The Director of Risk and Compliance manages Gracelight Community Health's ("Gracelight") corporate compliance and risk management programs across all health center sites and administrative operations, in support of the Chief Operating Officer, who serves as the organization's designated Compliance Officer and HIPAA Privacy Officer. The Director oversees the credentialing and privileging program, ensures ongoing compliance with HRSA Health Center Program requirements and applicable federal and state regulations, and prepares compliance and risk reporting for executive leadership and the Audit Committee of the Board of Directors. This role is based at the administrative office and requires regular travel to Gracelight locations.
ESSENTIAL DUTIES:
- Operates and continuously improves the corporate compliance program under the direction of the designated Compliance Officer, including written standards, education, monitoring and auditing, reporting channels, investigation and response, and corrective action.
- Ensures ongoing compliance with HRSA Health Center Program requirements (Section 330), including support for operational site visits, grant conditions, and required policies.
- Administers the HIPAA privacy program in support of the designated HIPAA Privacy Officer; manages privacy policies, breach assessment and reporting, and patient rights requests, and coordinates with the Security Officer function on the HIPAA security program and risk assessments.
- Oversees the credentialing and privileging program for licensed and certified personnel, including initial credentialing, recredentialing, privileging, primary source verification, and expirables tracking, in accordance with HRSA and FTCA requirements and in coordination with the Chief Medical Officer for clinical review and approval.
- Manages the incident reporting system across all sites; ensures incidents, patient grievances, and complaints are logged, investigated, resolved, and trended, and that findings reach the appropriate leaders.
- Conducts and documents internal investigations of compliance concerns; maintains confidential reporting channels and enforces non-retaliation.
- Performs monthly OIG/SAM exclusion screening for employees, contractors, and vendors; documents results and remediates findings.
- Owns the policy management cycle; maintains the policy library, drives scheduled reviews and approvals, and ensures policies reflect current law and practice.
- Manages the annual compliance training calendar, including new hire and annual refresher training and targeted training in response to identified risks.
- Coordinates risk management activities, including professional and general liability matters, FTCA deeming and redeeming applications, claims coordination with counsel and insurers, and insurance renewals.
- Prepares and presents compliance and risk reports for the Compliance Officer, executive team, and Board Audit Committee, including work plans, audit results, and corrective action status.
- Coordinates responses to external audits, surveys, payer reviews, and regulatory inquiries.
- Maintains the annual compliance work plan and risk assessment; adjusts priorities based on findings, enforcement trends, and organizational change.
- Maintains compliance with all applicable federal, state, and local regulations, HRSA Health Center Program requirements, and Gracelight policies and procedures.
- Performs other duties as assigned.
- Bachelor’s degree in healthcare administration, public health, business, or a related field; equivalent directly related experience may substitute for the degree.
- Minimum of five (5) years of progressive experience in healthcare compliance, risk management, or regulatory affairs, including at least two (2) years in a management or program-leadership role. Experience in a community health center, FQHC, or safety-net setting strongly preferred.
- Licensure and certification — Certification in Healthcare Compliance (CHC), Certified in Healthcare Privacy Compliance (CHPC), or similar credential preferred; may be obtained within twelve (12) months of hire.
- Working knowledge of HIPAA, HRSA Health Center Program requirements, and federal and California healthcare regulations, including compliance program structure, credentialing and privileging, incident and grievance management, and risk management practices. Proficiency with Microsoft Office; experience with compliance, incident reporting, or policy management systems preferred.
- Demonstrated ability to conduct investigations, write clear findings, and present to executive and board audiences. Strong interpersonal and communication skills and demonstrated ability to work with a diverse workforce and patient population. Bilingual English/Spanish preferred.
Gracelight Community Health Los Angeles, California, USA Office
Los Angeles, CA, United States
Similar Jobs
What you need to know about the Los Angeles Tech Scene
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering



