This job was posted more than 40 days ago and might be expired.
Bask Health logo

Head of Compliance (HIPAA) and Security

Posted 2 months ago

RemoteNew York, United States

At Bask Health, every role is AI-first. Work starts in an LLM to clarify intent and context, moves into the right tools to explore and execute, is tested with real users and stakeholders, and is continuously refined as we learn. AI and self-serve research are default parts of how we work, not side experiments.
We are looking for people who take full ownership of their work, treat AI as a real collaborator, and care deeply about building a company that meaningfully improves how healthcare is delivered.
What You'll Do

Work AI-first: Use LLMs as your starting point โ€” to clarify thinking, draft output, research problems, and move faster. Apply your own judgment to refine quality and make it count.

Validate and iterate: Test your work with real users and stakeholders. Use what you learn to improve before problems become patterns.

Share AI-native workflows: Document prompts, processes, and workflows that work. Share them across your team so we raise the bar together.

Key Responsibilities

  • Reporting to the General Counsel this position provides strategic and operational legal support across legal issues in cybersecurity, data privacy, artificial intelligence, and data governance.
  • Develop, implement, and maintain the organization's comprehensive data governance and security, privacy and compliance frameworks and policies.ย 
  • Serve as the Privacy Officer and primary legal and operational authority on HIPAA, including Privacy Rule and Security Rule requirements
  • Ensure adherence to global, federal, state and emerging privacy laws (GDPR, CPRA, etc.), as applicable
  • Advise executive leadership on cybersecurity risk, mitigation, data governance, and regulatory obligations
  • Lead internal audits, risk assessments, and incident response planning
  • Manage relationships with outside counsel, regulators, and third-party vendors on compliance matters
  • Educate staff on data handling, privacy practices, and security threats. Organize and oOversee employee training programs on data privacy, security protocols, and HIPAA obligations
  • Monitor evolving federal and state data privacy legislation and assess organizational impact
  • Draft and enforce internal data security policies, procedures, and Business Associate Agreements (BAAs)
  • Represent the organization in regulatory investigations or breach notification proceedings, remediation efforts, and regulatory notifications.

Requirements

  • J.D. from an accredited law school and active bar membership required in NY
  • 4 to 6 years of experience in health law, data privacy, or cybersecurity law
  • Deep expertise in HIPAA/HITECH, state privacy laws, and corporate data security standards
  • Experience advising on or litigating data breach, privacy, or regulatory enforcement matters
  • Familiarity with NIST, SOC 2, ISO 27001, or similar security frameworks
  • Strong understanding of emerging technologies, cloud infrastructure, AI, and their legal implications

Bonus Qualifications

  • IAPP Certified Information Privacy Professional designation (CIPP) or similar
  • Certified HIPAA Professional (CHP) or equivalent
Job details
Workplace
Remote
Location
New York, United States

Bask provides a full service software that allows you to build any digital health experience. Built for doctors, physicians, entrepreneurs, and developers, the Bask system was built at enterprise scale for the everyday user.

Industry
Internet Marketplace Platforms
Headquarters
New York, NY
Founded
2021
Company location
New York, NY

Key team members

Leonardo Silva

Leonardo Silva

Max Zamkow

Max Zamkow

Susanna Lewis

Susanna Lewis

Sandro Macchioli

Sandro Macchioli

Apply smarter with Jobr

Jobr aggregates jobs directly from company career portals โ€” no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

Direct from company career pages
AI-personalised cover letters
Human review before every submit
Application tracking & follow-ups