Compliance Manager

Posted 5 Hours Ago
Be an Early Applicant
7 Locations
In-Office or Remote
Senior level
Healthtech • Telehealth
The Role
Build and lead UpDoc’s healthcare compliance program across FDA-regulated software, privacy and security, fraud and abuse, clinical governance, licensure, and federal research. Serve as HIPAA Privacy Officer, manage BAAs and privacy processes, support SOC 2 and HITRUST readiness, oversee reimbursement and clinical compliance, establish policies and training, conduct risk assessments, and report compliance risks to executives and the Board.
Summary Generated by Built In
About UpDoc

At UpDoc, we are building the first clinically validated, physician-supervised AI agent that manages chronic diseases. We are an early-stage startup founded by Stanford physicians.

We are seeking a Compliance Manager to build and manage the compliance foundation that enables UpDoc to develop, deploy, and scale our technology responsibly. Compliance is central to how we earn the trust of health systems, regulators, payers, and patients while operating at the frontier of what software is permitted to do in medicine.

This is a remote role, with candidates preferred to be physically located in the San Francisco Bay Area.

The Role

You will be UpDoc's first dedicated compliance leader, owning the design and operation of our compliance program across five domains that rarely sit under one roof: medical device quality and regulatory, health data privacy and security, healthcare fraud and abuse, clinical governance and licensure, and federal research compliance.

You will work directly with the CEO, CTO, in-house regulatory and quality assurance team, outside counsel, and compliance teams at leading health systems.

Who You Are
  • You bring a thoughtful, risk-based approach to compliance, distinguishing between regulatory requirements, best practices, and business preferences and applying the appropriate level of scrutiny.

  • You exercise strong judgment and are comfortable taking a firm position when necessary, while working collaboratively to identify practical, compliant solutions.

  • You are a clear and precise communicator, capable of producing policies, responses, and documentation for regulators, auditors, health systems, and outside counsel.

  • You are comfortable navigating evolving regulatory environments and applying sound judgment where requirements or precedent are not yet fully established.

What You’ll OwnRegulatory & Quality Partnership
  • Partner with our Regulatory and Quality team where enterprise compliance requirements intersect with UpDoc’s FDA-regulated product and quality system.

  • Ensure broader compliance policies and processes align with established regulatory and quality requirements.

  • Support cross-functional compliance considerations as UpDoc expands its products, clinical programs, partnerships, and reimbursement models.

Privacy & Security Compliance
  • Serve as the HIPAA Privacy Officer and coordinate closely with the Security Officer on our HIPAA Security program.

  • Own Business Associate Agreements, minimum-necessary practices, and breach assessment and notification procedures, and partner with Security and Engineering on data flow documentation.

  • Partner with Security on SOC 2 Type II and HITRUST readiness and lead compliance responses to health system vendor risk assessments.

  • Advise on applicable federal and state privacy requirements, including HIPAA, CCPA/CPRA, and emerging health data privacy laws.

Healthcare Regulatory & Fraud and Abuse
  • Build the compliance framework for applicable care management, remote monitoring, and other reimbursement pathways, including documentation, supervision, and time-tracking requirements.

  • Assess arrangements with health systems, clinicians, and partners under the Anti-Kickback Statute, Stark Law, and beneficiary inducement rules, working with outside counsel.

  • Maintain Corporate Practice of Medicine compliance across the states in which we operate.

Clinical Governance & Licensure
  • Establish and oversee compliance requirements for clinician credentialing, licensure, scope of practice, and supervision, in partnership with Clinical Operations.

  • Ensure care delivered through UpDoc is appropriately documented, escalated, and audited to meet UpDoc's clinical governance standards and the requirements of partner health systems.

Research & Grant Compliance
  • Support compliance for federally funded research and grant programs, including human subjects protections, IRB coordination, data management requirements, and cost allowability.

  • Maintain conflict of interest and research integrity policies.

Program Leadership
  • Write, maintain, and train the company on policies and procedures; lead the annual compliance risk assessment and work plan.

  • Establish compliance training, reporting mechanisms, and an audit and monitoring cadence.

  • Prepare regular compliance and risk reporting for the CEO and Board.

  • Serve as the primary compliance counterpart to customer legal, privacy, and IT security teams during contracting and implementation.

  • Coordinate with outside counsel, auditors, and specialized advisors as needed.

What We’re Looking ForRequired
  • 8+ years of healthcare compliance experience, with at least 3 years in a leadership or program-owner role.

  • Experience working with FDA-regulated software or digital health products, with a strong understanding of SaMD quality systems and post-market obligations.

  • Deep working knowledge of HIPAA Privacy and Security Rules and experience negotiating BAAs with health systems.

  • Experience supporting SOC 2, HITRUST, or comparable healthcare security and compliance frameworks.

  • Familiarity with Medicare care management reimbursement compliance and healthcare fraud and abuse law.

  • Track record of building programs from an early stage rather than solely administering mature ones.

  • Ability to translate regulation into pragmatic guidance for engineers, clinicians, and executives, and to hold a firm line when it matters.

Strongly Preferred
  • Experience at a digital health or clinical AI company selling into large health systems or academic medical centers.

  • Exposure to federal research compliance, including NIH, ARPA-H, or similar federally funded programs.

  • Familiarity with AI-specific regulatory developments, including FDA guidance on AI-enabled device software and predetermined change control plans.

  • Certification such as CHC, CHPC, CIPP/US, or RAC.

  • JD, MPH, MHA, or equivalent graduate training; a clinical background is a plus.

Skills Required

  • 8+ years of healthcare compliance experience
  • At least 3 years in a leadership or program-owner role
  • Experience working with FDA-regulated software or digital health products
  • Strong understanding of SaMD quality systems and post-market obligations
  • Deep working knowledge of HIPAA Privacy and Security Rules
  • Experience negotiating Business Associate Agreements with health systems
  • Experience supporting SOC 2, HITRUST, or comparable healthcare security and compliance frameworks
  • Familiarity with Medicare care management reimbursement compliance and healthcare fraud and abuse law
  • Track record of building compliance programs at an early stage
  • Ability to translate regulations into practical guidance for engineers, clinicians, and executives
  • Experience at a digital health or clinical AI company selling to large health systems or academic medical centers
  • Exposure to federal research compliance, including NIH, ARPA-H, or similar programs
  • Familiarity with AI-specific regulatory developments and FDA guidance on AI-enabled device software
  • Familiarity with predetermined change control plans
  • Certification such as CHC, CHPC, CIPP/US, or RAC
  • JD, MPH, MHA, or equivalent graduate training
  • Clinical background
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
18 Employees
Year Founded: 2021

What We Do

Updoc is an Australian digital healthcare platform that enables 24/7 online consultations with AHPRA-registered partner doctors. It helps users obtain medical certificates, prescriptions, referrals, and other care through a secure service available across Australia. Its mission is to make healthcare more accessible and convenient by using technology to connect patients with practitioners and improve timely access to care for Australians.

Similar Jobs

Remote
Canada
441 Employees
165K-200K Annually

Quo Logo Quo

Senior Product Manager

Software • App development • Conversational AI
In-Office or Remote
Toronto, ON, CAN
160 Employees
166K-196K Annually

Portless Logo Portless

Senior Product Manager

eCommerce • Logistics • Transportation
Remote
2 Locations
42 Employees

The Utopia Studio Logo The Utopia Studio

Legal & Compliance Manager

Angel or VC Firm • Artificial Intelligence • Software
Remote or Hybrid
7 Locations
3 Employees
50K-50K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account