Your Role
We are seeking a detail-oriented and motivated Compliance Senior Associate to join our team. The ideal candidate will be responsible for tasks aligned with Innovaccers Compliance Program, which may include creation of training, policy management, performing audits and routine monitoring, and assisting with other responsibilities as assigned. This role will work closely with the broader Legal and Compliance Department to ensure adherence to regulatory requirements and internal policies.
A Day in the Life
- Drive the implementation and continuous improvement of Innovaccer's global privacy program, ensuring compliance with applicable laws and regulations across all jurisdictions where we operate, including but not limited to HIPAA, the HITECH Act, GDPR, and emerging U.S. state privacy laws (e.g., CCPA/CPRA). Aspects of the privacy program include without limitation:
- Maintain internal privacy policies, procedures, notices, and documentation for the handling of PHI and other personal data.
- Lead privacy incident investigations
- Conduct planned audit and monitoring activities (e.g., Business Associate Agreement audit)
- Serving as the Compliance representative on joint working groups and/or committees
- Support the development and delivery of compliance training programs for employees
What You Need
Partner with cross functional stakeholders to embed privacy-by-design principles into the entire product development lifecycle and provide actionable recommendations to mitigate privacy risks identified during assessments, balancing regulatory requirements with business and technological innovation
- Serve as the primary point of contact for privacy-related inquiries, escalations, and guidance from internal teams, customers, and regulatory bodies.
- Responsible for aspects of the compliance plan and driving completion of planned tasks Prepare draft reports for regulatory agencies and senior management as requested
- Proactively monitor the global regulatory landscape for changes in data privacy laws and enforcement trends relevant to the healthcare and technology industries
- Translate new regulatory requirements into actionable operational changes and strategic recommendations for the business
- Other duties as assigned.
- A minimum of 5 years of direct experience in a data privacy role, with at least 3 of those years operating in-house within a technology, SaaS, or cloud computing organization.
- Demonstrated, in-depth expertise with U.S. healthcare privacy laws, including HIPAA (Privacy, Security, and Breach Notification Rules) and the HITECH Act, and extensive experience applying them to complex data processing operations involving Protected Health Information (PHI).
- Proven experience managing compliance with international and domestic data protection regulations, including a strong working knowledge of GDPR and major U.S. state privacy laws (e.g., CCPA/CPRA).
- Experience reviewing, drafting, and negotiating privacy-related agreements, including Business Associate Agreements (BAAs) and Data Processing Addenda (DPAs) with enterprise customers and vendors.