UpDoc Logo

UpDoc

Compliance Manager

Posted 9 Hours Ago
Be an Early Applicant
In-Office or Remote
6 Locations
Senior level
In-Office or Remote
6 Locations
Senior level
Build and lead UpDoc’s healthcare compliance program across FDA-regulated software, privacy and security, fraud and abuse, clinical governance, licensure, and federal research. Serve as HIPAA Privacy Officer, manage BAAs and privacy processes, support SOC 2 and HITRUST readiness, oversee reimbursement and clinical compliance, establish policies and training, conduct risk assessments, and report compliance risks to executives and the Board.
The summary above was generated by AI
About UpDoc

At UpDoc, we are building the first clinically validated, physician-supervised AI agent that manages chronic diseases. We are an early-stage startup founded by Stanford physicians.

We are seeking a Compliance Manager to build and manage the compliance foundation that enables UpDoc to develop, deploy, and scale our technology responsibly. Compliance is central to how we earn the trust of health systems, regulators, payers, and patients while operating at the frontier of what software is permitted to do in medicine.

This is a remote role, with candidates preferred to be physically located in the San Francisco Bay Area.

The Role

You will be UpDoc's first dedicated compliance leader, owning the design and operation of our compliance program across five domains that rarely sit under one roof: medical device quality and regulatory, health data privacy and security, healthcare fraud and abuse, clinical governance and licensure, and federal research compliance.

You will work directly with the CEO, CTO, in-house regulatory and quality assurance team, outside counsel, and compliance teams at leading health systems.

Who You Are
  • You bring a thoughtful, risk-based approach to compliance, distinguishing between regulatory requirements, best practices, and business preferences and applying the appropriate level of scrutiny.

  • You exercise strong judgment and are comfortable taking a firm position when necessary, while working collaboratively to identify practical, compliant solutions.

  • You are a clear and precise communicator, capable of producing policies, responses, and documentation for regulators, auditors, health systems, and outside counsel.

  • You are comfortable navigating evolving regulatory environments and applying sound judgment where requirements or precedent are not yet fully established.

What You’ll OwnRegulatory & Quality Partnership
  • Partner with our Regulatory and Quality team where enterprise compliance requirements intersect with UpDoc’s FDA-regulated product and quality system.

  • Ensure broader compliance policies and processes align with established regulatory and quality requirements.

  • Support cross-functional compliance considerations as UpDoc expands its products, clinical programs, partnerships, and reimbursement models.

Privacy & Security Compliance
  • Serve as the HIPAA Privacy Officer and coordinate closely with the Security Officer on our HIPAA Security program.

  • Own Business Associate Agreements, minimum-necessary practices, and breach assessment and notification procedures, and partner with Security and Engineering on data flow documentation.

  • Partner with Security on SOC 2 Type II and HITRUST readiness and lead compliance responses to health system vendor risk assessments.

  • Advise on applicable federal and state privacy requirements, including HIPAA, CCPA/CPRA, and emerging health data privacy laws.

Healthcare Regulatory & Fraud and Abuse
  • Build the compliance framework for applicable care management, remote monitoring, and other reimbursement pathways, including documentation, supervision, and time-tracking requirements.

  • Assess arrangements with health systems, clinicians, and partners under the Anti-Kickback Statute, Stark Law, and beneficiary inducement rules, working with outside counsel.

  • Maintain Corporate Practice of Medicine compliance across the states in which we operate.

Clinical Governance & Licensure
  • Establish and oversee compliance requirements for clinician credentialing, licensure, scope of practice, and supervision, in partnership with Clinical Operations.

  • Ensure care delivered through UpDoc is appropriately documented, escalated, and audited to meet UpDoc's clinical governance standards and the requirements of partner health systems.

Research & Grant Compliance
  • Support compliance for federally funded research and grant programs, including human subjects protections, IRB coordination, data management requirements, and cost allowability.

  • Maintain conflict of interest and research integrity policies.

Program Leadership
  • Write, maintain, and train the company on policies and procedures; lead the annual compliance risk assessment and work plan.

  • Establish compliance training, reporting mechanisms, and an audit and monitoring cadence.

  • Prepare regular compliance and risk reporting for the CEO and Board.

  • Serve as the primary compliance counterpart to customer legal, privacy, and IT security teams during contracting and implementation.

  • Coordinate with outside counsel, auditors, and specialized advisors as needed.

What We’re Looking ForRequired
  • 8+ years of healthcare compliance experience, with at least 3 years in a leadership or program-owner role.

  • Experience working with FDA-regulated software or digital health products, with a strong understanding of SaMD quality systems and post-market obligations.

  • Deep working knowledge of HIPAA Privacy and Security Rules and experience negotiating BAAs with health systems.

  • Experience supporting SOC 2, HITRUST, or comparable healthcare security and compliance frameworks.

  • Familiarity with Medicare care management reimbursement compliance and healthcare fraud and abuse law.

  • Track record of building programs from an early stage rather than solely administering mature ones.

  • Ability to translate regulation into pragmatic guidance for engineers, clinicians, and executives, and to hold a firm line when it matters.

Strongly Preferred
  • Experience at a digital health or clinical AI company selling into large health systems or academic medical centers.

  • Exposure to federal research compliance, including NIH, ARPA-H, or similar federally funded programs.

  • Familiarity with AI-specific regulatory developments, including FDA guidance on AI-enabled device software and predetermined change control plans.

  • Certification such as CHC, CHPC, CIPP/US, or RAC.

  • JD, MPH, MHA, or equivalent graduate training; a clinical background is a plus.

Similar Jobs

19 Hours Ago
Remote
165K-200K Annually
Senior level
165K-200K Annually
Senior level
Gaming
Manages a data engineering team and oversees scalable, reliable data pipelines, infrastructure, tooling, and architecture. Partners with analytics, finance, compliance, product, and engineering stakeholders while communicating with regulators and supporting audit-driven deadlines. Responsibilities include team leadership, project prioritization, technical guidance, data governance, system design, performance management, and continuous improvement of data engineering practices.
Top Skills: AirflowAtlassianAWSAws LambdaDbtDjangoDockerFlaskGCPKubernetesPythonReactSQLTerraform
5 Days Ago
In-Office or Remote
166K-196K Annually
Senior level
166K-196K Annually
Senior level
Software • App development • Conversational AI
Own Quo’s billing, accounts and identity, and telecom compliance product domains. Lead metering, entitlements, invoicing, payment recovery, authentication, SSO, permissions, regulatory registration, fraud tooling, and deliverability systems. Build roadmaps, translate pricing into system behavior, partner with engineering on APIs and data models, and coordinate with finance, legal, security, and compliance stakeholders to deliver highly reliable systems.
Top Skills: A2P 10DlcAPIsAuthenticationIdentity And Access ManagementPayment ProcessingSsoTelecom Compliance SystemsUsage Metering
8 Days Ago
Remote
United States
Senior level
Senior level
eCommerce • Logistics • Transportation
Own the end-to-end compliance product for cross-border commerce, from merchant catalog data through cleared shipment. Define the build-versus-buy-partner strategy, improve classification and data quality, reduce manual operational work, create merchant-facing compliance workflows, and manage partner integrations. Success includes quantifying risks, establishing a roadmap, improving data quality, enabling merchant self-service, and making compliance a commercial differentiator.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account