Skip to Main Content
Professional Photo

Andrew J. Droke, CIPP/US


Andrew is co-leader of the Firm's GDPR Team, and he counsels clients in a broad range of data protection, privacy, and cybersecurity matters.

Featured Video

What to Do in 2022 – Privacy and Data Protection for the New Year January 28, 2022

Professional Biography

As a member of the Firm's Health Law group and Data Protection, Privacy, and Cybersecurity Team, Andrew advises clients regarding complex data use and sharing arrangements, digital health strategies, technology agreements, and information privacy and security compliance considerations.

Andrew routinely counsels clients with respect to their privacy, cybersecurity, and information practices, including the compliance obligations imposed by the Health Insurance Portability and Accountability Act (HIPAA), 42 CFR Part 2, the ONC and CMS interoperability and information blocking regulations, state privacy and security laws, and global data protection laws such as the General Data Protection Regulation (GDPR). As co-leader of the Firm's GDPR Team, Andrew assists U.S.-based and global organizations with data processing agreements, issues involving international data transfers, and navigating conflicts between foreign privacy laws and U.S. compliance obligations with respect to data use and processing.

Andrew also helps clients with technology agreements and with identifying and addressing data protection and privacy risks through diligence counseling and negotiations in mergers and acquisitions.

During law school, Andrew served as a judicial extern for the Honorable Bernice B. Donald on the United States Court of Appeals for the Sixth Circuit.

  • Worked with health IT companies and health care providers to analyze and establish complex data use and sharing relationships.

  • Counseled regional health system on the implementation of interoperability and information blocking requirements.

  • Worked with large not-for-profit hospital systems, behavioral health systems, and health IT companies to develop and implement comprehensive information privacy and security programs addressing HIPAA, 42 CFR Part 2, and applicable state laws.

  • Assisted in structuring, drafting, and negotiating technology, digital health, software, vendor, and other service provider agreements and business associate agreements.

  • Assisted national retailers and data analytics companies in strategic planning with respect to data collection, use, and intra-organization sharing.

  • Create privacy notices for retailers, distributors, health care providers, health care technology companies, mobile applications, non-profit organizations, and professional sports organizations.

  • Coordinated information privacy and security aspects of a $450M acquisition of a hotel data and analytics company.

  • Helped electronic medical record vendor analyze its obligations under the GDPR and revise its website terms of use and privacy notices.

  • Assisted regional health system with Promoting Interoperability program participation requirements.

  • Worked with clients to develop external notices and internal policies to facilitate compliant data collection and handling, including privacy notices, data privacy policies and privacy risk assessments.

  • Assisted with sales and acquisitions of health systems, physician groups, and technology companies, including information privacy and security diligence.

  • Named a Best Lawyers in America® "Ones to Watch" in Health Care Law and Technology Law (2021 – 2023)
  • Listed in Mid-South Super Lawyers as a Rising Star in Health Care (2020 – 2022)
  • Member – International Association of Privacy Professionals (CIPP/US)
  • Member – American Health Law Association
  • Member – International Association of Privacy Professionals
  • Member – American Bar Association
  • Member – Tennessee Bar Association, Health Law Section
  • Member – Nashville Bar Association
  • Past Chair – IAPP Nashville KnowledgeNet
  • "Data Privacy Liability in the 2020s: Installing Blinds on the Fishbowl," American Bar Association (January 2021)
  • "Data Incident Virtual Tabletop Exercise," International Association of Privacy Professionals, Nashville Chapter (December 2020)
  • "Data Privacy and Security: The Role of the Tennessee Attorney General's Office" (October 2019)
  • "The California Consumer Privacy Act," International Association of Privacy Professionals, Nashville Chapter (June 2019)

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept