Health Law & Corporate – Special Counsel (Data Privacy & Cybersecurity) - BOS | NY | DC
About the Health Law and Corporate Practices
Mintz's Health Law practice is uniquely positioned to guide clients through structural and operational challenges. Our clients include providers (non-profit, publicly traded, and private equity backed), payors, pharmacy benefit managers and administrators, manufacturers, distributors, and suppliers. The breadth and depth of our knowledge and experience inform our advice in related transactional, regulatory, and litigation matters. We also draw upon the capabilities of a wide range of related practices within the firm as the need arises. This cross-disciplinary approach allows our attorneys to solve the many problems our clients face while expanding their business opportunities.
Our corporate practice complements this work with a blend of comprehensive legal expertise and practical business counseling that enables our clients to clarify goals, find solutions, and achieve results across varied business transactions, including a wide variety of issues affecting commercial, financial, and industrial enterprises, both publicly and privately owned. Within the corporate practice, our Privacy & Cybersecurity team guides clients through the increasingly complex global regulatory landscape governing privacy, data protection, artificial intelligence, and cybersecurity. The team counsels on the full spectrum of privacy and cybersecurity matters, including scalable compliance program design, incident response readiness, vendor and supply chain risk management, cybersecurity governance, and the integration of privacy and security considerations into product development and technology procurement. We represent buyers, sellers, and sponsors in domestic and cross-border M&A and private equity transactions, including platform acquisitions and add-on investments, and advise on technology licensing, data commercialization, and strategic commercial arrangements.
Together, the two practices cover every aspect of the private equity market, including fundraising and investment fund formation, direct investments, portfolio company management and acquisitions, and platform exits, serving clients that include global commingled funds, independent sponsors, and family offices.
Responsibilities:
Mintz's Health Law and Corporate sections are seeking a Special Counsel with 6+ years of relevant experience to support HIPAA, privacy, cybersecurity, AI, digital health, and related data work at the intersection of health regulatory counseling and corporate transactions. This is a shared role, working across both the Health Law and Corporate sections, with a target allocation of approximately 60% Health Law and 40% Corporate. The preferred office location is Boston, with New York and Washington, DC available as secondary options.
The ideal candidate will operate at a senior level and be capable of managing sophisticated workstreams with a high degree of independence, while collaborating closely with partners, associates, clients, and cross-disciplinary teams. This role is well-suited for an attorney who brings strong technical experience, excellent judgment, and the ability to translate complex legal and regulatory issues into practical, business-oriented advice.
The Special Counsel will provide senior-level support and guidance on HIPAA, privacy, digital health, cybersecurity, AI matters and governance, data commercialization, technology contracting, vendor risk, incident response readiness, and scalable compliance programs. The role will operate in both counseling and transactional contexts, including M&A and private equity due diligence, risk assessment, regulatory issue-spotting, negotiation support, and deal-term drafting.
Responsibilities will include managing and executing diligence processes, identifying and assessing privacy and cybersecurity risk, advising on regulatory and compliance implications, drafting and negotiating privacy, security, and data-related provisions, supporting compliance program development, and assisting clients with technology contracting and vendor risk issues. The Special Counsel will also be expected to exercise sound judgment in prioritizing work, escalating issues appropriately, and helping guide more junior attorneys on discrete assignments or workstreams.
Collaboration with team members is an important component of any role at Mintz. Therefore, the firm requires working from the office approximately 60% of the time in accordance with the firm's published guidelines.
Qualifications:
- Graduated with a JD or LLM from an ABA-accredited law school.
- Admitted to or eligible for admission to the MA, NY or DC Bar.
- Excellent written and verbal communication skills.
- Professionalism in working and engaging with demanding clients.
- Ability to balance and prioritize multiple competing priorities and responsibilities.
- Ability to stay organized and exercise extreme attention to detail.
- Ability to collaborate and work effectively in team settings.
- Experience in privacy, cybersecurity, AI, digital health, health care regulatory, transactional, or technology/data matters.
- Familiarity with HIPAA/privacy compliance, state and global privacy regimes, AI governance, and sector-specific frameworks.
- Experience advising on compliance with major privacy and data protection frameworks (e.g., CCPA/CPRA, GDPR, HIPAA, GLBA, COPPA, BIPA, CAN-SPAM, TCPA) and experience or strong interest in AI regulatory developments and emerging AI governance frameworks.
- Experience with privacy and cybersecurity aspects of M&A and private equity transactions, including conducting data privacy and security diligence; assessing data assets, technology infrastructure, and regulatory exposure; identifying and quantifying privacy and cybersecurity risks; reviewing and negotiating privacy- and data-related deal terms in acquisition agreements, disclosure schedules, and ancillary documents; advising on representations, warranties, indemnities, and covenants related to data protection, security practices, and regulatory compliance; and supporting post-closing integration and remediation efforts.
- Experience negotiating privacy, security, and data-related terms in commercial technology agreements.
- Familiarity with or strong interest in AI regulatory developments and emerging AI governance frameworks is strongly preferred.
- Interest in or experience with cybersecurity risk management, incident response planning, vendor risk assessment, and security governance.
- Judgment to manage workstreams independently, prioritize competing responsibilities, and escalate issues appropriately.
- Ability to operate effectively across both health regulatory counseling and corporate transactional work.
- CIPP or other IAPP certifications are a plus.
About Mintz
Mintz is an Am Law 100 law firm with over 600 attorneys serving clients worldwide. Our attorneys combine legal, business, and industry insight to help navigate shifting challenges. We advise business leaders, entrepreneurs, and investors on pivotal deals, disputes, and regulatory matters within our core practice areas. We are strategically located to meet the needs of our clients, with offices in Boston, Los Angeles, Miami, New York, San Diego, San Francisco, Toronto, and Washington, DC.
The salary range for this position is $250,000 to $360,000. This position is bonus eligible.
Mintz offers a comprehensive benefits package.
