Senior Director, Information Technology
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
The Senior Director of Information Technology is the functional owner of BHC’s technology platform, cybersecurity posture, regulatory technology compliance program, and the secure enablement of artificial intelligence across the enterprise. Reporting to the CFO, this leader is accountable for the secure, reliable, and scalable operation of all clinical, revenue cycle, and administrative systems across BHC’s 24-clinic footprint and shared services organization. The role combines hands-on technical leadership with executive-level risk management - protecting protected health information (PHI), maintaining HIPAA and California regulatory compliance, and serving as the technology partner for BHC’s multi-year AI roadmap and modern data initiatives., Security & Compliance (primary focus)
- Own BHC’s information security program end-to-end: governance, policy, controls, monitoring, incident response, and executive-level reporting
- Maintain continuous HIPAA Privacy and Security Rule compliance, including administrative, physical, and technical safeguards
- Manage California-specific privacy and security obligations, including the Confidentiality of Medical Information Act (CMIA), CCPA/CPRA, and Department of Industrial Relations (DIR) requirements applicable to workers’ compensation operations
- Lead the Business Associate Agreement (BAA) program: vendor risk assessments, BAA execution, ongoing third-party monitoring, and right-to-audit enforcement - with particular rigor for AI and large language model vendors
- Oversee identity and access management, least-privilege provisioning, MFA, and periodic access reviews across clinical, back-office, and AI/agent systems
- Operate the security incident response program, including breach notification readiness under HIPAA and California state law
- Drive the annual security risk analysis, remediation roadmap, and supporting documentation for audits and payer/regulator inquiries
- Advance the program toward a recognized framework (HITRUST CSF, NIST CSF, or SOC 2) as it matures
- Maintain a tested disaster recovery and business continuity program covering EHR, practice management, RCM, and clinic operations, * Serve as the executive technology partner for BHC’s enterprise AI roadmap, including a multi-agent program spanning clinical operations, revenue cycle, and shared services
- Build and operate the AI governance framework: model and tool inventory, intake and approval workflow, risk tiering, acceptable use policy, and ongoing monitoring
- Establish a secure-by-default reference architecture for AI deployments - covering enterprise LLM platforms, agentic tools, retrieval-augmented generation (RAG), and custom models - with explicit guardrails for PHI handling
- Implement data loss prevention (DLP), prompt and output logging, and content filtering controls for AI tools used by clinical, RCM, finance, and administrative staff
- Evaluate and select AI platform vendors with appropriate HIPAA posture: signed BAAs, zero-data-retention or contractually bounded retention, no-training commitments, regional data residency, and SOC 2 / HITRUST attestation
- Define the boundary between approved AI workflows (eligible for PHI) and restricted ones (non-PHI / de-identified only), and enforce that boundary through tooling, training, and monitoring
- Stand up the technical controls for AI agents and automations that touch BHC systems: scoped credentials, audit logging, human-in-the-loop checkpoints, and rollback paths
- Partner with Compliance and Legal on AI-specific regulatory exposure, including evolving HIPAA guidance on AI, FTC enforcement trends, California AI legislation, and payer expectations
- Lead organization-wide AI security awareness training, including prompt injection, data exfiltration risks, shadow AI usage, and approved-tool playbooks
- Provide the secure data and integration foundation - access governance, lineage, masking, and de-identification - required for analytics and AI workloads to scale
Infrastructure & Operations
- Own the full technology stack: network, endpoints, cloud and on-premises infrastructure, telephony, and end-user computing across 24 clinics and corporate offices
- Ensure high availability of clinical and revenue-generating systems; manage SLAs with managed service providers and platform vendors
- Lead the IT service desk and field support operations with metrics-driven service management
- Manage IT capital and operating budgets, vendor contracts, and software licensing - including the AI tooling portfolio, * Partner with clinical and operations leadership on the EHR, practice management, scheduling, and patient engagement application portfolio
- Partner with finance and RCM leadership on billing, collections, payer integration, and analytics platforms
- Govern data architecture, integration, master data management, and reporting infrastructure with AI-readiness as a first-class design requirement
- Operate the controls that allow business owners to build and deploy AI-assisted workflows without compromising PHI or audit posture, * Build, mentor, and retain a high-performing IT and security team, including dedicated capacity for AI security and governance
- Serve as a trusted advisor to the executive team on technology risk, AI strategy, investment, and operating model
- Represent IT in payer audits, regulatory examinations, and due diligence engagements
Requirements
This is a foundational leadership role for an executive who treats security and compliance as first-order obligations, and who understands that responsibly scaling AI inside a HIPAA-regulated organization is one of the most important capabilities IT must deliver over the next three to five years., * Bachelor’s degree in computer science, information systems, or related field; advanced degree preferred
- 12+ years of progressive IT leadership experience, with at least 5 years at the director level or above in healthcare
- Demonstrated ownership of a HIPAA-regulated environment, including direct responsibility for the security risk analysis and remediation program
- Deep, hands-on knowledge of the HIPAA Privacy and Security Rules and California medical privacy law (CMIA, CCPA/CPRA)
- Experience leading or sustaining a recognized security framework: HITRUST CSF, NIST CSF, SOC 2, or equivalent
- Proven incident response leadership, including at least one material incident managed end-to-end
- Direct experience evaluating, deploying, and securing enterprise AI or large language model platforms - including BAA negotiation, data handling controls, and acceptable use policy - in a HIPAA or otherwise regulated environment
- Working understanding of AI threat models: prompt injection, training-data leakage, model output risk, agentic tool misuse, and supply-chain risk in AI vendors
- Multi-site operations experience; comfort with a distributed clinic or retail healthcare footprint
- Strong vendor management and BAA program experience
- Executive communication skills with the ability to brief the CEO, CFO, board, and external auditors on both security and AI risk, * Workers’ compensation, occupational medicine, or specialty physician group experience
- Active security certification (CISSP, CISM, HCISPP, or equivalent)
- AI governance, AI security, or responsible AI credential (e.g., IAPP AIGP, ISO/IEC 42001 familiarity, NIST AI RMF experience)
- Experience designing technical and policy controls for a multi-agent or production-grade AI deployment
- Experience supporting RCM operations and payer integrations
- Prior experience supporting M&A integration or de novo clinic build-out
Benefits & conditions
- Executive-level role with direct CFO sponsorship and a clear mandate to modernize
- Ownership of the security and AI enablement agenda at one of California’s leading workers’ compensation provider organizations
- Competitive base salary, performance bonus, and comprehensive benefits
About the company
Boomerang Healthcare (BHC) is a leading California-based workers’ compensation healthcare provider operating 24 multidisciplinary pain and physical rehabilitation clinics across Northern, Central, and Southern California. We help injured workers return to function and return to work through coordinated, evidence-based care that brings together physician services, physical medicine, behavioral health, and care coordination under one roof.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How to Become an AI Engineer
Trustworthy AI Starts at Deployment: 5 Checks Before You Ship
Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production
Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges