HealthPoint (CHC)

Privacy Design & Governance Director, Privacy-by-Design (Remote)

HealthPoint (CHC)  •  Oak Brook, IL (Remote)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Reporting to the Chief Privacy Officer (CPO), the Director of Privacy Design and Governance serves as the privacy lead for product development, ensuring that privacy is embedded into products and data initiatives from concept and design through development, deployment, and decommissioning. In this role, the Director advances a comprehensive privacy program aligned with HIPAA, GLBA, applicable state privacy laws, and emerging federal and industry standards, including privacy frameworks, control mapping, and privacy standards for AI/ML and vendor data handling.

Acting as a strategic partner to Product, Data Science, Legal, Security, Marketing, and Operations, the Director conducts privacy impact assessments and risk assessments, defines data-minimization and retention strategies, identifies safeguards and controls, and provides clear guidance on compliant data use and disclosures, and individual privacy rights. Through strong cross-functional leadership and measurable governance, the Director enables business innovation while ensuring regulatory compliance and fostering trust, transparency, and accountability in all product and data practices.

Duties & Responsibilities:

  • Build and maintain a privacy control framework that maps requirements across HIPAA, GLBA, state privacy laws, FTC expectations, and other applicable federal regulations.
  • Manage comprehensive standards addressing data sharing, de-identification, artificial intelligence and machine learning, and vendor data handling.
  • Manage the organization’s privacy-by-design framework, ensuring privacy considerations are embedded early in new product development, marketing initiatives, and business processes.
  • Lead a privacy advisory program that provides timely, practical, and risk-based guidance to business units on compliant data use and sharing.
  • Assist the CPO with stakeholder engagement and change management efforts, ensuring privacy requirements are clearly communicated, understood, and adopted across all departments.
  • Develop and manage the Privacy Impact Assessment (PIA) process to evaluate risks associated with new systems, projects, and technologies involving PHI, PII and NPPI.
  • Partner with Product, Engineering, and Security teams to define privacy control requirements and technical guardrails within design and deployment lifecycles.
  • Support Marketing, IT, Security, Legal and Data Sciences teams in ensuring compliant practices related to data profiling and tracking technologies.
  • Advise business units on individual rights processing (access, correction, deletion, opt-out) and ensure operational readiness for consumer privacy requests.
  • Assist CPO in the maintenance of privacy policies and procedures, workforce training, and deliver targeted privacy training for business units.
  • Monitor evolving HIPAA, GLBA, state, and federal privacy regulations, assessing their impact on organizational operations and policies.
  • Provide guidance and thought leadership on emerging privacy trends, regulatory expectations, and enforcement priorities.
  • Provide guidance and monitor compliance with the records retention policy to ensure proper administration in accordance with applicable laws and best practices.

Supervisory Responsibilities:

  • Recruits, interviews, hires, and trains new staff.
  • Oversees the daily workflow of the department.
  • Provides constructive and timely performance evaluations.

#LI-Remote

Qualifications

Education & Experience:

  • Bachelor’s degree in Healthcare Administration, Risk Management, Information Systems, Legal Studies, Public Policy, or a related field (JD or MBA/MHA preferred).
  • Relevant privacy certifications (CIPP/US, CIPM, CHPC, CHPS, or equivalent) preferred.
  • 5–8 years of privacy, compliance, or data governance experience within a HIPAA-regulated organization.

Skills & Abilities:

  • In-depth knowledge of the HIPAA Privacy, Security, and Breach Notification Rules, GLBA Safeguards and Privacy Rules, and major U.S. state privacy laws.
  • Expertise in privacy-by-design, PIAs, and risk analysis.
  • Demonstrated experience in privacy program development, policy design, risk management, and cross-functional advisory work.
  • Exceptional communication, leadership, and stakeholder management skills, with the ability to influence at all levels.
  • Strong analytical and problem-solving skills; ability to translate regulatory requirements into actionable guidance.
  • Excellent writing and communication skills for policies, training, and executive reporting.
  • Cross-functional collaboration and leadership experience across Legal, Security, IT, and Product.
  • Vendor risk and contract review advisory experience.
  • Ability to foster a culture of privacy accountability and continuous improvement.

Other Requirements:

  • Infrequent travel
    • Ability to provide personal transportation from time to time.
  • Occasionally lifts up to 25 pounds.
  • Prolonged periods of sitting at a desk and working on a computer
HealthPoint (CHC)

About HealthPoint (CHC)

HealthPoint is a community-based, community-supported and community-governed network of non-profit health centers dedicated to providing expert, high-quality care to all who need it, regardless of circumstances. Founded in 1971, we believe that the quality of your health care should not depend on how much money you make, what language you speak or what your health is. Because everyone deserves great care.

Today, HealthPoint is the health care home for more than 100,000 people in King County, Washington. High quality health care is essential to living well and thriving. Yet our region has huge disparities in both access to and quality of care. HealthPoint bridges that gap by breaking down barriers and providing care for ALL regardless of income, insurance, immigration status, or any other circumstance.

We offer a broad range of services (from primary medical and dental, to behavioral health, to natural medicine and acupuncture, to nutrition, to case management) and specialize in providing expert, innovative, and compassionate care to all who need it. That care is provided by over 150 doctors, dentists and other providers PLUS over 200 medical students and residents, dental residents and externs and more each year.

We also work beyond our 17 locations to promote healthy communities. Our mission is to strengthen communities and improve people’s health by delivering quality health care services, breaking down barriers, and providing access to all.

Curious what working at HealthPoint is all about? Check out this video: https://www.youtube.com/watch?time_continue=12&v=qDFlE07Zz_s

Industry
Healthcare & Social Services
Company Size
501-1,000 employees
Headquarters
Renton, Washington
Year Founded
1971
Social Media