
Head of Privacy
Job description
About the role
The Head of Privacy will own and evolve Abridge's privacy strategy and execution across the entire business. This role is responsible for building and scaling a robust privacy and data governance program that keeps pace with rapid growth and innovation. The position sits at the critical intersection of artificial intelligence, healthcare data, product development, and regulatory compliance. You will act as the central privacy authority, shaping how sensitive health information is collected, used, and shared responsibly. The role demands sound business judgment, autonomy, and the ability to lead through influence in a fast-paced, high-growth environment. You will be a strategic partner trusted to enable innovation while rigorously protecting individuals and the company.
Key facts
What you'll do
- Lead Abridge's enterprise privacy program, providing practical, product-focused counsel to Security, Product, and Engineering teams on complex privacy decisions.
- Advise cross-functional stakeholders on privacy obligations specific to artificial intelligence, machine learning models, clinical data workflows, and the responsible handling of sensitive information.
- Build and scale practical, cross-functional privacy programs and controls that align with HIPAA and other applicable U.S. privacy frameworks, including CCPA/CPRA, biometric privacy laws, and emerging state privacy legislation.
- Partner with commercial counsel to govern first-party and third-party data relationships, including vendor assessments, data sharing agreements, and contractual privacy expectations.
- Manage interactions with government agencies and regulators, preparing for audits, investigations, disclosures, and regulatory negotiations related to privacy and data protection.
- Monitor the evolving landscape of privacy, cybersecurity, healthcare, and AI regulations, assess their potential impact on Abridge operations, and translate developments into clear action plans and recommendations.
- Oversee the maintenance and updating of privacy policies, notices, and internal governance documents to ensure accuracy, completeness, and regulatory alignment.
- Draft, maintain, and operationalize privacy policies, playbooks, templates, governance standards, and training materials to promote awareness and consistent decision-making across the company.
- Drive the implementation of privacy-by-design principles within product development lifecycles, ensuring that privacy risks are identified and mitigated early.
- Collaborate with Security and Engineering to establish data mapping, classification, and retention programs that support compliance and risk management objectives.
- Lead privacy impact assessments and risk analysis initiatives, translating technical and operational details into actionable privacy controls and mitigations.
- Serve as a subject matter expert on privacy matters, representing Abridge internally and externally to customers, partners, and regulators.
- Coordinate cross-functional training and awareness programs to embed privacy best practices across product, engineering, sales, and support organizations.
- Provide guidance on biometric privacy laws and other specialized regimes that may intersect with AI-driven healthcare solutions.
Requirements
- Have 15+ years of professional experience, with a background spanning in-house roles, health technology environments, or technology-focused law firm engagements.
- Bring deep knowledge of HIPAA and other U.S. healthcare privacy requirements, along with CCPA/CPRA, biometric privacy laws, and relevant state privacy and data security frameworks.
- Demonstrate a proven track record of leading privacy teams and developing professionals within complex, regulated environments.
- Show a practical, risk-based approach to privacy, with the ability to balance legal obligations, regulatory expectations, business goals, and customer needs.
- Possess strong business judgment and the confidence to operate autonomously while exercising sound judgment in ambiguous situations.
- Exhibit excellent communication and relationship-building skills, with the ability to explain intricate legal requirements clearly to both technical and non-technical audiences.
- Display strong organizational skills and the capacity to manage multiple high-priority initiatives simultaneously in a dynamic, fast-moving growth-stage company.
- Hold a Juris Doctor degree from an accredited law school and maintain active membership in good standing with at least one U.S. state bar.
Nice to have
- Prior experience working within healthcare or a health technology company is strongly preferred.
- Familiarity with recent trends at the intersection of privacy regulations and artificial intelligence is desirable.
Practical notes
This is a hybrid role open to candidates in New York or San Francisco. Candidates must be willing to work from our SF or NY office 3x per week (M/W/F).