About the Role As
Senior Director, Compliance and Regulatory Affairs, you will own end-to-end accountability for OpenLoop's compliance program and demonstrable regulatory readiness across every regime that governs a multi-state telehealth company. You'll report to the VP of Compliance, Healthcare, sit alongside the Director of RCM/RPM Audit as a peer, and serve as the named responsible executive in regulator-facing documentation. The Training, Education & Culture function folds directly into this role - you personally own OIG Element 3 and the broader culture-of-compliance mandate.
What You'll Do- Compliance program design & oversight: Stand up and maintain all seven OIG elements as an effective, documented compliance program - you own written standards, training and education, and program oversight directly. Serve as the designated compliance officer for regulators, payors, and auditors.
- Policy, governance & standards: Own the policy and SOP lifecycle - authoring, versioning, attestation, and retirement across all OpenLoop subsidiaries. Maintain the governance framework and map all policies to OIG, FDA, GDPR, and CMS controls.
- Privacy & data protection (HIPAA/GDPR): Own the HIPAA Privacy and Security programs; manage breach response from detection through notification and documentation. Serve as or directly support the GDPR Data Protection Officer function.
- Investigations, ethics & screening: Oversee the hotline and investigation program - intake, triage, root-cause analysis, corrective action, and self-disclosure workflow. Own the exclusion and sanction screening program and administer the conflict-of-interest program.
- FDA & regulatory affairs: Establish quality-system and promotional controls for regulated device, diagnostic, and SaMD components. Track FDA regulatory status for RPM devices and connected-health components, and maintain the Stark Law and non-monetary compensation tracking program.
- Training, education & culture (OIG Element 3): Personally hold OIG Element 3 - design and maintain the compliance training curriculum across the workforce and clinician network, and set the cultural tone that compliance is infrastructure, not obstacle.
- Team leadership & governance: Manage the Healthcare Investigations Manager, Policy & Governance Manager, Exclusion & Sanction Screening Lead, and HIPAA & Privacy Compliance Manager. Oversee the Conflict of Interest Program Administrator and Stark Law & Non-Monetary Comp Analyst. Prepare board and leadership reporting on program status, risk posture, and open corrective actions.
- Other duties as assigned.
Who You Are- 12+ years in healthcare compliance, regulatory affairs, or health law, with end-to-end compliance program ownership - you've run it, not just contributed to it.
- Deep working knowledge of the OIG Seven Elements framework.
- HIPAA Privacy and Security program ownership; GDPR experience strongly preferred.
- FDA regulatory experience (device, SaMD, or digital health) a strong plus.
- Experience managing and developing a compliance team in a multi-state, technology-forward healthcare or pharmacy-adjacent environment.
- Familiarity with the telehealth regulatory landscape - multi-state practice authority and prescribing rules.
- CHC, CHPC, CCEP, or equivalent compliance credential preferred.
- Executive presence and sound judgment; comfortable being named as the responsible executive in regulator-facing documentation.
- High integrity, low-ego collaborator who can influence across Legal, Product, Security, and Clinical.
Our BenefitsIn addition, for salaried positions you would also be eligible for:
- Medical, Dental, and Vision plans
- Flexible Spending/Health Savings Accounts
- Flexible PTO
- 401(k) + Company Match
- Life Insurance, Pet insurance, and more