676,377open jobs
39,196companies
102,149added this week
Browse all
Salary
$204k – $226k per year
Location
Remote (United States)
Seniority
Senior · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Hello Heart is a healthcare technology company offering a mobile app to help individuals track and improve their heart health. The app provides real-time tips, allows users to track their blood pressure, and offers personalized insights to help users manage their heart health more effectively. Hello Heart also partners with businesses, health plans, and labor unions to provide these tools to their employees and members, demonstrating a significant impact on heart health outcomes through personalized and data-driven approaches.

About Hello Heart:

Hello Heart is on a mission to make heart attacks a thing of the past.

We’re an AI company focused exclusively on heart health, building a platform that predicts and prevents cardiac events before they happen-identifying risk up to 10 days in advance versus 10 years in traditional clinical models. 

This is already working at scale. Hello Heart has been shown to reduce inpatient hospital days by 47% and deliver ~$1,800 in annual savings per member. Hello Heart is the cardiac prevention partner to over 80% of large U.S. health plans and serves hundreds of public and private employers.

We’re defining how the #1 cause of death-heart disease-is managed in the AI era. Join us.

About the role:

As Senior Counsel, Data Governance, you will own Hello Heart’s legal and regulatory strategy for data use. You will lead negotiations on how Hello Heart can collect, use, share, retain, reuse, and apply AI to data, ensuring our agreements give the company the rights it needs to operate, innovate, and grow while meeting our regulatory and contractual obligations.

Reporting into our Chief Compliance and Privacy Officer, you will serve as their right hand. You will have direct exposure to and working relationships with Hello Heart’s C-suite and senior executives, partnering closely with leaders across Sales, Technology, Product, Security, and other functions on high-impact business decisions. You will lead the day-to-day operation of Hello Heart’s privacy and data governance programs and the execution of our AI governance program, translating complex privacy, data, and AI requirements into contracts, policies, controls, product requirements, and operating practices across the company.

This is an owner-operator role. You will not simply advise teams on requirements. You will negotiate, build, implement, maintain, run, monitor, audit, and remediate the programs and controls within your scope.

Responsibilities: 

  • Lead and execute negotiations regarding Hello Heart’s data rights across new and existing client and partner agreements, including BAAs, DPAs, data use agreements, data sharing agreements, and other agreements governing data rights and obligations, including data use, sharing, ownership, secondary use and reuse, AI use and training, system outputs and data-related intellectual property rights, retention, de-identification, deletion, disclosure, and downstream use; proactively identify and renegotiate existing agreements where needed to secure appropriate rights and manage regulatory and contractual risk.
  • Lead the day-to-day operation of Hello Heart’s Privacy Program under the direction of the Chief Compliance and Privacy Officer, including HIPAA and state privacy and consumer health data requirements, privacy notices and consents, consumer rights, privacy incidents and breach determinations, required notifications, regulator inquiries, and ongoing compliance.
  • Lead the day-to-day operation and administration of Hello Heart’s AI governance program, including interpretation and implementation of federal and state AI laws and regulatory requirements, the AI Governance Committee, governance framework, policies, procedures, approval processes, AI system and use-case inventory, risk assessments, responsible AI controls, governance records, and regulatory change management.
  • Lead the interpretation and implementation of the legal and regulatory framework for data governance, including requirements for data collection, use, sharing, secondary use and reuse, AI use, retention, de-identification, deletion, disclosure, residency, and cross-border transfers; translate changing requirements into practical policies, controls, procedures, and implementation plans.
  • Build and maintain the systems and controls that operationalize data governance, including data maps and records of processing, data classification and handling standards, contractual obligation repositories and processes for translating contractual obligations into operational controls, accountable owners, implementation requirements, and evidence of compliance, retention and disposal requirements, and vendor and third-party privacy and data reviews and data-use controls.
  • Partner with Product, Engineering, Security, AI, Commercial, User Support, and other teams to implement privacy, data, and AI requirements, including privacy by design, permissible data and AI uses, product notices and consents, technical and operational controls, and processes for addressing consumer and user questions; serve as the day-to-day escalation point for privacy, data rights, permissible data use, and AI governance questions, escalating material risks to the Chief Compliance and Privacy Officer.
  • Lead day-to-day privacy, data, and AI risk and incident management, including conducting assessments, leading the privacy, data, and AI aspects of incident response and breach analysis, escalating material risks, coordinating required notifications and corrective actions, and driving remediation through completion.
  • Lead privacy, data, and AI compliance monitoring and assurance, including audits, client audits, regulatory inquiries, investigations, certifications, attestations, client trust and assurance requests, and review of representations regarding Hello Heart’s privacy, data, and AI practices; monitor compliance and drive remediation when gaps are identified.
  • Build and maintain the program’s policies, playbooks, training, and reporting, including standards and procedures for privacy, data governance, AI governance, responsible AI, and data rights, as well as training for Product, Engineering, Commercial, User Support, and other relevant teams and executive reporting on program performance, risk, findings, and remediation.

Qualifications:

  • 8+ years of legal experience with substantial healthcare regulatory, privacy, and compliance experience in a HIPAA-regulated organization. Healthcare experience is required.
  • Significant experience negotiating complex data rights with sophisticated enterprise clients and partners, including large health plans, healthcare organizations, and other heavily represented counterparties; must be able to independently lead difficult negotiations involving data use, ownership, AI rights, secondary use, retention, deletion, de-identification, and related restrictions.
  • Experience operating healthcare privacy and compliance programs, including regulatory interpretation, incident and breach response, risk assessment, monitoring, auditing, corrective actions, and remediation.
  • Strong compliance judgment and an owner-operator mindset, with the ability to move from legal interpretation to practical implementation and drive issues through resolution.
  • Advanced AI fluency and automation capability. You use AI extensively in substantive legal and compliance work, automate repeatable workflows, and are comfortable building and using AI agents to increase speed, quality, consistency, and leverage in a lean team.
  • Experience with AI governance, including emerging AI laws, risk assessments, approval workflows, inventories, responsible AI controls, and monitoring.
  • Exceptional judgment, executive presence, and communication skills, with the ability to represent Hello Heart in high-stakes negotiations, defend well-reasoned positions, and effectively challenge sophisticated internal and external stakeholders when necessary.
  • Active license to practice law and membership in good standing with a U.S. state bar.

Nice to Have:

  • Experience with international privacy and data protection requirements, including cross-border data transfers.
  • Privacy or AI governance certifications such as CIPP/US, CIPM, or AIGP.
  • Experience building privacy or AI governance programs at a growth-stage or high-growth company.
  • Experience managing client trust, security questionnaires, certifications, attestations, or enterprise customer assurance programs.

The US base salary range for this full-time position is $204,000.00 to $226,000.00. Salary ranges are determined by role and level. Compensation is determined by additional factors, including job-related skills, experience, and relevant education or training. Please note that the compensation details listed in US role postings reflect the salary only, and do not include equity or benefits.

Hello Heart has a positive, diverse, and supportive culture - we look for people who are collaborative, creative, and courageous. Oh, and if you want to see some recent evidence of the fun things we do at Hello Heart, check out our Instagram page.  

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
676,377 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$53k – $98k per year • In office • Full-Time • Bachelor's Degree • Houston
Cybersecurity
HIPAA
Marketing
Salesforce
Apply
Senior AI Engineer 5 hours ago
$25k – $61k per year (Estimated) • In office • Full-Time
JavaScript
TypeScript
Node JS
Databases
PostgreSQL
Redis
Neo4j
pgvector
AI/ML
Model Context Protocol
Embeddings
Function Calling
AI Agents
AWS Bedrock
RAG
Semantic Search
OpenAI
Anthropic
Semantic Search
Knowledge Graph
Agentic Workflows
Tool Use
Mastra
DevOps
Git
AWS
Docker
Amazon S3
Amazon ECS
Apply
IT Support Analyst IV 5 hours ago
$68k – $138k per year (Estimated) • In office • Full-Time • 3+ years exp
SQL
PowerShell
Databases
Databricks
DevOps
Splunk
Datadog
Dynatrace
Azure
AppDynamics
Incident Management
SLI/SLO/SLA
Analytics
ETL/ELT
Management
ServiceNow
Apply
$107k – $287k per year (Estimated) • In office • Tel Aviv
AI/ML
XGBoost
Reinforcement Learning
Scikit-learn
LightGBM
PyTorch
DevOps
CI/CD
Analytics
A/B Testing
Apply
$128k – $239k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Tel Aviv
Analytics
A/B Testing
Apply
$126k – $233k per year (Estimated) • In office • 7+ years exp • Tel Aviv
Apply
$96k – $242k per year (Estimated) • In office • 7+ years exp • Bachelor's Degree • Tel Aviv
Python
Go
JavaScript
Java
TypeScript
Node JS
Scala
Scala
Play Framework
Databases
PostgreSQL
Redis
ElasticSearch
Apache Kafka
AI/ML
Spark
Frontend
Redux
React.js
Mobile
React Native
DevOps
AWS
Docker
Kubernetes
Apply
$90k – $110k per year • Remote • Full-Time • 3+ years exp
Python
SQL
Scala
DevOps
Kibana
AWS
Kubernetes
Amazon S3
Apply
See all jobs
This is one of many
676,377 more open roles from verified company boards, updated every day.