Description:

About Freshpaint
Customer data is the fuel that drives all modern businesses. From product analytics, to marketing, to support, to advertising, advanced data analysis in the warehouse, and even sales – customer data is the raw material for each function at a modern business.

For highly regulated businesses in healthcare, it's always been a challenge to harness that customer data and get it to the marketing and analytics tools that require it while following patient privacy laws….until now.

Something as simple as running ads to get more users is simple for an e-commerce of software company to do. But common web analytics and advertising tools collect sensitive user identifiers and healthcare information automatically. Those same tools are not HIPAA compliant.

We provide a layer of data governance to make current web analytics tools HIPAA-compliant. For analytics, our customers can continue getting the insights they need to improve the patient experience. For marketing, Freshpaint safeguards health information while helping our customers promote access to care through popular advertising platforms like Facebook, Google, and others.

In short, we help healthcare marketers promote access to care and safeguard patient privacy at the same time. This is an important, complex problem in a massive market (healthcare is 20% of the US GDP).

Our customers manage their customer data with two offerings:
  1. Privacy Platform. We help healthcare providers automate their website's + app's HIPAA compliance, and safeguard first-party customer data across their tech stack.
  2. Data Activation Platform. We make it really easy for teams to activate customer data using their preferred analytics, data, and marketing tools.

We're fully remote. If you strongly value in-person work, Freshpaint is likely not the best fit for you. Even though we don't care where you're located, we need employees to be based in the US. Many of our team is concentrated in various metro areas like SF or NYC.

To balance out our remote-ness, we gather the team 2-4 times per year for offsites. We've been to Greece, Jackson Hole, Cabo, Santa Fe, and California wine country in the recent past.

We're backed by leading investors including Y-Combinator, Intel Capital, and angel investors like the Head of Data from Slack, Head of Data at LinkedIn, and more.

In this role you will:
  • Act as the primary legal advisor for all matters related to customer Master Service Agreements (MSAs), ensuring both compliance with applicable laws and alignment with our business goals.
  • Collaborate heavily with the Sales team with stellar execution and operating principles
  • Review, draft, and redline MSAs, privacy policies, and other legal documents, balancing legal risk and business objectives.
  • Collaborate closely with customer legal teams to negotiate and finalize terms that are favorable and equitable for both parties.
  • Provide comprehensive legal support across various departments, advising on legal implications of company strategies and operational decisions, especially concerning software development, data privacy, and healthcare compliance.
  • Stay abreast of legislative changes that may impact the company's business or operations, particularly in healthcare privacy laws and software compliance, and adjust company policies accordingly.
  • Educate and train employees on legal best practices, HIPAA compliance, and risk management to foster a culture of compliance across the organization.

Requirements:
  • Juris Doctor (JD) degree from an accredited law school and admission to at least one state bar.
  • A minimum of 5 years of legal experience in a law firm or corporate setting, with a strong focus on healthcare law, privacy, and technology.
  • Ability to manage priorities and work load across all US time zones to ensure proper support for our teams.
  • Deep knowledge of HIPAA and other relevant healthcare compliance regulations, as well as experience with software-related legal issues.
  • Proven track record of successfully negotiating and drafting MSAs and other complex contracts.
  • Excellent analytical, negotiation, and communication skills, capable of effectively engaging with both internal teams and external parties.
  • Ability to work independently in a fast-paced startup environment, managing multiple priorities with tight deadlines.
  • Must be eligible for in-house counsel registration, certification, or obtain a limited license to practice in the state(s) where the company operates, if not already licensed in those states.

Nice to Have:
  • Prior experience in the healthcare technology sector, particularly in startups focusing on privacy and compliance solutions.
  • Additional certifications or advanced degrees in healthcare law, privacy, or a related field.
  • Familiarity with international privacy laws, such as GDPR, and experience in managing legal issues in a global context.
  • Technical proficiency or understanding of software development processes and the technological aspects of healthcare applications.