Passionate about precision medicine and advancing the healthcare industry?
Recent advancements in underlying technology have finally made it possible for AI to impact clinical care in a meaningful way. Tempus' proprietary platform connects an entire ecosystem of real-world evidence to deliver real-time, actionable insights to physicians, providing critical information about the right treatments for the right patients, at the right time.
Tempus is seeking a Senior Privacy Counsel reporting to the Chief Privacy Officer to manage privacy risks and drive regulatory compliance across our healthcare, clinical, and AI platform operations. In this role, you will serve as a lead HIPAA advisor—partnering with Information Security, Compliance, and Product teams to maintain robust data protection standards while advancing real-world data innovation.
Position Overview
We are seeking a dedicated, business-minded Senior Privacy Counsel to join our growing Legal team. In this role, you will be a key contributor to Tempus’ health data privacy function reporting directly to the Chief Privacy Officer, advising on privacy risk management and regulatory compliance initiatives across our healthcare and platform operations.
This role serves as a key legal advisor on HIPAA regulations, with an emphasis on HIPAA Risk Analysis, Risk Management, and Breach Notification frameworks. You will partner directly with Information Security, Compliance, Clinical Operations, and Product Engineering to evaluate privacy risks across our clinical laboratories, diagnostic tools, and AI products—ensuring Tempus maintains robust HIPAA compliance while continuing to innovate with real-world data (RWD).
What You’ll Do (Responsibilities)
- HIPAA Risk Analysis & Management: Serve as a key legal partner in the review and execution of organization-wide HIPAA Security Rule Risk Analyses. Contribute to evaluating potential vulnerabilities to the confidentiality, integrity, and availability of Electronic Protected Health Information (ePHI) across cloud platforms, laboratory systems, and software tools. Partner with Information Security and Compliance teams to track, remediate, and manage compliance risks arising from internal reviews, external audits, and third-party assessments.
- Core HIPAA Compliance Support: Provide sound legal guidance on daily HIPAA/HITECH matters, supporting Privacy Rule compliance, Security Rule safeguards, and Breach Notification Rule protocols across various business units.
- De-Identification & Data Use: Partner with product and data engineering teams to advise on de-identification standards (Expert Determination and Safe Harbor) under HIPAA to facilitate secondary research, machine learning model training, and data licensing.
- Business Associate & Vendor Risk: Draft, review, and negotiate complex Business Associate Agreements (BAAs). Perform pre-vendor privacy risk evaluations and help establish legally sound data-handling boundaries for third-party service providers.
- Policy Governance & Training: Assist in updating HIPAA policies, procedure manuals, and employee training modules to reflect regulatory changes and evolving risk analysis outcomes.
- Incident Response & Risk Assessment Support: Assist with the legal analysis of potential security incidents or privacy events.
- Litigation Support: Assist and advise on privacy-related matters impacting litigation.
Required Qualifications
- Education: Juris Doctor (J.D.) degree from an accredited U.S. law school.
- Bar Admission: Active license to practice law in at least one U.S. state (and eligible for Illinois In-House Counsel registration).
- Experience: At least 5 years of legal experience with a core concentration in healthcare data privacy, including significant hands-on experience with HIPAA compliance within a health system, life sciences company, health tech firm, or top-tier law firm practice group. In-house experience is strongly preferred.
- Demonstrated HIPAA Experience: Practical experience contributing to HIPAA Security Rule Risk Analyses, risk mitigation plans, and OCR compliance frameworks.
- Technical Aptitude: Ability to collaborate effectively with Chief Information Security Officers (CISOs), IT security engineers, and data architects to translate technical risk assessments into pragmatic legal strategies.
- Breach & Incident Assessment: Familiarity with assisting in four-factor risk evaluations under the HIPAA Breach Notification Rule and contributing to incident response workflows.
Preferred Qualifications
- Consumer & State Privacy Knowledge: Familiarity with U.S. consumer privacy frameworks and state-specific health privacy laws (e.g., CCPA/CPRA, Washington My Health My Data Act, and state omnibus privacy legislation).
- International Data Privacy Experience: Working knowledge of international privacy regulations, particularly the EU/UK General Data Protection Regulation (GDPR), including processing special category health/genomic data, consent standards, and international cross-border data transfer mechanisms (Standard Contractual Clauses, Data Privacy Framework).
- Certifications: Certified Information Privacy Professional / US (CIPP/US), CIPP/E, or Certified Information Privacy Manager (CIPM) from the IAPP.
- Framework Alignment: Familiarity with NIST Cybersecurity Framework (CSF) or ISO 27001 mappings to HIPAA Security Rule requirements.
- Industry Context: Experience evaluating privacy risks associated with genomic data, CLIA/CAP accredited laboratory workflows, or AI/ML model training on health data.
Chicago: $175,000-$210,000
The expected salary range may vary for other locations. Actual salary may vary based on qualifications and experience. Tempus offers a full range of benefits, which may include incentive compensation, restricted stock units, medical and other benefits depending on the position.
We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
Skills Required
- Juris Doctor degree from an accredited U.S. law school
- Active license to practice law in at least one U.S. state
- Eligibility for Illinois In-House Counsel registration
- At least 5 years of legal experience with a core concentration in healthcare data privacy
- Hands-on HIPAA compliance experience within a health system, life sciences company, health technology firm, or top-tier law firm practice group
- Experience contributing to HIPAA Security Rule risk analyses, risk mitigation plans, and OCR compliance frameworks
- Ability to collaborate with CISOs, IT security engineers, and data architects
- Familiarity with four-factor HIPAA Breach Notification Rule risk evaluations and incident response workflows
- In-house legal experience
- Knowledge of U.S. consumer privacy frameworks and state-specific health privacy laws, including CCPA/CPRA and Washington My Health My Data Act
- Working knowledge of EU and UK GDPR, special-category health and genomic data, consent standards, and cross-border data transfer mechanisms
- CIPP/US, CIPP/E, or CIPM certification
- Familiarity with NIST Cybersecurity Framework or ISO 27001 mappings to HIPAA Security Rule requirements
- Experience with genomic data, CLIA/CAP-accredited laboratory workflows, or AI/ML model training on health data
What We Do
We bring together one of the world’s largest libraries of multimodal clinical and molecular data with a robust suite of AI tools to help physicians personalize care in real time, connect patients with therapies and clinical trials, and enable partners to accelerate discovery and development of new treatments. With ~8 million de-identified research records and 350+ petabytes of data, Tempus partners with more than half of U.S. oncologists and the majority of the top 20 global pharma companies. Our teams are pioneering work across oncology, neurology, psychiatry, cardiology, and beyond—transforming how care is delivered and therapies are developed. At Tempus, every role contributes to our mission: to help each patient benefit from the experiences of those who came before. For more information, visit tempus.com.
Why Work With Us
We’re looking for people who can change the world. People who question the status quo and refuse to shy away from tough problems. For builders who are never done building, and the learners who are never done learning. Passionate individuals with undying curiosity who want to take on one of the greatest challenges humanity has ever faced—head on.
Gallery
Tempus AI Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Most of the team follows a hybrid policy, with some roles allowing for a fully remote arrangement and some roles being onsite only.
































