SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
UpDoc is building the first clinically validated, physician-supervised AI agent for chronic disease management, founded by Stanford physicians. As the company's first dedicated Compliance Manager, you will design and operate a comprehensive compliance program spanning five critical domains: FDA medical device quality and regulatory, health data privacy and security, healthcare fraud and abuse, clinical governance and licensure, and federal research compliance.
You will report directly to the CEO and CTO, partnering with the in-house regulatory and quality assurance team, outside counsel, and compliance teams at leading health systems. Your responsibilities include:
**Regulatory & Quality Partnership**: Align enterprise compliance requirements with FDA-regulated product and quality systems; support cross-functional compliance as UpDoc expands products, clinical programs, partnerships, and reimbursement models.
**Privacy & Security Compliance**: Serve as HIPAA Privacy Officer; coordinate with Security Officer on HIPAA Security program; own Business Associate Agreements, breach procedures, and data flow documentation; lead SOC 2 Type II and HITRUST readiness; advise on HIPAA, CCPA/CPRA, and emerging health data privacy laws.
**Healthcare Regulatory & Fraud/Abuse**: Build compliance framework for care management and remote monitoring reimbursement pathways; assess arrangements under Anti-Kickback Statute and Stark Law; maintain Corporate Practice of Medicine compliance.
**Clinical Governance & Licensure**: Establish clinician credentialing, licensure, scope of practice, and supervision compliance; ensure appropriate documentation and auditing.
**Research & Grant Compliance**: Support federally funded research compliance, including human subjects protections, IRB coordination, and conflict of interest policies.
**Program Leadership**: Write and maintain policies; lead annual compliance risk assessments; establish training and reporting mechanisms; prepare board-level compliance reporting; serve as primary compliance counterpart to customer legal and security teams.
You bring 8+ years of healthcare compliance experience with at least 3 years in a leadership role. You have deep expertise with FDA-regulated software or digital health products, SaMD quality systems, HIPAA Privacy and Security Rules, BAA negotiation, SOC 2/HITRUST frameworks, and Medicare care management reimbursement compliance. You excel at translating regulation into pragmatic guidance for engineers, clinicians, and executives while maintaining firm positions on critical compliance matters. Preferred qualifications include digital health or clinical AI company experience, federal research compliance exposure, AI-specific regulatory knowledge, relevant certifications (CHC, CHPC, CIPP/US, RAC), and advanced degrees (JD, MPH, MHA).