Tempus

Senior Privacy Counsel

Tempus • $175K — $210K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Juris Doctor (J.D.) degree from an accredited U.S. law school.
  • Active bar admission in at least one U.S. state; in-house counsel eligibility preferred.
  • Minimum 5 years of healthcare data privacy legal experience with in-depth knowledge of HIPAA compliance.
  • Experience in conducting HIPAA Security Rule Risk Analyses and developing risk mitigation plans.
  • Technical capability to communicate with IT security professionals and translate technical risks into legal frameworks.
  • Familiarity with HIPAA Breach Notification Rule and incident response protocols.

Responsibilities

  • Evaluate HIPAA compliance across various business units to mitigate privacy risks.
  • Provide legal guidance on HIPAA/HITECH matters, ensuring compliance with the Privacy and Security Rules.
  • Advise on HIPAA de-identification standards for secondary research and data analytics.
  • Negotiate complex Business Associate Agreements and conduct vendor risk assessments.
  • Update HIPAA policies and training programs to align with regulatory changes.
  • Support incident response efforts by analyzing security incidents and privacy breaches.
  • Advise on privacy issues concerning litigation matters.

Benefits

  • Full range of benefits including health and wellness programs.
  • Potential for incentive compensation and stock options.
  • Opportunities for professional development and career advancement.
Full Job Description

Tempus is seeking a Senior Privacy Counsel reporting to the Chief Privacy Officer to manage privacy risks and drive regulatory compliance across our healthcare, clinical, and AI platform operations. In this role, you will serve as a lead HIPAA advisor—partnering with Information Security, Compliance, and Product teams to maintain robust data protection standards while advancing real-world data innovation.


Position Overview

We are seeking a dedicated, business-minded Senior Privacy Counsel to join our growing Legal team. In this role, you will be a key contributor to Tempus’ health data privacy function reporting directly to the Chief Privacy Officer, advising on privacy risk management and regulatory compliance initiatives across our healthcare and platform operations.

This role serves as a key legal advisor on HIPAA regulations, with an emphasis on HIPAA Risk Analysis, Risk Management, and Breach Notification frameworks. You will partner directly with Information Security, Compliance, Clinical Operations, and Product Engineering to evaluate privacy risks across our clinical laboratories, diagnostic tools, and AI products—ensuring Tempus maintains robust HIPAA compliance while continuing to innovate with real-world data (RWD).


What You’ll Do (Responsibilities)

  • HIPAA Risk Analysis & Management: Serve as a key legal partner in the review and execution of organization-wide HIPAA Security Rule Risk Analyses. Contribute to evaluating potential vulnerabilities to the confidentiality, integrity, and availability of Electronic Protected Health Information (ePHI) across cloud platforms, laboratory systems, and software tools. Partner with Information Security and Compliance teams to track, remediate, and manage compliance risks arising from internal reviews, external audits, and third-party assessments.
  • Core HIPAA Compliance Support: Provide sound legal guidance on daily HIPAA/HITECH matters, supporting Privacy Rule compliance, Security Rule safeguards, and Breach Notification Rule protocols across various business units.
  • De-Identification & Data Use: Partner with product and data engineering teams to advise on de-identification standards (Expert Determination and Safe Harbor) under HIPAA to facilitate secondary research, machine learning model training, and data licensing.
  • Business Associate & Vendor Risk: Draft, review, and negotiate complex Business Associate Agreements (BAAs). Perform pre-vendor privacy risk evaluations and help establish legally sound data-handling boundaries for third-party service providers.
  • Policy Governance & Training: Assist in updating HIPAA policies, procedure manuals, and employee training modules to reflect regulatory changes and evolving risk analysis outcomes.
  • Incident Response & Risk Assessment Support: Assist with the legal analysis of potential security incidents or privacy events.
  • Litigation Support: Assist and advise on privacy-related matters impacting litigation.

Required Qualifications

  • Education: Juris Doctor (J.D.) degree from an accredited U.S. law school.
  • Bar Admission: Active license to practice law in at least one U.S. state (and eligible for Illinois In-House Counsel registration).
  • Experience: At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on experience with HIPAA compliance within a health system, life sciences company, health tech firm, or top-tier law firm practice group. In-house experience is strongly preferred.
  • Demonstrated HIPAA Experience: Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks.
  • Technical Aptitude: Ability to collaborate effectively with Chief Information Security Officers (CISOs), IT security engineers, and data architects to translate technical risk assessments into pragmatic legal strategies.
  • Breach & Incident Assessment: Familiarity with assisting in four-factor risk evaluations under the HIPAA Breach Notification Rule and contributing to incident response workflows.

Preferred Qualifications

  • Consumer & State Privacy Knowledge: Familiarity with U.S. consumer privacy frameworks and state-specific health privacy laws (e.g., CCPA/CPRA, Washington My Health My Data Act, and state omnibus privacy legislation).
  • International Data Privacy Experience: Working knowledge of international privacy regulations, particularly the EU/UK General Data Protection Regulation (GDPR), including processing special category health/genomic data, consent standards, and international cross-border data transfer mechanisms (Standard Contractual Clauses, Data Privacy Framework).
  • Certifications: Certified Information Privacy Professional / US (CIPP/US), CIPP/E, or Certified Information Privacy Manager (CIPM) from the IAPP.
  • Framework Alignment: Familiarity with NIST Cybersecurity Framework (CSF) or ISO 27001 mappings to HIPAA Security Rule requirements.
  • Industry Context: Experience evaluating privacy risks associated with genomic data, CLIA/CAP accredited laboratory workflows, or AI/ML model training on health data.

Chicago: $175,000-$210,000


The expected salary range may vary for other locations. Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.

About Tempus

Tempus is a technology company that has built an operating system to battle cancer. The company enables physicians to deliver personalized cancer care for patients through its interactive analytical and machine learning platform. Tempus provides genomic sequencing services and analyzes molecular and therapeutic data to empower physicians to make real-time, data-driven decisions. The company also offers research services to enable discovery of new therapeutic targets and clinical services that support clinical trial design and monitoring. Tempus was founded in 2015 by Eric Lefkofsky and has raised over $8 billion in funding to date.
Learn more about Tempus
Size
1,001 employees
Industry
Founded
2015

Similar Jobs

More Jobs at Tempus

More Healthcare Jobs

Find similar Senior Privacy Counsel jobs: