Memorial Sloan Kettering Cancer Center

Senior Privacy Counsel

Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Expertise in GDPR and other global privacy frameworks, with experience in HIPAA and state health information laws.
  • In-depth knowledge of US privacy laws and emerging state regulations.
  • Practical experience implementing data privacy laws, including individual rights and data anonymization.
  • Familiarity with digital technology, advertising, and AI, especially regarding consumer privacy and tracking issues.
  • Experience translating regulatory requirements into actionable business strategies.
  • Strong organizational and people management skills related to complex policies and processes.
  • JD with at least 5 years of relevant legal experience; NYS license or in-house registration eligibility.

Responsibilities

  • Serve as a privacy subject matter expert for business, clinical, and research teams at MSK.
  • Manage compliance with GDPR and other global privacy standards.
  • Advise the legal team on privacy laws and collaborate on related transactions.
  • Negotiate HIPAA Business Associate Agreements with IT and vendor partners.
  • Draft and review privacy notices for MSK's digital platforms and advise on online tracking practices.
  • Guide the Compliance team on handling privacy inquiries from patients and staff.
  • Collaborate across departments to enhance personal data use policies and stay updated on privacy regulations.

Benefits

  • Hybrid work flexibility with occasional travel required.
  • Direct reporting to the VP, Privacy Officer & Chief Privacy Counsel.
  • Access to comprehensive benefits and resources for employee well-being.
Full Job Description
Senior Privacy Counsel

Exciting Opportunity at MSK: MSK's Privacy team is committed to safeguarding the privacy of our patients' information and to promoting the highest standards of ethics and integrity in all we do. We work closely with our colleagues across the enterprise to help MSK achieve its mission of Ending Cancer for Life.

We seek an experienced Privacy attorney to join our team in advising our internal clients on privacy law and policy, supporting enterprise strategic initiatives, clinical and business operations, and research matters, and managing our operational compliance with GDPR and related global-privacy frameworks.

Role Overview:
  • Serve as subject matter expert to business, clinical, and research teams across MSK. Advise on key legal questions related to privacy by gaining detailed insight into business areas. Perform detailed legal research as needed and provide timely, effective advice.
  • Manage MSK's operational compliance with GDPR and other global-privacy frameworks.
  • Advise other members of the MSK legal team on data privacy laws and collaborate on transactions led by those team members.
  • Lead negotiation of HIPAA Business Associate Agreements with MSK's IT and supply chain vendors.
  • Draft, update, and regularly review consumer-facing privacy notices for MSK digital properties; Advise the Development, Marketing and Communications, and other digital teams on use of cookies, pixels and other trackers on MSK digital properties.
  • Provide legal guidance to other members of the Compliance team in their management of privacy-related inquiries from patients and staff.
  • Collaborate with departments across the organization, including clinical, research, hospital administration, IT, procurement, and Information Security departments, and MSK's AI Governance Council to develop and enhance policies governing MSK's use of personal data (PHI, PII).
  • Stay abreast of new domestic and global privacy and data protection requirements and assess their impact on existing operations and strategic plans.


Key Qualifications:
  • Expertise in advising clients on GDPR and other global privacy frameworks, and experience with HIPAA and state privacy laws related to health information.
  • Demonstrated knowledge of US privacy and data protection laws and a keen understanding of the changing US privacy legal landscape, including emerging comprehensive state privacy laws.
  • Experience implementing the practical requirements of data privacy laws, including individual data subject rights and requirements for de-identification and data anonymization.
  • Demonstrated understanding of technology, marketing and ad tech, emerging AI technology, and experience advising clients on use of trackers, pixels, digital consumer privacy and protection (including, e.g., TCPA, CAN-SPAM, etc.).
  • Familiarity with regulatory requirements for Human Subjects Research preferred.
  • An established track record of translating regulatory requirements into practical and impactful elements while supporting business strategy.
  • Ability to skillfully maneuver through complex policy, process, and people-related organizational dynamics.
  • A Juris Doctorate (JD) and a minimum of 5 years of direct experience advising clients on privacy law either at a law firm or as part of an in-house legal or compliance team.
  • Licensed to practice in NYS or eligible for in-house registration.


Core Skills:
  • Privacy & Regulatory Compliance Expertise - Deep knowledge of HIPAA, GDPR, and global privacy frameworks to ensure organizational compliance and mitigate legal risk.
  • Legal Research & Advisory Skills - Ability to conduct thorough legal research and provide timely, practical guidance on complex privacy and data protection matters.
  • Contract Negotiation & Vendor Management - Experience leading negotiations of Business Associate Agreements (BAAs) and engaging with vendors on privacy and data security requirements.
  • Cross-Functional Collaboration & Stakeholder Engagement - Proven ability to partner with clinical, research, IT, compliance, procurement, and legal teams to develop privacy-focused policies and solutions.
  • Data Governance & Digital Privacy Strategy - Expertise in managing PHI/PII governance, privacy notices, cookies/trackers compliance, de-identification methodologies, and assessing the impact of evolving privacy regulations on business operations.


Additional Information:
  • Report directly to the VP, Privacy Officer & Chief Privacy Counsel.
  • Location: 633 Third Avenue, Hybrid Flexibility to travel to other sites as needed


Helpful Links:
  • Compensation Philosophy
  • Benefits


Pay Range: $137,500.00 - $227,000.00

FSLA Status: Exempt

About Memorial Sloan Kettering Cancer Center

Memorial Sloan Kettering Cancer Center is a world-renowned cancer treatment and research institution located in New York City. The center was founded in 1884 and has since become one of the leading cancer centers in the world, with a focus on patient care, research, and education. Memorial Sloan Kettering Cancer Center employs over 20,000 people, including doctors, nurses, researchers, and support staff, and treats over 500,000 patients each year. The center is known for its innovative treatments and cutting-edge research, which has helped to improve the lives of cancer patients around the world. Memorial Sloan Kettering Cancer Center is committed to finding a cure for cancer and improving the quality of life for cancer patients everywhere.
Learn more about Memorial Sloan Kettering Cancer Center
Size
20,000 employees
Industry
Founded
1884

Similar Jobs

More Jobs at Memorial Sloan Kettering Cancer Center

More Healthcare Jobs

Find similar Senior Privacy Counsel jobs: