Senior Privacy and AI Counsel at Abby Care | USA | Rezi

Senior Privacy and AI Counsel at Abby Care

Senior Privacy and AI Counsel

Abby Care · USA

1 months ago

Senior Privacy and AI Counsel

Abby Care · USA

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Abby Care is seeking a Senior Privacy & AI Counsel to own the company's privacy and AI governance programs. This role involves setting program strategy, managing daily operations, and serving as a subject matter expert in a fast-paced, evolving regulatory environment. You will partner with various teams, brief executive leadership, and build the playbook for AI and privacy at scale.

Responsibilities

  • Own Abby Care's privacy program, including HIPAA and state privacy law compliance, BAA program, data mapping, incident response, and individual rights workflows.
  • Own Abby Care's AI governance program, including responsible AI policy, AI inventory, use case intake and review, model risk classification, monitoring, and incident response.
  • Lead AI use case reviews for internal and product-based AI tools, setting SLAs and review frameworks.
  • Set regulatory change management strategy for federal and state privacy and AI law.
  • Manage the BAA program end-to-end, including templates, vendor risk, and subcontractor flow-downs.
  • Serve as the senior legal partner to Product, Engineering, Operations, and Clinical teams on privacy and AI implications.
  • Lead privacy and AI incident response, including investigation, breach analysis, and remediation.
  • Prepare privacy and AI sections of Board packages.
  • Manage outside privacy and AI counsel relationships.
  • Hire, develop, and lead the privacy and AI team.
  • Partner with General Counsel and Compliance leadership on Privacy Officer designation, training, and integration of controls.

Requirements

  • JD from an accredited law school and active bar membership in good standing in at least one U.S. jurisdiction.
  • 7+ years of legal experience, in-house or at a top law firm, with substantial privacy and AI work.
  • In-house experience at a healthcare or healthcare technology company strongly preferred.
  • Deep working command of HIPAA/HITECH — including the Privacy, Security, and Breach Notification Rules — and a demonstrated track record of building HIPAA Privacy programs.
  • Deep working command of U.S. state privacy laws and the emerging U.S. state AI law landscape.
  • Demonstrated track record of building or materially rebuilding an AI governance program.
  • Demonstrated experience leading privacy incident response end-to-end.
  • Strong written communication and the credibility to take and defend a position with executives, the Board, regulators, and outside counsel.
  • Comfort operating in a fast-growth environment with imperfect data, parallel priorities, and the need to write the policy yourself before handing it off.
  • Experience advising on healthcare AI deployment, including FDA SaMD/CDS analysis, clinical decision support governance, and patient-facing AI disclosures.
  • Familiarity with 42 CFR Part 2, the 21st Century Cures Act information blocking rules, and state Medicaid confidentiality requirements.
  • Familiarity with NIST AI RMF, ISO/IEC 42001, and other AI assurance frameworks.
  • Prior work with state Medicaid agencies, MCOs, or other government payors on privacy or data use matters.
  • Experience hiring, developing, and leading a small legal or privacy team.
  • IAPP certifications: CIPP/US strongly preferred; AIGP a meaningful plus; CIPM useful.
  • A sense of humor and a steady temperament under pressure.

Skills

  • Privacy program management
  • AI governance
  • HIPAA compliance
  • State privacy law compliance
  • BAA program management
  • Data mapping
  • ROPA
  • Privacy incident response
  • Breach assessment and notification
  • Individual rights workflows
  • Responsible AI policy design
  • AI use case intake and review
  • Model risk classification
  • AI incident response
  • Regulatory change management
  • Vendor risk management
  • Product and Engineering legal partnership
  • Board reporting
  • Outside counsel management
  • Team leadership
  • Compliance program integration
  • Healthcare AI deployment
  • FDA SaMD/CDS analysis
  • Clinical decision support governance
  • Patient-facing AI disclosures
  • 42 CFR Part 2
  • 21st Century Cures Act information blocking rules
  • State Medicaid confidentiality requirements
  • NIST AI RMF
  • ISO/IEC 42001
  • AI assurance frameworks
  • Government payor relations

Location

  • San Francisco

Work Type

  • Full-Time
  • Hybrid

Experience Level

  • Senior

Education Level

  • JD from an accredited law school
  • Active bar membership in good standing in at least one U.S. jurisdiction

Benefits

  • Competitive compensation packages
  • Annual company performance bonus
  • Comprehensive health coverage (90% employee premiums, 70% dependent premiums)
  • Multiple PPO plan options for medical, vision, dental, life, and short-term disability
  • Generous paid time off
  • 10 paid company holidays
  • Team bonding activities
  • Annual company retreat
  • HSA contributions
  • Optional FSA
  • Commuter benefits
  • Full coverage of all 401(k) account fees
  • Paid parental leave

About the Company

  • Abby Care is building the leading AI-native platform for family-led care, addressing the growing care crisis in America.
  • The company combines clinical oversight with an AI-powered platform to train, enable, and support family caregivers.
  • Abby Care partners with health plans, providers, and community organizations, and is backed by top VCs.
  • The company envisions a future where family-led care is a core part of the healthcare system.

Equal Opportunity

  • We are an equal opportunity employer and welcome applicants from all backgrounds, consistent with applicable laws.
  • Employment is contingent upon successful completion of a background check, satisfactory references, and any required documentation.