Director, Compliance
About the role
About the Role
We're growing our Compliance team and looking for a talented Compliance Director to own and scale this critical function. Reporting to the Deputy General Counsel and partnering closely with the General Counsel and the broader Legal team, you will be the day-to-day leader of Blink's Compliance Program across a fast-paced, highly regulated business that spans pharmacy operations, pharmaceutical manufacturer programs, network pharmacies, and patient-facing digital products.
This is a hands-on, high-ownership role. In addition to setting compliance strategy, you will run the program's operating engine: privacy and HIPAA compliance, incident investigation and remediation, audits and certifications, regulator and consumer complaints, screening and integrity controls, training, and policy development. You'll work shoulder-to-shoulder with Legal, Information Security, Pharmacy Operations, Data/Engineering, and People teams, and you'll have meaningful room to shape the role as Blink continues to grow.
What You’ll Do
Compliance program leadership
- Own, advance, and champion Blink's enterprise Compliance Program, including the code of conduct, conflicts-of-interest, gifting, and whistleblower/reporting frameworks.
- Lead the established compliance operating cadence (including weekly compliance reviews and the compliance committee), maintaining clear action items, accountability, and follow-through.
- Provide periodic reports to the Deputy General Counsel and General Counsel on the nature, progress, and status of the program and emerging risks.
Privacy & HIPAA
- Own the HIPAA compliance program — policies, procedures, authorizations, revocation processes, and recordkeeping — keeping it current and continuing to strengthen it as the business and regulations evolve.
- Maintain and enhance the practical guardrails and job aids that help Data, Engineering, and IT teams handle PHI correctly (e.g., approved-vs-not-approved platforms for PHI, data-governance guidance, BAA tracking with vendors).
- Monitor and operationalize evolving privacy and consumer-protection requirements, including HIPAA, FTC, and state privacy laws.
Investigations, incidents & remediation
- Investigate and document potential compliance and privacy concerns, including HIPAA incidents and unauthorized-disclosure events, and partner with stakeholders to develop and execute remediation, coaching, and corrective-action plans.
- Manage intake and response for medical-records and legal-process requests