Director of Corporate Compliance - Hickory Recovery NetworkDepartment: Compliance
Direct Report To: Chief Compliance Officer
About the RoleThe Director of Corporate Compliance provides senior leadership and oversight for three core areas of Hickory Recovery Network's compliance program - Privacy & Security, Fraud, Waste & Abuse (FWA), and Risk & Monitoring. Reporting to the Chief Compliance Officer, the Director is accountable for the design, implementation, and effectiveness of these functions across HRN's behavioral health and substance-use-disorder (SUD) treatment operations, ensuring compliance with applicable laws and regulations - including HIPAA, 42 CFR Part 2, the federal Anti-Kickback Statute and Stark Law, and fraud, waste, and abuse requirements. The Director leads assigned staff and external partners, sets priorities aligned to the annual risk-based work plan, and reports program performance to the CCO and the Compliance Committee.
Job Qualifications- Bachelor's degree in healthcare administration, business, nursing, health information management, law, or a related field required; master's degree or JD preferred.
- Minimum 5 years of progressive healthcare compliance experience spanning privacy, FWA/billing, and/or risk and monitoring, including leadership or supervisory experience; behavioral health or SUD treatment experience strongly preferred.
- Certified in Healthcare Compliance (CHC) required, or required within 12 months of hire; CHPC, CHRC, or CCEP preferred.
- Coordinating multiple projects and managing complex documentation preferred.
- Exceptional communication, strategic thinking, and change-management skills.
- Strong understanding of compliance, security, and HIPAA regulations.
- Ability to occasionally travel to company facilities for audits, projects, training, or operational support.
- Ability to maintain the confidentiality of protected health information and SUD treatment records in accordance with HIPAA and 42 CFR Part 2.
Key ResponsibilitiesPrivacy & Security - Oversee the privacy program, HIPAA and 42 CFR Part 2 compliance, breach/incident response, and consent and redisclosure governance.
- Direct the HIPAA & Privacy Compliance Committee and partner with the CISO/IT on security risk analysis and safeguards (cybersecurity liaison).
- Ensure access auditing, minimum-necessary practices, and workforce privacy training.
Fraud, Waste & Abuse (FWA) - Oversee the FWA and revenue-integrity program, coding and billing compliance, and overpayment identification (including the 60-day rule).
- Direct anti-kickback and Stark compliance review and self-disclosure coordination in partnership with Legal.
- Ensure proactive detection, root-cause analysis, and timely remediation of identified issues.
Risk & Monitoring - Own the enterprise compliance risk assessment and risk register (with Ankura), ensuring the register drives the annual work plan.
- Direct the monitoring and testing program and the build-out of data analytics capabilities.
- Identify emerging risks and regulatory developments and escalate to the Chief Compliance Officer.
Leadership & Program Management - Lead, develop, and supervise assigned staff (including Health Information Management) and manage external partners (e.g., Ankura), coordinating matrixed work with Legal and Compliance Operations.
- Execute assigned elements of the annual risk-based compliance work plan and report effectiveness measures to the CCO and Compliance Committee.
- Support board reporting, auditing, investigations, and corrective action as they relate to these functions.
- Deputize for the Chief Compliance Officer on assigned matters.
Supervisory Responsibilities - Supervises the Health Information Management function and risk/analytics staff as assigned, including direction, coaching, workload prioritization, and performance management. Coordinates matrixed work with In-house Counsel (FWA) and the Compliance Manager (Compliance Operations).
Core Competencies- In-depth knowledge of the OIG seven elements; HIPAA/HITECH; 42 CFR Part 2; the Anti-Kickback Statute and Stark Law; fraud, waste, and abuse; coding/billing compliance; and risk-assessment and monitoring methodologies.
- Demonstrated ability to build, lead, and measure compliance functions in a multi-site healthcare environment.
- Strong leadership, analytical, and communication skills, with sound judgment and the ability to influence across functions.
- Ability to translate risk into prioritized, resourced work plans and to report effectiveness to executives and the Board.
- Proficiency with compliance, risk, and case-management systems and Microsoft Office applications.
Compensation$130,000 - $140,000 annuallyLearn Morehttps://hickorytreatmentcenters.com/