- Career Center Home
- Search Jobs
- Associate General Counsel
Description
NCQA is hiring an Associate General Counsel, Programs, Privacy and Research
NCQA is at an important point in its evolution as the nation’s leading independent authority on healthcare quality. As NCQA modernizes its accreditation, measurement, data, research, digital quality, and enterprise operations, the legal function must be more than a traditional support function. It must be a strategic partner that helps the organization move with confidence, protect trust, manage risk, and translate complex legal, regulatory, privacy, and governance requirements into practical business solutions. The Associate General Counsel, Programs, Privacy and Research will play a central role in that work. This leader will provide senior-level legal counsel across NCQA’s programs, products, contracts, research activities, data practices, privacy obligations, corporate operations, and stakeholder-facing processes. The role requires sound legal judgment, business orientation, privacy and healthcare regulatory depth, and the ability to advise senior leaders in a fast-moving, mission-driven environment. This is not simply a legal advisory role. It is a strategic risk, business enablement, transformation, privacy, and enterprise counsel role at the center of NCQA’s next chapter.
Position Summary
The Associate General Counsel, Programs, Privacy and Research serves as a senior attorney in the Office of General Counsel and as NCQA's designated Privacy Official. The position provides strategic, practical, and risk-informed legal counsel on privacy, healthcare regulatory, evaluation program, research, data governance, compliance, and operational matters.
Working in partnership with the General Counsel, Enterprise Risk Officer and Compliance Officer and other legal team members, this role helps NCQA achieve its mission while protecting the organization's legal, regulatory, operational, and reputational interests. The position translates complex legal and regulatory requirements into practical business guidance and serves as a trusted strategic advisor to leaders across the organization.
This role is a peer to other Associate General Counsel positions and serves as the primary legal lead for privacy and data protection, healthcare and AI regulation, research, evaluation programs and litigation matters.
Position Purpose
Serve as NCQA's lead attorney for:
- Privacy, HIPAA and cybersecurity compliance
- Healthcare regulatory matters, including AI
- Data governance and data-use issues
- Accreditation, certification and recognition legal support
- Regulatory and operational risk analysis
- Human subject research protections
- Litigation
The position helps ensure that NCQA's programs, products, research activities, data practices, and stakeholder-facing decisions remain legally sound, mission-aligned, and operationally effective. Strong strategic thinking, business enablement and transformation support skills are paramount.
Reporting Relationships
The Associate General Counsel, Privacy, Regulatory Affairs & Research reports to the General Counsel, Enterprise Risk Officer and Compliance Officer. The role works closely with leaders and teams across NCQA, including:
- Product and Customer Operations
- Information Security and Technology
- Product Development
- Quality Solutions
- Policy
- Research
- Compliance
- Human Resources
- Finance
- Executive Leadership
Primary Responsibilities
1. Privacy, HIPAA, Data Governance and Technology
Serve as NCQA's Privacy Official and principal legal advisor on privacy, data protection, data governance, technology, and emerging issues, including:
- HIPAA compliance
- Privacy policies and procedures
- Privacy impact assessments
- Breach and incident response
- Business Associate Agreements
- Data Use Agreements
- Sensitive data classification
- Privacy training and awareness
- Monitoring federal and state privacy developments
- Technology-related legal considerations, information-sharing arrangements, and regulatory developments affecting technology-enabled programs
Partner with Information Security and business leaders to support responsible innovation, and appropriate data governance controls while protecting NCQA's legal and reputational interests.
2. Healthcare Regulatory, Evaluation Program and Operational Legal Counsel
Advise NCQA leaders and staff on healthcare regulatory, evaluation program, product, customer-facing, and operational matters, including:
- Healthcare regulatory requirements, including AI
- Accreditation and recognition activities
- Program operations
- Customer-facing processes
- Product development initiatives
- Survey and review activities
- Quality measurement activities
- Regulatory developments affecting NCQA programs
Translate legal requirements into practical guidance that supports strategic and operational objectives.
3. Program Integrity and Determination Processes
Advise NCQA business units regarding:
- Standards implementation
- Recognition, accreditation, and certification processes
- Reconsideration and appeals procedures
- Procedural fairness considerations
- Customer communications
- Legal risks affecting operational determinations
Help maintain the integrity, defensibility, and transparency of stakeholder-facing programs.
4. Research Compliance and Responsible Data Use
Provide legal counsel and support related to:
- Human Subject Research Protection Program activities
- Federal wide Assurance requirements
- Institutional Review Board processes
- Research determinations
- Research policies and training
- Data-sharing and publication activities
- Ethical and legal considerations involving data use
Promote legally compliant and responsible research practices across NCQA.
5. Enterprise Risk, Compliance, Investigations and Litigation
Partner with the General Counsel, Enterprise Risk Officer and Compliance Officer and organizational leaders to:
- Identify legal and regulatory risks
- Support compliance activities
- Participate in risk assessments
- Assist with investigations and dispute resolution
- Analyze emerging legal and regulatory developments
- Support litigation and other significant legal matters within the role's designated practice areas
Provide legal recommendations that help the organization manage enterprise risks effectively.
Decision-Making Authority
The Associate General Counsel, Programs, Privacy and Research is expected to make independent legal recommendations and provide legal guidance regarding matters within the role's designated practice areas, including:
- Privacy determinations
- Regulatory interpretation
- Research compliance guidance
- Program integrity issues
- Data governance matters
- Operational legal advice
The role may approve privacy-related policies, legal guidance, and routine matters within delegated authority.
Significant organizational, governance, litigation, enterprise-risk, strategic-partnership, and Board-level matters remain subject to review by the General Counsel, Enterprise Risk Officer and Compliance Officer.
Requirements
Education
- Juris Doctor degree from an accredited law school.
- Active bar admission in good standing.
Required Experience
- Approximately 7–10 years of relevant legal experience.
- Experience advising on healthcare law, privacy, regulatory compliance, data governance, research, or related matters.
- Experience drafting and negotiating legal agreements.
- Ability to provide practical legal advice to business leaders and cross-functional teams.
Preferred Experience
- Experience serving as privacy counsel or privacy official.
- HIPAA and healthcare privacy and data governance expertise.
- Healthcare regulatory experience, including AI regulation
- Human subject research and IRB experience.
- Healthcare quality, accreditation, certification, or evaluation program experience.
- Familiarity with Commercial, Medicare, and Medicaid programs.
- Experience supporting governance, compliance, and enterprise-risk activities.
Core Competencies
- Strategic legal and business judgment
- Healthcare regulatory expertise
- Privacy and data governance knowledge
- Sound risk assessment skills
- Strong written and verbal communication
- Business-oriented problem solving
- Cross-functional collaboration
- Operational discipline and responsiveness
- Commitment to NCQA's mission, independence, and public trust
Compensation & Benefits:
- For new hires, this position pays in the range of $250K - $275K per year, depending on experience.
- This position is eligible for an annual incentive bonus, payable in accordance with policy.
- Click here for employee benefit
NCQA is committed to being an employer of choice and fostering an inclusive culture and workplace. We are an Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities. NCQA is a drug free workplace. NCQA recruits, hires, trains and promotes individuals, and administers any and all personnel actions, without regard to race, color, religion, national origin, age, sex, pregnancy, citizenship, familial status, disability status, veteran status, genetic information, or other protected statuses under applicable state and federal laws. NCQA will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c).
