Privacy Manager
Headway
- Location
- Remote
- Employment
- Full Time
- Work model
- Remote
- Level
- Mid
- Posted
- 1h ago
Skills
About this role
1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway’s mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that. But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens. We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better. The Privacy Manager is a hands-on member of Headway’s Privacy team, reporting to the Director of Privacy/Privacy Officer. You will partner closely with Legal, Security, Clinical, Product, and Operations to strengthen the privacy practices that support Headway’s growth and earn the trust of patients and providers. You will own core privacy operations across HIPAA, state privacy laws, behavioral health confidentiality, individual rights, vendor governance, and the responsible use of AI. Success in this role means building processes that work in practice: assessments are completed, incidents are investigated, rights requests meet statutory deadlines, and privacy risks are addressed. You will Operate and improve the privacy program Maintain policies, procedures, and controls supporting HIPAA, 42 CFR Part 2, state privacy laws, and other applicable requirements. Keep privacy controls, data maps, and records of processing current, with clear owners, evidence, and testing schedules. Track privacy risks and operational metrics, including request volume, aging items, and remediation progress. Translate regulatory, payer, and contractual requirements into practical guidance for teams across Headway. Develop privacy training and resources that help employees make sound decisions. Manage privacy requests and incidents Triage privacy inquiries, individual rights requests, and potential incidents. Manage HIPAA and state privacy rights workflows, including access, amendment, accounting of disclosures, restriction, confidential communications, and deletion. Support incident investigations, documentation, root-cause analysis, and corrective actions. Coordinate the evidence, timelines, and logistics required for notification and regulatory submissions. Assess product, AI, and vendor risk Conduct privacy assessments for products, vendors, workflows, and initiatives involving PHI or sensitive personal information. Partner with the AI Governance Program to evaluate AI and machine-learning use cases for appropriate data use, minimum necessary access, retention, transparency, and human oversight. Conduct privacy diligence on vendors with Legal and Security, maintain the BAA inventory, and drive identified gaps to resolution. Build practical checklists and playbooks that make privacy reviews consistent and scalable. You have 4–7 years of U.S. privacy experience in a regulated industry such as healthcare, health technology, health plans, or financial services. Direct HIPAA experience is strongly preferred. Hands-on experience in at least two of the following areas: privacy incidents, individual rights or DSAR workflows, privacy assessments, vendor and BAA governance, or privacy training. The ability to translate complex legal and regulatory requirements into clear, actionable guidance for non-experts. Strong judgment about which privacy