Full-Time

Compliance and Privacy Officer

Posted on 8/20/2026

We Care Daily Clinic

We Care Daily Clinic

Compensation Overview

$105k - $125k/yr

Auburn, WA, USA

Hybrid

Hybrid role with regular travel to clinic sites across King and Pierce Counties.

Category
Legal & Compliance (1)
Required Skills
OSHA
HIPAA
Requirements
  • At least 7 years of healthcare compliance experience, with opioid treatment program, substance use disorder, or behavioral-health experience strongly preferred.
  • Deep working knowledge of 42 CFR Part 2, the HIPAA Privacy and Security Rules, OSHA, DEA requirements, Medicaid regulations, and Washington Administrative Code requirements, including how 42 CFR Part 2 consent requirements differ from and exceed HIPAA requirements.
  • Experience overseeing compliance across multiple sites or a clinic network and setting policies and standards that others execute against.
  • Direct experience serving as a primary or executive-level liaison with regulatory agencies such as SAMHSA, DEA, and state health departments during inspections, investigations, or audits.
  • Strong policy-writing, audit-framework design, and training-curriculum development skills.
  • Judgment and communication skills for working with site-level and executive leadership.
Responsibilities
  • Set the enterprise-wide compliance program, policies, and standards covering federal, state, and accreditation requirements for opioid treatment programs.
  • Monitor regulatory, legal, and accreditation changes affecting opioid treatment programs and translate them into policy updates and leadership guidance.
  • Set standard processes, templates, and requirements for licensure applications, renewals, modifications, and change-of-ownership submissions, and directly handle complex or high-stakes filings.
  • Serve as the executive-level liaison and escalation point with regulatory agencies, SAMHSA, DEA, Washington State Department of Health, Health Care Authority, the State Opioid Treatment Authority, and accrediting organizations during inspections, investigations, audits, and reviews.
  • Own the master regulatory calendar and reporting framework across all clinics and review site-submitted regulatory reports, plans of correction, and corrective action plans before submission to regulators.
  • Advise executive leadership on compliance and regulatory considerations for strategic growth, new clinics, medication units, satellite sites, and expansion into new states.
  • Own the compliance framework across HIPAA, 42 CFR Part 2, OSHA, DEA requirements, Medicaid regulations, and Washington Administrative Code requirements.
  • Lead enterprise-wide compliance risk assessments and set risk-mitigation strategy; author and maintain organization-wide policies, procedures, and standard operating procedures.
  • Set standards for investigating and documenting compliance concerns and serve as the escalation point for complex, sensitive, or high-risk investigations through resolution.
  • Set the clinical, operational, and regulatory audit framework for clinical documentation, medication dispensing, treatment planning, counseling, toxicology testing, and discharge processes, and spot-check findings for cross-site consistency.
  • Own network-wide quality indicators, clinical outcomes, incident trends, and risk-management data to identify cross-site patterns.
  • Set the enterprise quality-improvement framework based on audit findings, performance metrics, and corrective action plans, and hold site leadership accountable for completing corrective actions.
  • Own the enterprise recordkeeping standard for audits, investigations, and corrective actions and ensure site-level documentation consistently meets it.
  • Own emergency preparedness, business continuity, and enterprise risk-management strategy across the clinic network.
  • Chair the Compliance Committee and prepare reports and recommendations for executive leadership.
  • Own the privacy compliance program for opioid treatment program and substance use disorder treatment records, especially 42 CFR Part 2, alongside the HIPAA Privacy and Security Rules and applicable Washington State privacy law.
  • Provide guidance on 42 CFR Part 2 consent, disclosure, and re-disclosure requirements and own privacy provisions in vendor business associate agreements and Qualified Service Organization Agreements with Legal Counsel.
  • Own breach-notification protocols and serve as the escalation point for suspected 42 CFR Part 2 or HIPAA privacy incidents across the clinic network.
  • Partner with the Director of Recovery Programs, Medical Director, and Clinic Administrators to improve workflows and operational efficiency from a compliance perspective.
  • Own compliance sign-off on new clinical programs, regulatory initiatives, and operational processes before rollout.
  • Partner with the Safety and Risk Manager on OSHA recordkeeping and workplace-injury reporting.
  • Own the compliance, regulatory, and documentation training curriculum covering policies, regulatory changes, documentation standards, and privacy requirements.
  • Work with Indigenous Pact on compliance training for staff and leadership across all locations.
Desired Qualifications
  • Experience in opioid treatment programs, substance use disorder, or behavioral health.
  • Certified in Healthcare Compliance or an equivalent certification.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A