Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Health Insurance, HealthcareIndustries

Privacy Manager

Employment Type: Full Time

Position Overview

Gravie is seeking a Privacy Manager to play a critical role in safeguarding sensitive information and ensuring Gravie’s compliance with a complex landscape of privacy laws and regulations. This individual will be responsible for developing, implementing, and monitoring privacy policies and procedures, managing privacy incidents, and collaborating cross-functionally to embed privacy-by-design principles across the organization. This role requires a strong understanding of the Health Insurance Portability and Accountability Act (HIPAA) and broader healthcare privacy practices, particularly within the payer/plan/carrier environment.

Responsibilities

  • Assist in the development, implementation, and maintenance of comprehensive privacy policies, procedures, and training programs in alignment with applicable laws and industry best practices.
  • Conduct regular privacy risk assessments and impact analyses to identify and mitigate potential privacy vulnerabilities.
  • Monitor changes in privacy laws and regulations, assessing their impact on company operations and recommending necessary adjustments to policies and practices.
  • Lead or assist in the investigation and resolution of privacy incidents, including potential breaches of Protected Health Information (PHI) and other sensitive data.
  • Manage the incident response lifecycle from detection and containment to eradication, recovery, and post-incident analysis.
  • Maintain accurate records of all privacy incidents, investigations, and remediation efforts.
  • Ensure timely and compliant breach notification processes as required by HIPAA and state laws.
  • Collaborate closely with the Information Security team on data protection initiatives, ensuring privacy requirements are integrated into security controls and data governance frameworks.
  • Advise on privacy-by-design principles for new products, systems, and processes.
  • Participate in vendor due diligence processes, particularly regarding Business Associate Agreements (BAAs) and data handling practices.
  • Prepare for and support internal and external privacy audits, including HIPAA compliance assessments.
  • Assist in the preparation and maintenance of documentation for SOC 2 (Service Organization Control 2) audits related to privacy criteria.
  • Contribute to regulatory reporting requirements related to privacy.
  • Serve as a subject matter expert on privacy matters, providing guidance and support to internal departments (e.g., Legal, IT, HR, Product, Operations, Sales).
  • Review and approve language related to privacy in member communications, contracts, and marketing materials.
  • Manage privacy-related inquiries and requests from members, clients, and regulatory bodies.

Requirements

  • Bachelor's degree in a relevant field (e.g., Healthcare Administration, Information Systems, Legal Studies, Business).
  • 3-5 years of progressive experience in privacy compliance within a relevant industry.

Company Information

Hi, we’re Gravie. Our mission is to improve the way people purchase and access healthcare through innovative, consumer-centric health benefit solutions that people can actually use. Our industry-changing products and services are developed and delivered by a diverse group of unique people. We encourage you to be your authentic self - we like you that way.

Skills

Privacy policies
HIPAA
Healthcare privacy
Risk assessments
Incident management
Privacy-by-design
Regulatory compliance
PHI management

Gravie

Health benefits and insurance solutions provider

About Gravie

Gravie provides health benefits by offering straightforward and affordable health plans, primarily targeting individuals and small to midsize businesses. Their main product, Comfort, stands out because it has no deductible and no copays for most common healthcare services, allowing members to access care without unexpected costs. Additionally, Comfort includes virtual care options for musculoskeletal and mental health issues. Gravie also offers a payment solution called Gravie Pay, which enables members to pay for healthcare expenses interest-free, further easing financial stress. Unlike traditional health plans, Gravie claims that Comfort members save on out-of-pocket costs, and employers switching to Gravie often see lower premium expenses. The company has a high retention rate, indicating that many employees choose to continue with the Comfort plan in subsequent years. Gravie's goal is to simplify health benefits and reduce the financial burden of healthcare for its members.

Minneapolis, MinnesotaHeadquarters
2013Year Founded
$333.3MTotal Funding
DEBTCompany Stage
Fintech, HealthcareIndustries
201-500Employees

Benefits

Health Insurance
401(k) Retirement Plan
401(k) Company Match
Paid Holidays
Paid Vacation
Paid Sick Leave
Flexible Work Hours
Paid Parental Leave
Wellness Program
Alternative Medicine Coverage
Cell Phone Reimbursement
Transportation Perks
Education Reimbursement
Paid Paw-ternity Leave

Risks

Potential backlash from traditional insurers could increase competition or lobbying.
Rapid ICHRA adoption may invite regulatory scrutiny or changes.
Aggressive expansion strategy could strain resources and lead to inefficiencies.

Differentiation

Gravie's Comfort plan offers zero deductibles and copays, unlike traditional health plans.
Gravie Pay provides interest-free payment solutions, reducing financial burdens for members.
Focus on virtual healthcare services enhances accessibility and member satisfaction.

Upsides

Increased ICHRA adoption since 2020 expands Gravie's market opportunities.
Comfort plan's zero-deductible model attracts cost-conscious employers and employees.
Virtual healthcare services align with rising demand, boosting member engagement.

Land your dream remote job 3x faster with AI