
Head of Compliance – HIPAA and Security
Bask Health
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Job Level
Tech Stack
About the role
- Reporting to the General Counsel this position provides strategic and operational legal support across legal issues in cybersecurity, data privacy, artificial intelligence, and data governance.
- Develop, implement, and maintain the organization's comprehensive data governance and security, privacy and compliance frameworks and policies.
- Serve as the Privacy Officer and primary legal and operational authority on HIPAA, including Privacy Rule and Security Rule requirements.
- Ensure adherence to global, federal, state and emerging privacy laws (GDPR, CPRA, etc.), as applicable.
- Advise executive leadership on cybersecurity risk, mitigation, data governance, and regulatory obligations.
- Lead internal audits, risk assessments, and incident response planning.
- Manage relationships with outside counsel, regulators, and third-party vendors on compliance matters.
- Educate staff on data handling, privacy practices, and security threats. Organize and oversee employee training programs on data privacy, security protocols, and HIPAA obligations.
- Monitor evolving federal and state data privacy legislation and assess organizational impact.
- Draft and enforce internal data security policies, procedures, and Business Associate Agreements (BAAs).
- Represent the organization in regulatory investigations or breach notification proceedings, remediation efforts, and regulatory notifications.
Requirements
- J.D. from an accredited law school and active bar membership required in NY
- 4 to 6 years of experience in health law, data privacy, or cybersecurity law
- Deep expertise in HIPAA/HITECH, state privacy laws, and corporate data security standards
- Experience advising on or litigating data breach, privacy, or regulatory enforcement matters
- Familiarity with NIST, SOC 2, ISO 27001, or similar security frameworks
- Strong understanding of emerging technologies, cloud infrastructure, AI, and their legal implications
- Bonus Qualifications
- IAPP Certified Information Privacy Professional designation (CIPP) or similar
- Certified HIPAA Professional (CHP) or equivalent
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
data governancedata privacycybersecurityHIPAAdata breachregulatory enforcementNISTSOC 2ISO 27001cloud infrastructure
Soft Skills
strategic thinkingoperational supportadvisory skillsrelationship managementeducational skillsorganizational skillscommunication skillsleadershiprisk assessmentincident response
Certifications
J.D.active bar membershipIAPP Certified Information Privacy Professional (CIPP)Certified HIPAA Professional (CHP)