
Privacy Manager
Posted Sep 2

Posted Sep 2
This is a fully remote position, open to applicants in United States.
• Report to the Director of Privacy/Privacy Officer
• Collaborate with Legal, Security, Clinical, Product, and Operations teams
• Uphold policies, procedures, and controls that align with HIPAA, 42 CFR Part 2, state privacy laws, and other relevant regulations
• Ensure privacy controls, data maps, and records of processing are up-to-date with designated owners, evidence, and testing schedules
• Monitor privacy risks and operational metrics, including request volume, aging items, and remediation progress
• Convert regulatory, payer, and contractual requirements into actionable guidance
• Create privacy training programs and resources for employees
• Address privacy inquiries, individual rights requests, and potential incidents
• Oversee workflows related to HIPAA and state privacy rights, including access, amendment, accounting of disclosures, restrictions, confidential communications, and deletion
• Assist with incident investigations, documentation, root-cause analysis, and corrective measures
• Organize evidence, timelines, and logistics for notifications and regulatory submissions
• Perform privacy assessments for products, vendors, workflows, and initiatives involving PHI or sensitive personal information
• Collaborate with the AI Governance Program to assess AI and machine-learning use cases
• Conduct vendor privacy due diligence alongside Legal and Security
• Maintain the BAA inventory and work towards resolving identified gaps
• Develop practical checklists and playbooks to ensure consistent, scalable privacy reviews
• 4–7 years of privacy experience in a regulated industry such as healthcare, health technology, health plans, or financial services in the U.S.
• Direct experience with HIPAA is highly preferred
• Practical experience in at least two of the following areas: privacy incidents, individual rights or DSAR workflows, privacy assessments, vendor and BAA governance, or privacy training
• Capacity to interpret complex legal and regulatory requirements into clear, actionable advice for non-experts
• Strong judgment when making privacy decisions and escalating legal matters
• Exceptional written and verbal communication abilities
• Skill to balance daily operations with long-term program development and enhancement
• Proficiency with AI tools for research, drafting, and analysis
• Sound judgment regarding the verification and management of PHI and other regulated information
• Ability to assess AI use cases that involve patient data
• Collaborative and pragmatic approach when dealing with ambiguity and resistance
• Strong alignment with Headway’s mission
• Familiarity with 42 CFR Part 2, minor consent and confidentiality requirements, or other heightened-confidentiality rules is a plus
• Knowledge of payer or contractual privacy obligations is a plus
• Experience in evaluating privacy risks in SaaS, cloud, or AI-enabled products is a plus
• Relevant certifications such as CIPP/US, CIPM, CIPT, CHPC, CHPS, or an AI governance credential are a plus
• Authorization to work in the United States for any employer
• Comprehensive health and wellness benefits
• Retirement savings options
• Meaningful equity ownership opportunities
• Reasonable accommodations for individuals with disabilities
DraftKings Inc.
Astrana Health
Herbal Goodness
Worldwide Clinical Trials
Get handpicked remote jobs straight to your inbox weekly.