Technology & AI Law

Technology, Data & AI Law

A technology lawyer who actually built technology.

Years in the systems. Then the law.

Schedule a Free Consultation(314) 732-1547

Privacy & surveillance — he wrote it up in 2010, years before Snowden ↓

HIPAA, data privacy, AI governance, and emerging-tech counsel — from an attorney who spent years building the systems before he ever argued about them.

Why fluency matters

Technology law needs someone who’s built technology

Most lawyers advising on software, data, and AI have never shipped any of it. Advice on a system you don’t truly understand is a guess — here’s what real fluency changes.

  • HIPAA handled before a breach, not after
  • Privacy compliance across states & federal law, without over-engineering
  • AI contracts you actually understand before you sign
  • Contracts read like an engineer would read them
  • Breach response measured in hours, not weeks
  • A virtual-first practice that moves at startup speed

How we help

Counsel across the technology stack

From HIPAA to AI contracts to the 2 a.m. breach call — tap any area to learn more.

HIPAA Compliance

Risk assessments, Business Associate Agreements, Privacy & Security Rule compliance, and breach-response support — for covered entities and business associates.

Data Privacy

Privacy policies, terms of service, data-processing agreements, and state, GDPR, and COPPA compliance — sized to your actual business.

AI Governance

AI procurement contracts, internal AI policies, algorithmic-bias assessment, and EU AI Act & emerging state-law readiness.

Technology Contracts

SaaS agreements, software licensing, open-source compliance, cybersecurity terms, and technology M&A diligence.

Healthcare Technology

Where HIPAA, the FDA, and software law overlap — for healthtech startups, telehealth platforms, and clinical software.

Breach Response

Federal, state, and contractual notification handled on a clock measured in hours and days — alongside your technical team.

HIPAA Compliance — in detail

If you’re a covered entity or a business associate, HIPAA applies to you whether or not you’ve ever thought about it — and “we didn’t know” is not a defense when the Office for Civil Rights comes calling.

We handle the practical side: risk assessments that actually find your gaps, Business Associate Agreements that protect you, Privacy and Security Rule compliance, and a breach-response plan built before you need it.

Getting compliance right up front costs a fraction of mishandling a breach — in penalties, in notification costs, and in reputation.

Data Privacy — in detail

Privacy law in the U.S. is a patchwork: California, Virginia, Colorado, and a growing list of states each have their own rules, layered on top of federal laws like HIPAA, GLBA, FERPA, and COPPA. GDPR reaches you the moment you touch EU data.

We build privacy programs that fit your actual business — privacy policies, terms of service, and data-processing agreements that hold up — without over-engineering a solution you don’t need.

The goal is simple: collect and use data in a way that’s compliant, honest with your users, and defensible if anyone ever asks.

AI Governance — in detail

AI moved into everyday business faster than the law could keep up — and companies are signing AI contracts every week without understanding what they’ve agreed to about their data, their liability, or their customers.

We help you adopt AI responsibly: reviewing vendor contracts, writing internal AI-use policies, assessing algorithmic-bias exposure, and preparing for the EU AI Act and the wave of emerging state regulation.

You get to use these tools with confidence, instead of discovering the risks after something has already gone wrong.

Technology Contracts — in detail

Whether you’re buying software or selling it, the contract is where the risk lives — SaaS agreements, software licensing, open-source obligations, cybersecurity commitments, and the diligence behind a technology acquisition.

Because I spent years inside the technology itself, I read these agreements the way an engineer would — catching the terms that will actually bite you, not just the ones a form checklist flags.

We make sure what you sign matches what you think you’re getting.

Healthcare Technology — in detail

Healthtech lives at the intersection of three regulators at once — HIPAA, the FDA, and software law — and startups routinely trip over rules they didn’t know applied to them.

We advise healthtech startups, telehealth platforms, and clinical-software companies on where these regimes overlap, what your product can and can’t claim, and how to build compliance in from the start instead of retrofitting it under pressure.

It’s a niche most general practitioners simply don’t have the technical or regulatory depth to handle.

Breach Response — in detail

When a breach or ransomware event hits, the clock is measured in hours and days, not weeks — and the legal steps you take (or miss) in that window shape everything that follows.

We coordinate the legal side of the response: federal, state, and contractual notification requirements, regulatory filings, and disclosure obligations, working alongside your technical incident-response team.

Having counsel who understands both the technology and the notification rules is the difference between a contained incident and a compounding one.

Original scholarship

He was writing about this in 2010 — years before Snowden

Not a lawyer who discovered “AI and privacy” once it got popular. Someone who’s been thinking rigorously about data and surveillance for fifteen years.

Written in 2010

While in law school, Derek wrote his thesis — “Personal Data Collection, Data Mining, Privacy, Fairness and National Security” — on exactly the questions that now dominate technology law: behavioral targeting, predictive profiling, and how much of your life can be reconstructed from data you never thought twice about.

Three years before Snowden

It described a government amassing Americans’ phone records, mandated backdoors in consumer services, and agencies judging people from an “audit trail in a vacuum” — without ever meeting them. Much of it was confirmed publicly years later.

It saw the physical risk coming, too

The paper walked through cyber-physical attacks — crippling telecom and hacking the power grid through “smart” infrastructure — a decade before these became mainstream national-security concerns.

Why it matters for you

When your business faces a hard question about data, AI, or surveillance, you want counsel who has been reasoning carefully about these exact trade-offs for years — and who also built the systems that collect the data in the first place.

Inside the technology itself

Built the systems first, then learned the law

Fiber optic network cabling

Telecom operator. Vice President of Development at OptiCon Systems during its acquisition of fiber-optic intellectual property from a business unit of Corning Cable Systems, and a member of the ALLTEL account team behind the creation of Valor Telecom — which later merged into Windstream Communications.

Data, hands-on. Taught CA Easytrieve programming and IBM DB2 data warehousing — the actual plumbing of how large organizations store, move, and mine data.

Founder. Started his own technology company, so he understands an early-stage company’s constraints, budget, and speed from the inside — not just from a form file.

Then the law. Licensed in Missouri since 2011, with roughly fifteen years of practice bridging technology, privacy, and business — the rare lawyer who is genuinely fluent on both sides of the table.

How we can work together

Engagements that fit how you actually operate

Whether you need one clean deliverable or an ongoing legal partner, there’s a model that fits.

Project Work

Flat-fee, discrete matters with a clear scope — a privacy policy, a contract review, a compliance assessment. You know the cost before we start.

Outside General Counsel

A monthly retainer for companies that want a technology-fluent lawyer on call — contracts, questions, and risk handled as they come up.

Hourly Engagement

For complex matters, regulatory investigations, and breach response, where the work can’t be scoped in advance and you need senior attention now.

Your attorney

Technology counsel that speaks both languages

Derek R. Haake, Attorney

Two things are unusual here at once. Derek drafts the SaaS agreements, licences and data-processing terms — and handles the disputes and breach responses when they fail, which is what tells you which clauses actually bite. And the technical claim underneath it is specific rather than atmospheric.

The claim is specific rather than atmospheric. As a business analyst at ALLTEL Communications, Derek wrote data-mining software against the company’s DB2 and Oracle warehouses, developed and taught training on DB2, Cobol, Fortran and Oracle, drafted and sought approval of publicly filed tariffs before the public utility commissions of Texas, Oklahoma, New Mexico and Arkansas, and worked with directors on disaster control policy — regulatory compliance and incident response, before either carried the names they carry now.

At OptiCon Systems in Dallas he was VP of Development, where he assisted in the due diligence and negotiations for the acquisition of intellectual property from a business unit of Corning Cable Systems, and negotiated the software agreements underneath OptiCon’s own product. Technology M&A and licensing, from inside the deal.

Campus Shift, where he was Vice President of Development — building a pricing engine that cut students’ textbook costs, an API, and web and mobile applications across jQuery, Angular, Bootstrap, MySQL and SQL Server, and securing the company’s seed funding and its place in the Youngstown Business Incubator. He understands an early-stage company’s constraints because he built one.

He holds an MBA alongside the JD, and wrote his 2010 law school thesis on data privacy and government surveillance. When a vendor contract says something odd about what it may do with your data, that is not a translation problem here.

Schedule a Free ConsultationCall (314) 732-1547

Not sure whether the rules reach you?

That is usually the question worth twenty minutes, and it is the one most companies skip.

Bring the contract, the product, or the incident. We will tell you which regimes apply, what actually has to happen and by when, and what can wait — before you spend money building compliance you may not need.

Schedule a Free Consultation

Common questions

Technology & AI law, answered

Do I really need a HIPAA attorney?

If you’re a covered entity or a business associate, your HIPAA obligations exist whether or not you’ve addressed them — and “we didn’t realize” is not a defense in an OCR investigation. Getting compliance right up front is far cheaper than mismanaging a breach after the fact.

The Security Rule is specific about what “addressed them” means. A covered entity or business associate must “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information” it holds — 45 C.F.R. § 164.308(a)(1)(ii)(A). A missing or stale risk analysis is the single most common finding in OCR enforcement actions, and it is the one that turns an incident into a penalty.

The other recurring gap is contractual. A covered entity may disclose protected health information to a business associate only with satisfactory assurances, documented in a written agreement meeting 45 C.F.R. § 164.504(e). Vendors get added faster than paperwork gets signed, and the gap is only discovered under investigation.

Worth knowing: HHS proposed a substantial Security Rule overhaul in an NPRM published January 6, 2025 — eliminating the “addressable” category so controls like encryption, multifactor authentication, network segmentation, asset inventories, and regular vulnerability scanning become mandatory. It has not been finalized; the Office of Management and Budget’s timetable now shows final action in 2027. Planning against the proposal now is cheaper than reacting to it later. HHS Security Rule guidance.

Is “AI governance” a real practice area, or a buzzword?

It’s real and it’s here. The EU AI Act reaches companies well outside Europe, U.S. states are passing their own AI rules, and businesses are signing AI contracts every week without understanding what they’ve agreed to about their data and liability. That gap is exactly what AI governance work addresses.

The EU. Regulation (EU) 2024/1689 applies in phases. The prohibited-practice bans and AI-literacy duties took effect February 2, 2025; general-purpose AI model obligations followed on August 2, 2025; the Article 50 transparency duties — disclosing that a user is interacting with an AI system, and marking synthetic content — apply from August 2, 2026. The Digital Omnibus agreement deferred the high-risk obligations: Annex III systems move from August 2026 to December 2, 2027, and Annex I systems from August 2027 to August 2, 2028. Those new dates depend on formal publication in the Official Journal, so treat them as the working assumption rather than a settled fact.

The states. Colorado’s much-discussed AI Act (SB 24-205) never took effect — it was replaced by SB 26-189, signed May 14, 2026, which shifts from impact assessments to a notice-and-disclosure model and applies January 1, 2027. Texas’s Responsible AI Governance Act (HB 149) took effect January 1, 2026. More than twenty states now have comprehensive consumer privacy laws with automated-decision and profiling provisions layered inside them. Bloomberg Law maintains a current state privacy legislation tracker.

The practical work is unglamorous and it is what actually reduces exposure: an inventory of where AI is used in the business, a written internal use policy, contract terms that control what a vendor may do with your data, and a record of the decisions you made and why.

Can you perform our SOC 2 audit?

No — SOC 2 is an audit performed by a licensed CPA firm, and we don’t provide audit services. What we can do is review the contracts and controls around it and draft the data-processing terms your customers and vendors will require.

Where legal work and the audit meet is usually the customer contract. Enterprise buyers ask for a SOC 2 Type II report, a security addendum, a data-processing agreement, breach-notification timelines measured in hours, and audit rights. Those commitments are legally binding whether or not the audit ever happens, and committing to a control you do not have is a breach of contract waiting to be discovered.

We also review the auditor engagement letter itself — scope, carve-outs for subservice organizations, limitation of liability, and who may rely on the report.

Can you tell us which AI tool to buy?

We don’t recommend specific products. What we do is review the contract behind whatever tool you’re considering and flag the legal, privacy, and security risks — so you can make the buying decision with your eyes open.

The terms that decide most of the risk are consistent across vendors. Does the vendor train on your inputs or outputs, and can you opt out in the contract rather than in a settings page it can change? Who owns the output, and what does the vendor warrant about it? Is there an intellectual-property indemnity for infringement claims arising from generated content, and what conditions void it? Where is the data processed, which subprocessors are involved, and how are you notified when they change? What happens to your data on termination, and can you export it in a usable form?

For anything touching regulated data, the answer to “is there a Business Associate Agreement or a data-processing agreement in place” comes before the answer to “is the tool any good.”

We’ve been hit with ransomware. Can you help?

Yes, on the legal side. We coordinate notification obligations, regulatory filings, and contractual disclosures, working alongside the technical incident-response specialists who handle containment and recovery. Move fast — the legal clock starts immediately.

Several clocks usually run at once. HIPAA requires notice to affected individuals without unreasonable delay and in no case later than 60 days after discovery, with contemporaneous notice to HHS for breaches affecting 500 or more individuals (45 C.F.R. §§ 164.400–414). Missouri requires notice to affected residents without unreasonable delay, plus notice to the Attorney General when more than 1,000 consumers are notified at once. Your customer contracts often impose shorter windows than any statute — 24 or 48 hours is common. Public companies face a separate Item 1.05 Form 8-K obligation on material incidents.

Two decisions in the first hours matter disproportionately. Engaging counsel to direct the forensic investigation is what gives the resulting report its best claim to privilege. And what gets written in internal chat and email during the response frequently becomes the most damaging evidence in later litigation, because it is written fast and without context.

If this is happening now, call rather than email: (314) 732-1547.

We move data internationally — can you handle that?

Yes. We handle Standard Contractual Clauses, transfer impact assessments, and the data-processing terms cross-border transfers require, and coordinate with EU counsel where local advice is needed.

The threshold question is usually whether the GDPR reaches you at all. Under Article 3(2), it applies to a controller or processor with no EU establishment where processing relates to offering goods or services to people in the EU, or to monitoring their behaviour within it. A U.S. company with no European office can be squarely inside that.

For the transfer itself, the current Standard Contractual Clauses are set out in Commission Implementing Decision (EU) 2021/914, with four modules depending on whether each side is a controller or processor — picking the wrong module is a common and consequential error. The EU–U.S. Data Privacy Framework offers an alternative route for participating U.S. organizations, though it faces continuing legal challenge, so a fallback mechanism is worth having in place.

Article 3(2) also means an Article 27 representative in the EU may be required. That obligation is quietly ignored far more often than it is met.

What does Missouri law require if we have a data breach?

Missouri’s breach notification statute is RSMo § 407.1500. It is triggered by unauthorized access to and unauthorized acquisition of unencrypted or unredacted personal information that compromises its security, confidentiality, or integrity — a first name or initial plus last name combined with a Social Security number, driver’s license or other government ID number, a financial account number with the code that would permit access, medical information, or health insurance information.

Notice must go to affected Missouri residents without unreasonable delay, subject to a law-enforcement delay request. If more than one thousand consumers are notified at once, notice must also go to the Attorney General’s office and to the nationwide consumer reporting agencies.

Enforcement runs through the Attorney General, who has exclusive authority to bring an action for a willful and knowing violation, with civil penalties up to $150,000 per breach or series of similar breaches discovered in a single investigation. There is no private right of action under the statute — which does not stop plaintiffs from pleading negligence and the Merchandising Practices Act instead.

The practical trap is that Missouri’s statute is rarely the only one that applies. Notification obligations follow the residence of the affected individuals, so a single incident routinely triggers a dozen state regimes with different definitions, timelines, and regulator-notice thresholds.

Does Missouri have a comprehensive privacy law like California’s?

Not as of now. Missouri has the breach notification statute above, the Merchandising Practices Act (RSMo § 407.020) reaching deceptive practices including misrepresentations in a privacy policy, and computer tampering offenses under RSMo §§ 569.095–569.099 — but no general consumer privacy statute of the California or Virginia type.

That is much less comforting than it sounds. Privacy laws attach to where your users live, not where your servers or your office are. A Missouri company with customers in California, Colorado, Connecticut, or Texas is subject to those states’ laws once it crosses their thresholds, and more than twenty states now have such laws in force or coming into force.

The workable approach for most small and mid-sized businesses is a single baseline built to the stricter common denominator — a truthful privacy notice, a real data inventory, honored deletion and access requests, and vendor agreements that pass obligations down the chain — rather than fifty parallel compliance programs.

Can we use our customer data to train an AI model?

It depends on three things, and companies usually check only the first. What do your contracts with those customers permit? What does your own privacy notice say you do with the data — because doing something materially different is exactly the deception theory the FTC pursues under Section 5 of the FTC Act? And is the data regulated, so that a secondary use requires a legal basis, an authorization, or a Business Associate Agreement?

Protected health information is the sharpest case. Using it to train a model is generally not treatment, payment, or health care operations, so it typically requires either a valid HIPAA authorization or properly de-identified data under 45 C.F.R. § 164.514 — and “we removed the names” is not de-identification under either the safe harbor or the expert determination method.

The remedy also matters. Where the FTC has found a model built on improperly obtained data, it has ordered algorithmic disgorgement — deletion of the model itself, not just the data. That is a materially worse outcome than a fine, and it is why this question is worth answering before training rather than after.

Is training an AI model on copyrighted material lawful?

Unsettled, and moving. Two 2025 decisions in the Northern District of California found the training itself transformative: Bartz v. Anthropic (Judge Alsup, June 23, 2025) and Kadrey v. Meta (Judge Chhabria, June 25, 2025). But Bartz drew a sharp line between training and acquisition — the court held that downloading millions of pirated books to build a permanent library was not fair use, and that exposure produced a $1.5 billion class settlement, granted final approval in July 2026.

Pointing the other way, Thomson Reuters v. Ross Intelligence (D. Del., February 2025) rejected fair use where the output competed directly with the copyrighted source. That decision is on appeal — the Third Circuit heard argument on June 11, 2026 in No. 25-2153, and its ruling will be the first appellate word on fair use in AI training.

The practical lesson is already clear even while the law is not: how the training data was obtained may matter more than what the model does with it. For a company buying or building AI, that means diligence on data provenance, contractual representations about the training corpus, and an indemnity that survives contact with a real claim.

Who owns what an AI tool produces for us?

Copyright requires a human author. In Thaler v. Perlmutter, the D.C. Circuit affirmed on March 18, 2025 that a work generated autonomously by a machine, with no human author, cannot be registered — the Supreme Court denied certiorari in 2026. Purely machine-generated output therefore has no copyright, meaning neither you nor anyone else can stop a competitor from using it.

Human-directed work is different. The Copyright Office’s position is that material a human selects, arranges, or meaningfully modifies can be protected as to those human contributions, while the machine-generated elements are disclaimed. Registration applications are expected to disclose AI-generated content. See the Office’s Copyright and Artificial Intelligence materials.

Between you and the vendor, the answer is contractual. Most terms assign you whatever rights exist in the output — which is not the same as promising those rights are worth anything, and rarely the same as promising the output infringes nobody. Read the ownership clause and the indemnity together; separately they mislead.

Our site uses a chatbot, session replay, or analytics pixels. Is that a risk?

It has become one of the most active areas of privacy litigation. Plaintiffs are recasting ordinary website tracking as unlawful interception under decades-old wiretapping statutes, with California’s Invasion of Privacy Act the most common vehicle, and are pleading the same theory against chat widgets that route conversations through a third-party vendor and session-replay scripts that record keystrokes and form entries.

Missouri is a one-party consent state: RSMo § 542.402 permits interception where a person is a party to the communication or one party has given prior consent, provided the interception is not for the purpose of committing a criminal or tortious act. But your exposure follows your visitors, and several states require all-party consent — which is why national websites end up designing to the stricter rule.

The defensible posture is unglamorous: know every third-party script actually running on the site, disclose it accurately, obtain consent where consent is what the law requires, and make sure the vendor contract says the vendor may use the data only to provide the service to you. Most of the trouble comes from a tag someone added years ago that nobody has inventoried since.

Is our open-source usage a problem?

Usually manageable, occasionally serious, and almost always discovered at the worst moment — during acquisition diligence or an enterprise security review. The risk is not using open source; it is not knowing what you use.

Permissive licenses (MIT, BSD, Apache 2.0) mostly require attribution and notice preservation, which is easy to satisfy and easy to forget. Copyleft licenses are the ones that reshape a product: the GPL family can require distributing source for derivative works, and the AGPL extends that obligation to software made available over a network — a term that surprises SaaS companies who assumed they were not “distributing” anything.

What we do is practical: a software bill of materials, a written policy about which licenses are approved for which uses, remediation where a copyleft component sits somewhere it should not, and the contractual representations you will be asked to give in an acquisition. Fixing this before diligence costs a fraction of renegotiating a purchase price during it.

We’re an early-stage company. How much of this do we actually need right now?

Less than a compliance vendor will tell you, and more than nothing. Most state privacy laws have thresholds — commonly tied to the number of consumers whose data you process or the share of revenue from selling data — and a genuinely small company often falls under them. That is worth confirming rather than assuming in either direction.

What is worth doing early, because retrofitting it is expensive: an accurate privacy notice that matches what your product actually does; customer agreements and a data-processing addendum you can hand an enterprise buyer without renegotiating from scratch; a Business Associate Agreement if you touch protected health information; a written AI-use policy before employees paste confidential material into a chatbot; and knowing which vendors hold your data.

What can usually wait: certification programs, formal governance committees, and tooling bought before there is a process for it to support.

This is exactly the conversation the free consultation is for. Sequencing the work correctly is worth more to an early-stage company than any single deliverable.

How do you charge for this work?

Three structures, chosen to match the work rather than the other way round. Flat fee for discrete, scopeable deliverables — a privacy policy, a contract review, a compliance assessment — where you know the number before we start. Monthly retainer for outside general counsel, which removes the meter from the routine questions companies otherwise avoid asking until they become expensive. Hourly for regulatory investigations, breach response, and complex matters that genuinely cannot be scoped in advance.

Whichever applies, it is confirmed in a written engagement agreement before substantive work begins, and Missouri Rule 4-1.5 requires the fee to be reasonable and its basis communicated to you.

If a matter needs a specialist we are not — patent prosecution, securities work, an FDA submission — we say so and refer, rather than learning on your budget.

Ready to start?

Get advice from someone who has built the technology.

Bring your hardest question about data, AI, HIPAA, or a contract — and get an answer grounded in how the technology actually works, not how a form checklist assumes it does.

Schedule a Free Consultation(314) 732-1547

This page is general information, not legal advice, and does not create an attorney-client relationship. Technology and AI law is changing quickly — effective dates and pending rules described here may have moved. The scope of any engagement is set out in a written agreement. Consult a licensed attorney about your situation.

Scroll to Top