Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We’re HITRUST i1 Validated and SOC 2 Type 2.
You’ll own security and compliance end to end. Today it’s split between the CTO and whichever engineer happens to be nearest. You’ll take all of it.
You’ll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.
Audits and certifications
Compliance tooling
Contracts, BAAs, and vendor risk
Policies, training, and incident response
Privacy and AI governance
A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it. Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP. Process Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home. Please be prepared to actively research information during the exercise.
Collectly is a tech-enabled patient billing platform that works as an add-on for your EHR/PM. Collectly accelerates and increases patient cash flow, streamlines post-service billing operations, and provides the best patient experience that works for all demographics.
Please, see a short video about us