Skip to Main Content
Professional Photo

Andrew J. Droke, CIPP/US


Andrew leads the Firm's Artificial Intelligence (AI) and GDPR Teams, and he counsels clients in a broad range of data protection, privacy, and cybersecurity matters.

Professional Biography

As a member of the Firm's Health Law group and Data Protection, Privacy, and Cybersecurity Team, Andrew advises clients regarding complex data use and sharing arrangements, digital health strategies, technology agreements, and information privacy and security compliance considerations.

Andrew routinely counsels clients with respect to their privacy, cybersecurity, and information practices, including the compliance obligations imposed by the Health Insurance Portability and Accountability Act (HIPAA), 42 CFR Part 2, the ONC and CMS interoperability and information blocking regulations, state privacy and security laws, and global data protection laws such as the General Data Protection Regulation (GDPR). Andrew also helps clients in negotiating key technology agreements, data processing agreements, data use agreements, and clinical trial agreements, as well as addressing risks through diligence counseling and negotiations in mergers and acquisitions.

In leading the Firm's AI Team, Andrew also advises clients regarding the contracting and compliance considerations associated with AI-based technologies, including with respect to data use. As leader of the Firm's GDPR Team, Andrew assists U.S.-based and global organizations with issues involving international data transfers and navigating conflicts between foreign privacy laws and U.S. compliance obligations with respect to data use and processing.

During law school, Andrew served as a judicial extern for the Honorable Bernice B. Donald on the United States Court of Appeals for the Sixth Circuit.

  • Worked with health IT companies, data analytics companies, and health care providers to analyze and establish complex data use and sharing relationships.

  • Negotiated multimillion dollar technology agreements for critical IT systems for health care providers, a multinational medical device manufacturer, and technology companies.

  • Advised an international technology company regarding AI governance and the policies and procedures applicable to its AI products, systems, and services.

  • Negotiated clinical trial agreements and related data sharing arrangements for technology providers, academic medical centers, and national retailers.

  • Counseled a regional health system on the implementation of interoperability and information blocking requirements.

  • Assisted a health care provider in deployment of AI-enabled chatbot.

  • Worked with large not-for-profit hospital systems, behavioral health systems, and health IT companies to develop and implement comprehensive information privacy and security programs addressing HIPAA, 42 CFR Part 2, and applicable state laws.

  • Advised health systems regarding compliance with OCR's guidance regarding online tracking technologies.

  • Assisted in structuring, drafting, and negotiating technology, digital health, interface, software, vendor, and other service provider agreements and business associate agreements.

  • Negotiated professional services agreements and telehealth arrangements for health care providers.

  • Assisted national retailers and data analytics companies in strategic planning with respect to data collection, use, and intra-organization sharing.

  • Created privacy notices for retailers, distributors, health care providers, health care technology companies, mobile applications, non-profit organizations, and professional sports organizations.

  • Advised numerous clients across industries regarding compliance with U.S. state privacy law requirements.

  • Coordinated information privacy and security aspects of a $450M acquisition of a hotel data and analytics company.

  • Helped an electronic medical record vendor analyze its obligations under the GDPR and revise its website terms of use and privacy notices.

  • Assisted a regional health system with Promoting Interoperability program participation requirements.

  • Worked with clients to develop external notices and internal policies to facilitate compliant data collection and handling, including privacy notices, data privacy policies and privacy risk assessments.

  • Assisted with sales and acquisitions of health systems, physician groups, and technology companies, including information privacy and security diligence.

  • Represented a Fortune 100 client in its negotiations with a vendor of AI-enabled clinical trial recruitment services.

  • Serving as outside general counsel for a provider of AI-enabled patient engagement and symptom management services.

  • Advised a provider of computer-vision security services regarding the deployment of its service offerings and applicable data privacy and security requirements.

  • Advised a higher education institution regarding the regulatory considerations for its use of AI-enabled services for student engagement.

  • Developed policies and procedures regarding the use of AI tools and services for a national non-profit organization.

  • Listed in Best Lawyers: Ones to Watch in America™ for Health Care Law and Technology Law (2021 – 2024)
  • Selected to Mid-South Rising Stars in Health Care (2020 – 2023)
  • Member – International Association of Privacy Professionals (CIPP/US)
  • Member – American Health Law Association
  • Member – International Association of Privacy Professionals
  • Member – American Bar Association
  • Member – Tennessee Bar Association, Health Law Section
  • Member – Nashville Bar Association
  • Past Chair – IAPP Nashville KnowledgeNet
  • "Key Issues Surrounding AI Governance in Health Care," AHLA's Speaking of Health Law (December 2023)
  • "U.S. Data Privacy and Security," National Association for the Support of Long-Term Care National Conference (October 2022)
  • "Data Privacy Liability in the 2020s: Installing Blinds on the Fishbowl," American Bar Association (January 2021)
  • "Data Incident Virtual Tabletop Exercise," International Association of Privacy Professionals, Nashville Chapter (December 2020)
  • "Data Privacy and Security: The Role of the Tennessee Attorney General's Office" (October 2019)
  • "The California Consumer Privacy Act," International Association of Privacy Professionals, Nashville Chapter (June 2019)

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept