Security Risk & Compliance, Hipaa

Anthropic Anthropic · AI Frontier · San Francisco, CA · Security

This role is responsible for owning and operating Anthropic's HIPAA compliance program end-to-end, ensuring adherence to HIPAA obligations across the product portfolio. It involves building and maintaining compliance infrastructure, assessing data flows, writing policies, and managing Business Associate Agreements, with a focus on integrating compliance into the product development lifecycle.

What you'd actually do

  1. Operate Anthropic’s HIPAA compliance review program, executing on HIPAA obligations across the product portfolio.
  2. Run a dedicated HIPAA review track in parallel with the Product Security Review (PSR) process, applying compliance checklist to every in-scope change and recording a complete, auditable disposition before release.
  3. Build and maintain change monitoring mechanisms to catch HIPAA-relevant changes — including default setting changes and incremental updates.
  4. Partner with product and engineering teams upstream to ensure HIPAA considerations are built into first releases rather than addressed as post-launch remediations.
  5. Assess and document PHI data flows, infrastructure boundaries, and control coverage across Anthropic’s cloud-native product environments.

Skills

Required

  • 3+ years of progressive experience in compliance roles
  • direct ownership of a HIPAA compliance program at a technology company
  • evaluated PHI data flows and infrastructure boundaries in cloud-native environments (AWS, GCP, or Azure)
  • assess HIPAA exposure
  • designed and operated a compliance review mechanism integrated into a product development or release process
  • translate HIPAA technical compliance requirements into actionable workstreams for engineering and product teams
  • Deliver clear, precise compliance documentation — policies, checklists, audit evidence, deployment guides — for both technical and non-technical audiences
  • Thrive in fast-paced, ambiguous environments
  • build processes from scratch
  • organizational expert who educates and influences

Nice to have

  • worked in AI/ML or developer-platform companies
  • understand the unique challenges of PHI exposure in model inference and API environments
  • HITRUST CSF experience
  • experience mapping HIPAA requirements to HITRUST controls
  • experience from high-growth technology companies where compliance programs had to scale alongside rapid product expansion
  • implemented or significantly contributed to compliance automation or GRC tooling integrations
  • Relevant certifications (CHPC, HCISPP, CISA, CISM, CISSP, or equivalent)

What the JD emphasized

  • own HIPAA compliance operations end-to-end
  • build processes from scratch
  • direct ownership of a HIPAA compliance program at a technology company