OUR CARE VALUES
Hoan My is guided by our CARE values: Commitment to Quality Care, Accountability for Outcomes, Respect for Our Communities, and Empathy with Our Patients. These principles shape how we work and how we treat one another. We seek people who put these values into practice and show excellence, innovation, and integrity in their work.
---
JOB SUMMARY
Compliance Manager oversees the compliance program for assigned regional business units within Hoan My Group, ensuring effective risk management, ethical business practices and adherence to company policies and applicable regulations.
The role also serves as Group's designated Data Protection Officer (DPO), leading and coordinating the implementation of the Group’s personal data protection framework and ensuring compliance with applicable data protection requirements.
---
MAIN RESPONSIBILITIES
1. Compliance & Risk
- Lead compliance initiatives across assigned hospitals and clinics.
- Identify and assess compliance and operational risks, and implement prevention, detection and corrective actions.
- Strengthen internal controls and promote a strong compliance and ethical culture.
2. Whistleblowing, COI & Compliance Training
- Oversee investigations and resolution of non-compliance and whistleblowing cases.
- Conduct employee and vendor Conflict of Interest (COI) checks and risk assessments.
- Deliver compliance training and counseling on anti-corruption, applicable laws and healthcare standards.
3. Data Protection / DPO – Key Focus
- Serve as HMC’s Data Protection Officer (DPO) and coordinate Group-wide implementation of the personal data protection framework.
- Coordinate with BU DPOs and relevant functions to implement data protection policies, procedures and controls.
- Oversee regulatory requirements and submissions, including Data Protection Impact Assessment (DPIA) and Data Transfer Impact Assessment (DTIA), and monitor compliance across the Group.
- Coordinate key data protection activities, including consent management, data subject requests, data sharing, data incidents and training.
- Act as the key coordination point with authorities, external advisers and service providers; escalate material data protection risks and non-compliance to management.
- Coordinate with Legal on matters requiring legal interpretation or advice.

