Director of Compliance

JRG Partners

  • Baltimore, MD
  • 8 days ago

    Highlights

    Notify the CEO promptly of significant matters such as SIU or government inquiries; credible fraud, waste, or abuse concerns; suspected services not rendered; falsification or material record alteration; kickback or improper inducement allegations; major privacy breaches; patient-safety concerns; significant systemic billing problems; or material legal, financial, or reputational exposure. Report meaningful but non-emergent trends such as recurring documentation deficiencies, authorization problems, training gaps, credentialing concerns, repeat findings, and overdue or approaching corrective-action deadlines.

    Numbers & Facts

    LocationBaltimore, MD

    Description

    Director of Compliance

    Your Mandate

    Your role is to make compliance visible, measurable, correctable, and sustainable. Each day, the compliance function should be able to answer:

    • Are we doing what we are supposed to do?
    • Can we prove it with reliable evidence?
    • Where are we at greatest risk?
    • Who owns the correction?

    Has the correction actually worked?

    Operating method: ASK → SHOW → VERIFY → CORRECT → RE-VERIFY

    Daily Duties

    Daily risk scan: Review new incidents, complaints, payer correspondence, documentation and authorization exceptions, billing concerns, credentialing issues, HIPAA/privacy matters, and other emerging risks.

    Risk-based auditing: Personally conduct focused audits while you are the sole compliance professional. Prioritize high-risk issues, new or emerging risks, previous deficiencies, and then routine samples.

    Exception management: Document meaningful findings, identify the applicable requirement, determine risk level, assign an owner and deadline, and decide whether escalation or a billing hold should be recommended.

    Corrective-action follow-up: Track significant findings through correction and verify evidence before closing them. A report that an issue is fixed is not sufficient; significant corrections must be verified.

    Investigation readiness: Preserve original evidence, distinguish known facts from allegations, coordinate appropriate escalation, and maintain organized records for significant internal, payer, SIU, regulatory, or legal matters.

    System building: Protect dedicated time to convert recurring compliance work into policies, checklists, controls, dashboards, training, and appropriate automation so the function becomes less dependent on one person.

    Leadership guidance: Coach department leaders on compliance expectations and help them own compliance within their operations rather than transferring operational responsibility to the compliance function.

    Daily Work Allocation

    Guideline Primary Use

    30% Auditing and monitoring

    25% Findings, corrective action, and verification

    20% Building compliance systems, tools, policies, dashboards, and controls

    15% Investigations and enterprise risk management

    10% Leadership communication and education

    These percentages are guidelines. Significant incidents may temporarily change the allocation.

    CEO Escalation & Reporting Cadence

    RED — Immediate Escalation

    Notify the CEO promptly of significant matters such as SIU or government inquiries; credible fraud, waste, or abuse concerns; suspected services not rendered; falsification or material record alteration; kickback or improper inducement allegations; major privacy breaches; patient-safety concerns; significant systemic billing problems; or material legal, financial, or reputational exposure.

    Initial format: FACTS | RISK | IMMEDIATE ACTION | DECISION NEEDED

    YELLOW — Weekly Management

    Report meaningful but non-emergent trends such as recurring documentation deficiencies, authorization problems, training gaps, credentialing concerns, repeat findings, and overdue or approaching corrective-action deadlines.

    GREEN — Routine Management

    Manage isolated, low-risk, easily corrected issues without unnecessary CEO involvement, while documenting them sufficiently to identify recurrence or trends.

    Weekly CEO Compliance Review — 30 Minutes

    • RED: What requires executive attention?
    • YELLOW: What significant risks are being managed?
    • TREND: What patterns are appearing?
    • CORRECTIVE ACTION: What major actions remain open?
    • DECISION: What do you need from the CEO?

    NEXT WEEK: What are the three highest compliance priorities?

    Weekly Operating Rhythm

    Day Focus Expected Work

    Monday Risk Scan & Planning Review incidents, external communications, prior findings, and overdue corrective actions. Select the week's top three compliance priorities.

    Tuesday Audit & Verification Conduct focused audits in the highest-risk areas. Expand samples when findings suggest a systemic issue.

    Wednesday Correct & Teach Meet responsible leaders, explain findings, establish corrective actions, and provide targeted education.

    Thursday Build & Re-Verify Re-audit prior deficiencies and build policies, checklists, workflows, controls, or automation that reduce recurrence.

    Friday Analyze & Report Update the risk dashboard, identify trends, prepare the one-page CEO report, and identify preliminary priorities for the following week.

    Monthly & Quarterly Cadence

    Monthly enterprise compliance review: Present the five greatest current risks, evidence, trends, root causes, corrective actions, owners, verification status, and emerging risks. Select one major compliance domain for a deeper review based on risk.

    Quarterly enterprise risk review: Assess regulatory, payer, billing, documentation, authorization, workforce, credentialing, privacy, contracting, training, investigation, and growth-related risks. Identify where company would be most vulnerable if audited tomorrow and what will be changed before the next quarter.

    GRIT Values in This Role

    GENEROSITY: Help people succeed before defaulting to punishment. Teach expectations, provide useful tools, and distinguish knowledge gaps from intentional misconduct when appropriate.

    RESPECT: Correct without humiliating. Listen, protect confidentiality, investigate fairly, and separate the person from the compliance problem.

    INTEGRITY: Follow the evidence. Never hide, alter, minimize, exaggerate, or explain away inconvenient findings. What company says happened must match what the evidence demonstrates.

    TEAMWORK: Compliance belongs to the entire organization. Department leaders own compliance in their operations; you set standards, audit, advise, challenge, verify, and escalate.

    First 90 Days

    Days 1–30 — Know the Risk: Review prior audits, SIU and legal lessons, policies, and major workflows. Build a Compliance Risk Map, establish Red/Yellow/Green classification, start risk-based audits, and establish the corrective-action tracker and weekly CEO report.

    Days 31–60 — Control the Risk: Strengthen controls around the highest-risk areas, especially documentation, authorization, billing, credentialing, service verification, and incident escalation.

    Days 61–90 — Build the System: Convert recurring manual work into Policy → Checklist → Owner → Evidence → Audit → Dashboard. Identify activities that can later be automated or delegated and deliver Compliance Operating System v1.

    Role Evolution & Leadership Development

    This role is intended to grow as compliance infrastructure matures. The expected progression is:

    DO → BUILD → DELEGATE → VERIFY → LEAD

    Initially, you will personally audit, investigate, report, train, and build tools. As systems mature and additional resources become appropriate, routine monitoring should move to trained staff, department-owned controls, or approved technology. Your role should progressively expand toward enterprise risk, compliance strategy, executive advising, system effectiveness, governance, and broader organizational leadership.

    Company also views this position as an opportunity to evaluate and develop broader executive leadership capacity. This is not a promise of succession or a guaranteed future title. Rather, demonstrated success in compliance, enterprise judgment, people leadership, operations, strategy, financial understanding, and responsible growth may lead to expanded executive responsibilities over time.

    Definition of Success

    Serious risks reach leadership quickly.

    Routine issues are managed without unnecessary CEO involvement.

    Important problems are increasingly identified internally before outside parties identify them.

    Repeat findings decrease and corrective actions are verified.

    Department leaders take ownership of compliance within their operations.

    Company can reliably demonstrate what happened with evidence.

    Compliance becomes increasingly systematic rather than dependent on one person.

    Growth does not outrun company's controls.

    Most importantly: The compliance department may initially be one person, but compliance must belong to the entire organization.

     

    Similar Jobs