Director, Privacy Counsel
Job description
About the role
Omada Health is on the lookout for a Director of Privacy Counsel to spearhead and elevate our privacy initiatives across the organization. This position operates at the crossroads of healthcare regulations, consumer technology, and clinical services. The successful candidate will provide actionable guidance to foster innovation while ensuring the protection of member data and maintaining trust. As the primary leader in operational privacy matters, you will work closely with various departments to create and enhance policies and processes that guarantee compliance and address emerging risks effectively.
Key facts
What you'll do
- Oversee the management of Omada's HIPAA privacy program, which includes crafting policies, investigating privacy incidents, and determining responses to breaches.
- Ensure that privacy considerations are integrated into the design and development of digital products and services from the very beginning.
- Lead the privacy risk assessment program, which encompasses vendor evaluations and privacy reviews for commercial agreements.
- Provide expert legal counsel on consumer privacy laws, including state-specific health data regulations and practices related to digital advertising.
- Advise on the privacy implications associated with artificial intelligence and machine learning technologies.
- Support initiatives for data exchange by providing guidance on privacy requirements for health information sharing.
- Assist with privacy-related issues concerning ERISA and self-funded health benefit plans.
- Offer support for maintaining privacy compliance in clinical research activities.
- Develop and implement privacy training programs aimed at cultivating a culture of privacy awareness within the organization.
- Collaborate with cross-functional teams to ensure that privacy policies are effectively communicated and understood across the organization.
- Monitor and analyze changes in privacy regulations and assess their impact on the organization's operations.
- Serve as a point of contact for privacy-related inquiries from internal stakeholders and external partners.
Requirements
- Juris Doctor (J.D.) degree from an accredited law school and active admission to the bar.
- At least 8 years of experience specializing in privacy law, with substantial in-house experience in healthcare, digital health, or life sciences, or relevant experience at a top-tier law firm serving such clients.
- Comprehensive understanding of HIPAA Privacy, Security, and Breach Notification Rules.
- Familiarity with state-level consumer privacy laws, such as WMHMDA, CCPA/CPRA, and governance related to AI.
- Proven track record in managing privacy incident responses and breach notification processes effectively.
- Demonstrated ability to provide guidance on privacy-by-design principles for digital products and marketing strategies.
- Strong communication skills to simplify complex regulatory concepts for non-legal audiences and offer practical advice.
- Capacity to work autonomously, exercise sound judgment in ambiguous regulatory contexts, and juggle multiple complex projects simultaneously.
- Exceptional organizational skills and a keen eye for detail.
- A collaborative mindset with a focus on teamwork and building relationships across different functions.
Nice to have
- Experience working in a digital health, telehealth, or health technology organization that interacts directly with members.
- Knowledge of privacy governance related to AI and machine learning, as well as emerging regulations in this area.
- Familiarity with health information exchange (HIE) frameworks, including Carequality, CommonWell, and TEFCA.
- Understanding of ERISA regulations and privacy considerations for self-funded health benefit plans.
- Relevant privacy certifications, such as CIPP/US, CIPM, or CHPS.
- Experience in supporting privacy compliance for clinical research endeavors.
Skills & tools
- Proficiency in HIPAA regulations
- Knowledge of State Consumer Privacy Laws
- Understanding of AI Governance
- Expertise in Privacy-by-Design principles
- Experience in Incident Response procedures
- Skills in Risk Assessment methodologies
- Familiarity with Digital Health Technologies
Practical notes
Zone 1: $242,880 - $303,600
Zone 2: $232,320 - $290,400
Zone 3: $211,200 - $264,000
Compensation will be based on the candidate's experience, location, and other relevant factors.
Benefits include a competitive salary, annual bonuses, equity grants, an employee stock purchase plan (ESPP), flexible time off, parental leave, health insurance, a 401k plan, life and disability insurance, and mental health support.
Omada Health operates as a remote-first organization, allowing for flexibility and work-life balance.