Passionate about precision medicine and advancing the healthcare industry?
Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.
Tempus is seeking a Senior Privacy Counsel reporting to the Chief Privacy Officer to manage privacy risks and drive regulatory compliance across our healthcare, clinical, and AI platform operations. In this role, you will serve as a lead HIPAA advisor—partnering with Information Security, Compliance, and Product teams to maintain robust data protection standards while advancing real-world data innovation.
Position Overview
We are seeking a dedicated, business-minded Senior Privacy Counsel to join our growing Legal team. In this role, you will be a key contributor to Tempus’ health data privacy function reporting directly to the Chief Privacy Officer, advising on privacy risk management and regulatory compliance initiatives across our healthcare and platform operations.
This role serves as a key legal advisor on HIPAA regulations, with an emphasis on HIPAA Risk Analysis, Risk Management, and Breach Notification frameworks. You will partner directly with Information Security, Compliance, Clinical Operations, and Product Engineering to evaluate privacy risks across our clinical laboratories, diagnostic tools, and AI products—ensuring Tempus maintains robust HIPAA compliance while continuing to innovate with real-world data (RWD).
What You’ll Do (Responsibilities)
- HIPAA Risk Analysis & Management: Serve as a key legal partner in the review and execution of organization-wide HIPAA Security Rule Risk Analyses. Contribute to evaluating potential vulnerabilities to the confidentiality, integrity, and availability of Electronic Protected Health Information (ePHI) across cloud platforms, laboratory systems, and software tools. Partner with Information Security and Compliance teams to track, remediate, and manage compliance risks arising from internal reviews, external audits, and third-party assessments.
- Core HIPAA Compliance Support: Provide sound legal guidance on daily HIPAA/HITECH matters, supporting Privacy Rule compliance, Security Rule safeguards, and Breach Notification Rule protocols across various business units.
- De-Identification & Data Use: Partner with product and data engineering teams to advise on de-identification standards (Expert Determination and Safe Harbor) under HIPAA to facilitate secondary research, machine learning model training, and data licensing.
- Business Associate & Vendor Risk: Draft, review, and negotiate complex Business Associate Agreements (BAAs). Perform pre-vendor privacy risk evaluations and help establish legally sound data-handling boundaries for third-party service providers.
- Policy Governance & Training: Assist in updating HIPAA policies, procedure manuals, and employee training modules to reflect regulatory changes and evolving risk analysis outcomes.
- Incident Response & Risk Assessment Support: Assist with the legal analysis of potential security incidents or privacy events.
- Litigation Support: Assist and advise on privacy-related matters impacting litigation.
Required Qualifications
- Education: Juris Doctor (J.D.) degree from an accredited U.S. law school.
- Bar Admission: Active license to practice law in at least one U.S. state (and eligible for Illinois In-House Counsel registration).
- Experience: At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on experience with HIPAA compliance within a health system, life sciences company, health tech firm, or top-tier law firm practice group. In-house experience is strongly preferred.
- Demonstrated HIPAA Experience: Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks.
- Technical Aptitude: Ability to collaborate effectively with Chief Information Security Officers (CISOs), IT security engineers, and data architects to translate technical risk assessments into pragmatic legal strategies.
- Breach & Incident Assessment: Familiarity with assisting in four-factor risk evaluations under the HIPAA Breach Notification Rule and contributing to incident response workflows.
Preferred Qualifications
- Consumer & State Privacy Knowledge: Familiarity with U.S. consumer privacy frameworks and state-specific health privacy laws (e.g., CCPA/CPRA, Washington My Health My Data Act, and state omnibus privacy legislation).
- International Data Privacy Experience: Working knowledge of international privacy regulations, particularly the EU/UK General Data Protection Regulation (GDPR), including processing special category health/genomic data, consent standards, and international cross-border data transfer mechanisms (Standard Contractual Clauses, Data Privacy Framework).
- Certifications: Certified Information Privacy Professional / US (CIPP/US), CIPP/E, or Certified Information Privacy Manager (CIPM) from the IAPP.
- Framework Alignment: Familiarity with NIST Cybersecurity Framework (CSF) or ISO 27001 mappings to HIPAA Security Rule requirements.
- Industry Context: Experience evaluating privacy risks associated with genomic data, CLIA/CAP accredited laboratory workflows, or AI/ML model training on health data.
Chicago: $175,000-$210,000
The expected salary range may vary for other locations. Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

