Role at a glance
- Job function
-
Legal & Compliance Attorneys & Legal Counsel
- Salary
- Not Disclosed
- Location
- Chicago, United States
- Employment
- Full-time
- Experience
- At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on experience...
- Education
- Juris Doctor (J.D.) degree from an accredited U.S. law school.
Spotted an issue?
We’ll check it against the original posting.
Role Summary
The Senior Privacy Counsel advises Tempus on privacy risk management and regulatory compliance across its healthcare and platform operations, reporting to the Chief Privacy Officer. The role focuses on HIPAA legal guidance and privacy risks involving clinical laboratories, diagnostic tools, and AI products.
What You'll Do
- Partner on organization-wide HIPAA Security Rule Risk Analyses and help assess ePHI vulnerabilities across cloud platforms, laboratory...
- Work with Information Security and Compliance to track and remediate risks arising from internal reviews, audits, and third-party...
- Advise on HIPAA/HITECH compliance, including Privacy Rule, Security Rule, and Breach Notification requirements.
- Advise product and data engineering teams on HIPAA de-identification standards for secondary research, machine learning, and data licensing.
- Draft, review, and negotiate Business Associate Agreements and support vendor privacy risk evaluations.
- Assist with updating HIPAA policies, procedures, and training; provide legal analysis for potential privacy or security incidents and...
Generated from the employer's posting. Verify important details before applying.
View full postingQualifications
Required: J.D. from an accredited U.S. law school; active license to practice law in at least one U.S. state and eligibility for Illinois In-House Counsel registration; at least 5 years of legal experience concentrated in healthcare data privacy, including hands-on HIPAA compliance experience. Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks; ability to work with security and data teams to translate technical risk assessments into legal strategies; familiarity with HIPAA Breach Notification four-factor risk evaluations and incident response workflows.
Required
- Juris Doctor (J.D.) degree from an accredited U.S. law school.
- Active license to practice law in at least one U.S. state and eligible for Illinois In-House Counsel registration.
- At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on HIPAA...
- Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks.
- Ability to collaborate with CISOs, IT security engineers, and data architects to translate technical risk assessments into pragmatic...
- Familiarity with assisting in four-factor risk evaluations under the HIPAA Breach Notification Rule and contributing to incident...
Preferred
- In-house experience.
- Familiarity with U.S. consumer privacy frameworks and state-specific health privacy laws, including CCPA/CPRA, Washington My Health My...
- Working knowledge of international privacy regulations, particularly EU/UK GDPR, including special category health/genomic data, consent...
- IAPP CIPP/US, CIPP/E, or CIPM certification.
- Familiarity with NIST Cybersecurity Framework or ISO 27001 mappings to HIPAA Security Rule requirements.
- Experience evaluating privacy risks associated with genomic data, CLIA/CAP-accredited laboratory workflows, or AI/ML model training on...
Original job description
Content provided by the employer
Original job description
Content provided by the employer
Passionate about precision medicine and advancing the healthcare industry?
Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.
Tempus is seeking a Senior Privacy Counsel reporting to the Chief Privacy Officer to manage privacy risks and drive regulatory compliance across our healthcare, clinical, and AI platform operations. In this role, you will serve as a lead HIPAA advisor—partnering with Information Security, Compliance, and Product teams to maintain robust data protection standards while advancing real-world data innovation.
Position Overview
We are seeking a dedicated, business-minded Senior Privacy Counsel to join our growing Legal team. In this role, you will be a key contributor to Tempus’ health data privacy function reporting directly to the Chief Privacy Officer, advising on privacy risk management and regulatory compliance initiatives across our healthcare and platform operations.
This role serves as a key legal advisor on HIPAA regulations, with an emphasis on HIPAA Risk Analysis, Risk Management, and Breach Notification frameworks. You will partner directly with Information Security, Compliance, Clinical Operations, and Product Engineering to evaluate privacy risks across our clinical laboratories, diagnostic tools, and AI products—ensuring Tempus maintains robust HIPAA compliance while continuing to innovate with real-world data (RWD).
What You’ll Do (Responsibilities)
- HIPAA Risk Analysis & Management: Serve as a key legal partner in the review and execution of organization-wide HIPAA Security Rule Risk Analyses. Contribute to evaluating potential vulnerabilities to the confidentiality, integrity, and availability of Electronic Protected Health Information (ePHI) across cloud platforms, laboratory systems, and software tools. Partner with Information Security and Compliance teams to track, remediate, and manage compliance risks arising from internal reviews, external audits, and third-party assessments.
- Core HIPAA Compliance Support: Provide sound legal guidance on daily HIPAA/HITECH matters, supporting Privacy Rule compliance, Security Rule safeguards, and Breach Notification Rule protocols across various business units.
- De-Identification & Data Use: Partner with product and data engineering teams to advise on de-identification standards (Expert Determination and Safe Harbor) under HIPAA to facilitate secondary research, machine learning model training, and data licensing.
- Business Associate & Vendor Risk: Draft, review, and negotiate complex Business Associate Agreements (BAAs). Perform pre-vendor privacy risk evaluations and help establish legally sound data-handling boundaries for third-party service providers.
- Policy Governance & Training: Assist in updating HIPAA policies, procedure manuals, and employee training modules to reflect regulatory changes and evolving risk analysis outcomes.
- Incident Response & Risk Assessment Support: Assist with the legal analysis of potential security incidents or privacy events.
- Litigation Support: Assist and advise on privacy-related matters impacting litigation.
Required Qualifications
- Education: Juris Doctor (J.D.) degree from an accredited U.S. law school.
- Bar Admission: Active license to practice law in at least one U.S. state (and eligible for Illinois In-House Counsel registration).
- Experience: At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on experience with HIPAA compliance within a health system, life sciences company, health tech firm, or top-tier law firm practice group. In-house experience is strongly preferred.
- Demonstrated HIPAA Experience: Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks.
- Technical Aptitude: Ability to collaborate effectively with Chief Information Security Officers (CISOs), IT security engineers, and data architects to translate technical risk assessments into pragmatic legal strategies.
- Breach & Incident Assessment: Familiarity with assisting in four-factor risk evaluations under the HIPAA Breach Notification Rule and contributing to incident response workflows.
Preferred Qualifications
- Consumer & State Privacy Knowledge: Familiarity with U.S. consumer privacy frameworks and state-specific health privacy laws (e.g., CCPA/CPRA, Washington My Health My Data Act, and state omnibus privacy legislation).
- International Data Privacy Experience: Working knowledge of international privacy regulations, particularly the EU/UK General Data Protection Regulation (GDPR), including processing special category health/genomic data, consent standards, and international cross-border data transfer mechanisms (Standard Contractual Clauses, Data Privacy Framework).
- Certifications: Certified Information Privacy Professional / US (CIPP/US), CIPP/E, or Certified Information Privacy Manager (CIPM) from the IAPP.
- Framework Alignment: Familiarity with NIST Cybersecurity Framework (CSF) or ISO 27001 mappings to HIPAA Security Rule requirements.
- Industry Context: Experience evaluating privacy risks associated with genomic data, CLIA/CAP accredited laboratory workflows, or AI/ML model training on health data.
Chicago: $175,000-$210,000
The expected salary range may vary for other locations. Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
About the company
Tempus AI
Large Enterprise
Tempus AI is a cutting-edge technology company specializing in artificial intelligence solutions for healthcare. By harnessing advanced machine learning algorithms, Tempus AI aims to enhance patient outcomes through data-driven insights and personalized treatment plans. The company collaborates with medical professionals and researchers to bridge the gap between clinical data and actionable intelligence, thereby transforming the way healthcare is delivered and understood. With a commitment to innovation and excellence, Tempus AI is at the forefront of revolutionizing healthcare through technology.