Role Description
As Senior Counsel, Data Governance, you will own Hello Heart’s legal and regulatory strategy for data use. You will lead negotiations on how Hello Heart can collect, use, share, retain, reuse, and apply AI to data, ensuring our agreements give the company the rights it needs to operate, innovate, and grow while meeting our regulatory and contractual obligations.
Reporting into our Chief Compliance and Privacy Officer, you will serve as their right hand. You will have direct exposure to and working relationships with Hello Heart’s C-suite and senior executives, partnering closely with leaders across Sales, Technology, Product, Security, and other functions on high-impact business decisions. You will lead the day-to-day operation of Hello Heart’s privacy and data governance programs and the execution of our AI governance program, translating complex privacy, data, and AI requirements into contracts, policies, controls, product requirements, and operating practices across the company.
This is an owner-operator role. You will not simply advise teams on requirements. You will negotiate, build, implement, maintain, run, monitor, audit, and remediate the programs and controls within your scope.
Responsibilities
-
Lead and execute negotiations regarding Hello Heart’s data rights across new and existing client and partner agreements, including BAAs, DPAs, data use agreements, data sharing agreements, and other agreements governing data rights and obligations.
-
Proactively identify and renegotiate existing agreements where needed to secure appropriate rights and manage regulatory and contractual risk.
-
Lead the day-to-day operation of Hello Heart’s Privacy Program under the direction of the Chief Compliance and Privacy Officer, including HIPAA and state privacy and consumer health data requirements.
-
Lead the day-to-day operation and administration of Hello Heart’s AI governance program, including interpretation and implementation of federal and state AI laws and regulatory requirements.
-
Lead the interpretation and implementation of the legal and regulatory framework for data governance, including requirements for data collection, use, sharing, secondary use and reuse, AI use, retention, de-identification, deletion, disclosure, residency, and cross-border transfers.
-
Build and maintain the systems and controls that operationalize data governance, including data maps and records of processing, data classification and handling standards, and contractual obligation repositories.
-
Partner with Product, Engineering, Security, AI, Commercial, User Support, and other teams to implement privacy, data, and AI requirements.
-
Lead day-to-day privacy, data, and AI risk and incident management, including conducting assessments and leading the privacy, data, and AI aspects of incident response and breach analysis.
-
Lead privacy, data, and AI compliance monitoring and assurance, including audits, client audits, regulatory inquiries, investigations, certifications, and attestations.
-
Build and maintain the program’s policies, playbooks, training, and reporting, including standards and procedures for privacy, data governance, AI governance, responsible AI, and data rights.
Qualifications
-
8+ years of legal experience with substantial healthcare regulatory, privacy, and compliance experience in a HIPAA-regulated organization.
-
Significant experience negotiating complex data rights with sophisticated enterprise clients and partners.
-
Experience operating healthcare privacy and compliance programs, including regulatory interpretation and incident response.
-
Strong compliance judgment and an owner-operator mindset.
-
Advanced AI fluency and automation capability.
-
Experience with AI governance, including emerging AI laws and responsible AI controls.
-
Exceptional judgment, executive presence, and communication skills.
-
Active license to practice law and membership in good standing with a U.S. state bar.
Nice to Have
-
Experience with international privacy and data protection requirements.
-
Privacy or AI governance certifications such as CIPP/US, CIPM, or AIGP.
-
Experience building privacy or AI governance programs at a growth-stage or high-growth company.
-
Experience managing client trust, security questionnaires, certifications, attestations, or enterprise customer assurance programs.
Compensation
The US base salary range for this full-time position is $204,000.00 to $226,000.00. Salary ranges are determined by role and level. Compensation is determined by additional factors, including job-related skills, experience, and relevant education or training.