation and disciplinary action for confirmed violations or failures to report or address known concerns. (15% of time)

Provides enterprise oversight of healthcare regulatory compliance and privacy activities, including billing, coding, clinical documentation, reimbursement, medical necessity, cost reporting, government program requirements, and arrangements involving referral sources. Supports compliance with applicable federal and state healthcare laws, including the False Claims Act, Anti‑Kickback Statute, Stark Law, Civil Monetary Penalties Law, exclusion requirements, and other fraud‑and‑abuse provisions. Oversee compliance with HIPAA Privacy, Security, and Breach Notification requirements and 42 CFR Part 2 and participates in the assessment, investigation, mitigation, notification, and remediation of potential privacy and information‑security incidents. (15% of time)

Develops and oversees enterprise compliance and privacy education, communication, and policy‑management programs to ensure employees, leaders, clinicians, contractors, and other workforce members understand applicable standards, policies, reporting expectations, and individual responsibilities. Maintains and regularly updates the Code of Conduct, compliance and privacy policies, training materials, and related communications. Promotes a culture of integrity, accountability, transparency, ethical decision‑making, and non‑retaliation through visible leadership and ongoing engagement with clinical and operational teams. (10% of time)

Oversees compliance due diligence and monitoring related to third parties, transactions, and business arrangements, including vendors, contractors, delegated entities, providers, business partners, and other external parties. Ensures effective processes are maintained for required exclusion, debarment, licensure, and sanction screening. Advises on compliance considerations associated with acquisitions, affiliations, joint ventures, clinical arrangements, value‑based care initiatives, new programs, and other significant business activities. (10% of time)

Coordinates the Health System’s response to compliance‑related government and payer inquiries, audits, subpoenas, investigations, and information requests in partnership with Legal Counsel and other appropriate leaders. Evaluates potential overpayments, reportable events, and disclosure obligations and oversees timely remediation, repayment, reporting, or self‑disclosure when required. Ensures the Health System cooperates with government and payer reviews and maintains appropriate documentation, escalation, and follow‑through. (5% of time)

Leads, develops, and retains a high‑performing compliance and privacy team by establishing clear priorities, accountability, performance expectations, and resource allocation. Partners with Legal, Finance, Internal Audit, Human Resources, Quality, Patient Safety, Information Security, clinical leadership, and operational leaders to integrate compliance and privacy considerations into organizational decisions and daily operations. Maintains current knowledge of federal and state laws, regulations, enforcement priorities, and industry standards and translates changes into timely organizational action. Adheres to and models BMC’s behavioral attributes: responsibility, empathy, service excellence, problem solving and continuous improvement, efficiency, cultural competency, and teamwork. (5% of time)

Required Education And Experience

Bachelor’s degree in business, healthcare administration, law, public health, or a related field and at least twelve (12) years of progressively responsible healthcare compliance, privacy, legal, regulatory, audit, or related experience, including experience leading a compliance program in a complex healthcare organization. Or equivalent combination of education and experience.

Preferred Education And Experience

Graduate degree in law, business administration, healthcare administration, public health, or a related discipline preferred. Experience leading compliance within an integrated health system that includes hospitals, physician organizations, health plans, accountable care arrangements, or value‑based care entities is preferred.

Certifications, Licenses, Registrations Preferred

Certification in Healthcare Compliance, or CHC; Certified in Healthcare Privacy Compliance, or CHPC; Certified Compliance and Ethics Professional, or CCEP; or another relevant compliance, privacy, audit, or legal credential preferred.

KNOWLEDGE, SKILLS & ABILITIES (KSAs)
  • Knowledge of federal and state healthcare compliance requirements, including fraud‑and‑abuse, billing, coding, reimbursement, privacy, and government program regulations.
  • Working knowledge of pharmacy regulations and 340B compliance requirements.
  • Ability to design, implement, and evaluate an enterprise compliance and privacy program using recognized regulatory guidance and program‑effectiveness measures.
  • Ability to conduct compliance risk assessments and translate identified risks into prioritized monitoring, auditing, education, and corrective‑action plans.
  • Ability to direct sensitive investigations, assess evidence, document findings, identify root causes, and oversee sustainable corrective actions.
  • Ability to interpret complex laws, regulations, enforcement guidance, payer requirements, and contractual obligations and translate them into operational requirements.
  • Ability to develop and present compliance reports, trends, key indicators, and significant findings to executive leaders, governance committees, and Boards of Trustees.
  • Ability to manage confidential reporting channels, non‑retaliation processes, regulatory inquiries, repayment obligations, and government or payer disclosures.
  • Ability to lead a multidisciplinary compliance and privacy team and coordinate work across legal, clinical, operational, financial, audit, information‑security, and human‑resources functions.
Compensation Range

Compensation Range: $321,400 - $370,000. This range offers an estimate based on the minimum job qualifications. However, our approach to determining base pay is comprehensive, and a broad range of factors is considered when making an offer. This includes education, experience, skills, and certifications/licensures as they directly relate to position requirements; as well as business/organizational needs, internal equity, and market‑competitiveness. In addition, BMCHS offers generous total compensation that includes, but is not limited to, benefits (medical, dental, vision, pharmacy), discretionary annual bonuses and merit increases, Flexible Spending Accounts, 403(b) savings matches, paid time off, career advancement opportunities, and resources to support employee and family well‑being.

NOTE: This range is based on Boston‑area data, and is subject to modification based on geographic location.

Equal Opportunity Employer/Disabled/Veterans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Chief Compliance Officer
VP, Chief Compliance Officer

Boston Medical Center, Corp. • Boston (MA), Northern (KY)

Hybrid
USD 321,000 - 370,000
VP, Chief Compliance Officer
VP, Chief Compliance Officer

Boston Medical Center • Boston (MA)

On-site
USD 321,000 - 370,000
Medical
Dental
Vision
+7
Operations Manager - Cardiology
Operations Manager - Cardiology

Boston Medical Center • Boston (MA)

On-site
USD 78,000 - 113,000
Senior Risk Management Specialist
Senior Risk Management Specialist

BMC Health System • Boston (MA), Northern (KY)

Hybrid
USD 98,000 - 142,000
Manager of Training, Standards & Compliance
Manager of Training, Standards & Compliance

Boston Medical Center (BMC) • Boston (MA)

On-site
USD 78,000 - 113,000
Practice Manager, Whitman Primary Care, 40 hours
Practice Manager, Whitman Primary Care, 40 hours

Boston Medical Center (BMC) • Whitman (MA)

On-site
USD 61,000 - 90,000
Quality and Patient Safety Specialist
Quality and Patient Safety Specialist

Boston Medical Center (BMC) • Boston (MA)

On-site
USD 90,000 - 130,000
Quality and Patient Safety Specialist
Quality and Patient Safety Specialist

Boston Medical Center • Boston (MA)

On-site
USD 78,000 - 113,000
Medical benefits
Dental benefits
Vision benefits
+2
Senior Compliance & Privacy Specialist
Senior Compliance & Privacy Specialist

Beth-Israel-Lahey-Health • Boston (MA)

On-site
USD 80,000 - 110,000
Manager of Training, Standards & Compliance
Manager of Training, Standards & Compliance

Boston Medical Center • Boston (MA)

On-site
USD 78,000 - 113,000