
Senior Director, Digital Legal Office – Health and Wellness Privacy Counsel
- Indianapolis, IN
- Permanent
- Full-time
- Serve as the primary legal advisor on HIPAA Privacy and Security Rules, HITECH, and related healthcare data protection laws.
- Provide legal counsel on the design and implementation of digital health technologies, Pharmacy Management Systems, EHR platforms, health plans, onsite employee health clinics and related primacy care services, mobile health applications and other healthcare IT solutions.
- Advise on legal risks and mitigation strategies related to pharmacy intake and dispensing operations, including patient data intake, prescription processing, and digital consent.
- Draft, review, and negotiate contracts involving protected health information (PHI), including Business Associate Agreements (BAAs), data sharing agreements, and vendor contracts.
- Collaborate with IT, Compliance, and Product teams to ensure privacy-by-design principles are embedded in all digital solutions.
- Monitor and interpret evolving federal and state privacy laws (e.g., CCPA, CPRA, state-specific pharmacy laws) and advise on their impact.
- Support incident response and breach notification processes in accordance with HIPAA and state breach laws.
- Provide training and education to internal team members on HIPAA, digital privacy, and pharmacy compliance.
- Draft and review, and otherwise support negotiations regarding privacy provisions in a wide variety of agreements
- Oversee legal response to data breaches or privacy/security incidents including investigations, notifications, and remediation
- Support audits, regulatory inquiries, and enforcement actions
- J.D. degree from accredited schools.
- Active license to practice law in the United States.
- Minimum of 6 years of legal experience, with a focus on healthcare law.
- Extensive experience and in-depth knowledge of the Health Insurance Portability and Accountability Act (HIPAA) and its regulations with consistent record of providing legal support to pharmacies, Covered Entities, and Business Associates.
- Demonstrated experience standing up, supporting, and maintaining complex health and wellness privacy programs for regulated entities
- Working knowledge and understanding of various privacy regulations, frameworks, and accompanying guidance
- Experience successfully and strategically handling privacy risks, threats, and breaches
- Ability to research, track, and turn regulations and enforcement trends into practical, actionable advice
- Demonstrated collaboration skills with corporate business partners and/or clients, including the ability to work closely with information technology and security teammates and a clear understanding of roles and responsibilities
- Basic knowledge of and understanding of privacy regulators, including the FTC, states attorneys general, and HHS
- Familiarity with AI/ML in healthcare, interoperability standards, and health information exchanges
- Highly motivated and collaborative partner with strong interpersonal skills and the ability to work effectively with team members and members of management across all levels of the company
- Good judgement and a meticulous level of attention to detail
- Excellent written and verbal communication skills with a demonstrated ability to influence others
- Demonstrated commitment to expand knowledge and adapt to the changing environment
- Comfortable operating with a sense of urgency and ability to manage competing priorities in a fast-paced and evolving environment
- Experience counseling on emerging regulations and best practices in data governance, artificial intelligence, privacy, and cyber security
- Experience counseling technology teams
- Preferred Location: Indianapolis based. Open to remote with willingness to travel to Indianapolis on a quarterly basis or more often as required to meet relevant business needs