We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health , you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
Role Summary
Leads and operationalizes the enterprise Data Governance, Risk, and Privacy program across Commercial, Medicare, and Medicaid lines of business. Establishes governance frameworks, decision rights, standards, and controls that promote data quality, transparency, accountability, and appropriate use of sensitive health information. Partners with Legal, Compliance, Security, Informatics, and business leaders to translate regulatory requirements into practical governance processes and risk-based controls, ensuring compliant, secure, and responsible data use aligned with HIPAA, CMS mandates, and state privacy requirements.
Core Responsibilities
Governance Framework & Program Execution
Define and operationalize governance frameworks, policies, standards, and stewardship models
Translate enterprise strategy into program plans, roadmaps, and execution trackers
Establish data ownership, lineage, quality controls, and metadata management across critical data domains
Enable audit-defensible data use aligned with TPO (Treatment, Payment, and Operations)
Day-to-Day Governance Operations
Execute governance workflows for data sharing, access approvals, and risk evaluation
Enforce data use policies, including TPO-aligned use, secondary use, and access controls
Define controls for de-identified, limited, and identified datasets
Monitor downstream data handling and ensure alignment of contractual terms, consent, and actual data use
Risk, Privacy & Compliance
Identify, assess, and mitigate data-related risks across sharing, access, and downstream use
Ensure compliance with HIPAA, state privacy laws, and CMS interoperability requirements
Evaluate data use cases for permissible use (TPO, non-TPO, secondary use)
Assess vendor and third-party data sharing risks and control requirements
Support audits, compliance reviews, and regulatory inquiries with governance documentation
KPI Management & Reporting
Define and track governance KPIs and operational metrics
Develop executive-ready dashboards and visualizations for governance performance and risk trends
Cross-Functional Leadership
Serve as subject matter expert for data use, governance, and regulatory alignment
Lead governance forums and working groups to drive decision-making and accountability
Enable knowledge sharing, training, and capability uplift across governance practitioners
Enable scalable, reusable governance processes across programs and business functions
Key Deliverables
Documented governance frameworks, policies, standards, and stewardship models
Governance program plans, roadmaps, and execution trackers
Enterprise data lineage, metadata, and approved data use inventories
Risk assessments, risk logs, and mitigation plans
TPO-aligned data use decisions with supporting rationale and approvals
KPI dashboards and governance performance reporting
Audit-ready governance documentation and evidence
Required Skills & Experience
7+ years in healthcare, data governance, privacy, risk management, or a related field
Deep knowledge of HIPAA, CMS requirements, and state privacy laws
Experience with data governance frameworks, data lineage, metadata management, and stewardship practices
Strong understanding of payer operations (claims, utilization management, risk adjustment, STARS)
Expertise in risk identification, assessment, mitigation planning, control design, and reporting
Ability to translate legal and regulatory requirements into operational and technical processes
Strong stakeholder management, executive communication, and cross-functional collaboration skills
Ability to influence leaders and drive alignment across the enterprise
Strong program management, financial, and operational planning capabilities
Preferred Skills
Degree in legal studies, privacy engineering, information technology, or a related discipline
Experience with AI governance, bias oversight, or emerging technology risk management
Understanding of clinical data, EMRs, HIEs, and health information exchange practices
Privacy certifications (CIPM, CIPP) or risk management certifications (CRISC, PMI-RMP, COSO ERM)
Familiarity with enterprise or solution architecture concepts
Lean Six Sigma or other process improvement experience
Experience with data governance tools, data catalogs, or metadata platforms
Experience assessing third-party data sharing arrangements and downstream data use
Experience with issue management, remediation planning, and control monitoring in a regulated environment
Pay Range
The typical pay range for this role is:
$82,940.00 - $182,549.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full-time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 10/12/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 80180635
- Position Id: e40a653a32274c23d5b13de09d0e1fe3
- Posted 30+ days ago