
Assistant General Counsel, Privacy & Regulatory
- Salt Lake City, UT
- Permanent
- Full-time
- Serve as subject matter expert and internal escalation point for privacy and data protection issues in contracting, sales and marketing, business development and operations.
- Ensure the organization has appropriate privacy contract provisions, including DPAs, Business Associate Agreements, Standard Contractual Clauses and Transfer Impact Assessments, if and as required.
- Monitor developments in data protection, regulatory, and privacy laws applicable to advanced diagnostics, and develop and lead cross functional project teams to support company compliance.
- Provide practical legal advice on data driven projects while anticipating and navigating regulatory and privacy considerations. This includes advising on issues related to data sharing and analytics, mobile applications, and use of artificial intelligence.
- Participate in the review of customer-facing materials for alignment with applicable data protection and privacy policies, laws, and regulations.
- Oversee and provide legal advice on privacy incident and breach response program.
- Provide legal advice on the use of technology within the organization (i.e. enterprise digital marketing, websites, etc.).
- Partner with Information Security, Governance/Risk/Compliance (GRC), and Government Affairs on diagnostics regulatory oversight (FDA/CLIA etc.), privacy and cyber related policy/regulation impacting the company.
- Create and/or assist with privacy operations management, including, where applicable, DSARs, data mapping, data inventory, records of processing activities, DPIAs and PIAs.
- Provide legal advice to support compliance with HIPAA, GDPR, global privacy regulation, and state genetic testing, data breach notification, regulatory and privacy laws.
- Provide support for human subject research, IRB protocol, and informed consent review in compliance with the Common Rule and Clinical Trial Regulations.
- Provide privacy and regulatory advice in research and commercialization collaborations and M&A transactions and integrations.
- Assist in special projects and other duties as assigned.
- Juris Doctor degree and bar admission in good standing required, License in Utah preferred or ability to obtain Utah license upon hire.
- 7-10 years of law firm or in-house legal practice with a minimum of 3-5 years in a role focused on privacy, regulatory compliance, and risk management.
- Deep understanding of and demonstrated experience working with HIPAA/HITECH, the Common Rule, GDPR, CAN SPAM/TCPA, 21st Century Cures Information Blocking Rules, state comprehensive privacy laws (including CCPA) and emerging US state and global privacy laws.
- Experience in the diagnostics industry and working knowledge of CLIA and state regulations related to laboratory developed tests is strongly preferred.
- Strong business sense coupled with the ability to provide practical legal advice.
- Thorough organizational skills, and resourceful self-starter with excellent problem-solving capabilities, judgment, communication (written and verbal) and interpersonal skills.
- Ability to work collaboratively with cross functional teams and provide clear, concise and actionable legal advice.
- Understanding and adherence to legal ethics and ability to maintain confidentiality.