Blue Cross and Blue Shield Association

Senior Director, Compliance and Privacy

Healthcare
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • BS degree or equivalent work experience required; MS in Law or Business Administration preferred.
  • 12+ years of experience in the healthcare industry, specializing in regulatory compliance and privacy (HIPAA).
  • Proven leadership skills in managing teams and driving organizational change.
  • In-depth knowledge of HIPAA, GDPR, and compliance ethics within healthcare.
  • Strong analytical, communication, and interpersonal skills.

Responsibilities

  • Serve as BCBSA’s Medicare Compliance Official, overseeing compliance obligations.
  • Lead BCBSA's Compliance and Ethics Program, including the annual reporting to leadership and the Board.
  • Manage and implement HIPAA compliance as BCBSA’s Privacy Official.
  • Investigate and resolve privacy incidents across the organization.
  • Develop high-performing compliance and privacy teams, promoting professional growth.

Benefits

  • Paid time off and 11 holidays.
  • Medical, dental, and vision insurance.
  • Generous 401(k) matching.
  • Lifestyle spending account.
  • Additional benefits available to eligible employees.
Full Job Description
Job Description Summary:

This role is responsible for providing strategic direction and oversight for the organization's corporate compliance and privacy programs. It ensures alignment with evolving healthcare regulations, industry standards, and internal policies. As a key advisor to executive leadership, the Board of Directors, and governance committees, the role fosters a culture of ethics, accountability, and transparency across the enterprise. This role will serve as the designated Privacy Official, responsible for the development and implementation of policies and procedures, personnel training, and processes to investigate and respond to complaints regarding impermissible uses or disclosures of PHI and related policy violations. Has full ownership of HIPAA compliance for BCBSA.

The position leads a team of compliance and privacy professionals, driving continuous improvement and operational excellence. It plays a critical role in risk mitigation, regulatory readiness, and the development of policies and practices that safeguard patient and organizational data.

Responsibilities include but are not limited to:


Government Programs Compliance
• Serve as BCBSA’s Medicare Compliance Official for purposes of complying with Medicare Compliance obligations.
• Serve as the subject matter expert for Medicare Part D and other government programs compliance.
• Build and oversee the operations of government programs compliance programs, as necessary
• Support and oversee the operations of Compliance Committee(s), and report findings to leadership and through appropriate BCBSA governance Committee(s).

Corporate Compliance Oversight
• Serve as BCBSA's Compliance Official
• Provide leadership and operational oversight for BCBSA's Compliance and Ethics Program, including the Code of Business Conduct and annual reporting to leadership and the Board.
• Address compliance issues in collaboration with internal stakeholders.

Privacy Program Leadership
• Serve as BCBSA’s Privacy Official for purposes of HIPAA compliance
• Oversee the organization’s Privacy Program, including HIPAA and GDPR compliance.
• Lead cross-functional efforts to investigate and resolve privacy incidents.

Team Leadership
• Lead and develop a high-performing compliance and privacy team, fostering professional growth and a positive, inclusive work environment.
Systemwide Engagement
• Promote best practices and coordinate incident response efforts across the system.

Training & Education
• Oversee compliance and ethics training programs for Blue Plan Compliance leaders.

The posting range for this position is:

173,400.00 - 251,400.00



Required Education, Certifications and Experience:


Education

  • Required BS or equivalent work experience
  • Preferred MS in Law; Business Administration; or equivalents

Experience

  • Required 12+ Years Experience in the healthcare industry with demonstrated knowledge of regulatory, privacy (HIPAA), and compliance and ethics issues


Knowledge Skills and Abilities

  • Proven ability to lead teams, drive organizational change, and influence cross-functional initiatives in complex environments.
  • Deep understanding of healthcare compliance, privacy program administration, and data security technologies, including HIPAA and GDPR.
  • Strong capability to assess regulatory and operational risks and develop effective mitigation strategies.
  • Excellent analytical skills with sound business judgment, creativity, and initiative to solve complex problems.
  • Advanced interpersonal and communication skills, including experience facilitating training and presenting to executive leadership and governance bodies.
  • Ability to build and maintain credible relationships with internal and external stakeholders, including senior executives and board members.
  • Skilled in strategic project planning and execution, with the ability to remain composed and tactful under pressure.
  • Competent in Microsoft Office applications and other relevant compliance and privacy tools.
  • Understanding of data security technologies and privacy program administration
  • Preferred: Demonstrates AI literacy and an understanding of generative AI tools, including appropriate business applications and limitations.



Certifications & Licenses

  • Preferred: Licensed Attorney (varies by state) - Various
  • Preferred: Professional, Academy for Health Care Management (PAHM) - AHIP
  • Preferred: Certified Information Privacy Professional (CIPP) - IAPP



Extra Posting Information:

  • Minimum twelve years' experience in the healthcare business arena with demonstrated knowledge of current regulatory and compliance and ethics issues, including knowledge of and experience working with Centers for Medicare and Medicaid Services/Medicare compliance requirements.
  • Experience managing privacy programs subject to healthcare laws and regulations, including HIPAA
  • Must have at least one year of experience managing privacy programs subject to healthcare laws and regulations, and a proven track record of leading and implementing regulatory compliance initiatives.
  • Direct experience with CMS/Medicare compliance requirements is required.
  • Proven record in leading and implementing regulatory compliance programs



#LI_HYBRID

The posted salary range is the lowest to highest salary we, in good faith, believe we would pay for this role at the time of this posting.  We may ultimately pay more or less than the hiring range andthis hiring range may also be modified in the future. A candidate’s position within the hiring range may be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, relevant experience, skills, seniority, performance, shift, travel requirements, and business or organizational needs.This job is also eligible for annual bonusincentive pay.

We offer a comprehensive package of benefits including paid time off, 11 holidays,medical/dental/vision insurance, generous 401(k) matching, lifestyle spending account and many other benefits to eligible employees.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.

About Blue Cross and Blue Shield Association

The Blue Cross Blue Shield Association (BCBSA) is a federation of 36 separate United States health insurance companies that provide health insurance in the United States to more than 106 million people. It was formed in 1982 from the merger of its two namesake organizations: Blue Cross was founded in 1929 and became the Blue Cross Association in 1960, while Blue Shield emerged in 1939 and the Blue Shield Association was created in 1948. The Blue Cross Blue Shield Association is headquartered in Chicago and has offices in Washington, D.C. The association provides health insurance products and services to more than 106 million Americans.
Learn more about Blue Cross and Blue Shield Association
Size
1,000 employees
Industry
Founded
1929

Similar Jobs

More Jobs at Blue Cross and Blue Shield Association

More Healthcare Jobs

Find similar Senior Director, Compliance and Privacy jobs: