Vice President, US Privacy and Global Data Protection Officer
Our mission: eliminating every barrier to mental health. Spring Health is a global mental health company building a world where getting support is simple, personal, and built around the person, so care can continue through every job, move, health plan, and life stage. Our AI-native platform delivers personalized support across self-guided tools, coaching, therapy, medication management, and specialty care, with outcomes independently validated by JAMA Network Open and the Validation Institute. Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.
About the role
Reporting to the General Counsel and partnering with the Security, Product, and Engineering teams, the VP, Privacy Officer will own the US and Global privacy strategy and lead efforts in maintaining the highest standards of data protection. This is a full-time, remote-friendly position with a preference for candidates in the NYC area, requiring periodic travel to our NYC headquarters.
Responsibilities
- Serve as the designated US Privacy and Global Data Protection Officer, providing strategic leadership and vision for the company’s comprehensive privacy and data protection program.
- Lead and mentor the privacy legal team, including attorneys and privacy paraprofessionals, to ensure cohesive US and Global operations.
- Develop creative and compliant legal strategies to navigate the intersection of healthcare privacy and cutting-edge AI, enabling the business to innovate while managing risk effectively.
- Architect and scale a comprehensive privacy framework that accommodates Spring Health’s expansion into new international markets while remaining compliant with GDPR, HIPAA, and local regulations.
- Act as the executive-level advisor on the privacy implications of emerging technologies, including the ethical and regulatory use of AI in clinical settings.
- Oversee the execution of enterprise-wide privacy risk assessments, ensuring that "Privacy by Design" is a fundamental component of the product development lifecycle.
- Direct the company’s response strategy for data incidents and breaches, including managing regulatory relationships and notification obligations.
- Collaborate with the Sales and Customer Success teams to serve as a high-level subject matter expert during complex contract negotiations with Fortune 500 clients.
- Define and maintain all external and internal privacy policies, ensuring transparency and trust with members, customers, and providers.
- Partner with the People Team to ensure internal data practices regarding employee information are handled with the same level of rigor as member data.
What Success Looks Like
- Successfully establish a risk-based governance framework for AI deployment that enables product velocity while maintaining strict privacy standards.
- Achieve 100% completion of annual HIPAA and global privacy training across the enterprise.
- Reduce privacy-related friction in the sales cycle by maintaining a comprehensive and updated Trust Center/Knowledge Base for customer inquiries.
- Implement a scalable, automated Privacy Impact Assessment (PIA) workflow.
- Successfully navigate and document compliance for two new international market entries within the first year.
- Maintain a zero-finding status on privacy controls during annual SOC2 Type II and HITRUST audits.
Requirements
- Juris Doctorate (JD) from an accredited law school and active membership in at least one state bar.
- 12+ years of legal experience, with at least 8 years of dedicated focus on data privacy, security, and healthcare law.
- Proven track record of leading and scaling privacy teams in a high-growth, global technology environment.
- Deep expertise in HIPAA/HITECH, GDPR, CCPA/CPRA, and a working knowledge of international frameworks like LGPD or PIPEDA.
- Professional privacy certifications (e.g., CIPP/US, CIPP/E, CIPM, or CIPT).
- Exceptional communication skills with the ability to translate complex legal requirements into actionable, risk-based business strategies for non-legal stakeholders.
- Experience navigating the privacy complexities of AI and machine learning in a regulated industry, with a focus on creative problem-solving.
- A mission-driven mindset with a commitment to removing barriers to mental health through secure and ethical data practices.
Pay
The target base salary range for this position is $236,250 - $290,000 and is part of a competitive total rewards package including equity and benefits. Individual pay may vary from the target range and is determined by factors including experience, location, and internal pay equity.
Benefits
- Health, Dental, and Vision benefits starting on your first day, including access to One Medical accounts for you and your dependents.
- HSA and FSA plans, with Spring contributing up to $1K for HSAs, depending on your plan type.
- Employer-sponsored 401(k) match of up to 2% for retirement planning.
- A yearly allotment of no-cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
- Competitive paid time off policies including vacation, sick leave, and company holidays.
- Parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents, available at 6 months tenure.
- Access to Noom, a psychology-based weight management program tailored to your unique needs and goals.
- Fertility care support through Carrot, including $4,000 reimbursement for related expenses.
- Access to Wellhub, connecting employees to fitness, mindfulness, nutrition, and sleep resources in one subscription.
- Access to BrightHorizons for sponsored child care, back-up care, and elder care.
- Up to $1,000 Professional Development Reimbursement per year.
- $200 per year donation matching to support your favorite causes.