VP, Chief Compliance Officer

BMC SoftwareBoston, MA
$228,500 - $331,500Hybrid

About The Position

The Vice President & Chief Compliance Officer provides strategic and independent leadership for Boston Medical Center Health System’s compliance and privacy programs across Boston Medical Center hospitals, Health Plan, and Physician Organizations. The position designs, implements, evaluates, and continuously improves an effective enterprise compliance program that identifies, prevents, detects, investigates, and remediates potential violations of law, regulation, policy, and ethical standards. Reporting to the Senior Vice President, General Counsel, the Vice President & Chief Compliance Officer leads the Health System’s compliance and privacy staff and has direct and unrestricted access to the Chief Executive Officer, senior leadership, and the Audit and Compliance Committee of the Board regarding significant compliance matters.

Requirements

  • Bachelor’s degree in business, healthcare administration, law, public health, or a related field
  • At least twelve (12) years of progressively responsible healthcare compliance, privacy, legal, regulatory, audit, or related experience
  • Experience leading a compliance program in a complex healthcare organization
  • Knowledge of federal and state healthcare compliance requirements, including fraud-and-abuse, billing, coding, reimbursement, privacy, and government program regulations.
  • Working knowledge of pharmacy regulations and 340B compliance requirements.
  • Ability to design, implement, and evaluate an enterprise compliance and privacy program using recognized regulatory guidance and program-effectiveness measures.
  • Ability to conduct compliance risk assessments and translate identified risks into prioritized monitoring, auditing, education, and corrective-action plans.
  • Ability to direct sensitive investigations, assess evidence, document findings, identify root causes, and oversee sustainable corrective actions.
  • Ability to interpret complex laws, regulations, enforcement guidance, payer requirements, and contractual obligations and translate them into operational requirements.
  • Ability to develop and present compliance reports, trends, key indicators, and significant findings to executive leaders, governance committees, and Boards of Trustees.
  • Ability to manage confidential reporting channels, non-retaliation processes, regulatory inquiries, repayment obligations, and government or payer disclosures.
  • Ability to lead a multidisciplinary compliance and privacy team and coordinate work across legal, clinical, operational, financial, audit, information-security, and human-resources functions.

Nice To Haves

  • Graduate degree in law, business administration, healthcare administration, public health, or a related discipline
  • Experience leading compliance within an integrated health system that includes hospitals, physician organizations, health plans, accountable care arrangements, or value-based care entities
  • Certification in Healthcare Compliance, or CHC
  • Certified in Healthcare Privacy Compliance, or CHPC
  • Certified Compliance and Ethics Professional, or CCEP
  • Another relevant compliance, privacy, audit, or legal credential

Responsibilities

  • Establishes, leads, and continuously improves the Health System’s enterprise compliance and privacy program to prevent, detect, and address conduct inconsistent with applicable laws, regulations, contractual requirements, ethical standards, and Health System policies. Maintains the independence, authority, visibility, and resources necessary to administer an effective compliance program, working directly with senior leadership, and the Audit and Compliance Committee of the Board. Chairs the Hospital Compliance Oversight Committee; participates in WellSense Health Plan, Boston University Medical Group, and other compliance or governance committees; and provides regular reports to the Boards of Trustees, Audit and Compliance Committee, General Counsel, and senior leadership regarding compliance priorities, significant matters, emerging risks, and corrective actions. (20% of time)
  • Leads the enterprise compliance risk assessment and annual compliance work-planning process to identify and prioritize regulatory, billing, privacy, operational, financial, and business-conduct risks. Oversees risk-based monitoring, auditing, data analysis, and testing activities; develops key compliance indicators; evaluates trends, audit findings, training completion, reporting activity, and corrective-action status; and uses results to assess program effectiveness and implement continuous improvements. (20% of time)
  • Directs the intake, triage, investigation, escalation, documentation, and resolution of reported compliance and privacy concerns in coordination with Legal, Human Resources, Internal Audit, Information Security, and other functions, as appropriate. Maintains confidential reporting channels, promotes good-faith reporting without fear of retaliation, evaluates substantiated concerns for root causes, and ensures timely and sustainable corrective-action plans are implemented and monitored. Advises senior management regarding appropriate remediation and disciplinary action for confirmed violations or failures to report or address known concerns. (15% of time)
  • Provides enterprise oversight of healthcare regulatory compliance and privacy activities, including billing, coding, clinical documentation, reimbursement, medical necessity, cost reporting, government program requirements, and arrangements involving referral sources. Supports compliance with applicable federal and state healthcare laws, including the False Claims Act, Anti-Kickback Statute, Stark Law, Civil Monetary Penalties Law, exclusion requirements, and other fraud-and-abuse provisions. Oversee compliance with HIPAA Privacy, Security, and Breach Notification requirements and 42 CFR Part 2 and participates in the assessment, investigation, mitigation, notification, and remediation of potential privacy and information-security incidents. (15% of time)
  • Develops and oversees enterprise compliance and privacy education, communication, and policy-management programs to ensure employees, leaders, clinicians, contractors, and other workforce members understand applicable standards, policies, reporting expectations, and individual responsibilities. Maintains and regularly updates the Code of Conduct, compliance and privacy policies, training materials, and related communications. Promotes a culture of integrity, accountability, transparency, ethical decision-making, and non-retaliation through visible leadership and ongoing engagement with clinical and operational teams. (10% of time)
  • Oversees compliance due diligence and monitoring related to third parties, transactions, and business arrangements, including vendors, contractors, delegated entities, providers, business partners, and other external parties. Ensures effective processes are maintained for required exclusion, debarment, licensure, and sanction screening. Advises on compliance considerations associated with acquisitions, affiliations, joint ventures, clinical arrangements, value-based care initiatives, new programs, and other significant business activities. (10% of time)
  • Coordinates the Health System’s response to compliance-related government and payer inquiries, audits, subpoenas, investigations, and information requests in partnership with Legal Counsel and other appropriate leaders. Evaluates potential overpayments, reportable events, and disclosure obligations and oversees timely remediation, repayment, reporting, or self-disclosure when required. Ensures the Health System cooperates with government and payer reviews and maintains appropriate documentation, escalation, and follow-through. (5% of time)
  • Leads, develops, and retains a high-performing compliance and privacy team by establishing clear priorities, accountability, performance expectations, and resource allocation. Partners with Legal, Finance, Internal Audit, Human Resources, Quality, Patient Safety, Information Security, clinical leadership, and operational leaders to integrate compliance and privacy considerations into organizational decisions and daily operations. Maintains current knowledge of federal and state laws, regulations, enforcement priorities, and industry standards and translates changes into timely organizational action. Adheres to and models BMC’s behavioral attributes: responsibility, empathy, service excellence, problem solving and continuous improvement, efficiency, cultural competency, and teamwork. (5% of time)

Benefits

  • medical
  • dental
  • vision
  • pharmacy
  • discretionary annual bonuses
  • merit increases
  • Flexible Spending Accounts
  • 403(b) savings matches
  • paid time off
  • career advancement opportunities
  • resources to support employee and family well-being
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service