UpDoc Logo

UpDoc

Compliance Manager

Posted 14 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in CA
Senior level
In-Office or Remote
Hiring Remotely in CA
Senior level
Build and lead UpDoc’s healthcare compliance program across FDA-regulated software, privacy and security, fraud and abuse, clinical governance, licensure, and federal research. Serve as HIPAA Privacy Officer, manage BAAs and privacy processes, support SOC 2 and HITRUST readiness, oversee reimbursement and clinical compliance, establish policies and training, conduct risk assessments, and report compliance risks to executives and the Board.
The summary above was generated by AI
About UpDoc

At UpDoc, we are building the first clinically validated, physician-supervised AI agent that manages chronic diseases. We are an early-stage startup founded by Stanford physicians.

We are seeking a Compliance Manager to build and manage the compliance foundation that enables UpDoc to develop, deploy, and scale our technology responsibly. Compliance is central to how we earn the trust of health systems, regulators, payers, and patients while operating at the frontier of what software is permitted to do in medicine.

This is a remote role, with candidates preferred to be physically located in the San Francisco Bay Area.

The Role

You will be UpDoc's first dedicated compliance leader, owning the design and operation of our compliance program across five domains that rarely sit under one roof: medical device quality and regulatory, health data privacy and security, healthcare fraud and abuse, clinical governance and licensure, and federal research compliance.

You will work directly with the CEO, CTO, in-house regulatory and quality assurance team, outside counsel, and compliance teams at leading health systems.

Who You Are
  • You bring a thoughtful, risk-based approach to compliance, distinguishing between regulatory requirements, best practices, and business preferences and applying the appropriate level of scrutiny.

  • You exercise strong judgment and are comfortable taking a firm position when necessary, while working collaboratively to identify practical, compliant solutions.

  • You are a clear and precise communicator, capable of producing policies, responses, and documentation for regulators, auditors, health systems, and outside counsel.

  • You are comfortable navigating evolving regulatory environments and applying sound judgment where requirements or precedent are not yet fully established.

What You’ll OwnRegulatory & Quality Partnership
  • Partner with our Regulatory and Quality team where enterprise compliance requirements intersect with UpDoc’s FDA-regulated product and quality system.

  • Ensure broader compliance policies and processes align with established regulatory and quality requirements.

  • Support cross-functional compliance considerations as UpDoc expands its products, clinical programs, partnerships, and reimbursement models.

Privacy & Security Compliance
  • Serve as the HIPAA Privacy Officer and coordinate closely with the Security Officer on our HIPAA Security program.

  • Own Business Associate Agreements, minimum-necessary practices, and breach assessment and notification procedures, and partner with Security and Engineering on data flow documentation.

  • Partner with Security on SOC 2 Type II and HITRUST readiness and lead compliance responses to health system vendor risk assessments.

  • Advise on applicable federal and state privacy requirements, including HIPAA, CCPA/CPRA, and emerging health data privacy laws.

Healthcare Regulatory & Fraud and Abuse
  • Build the compliance framework for applicable care management, remote monitoring, and other reimbursement pathways, including documentation, supervision, and time-tracking requirements.

  • Assess arrangements with health systems, clinicians, and partners under the Anti-Kickback Statute, Stark Law, and beneficiary inducement rules, working with outside counsel.

  • Maintain Corporate Practice of Medicine compliance across the states in which we operate.

Clinical Governance & Licensure
  • Establish and oversee compliance requirements for clinician credentialing, licensure, scope of practice, and supervision, in partnership with Clinical Operations.

  • Ensure care delivered through UpDoc is appropriately documented, escalated, and audited to meet UpDoc's clinical governance standards and the requirements of partner health systems.

Research & Grant Compliance
  • Support compliance for federally funded research and grant programs, including human subjects protections, IRB coordination, data management requirements, and cost allowability.

  • Maintain conflict of interest and research integrity policies.

Program Leadership
  • Write, maintain, and train the company on policies and procedures; lead the annual compliance risk assessment and work plan.

  • Establish compliance training, reporting mechanisms, and an audit and monitoring cadence.

  • Prepare regular compliance and risk reporting for the CEO and Board.

  • Serve as the primary compliance counterpart to customer legal, privacy, and IT security teams during contracting and implementation.

  • Coordinate with outside counsel, auditors, and specialized advisors as needed.

What We’re Looking ForRequired
  • 8+ years of healthcare compliance experience, with at least 3 years in a leadership or program-owner role.

  • Experience working with FDA-regulated software or digital health products, with a strong understanding of SaMD quality systems and post-market obligations.

  • Deep working knowledge of HIPAA Privacy and Security Rules and experience negotiating BAAs with health systems.

  • Experience supporting SOC 2, HITRUST, or comparable healthcare security and compliance frameworks.

  • Familiarity with Medicare care management reimbursement compliance and healthcare fraud and abuse law.

  • Track record of building programs from an early stage rather than solely administering mature ones.

  • Ability to translate regulation into pragmatic guidance for engineers, clinicians, and executives, and to hold a firm line when it matters.

Strongly Preferred
  • Experience at a digital health or clinical AI company selling into large health systems or academic medical centers.

  • Exposure to federal research compliance, including NIH, ARPA-H, or similar federally funded programs.

  • Familiarity with AI-specific regulatory developments, including FDA guidance on AI-enabled device software and predetermined change control plans.

  • Certification such as CHC, CHPC, CIPP/US, or RAC.

  • JD, MPH, MHA, or equivalent graduate training; a clinical background is a plus.

Similar Jobs

10 Hours Ago
In-Office or Remote
CA
Senior level
Senior level
Artificial Intelligence • Information Technology • Software
Own Retell AI’s security and compliance program, including SOC 2 Type II, HIPAA, and ISO 27001 audits; manage auditors, GRC tools, policies, vendor risk, training, security questionnaires, RFP responses, and the trust center. Partner with Engineering and Sales, support enterprise customer calls, monitor regulatory changes affecting voice AI, and build an audit-ready compliance program.
Top Skills: DrataGrc PlatformsHipaaIso 27001Soc 2 Type IiVanta
14 Days Ago
Remote
Canada
Senior level
Senior level
Gaming
Manages a data engineering team and oversees scalable, reliable data pipelines, infrastructure, tooling, and architecture. Partners with analytics, finance, compliance, product, and engineering stakeholders while communicating with regulators and supporting audit-driven deadlines. Responsibilities include team leadership, project prioritization, technical guidance, data governance, system design, performance management, and continuous improvement of data engineering practices.
Top Skills: AirflowAtlassianAWSAws LambdaDbtDjangoDockerFlaskGCPKubernetesPythonReactSQLTerraform
19 Days Ago
In-Office or Remote
Senior level
Senior level
Software • App development • Conversational AI
Own Quo’s billing, accounts and identity, and telecom compliance product domains. Lead metering, entitlements, invoicing, payment recovery, authentication, SSO, permissions, regulatory registration, fraud tooling, and deliverability systems. Build roadmaps, translate pricing into system behavior, partner with engineering on APIs and data models, and coordinate with finance, legal, security, and compliance stakeholders to deliver highly reliable systems.
Top Skills: A2P 10DlcAPIsAuthenticationIdentity And Access ManagementPayment ProcessingSsoTelecom Compliance SystemsUsage Metering

What you need to know about the Calgary Tech Scene

Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account