Privacy Manager
Own and improve privacy operations for a healthcare technology company, covering regulated data, individual rights, incidents, vendors, products, and AI use cases. The role requires 4–7 years of U.S. privacy experience, preferably including direct HIPAA work.
About the job
Responsibilities
- Operate and improve the privacy program across HIPAA, 42 CFR Part 2, state privacy laws, behavioral health confidentiality, individual rights, vendor governance, and responsible AI use.
- Maintain privacy policies, procedures, controls, data maps, records of processing, ownership records, evidence, and testing schedules.
- Track privacy risks and operational metrics, including request volume, aging items, and remediation progress.
- Translate regulatory, payer, and contractual requirements into practical guidance and develop privacy training and resources.
- Triage privacy inquiries, individual rights requests, and potential incidents.
- Manage HIPAA and state privacy rights workflows, including access, amendment, accounting of disclosures, restriction, confidential communications, and deletion.
- Support incident investigations, documentation, root-cause analysis, corrective actions, notifications, and regulatory submissions.
- Conduct privacy assessments for products, vendors, workflows, and initiatives involving PHI or sensitive personal information.
- Evaluate AI and machine-learning use cases for appropriate data use, minimum-necessary access, retention, transparency, and human oversight.
- Conduct vendor privacy diligence with Legal and Security, maintain the BAA inventory, and drive gaps to resolution.
- Build scalable privacy checklists and playbooks.
Requirements
- 4–7 years of U.S. privacy experience in a regulated industry, such as healthcare, health technology, health plans, or financial services.
- Direct HIPAA experience strongly preferred.
- Hands-on experience in at least two of: privacy incidents, individual rights or DSAR workflows, privacy assessments, vendor and BAA governance, or privacy training.
- Ability to translate complex legal and regulatory requirements into clear, actionable guidance for non-experts.
- Strong judgment, communication, documentation, cross-functional influence, and ability to balance execution with program design.
- Fluency with AI tools for research, drafting, and analysis, with sound judgment regarding verification and regulated data.
- Ability to evaluate AI use cases involving patient data.
- Collaborative, pragmatic approach to ambiguity and pushback.
Nice to have
- Experience with 42 CFR Part 2, minor consent and confidentiality requirements, or other heightened-confidentiality regimes.
- Familiarity with payer or contractual privacy requirements.
- Experience assessing privacy risk in SaaS, cloud, or AI-enabled products.
- CIPP/US, CIPM, CIPT, CHPC, CHPS, or an AI governance credential.
Compensation
- $121,600–$190,000 annually.
Skills
HIPAA, 42 Cfr Part 2, State Privacy Laws, Privacy Assessments, Privacy Incident Management, Dsar Workflows, Vendor Governance, Baa Governance, Ai Governance, Machine Learning, Phi, Data Mapping, Records Of Processing, SaaS, Cloud Computing
Similar jobs
Legal jobsOwn and enhance second-line compliance controls, risk assessments, and monitoring for a US-focused fintech. The role requires 5–10 years of regulated financial services experience, strong GRC and analytical capabilities, and the ability to influence cross-functional stakeholders.
Supports civil litigation and eDiscovery operations across multiple matters, coordinating legal holds, collections, vendors, subpoenas, deadlines, billing, and legal-operations systems. Requires at least three years of paralegal or litigation coordination experience and strong discretion with confidential material.
Employment Counsel will advise the People team on employment law, investigations, policies, compliance, and multijurisdictional workforce matters while supporting broader legal and governance needs. The role requires a J.D., U.S. bar admission, at least five years of legal experience, and meaningful employment law experience.
Commercial Counsel will negotiate high-volume B2B SaaS customer contracts and advise Sales and business stakeholders on risk, privacy, security, and compliance. The role requires a JD, U.S. bar admission, and 3–5 years of legal experience with substantial commercial or transactional work.
Own Legal Tracker and the operational systems supporting an in-house legal function, including matter management, e-billing, invoice compliance, accruals, and outside counsel spend control. Requires 5+ years of legal operations or legal finance experience and strong Legal Tracker expertise.