Vice President, US Privacy and Global Data Protection Officer

Springhealth66 · Remote · Data

Posted 2026-08-05

Apply for this role →

Spring Health is actively seeking a VP, Privacy Officer to join our team. Reporting to the General Counsel and partnering with the Security, Product, and Engineering teams, the VP, Privacy Officer will own the US and Global privacy strategy and lead our efforts in maintaining the highest standards of data protection. We are looking for a creative problem-solver who can navigate the complex legal and regulatory landscape of a high-growth health tech startup, helping the company make sound, risk-based decisions in the transformational age of AI. This is a full-time, remote-friendly position with a preference for candidates in the NYC area, with periodic travel to our NYC headquarters.

What you’ll do

Serve as the designated US Privacy and Global Data Protection Officer, providing strategic leadership and vision for the company’s comprehensive privacy and data protection program.

Lead and mentor the privacy legal team, including attorneys and privacy paraprofessional, to ensure cohesive US and Global operations.

Develop creative and compliant legal strategies to navigate the intersection of healthcare privacy and cutting-edge AI, enabling the business to innovate while managing risk effectively.

Architect and scale a comprehensive privacy framework that accommodates Spring Health’s expansion into new international markets while remaining compliant with GDPR, HIPAA, and local regulations.

Act as the executive-level advisor on the privacy implications of emerging technologies, including the ethical and regulatory use of AI in clinical settings.

Oversee the execution of enterprise-wide privacy risk assessments, ensuring that "Privacy by Design" is a fundamental component of the product development lifecycle.

Direct the company’s response strategy for data incidents and breaches, including managing regulatory relationships and notification obligations.

Collaborate with the Sales and Customer Success teams to serve as a high-level subject matter expert during complex contract negotiations with Fortune 500 clients.

Define and maintain all external and internal privacy policies, ensuring transparency and trust with members, customers, and providers.

Partner with the People Team to ensure internal data practices regarding employee information are handled with the same level of rigor as member data.

What success looks like in this role

Successfully establish a risk-based governance framework for AI deployment that enables product velocity while maintaining strict privacy standards.

Achieve 100% completion of annual HIPAA and global privacy training across the enterprise.

Reduce privacy-related friction in the sales cycle by maintaining a comprehensive and updated Trust Center/Knowledge Base for customer inquiries.

Implement a scalable, automated Privacy Impact Assessment (PIA) workflow.

Successfully navigate and document compliance for two new international market entries within the first year.

Maintain a zero-finding status on privacy controls during annual SOC2 Type II and HITRUST audits.

What you’ll bring

Juris Doctorate (JD) from an accredited law school and active membership in at least one state bar.

12+ years of legal experience, with at least 8 years of dedicated focus on data privacy, security, and healthcare law.

Proven track record of leading and scaling privacy teams in a high-growth, global technology environment.

Deep expertise in HIPAA/HITECH, GDPR, CCPA/CPRA, and a working knowledge of international frameworks like LGPD or PIPEDA.

Professional privacy certifications (e.g., CIPP/US, CIPP/E, CIPM, or CIPT).

Exceptional communication skills with the ability to translate complex legal requirements into actionable, risk-based business strategies for non-legal stakeholders.

Experience navigating the privacy complexities of AI and machine learning in a regulated industry, with a focus on creative problem-solving.

A mission-driven mindset with a commitment to removing barriers to mental health through secure and ethical data practices.

The target base salary range for this position is $236,250 - $290,000 and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by a number of factors including experience, location, internal pay equity, and other relevant business considerations. We review all employee pay and compensation programs annually using Radford Global Compensation Database at minimum to ensure competitive and fair pay.

Apply for this role →

← Back to all jobs