Senior Director, Compliance and Privacy

Blue Cross Blue Shield Association•Washington, DC
•$173,400 - $251,400•Hybrid

About The Position

This role is responsible for providing strategic direction and oversight for the organization's corporate compliance and privacy programs. It ensures alignment with evolving healthcare regulations, industry standards, and internal policies. As a key advisor to executive leadership, the Board of Directors, and governance committees, the role fosters a culture of ethics, accountability, and transparency across the enterprise. This role will serve as the designated Privacy Official, responsible for the development and implementation of policies and procedures, personnel training, and processes to investigate and respond to complaints regarding impermissible uses or disclosures of PHI and related policy violations. Has full ownership of HIPAA compliance for BCBSA. The position leads a team of compliance and privacy professionals, driving continuous improvement and operational excellence. It plays a critical role in risk mitigation, regulatory readiness, and the development of policies and practices that safeguard patient and organizational data.

Requirements

  • BS or equivalent work experience
  • 12+ Years Experience in the healthcare industry with demonstrated knowledge of regulatory, privacy (HIPAA), and compliance and ethics issues
  • Proven ability to lead teams, drive organizational change, and influence cross-functional initiatives in complex environments.
  • Deep understanding of healthcare compliance, privacy program administration, and data security technologies, including HIPAA and GDPR.
  • Strong capability to assess regulatory and operational risks and develop effective mitigation strategies.
  • Excellent analytical skills with sound business judgment, creativity, and initiative to solve complex problems.
  • Advanced interpersonal and communication skills, including experience facilitating training and presenting to executive leadership and governance bodies.
  • Ability to build and maintain credible relationships with internal and external stakeholders, including senior executives and board members.
  • Skilled in strategic project planning and execution, with the ability to remain composed and tactful under pressure.
  • Competent in Microsoft Office applications and other relevant compliance and privacy tools.
  • Understanding of data security technologies and privacy program administration
  • Minimum twelve years' experience in the healthcare business arena with demonstrated knowledge of current regulatory and compliance and ethics issues, including knowledge of and experience working with Centers for Medicare and Medicaid Services/Medicare compliance requirements.
  • Experience managing privacy programs subject to healthcare laws and regulations, including HIPAA.
  • Must have at least one year of experience managing privacy programs subject to healthcare laws and regulations, and a proven track record of leading and implementing regulatory compliance initiatives.
  • Direct experience with CMS/Medicare compliance requirements is required.
  • Proven record in leading and implementing regulatory compliance programs

Nice To Haves

  • MS in Law; Business Administration; or equivalents
  • Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.
  • Licensed Attorney (varies by state)
  • Professional, Academy for Health Care Management (PAHM)
  • Certified Information Privacy Professional (CIPP)

Responsibilities

  • Serve as BCBSA’s Medicare Compliance Official for purposes of complying with Medicare Compliance obligations.
  • Serve as the subject matter expert for Medicare Part D and other government programs compliance.
  • Build and oversee the operations of government programs compliance programs, as necessary.
  • Support and oversee the operations of Compliance Committee(s), and report findings to leadership and through appropriate BCBSA governance Committee(s).
  • Serve as BCBSA's Compliance Official.
  • Provide leadership and operational oversight for BCBSA's Compliance and Ethics Program, including the Code of Business Conduct and annual reporting to leadership and the Board.
  • Address compliance issues in collaboration with internal stakeholders.
  • Serve as BCBSA’s Privacy Official for purposes of HIPAA compliance.
  • Oversee the organization’s Privacy Program, including HIPAA and GDPR compliance.
  • Lead cross-functional efforts to investigate and resolve privacy incidents.
  • Lead and develop a high-performing compliance and privacy team, fostering professional growth and a positive, inclusive work environment.
  • Promote best practices and coordinate incident response efforts across the system.
  • Oversee compliance and ethics training programs for Blue Plan Compliance leaders.

Benefits

  • paid time off
  • 11 holidays
  • medical/dental/vision insurance
  • generous 401(k) matching
  • lifestyle spending account
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service