Vice President, PBM Compliance & Regulatory Operations - Remote
Naperville, DuPage County, Illinois, 60540, USA
Listed on 2026-05-30
-
IT/Tech
Data Security, Cybersecurity, Information Security
Vice President, PBM Compliance & Regulatory Operations - Remote
Role overview:
Lead Liviniti’s PBM compliance and privacy operations to ensure adherence to applicable state and federal laws and regulations, including PBM-specific requirements and HIPAA, HITECH, ERISA-related disclosures, and the Consolidated Appropriations Act (CAA). Translate regulatory and privacy obligations into operational workflows, controls, and audit-ready processes. Own PBM regulatory compliance, market conduct exam readiness, and privacy operations, with oversight of HIPAA incidents, breach response, corrective action plans, and ongoing risk mitigation.
Partner with Legal, Operations, Product, and Technology to ensure PBM operations, data, disclosures, and privacy practices meet regulatory and contractual requirements as part of the Legal and Compliance leadership team.
Responsibilities
- Build and implement the Compliance Function:
Stand up the program from scratch and drive full implementation across the business; develop policies and procedures and convert them into actionable workflows, controls, and system requirements; establish governance, reporting, and accountability mechanisms. - State PBM Regulatory Compliance:
Own and maintain a state-by-state regulatory inventory and monitoring process; translate regulatory requirements into business rules and system configurations; collaborate with operations and technology to implement requirements in claims adjudication, MAC pricing, network standards, and appeals; validate requirements are correctly implemented. - Market Conduct Exam Readiness:
Maintain ongoing exam readiness; develop documentation, evidence repositories, and audit trails; conduct internal readiness reviews and mock exams; lead regulatory exams, data requests, responses, and remediation efforts. - Systems, Controls, and Monitoring:
Design and implement system-based compliance controls and automated edits within PBM platforms; embed compliance in claims logic and workflows; establish ongoing monitoring, control testing, and reporting dashboards. - CAA and Gag Clause Compliance (PBM scope):
Oversee PBM responsibilities under the CAA; support RxDC data reporting; ensure gag clause compliance and related attestations; build repeatable cross-functional data aggregation and reporting processes; ensure outputs are accurate and audit-ready. - Audit, Risk, and Third-Party Oversight:
Build a risk-based audit program; identify control gaps and coordinate remediation with business owners; oversee compliance of pharmacies, vendors, and downstream partners. - Privacy Governance & HIPAA Oversight:
Provide executive leadership for HIPAA Privacy, Security, and Breach Notification programs; develop and maintain HIPAA policies and procedures; operationalize health privacy regulations into controls; partner with Legal, Information Security, IT, HR, and business leaders to embed privacy across the organization; report privacy risk metrics to leadership; serve as executive lead for HIPAA incidents and breach notifications; drive remediation and continuous improvement;
manage OCR inquiries, audits, and enforcement actions in coordination with Legal. - Leadership and Execution:
Act as a hands-on leader, own key deliverables in early stages, build and scale the compliance team, be primary contact for regulators, auditors, and external counsel; provide regular reporting to executive leadership. - General Duties:
Complete required HIPAA training; comply with HIPAA obligations related to PHI; manage calendars and inquiries; participate in special projects; maintain compliance inbox; perform other duties as assigned; acknowledge that duties may change over time.
Required Skills and Competencies
- Ability to translate state and federal guidelines into practical operational solutions.
- Executive-level leadership experience building and leading high-performing compliance or regulatory operations teams.
- Judgment in ambiguity, escalation, and regulatory risk scenarios; strong controls, audit readiness, and documentation skills.
- Ability to balance compliance rigor with business enablement; strategic mindset to anticipate regulatory trends; strong analytical skills…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).