Lynn Sessions

Partner

Houston
T 713.646.1352  |  F 713.751.1717

"'Attentive and responsive' Lynn Sessions elicits praise for her practice advice and excellent customer service...[she] maintains a fine track record for her regulatory work."

— Chambers USA 2014

With more than 20 years of working with healthcare industry clients, Lynn Sessions focuses her practice on healthcare operations and regulatory work, with an emphasis on healthcare privacy and data security, breach response, and HIPAA compliance. Having previously served as in-house counsel and director of several departments at a nationally ranked children's hospital, Lynn collaborates closely with healthcare clients and approaches her legal representation from a client's perspective. 

Lynn is a frequent speaker on a range of topics affecting health industry clients, including HIPAA compliance, data breach response, cyber and network security, enterprise risk management, EMTALA, handling adverse patient events and insurance and risk financing. Lynn is also a regular contributor to BakerHostetler's Data Privacy Monitor blog, available at www.dataprivacymonitor.com, as well as the Health Law Update.

Select Experience

  • Has handled more than 150 healthcare data breaches, including several of the largest breaches reported to date. In her representation, Lynn provides counsel to healthcare providers and other covered entities on breach analysis, breach response, crisis management with patients, media and employees, and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.
  • Has responded to more than 30 post-breach investigations from the OCR and state attorneys general arising from large and small data breaches reported by covered entities and has successfully defended healthcare organizations in these investigations.
  • Regularly advises hospitals on Emergency Medical Treatment and Active Labor Act (EMTALA).
More »

Experience

Privacy and Data Security 
  • Has handled more than 150 healthcare data breaches, including several of the largest breaches reported to date. In her representation, Lynn provides counsel to health care providers and other covered entities on breach analysis, breach response, crisis management with patients, media and employees, and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.
  • Has responded to more than 30 post-breach investigations from the OCR and state attorneys general arising from large and small data breaches reported by covered entities and has successfully defended healthcare organizations in these investigations.
  • Advises clients on HIPAA compliance, including preparation of policies and procedures, notice of privacy practices, business associate agreements, and incident response plans. Works with healthcare organizations post-data breach to strengthen safeguards under HIPAA and implementation of corrective action plans.
  • Advises with large non-healthcare employers on HIPAA issues for their self-insured health plans and onsite provider clinics on HIPAA compliance, including policies and procedures, business associate arrangements, and sharing of employee information.  
Operations and Regulatory Practice 
  • Regularly advises hospitals on Emergency Medical Treatment and Active Labor Act (EMTALA).
  • Conducted an audit of a top children’s hospital's risk management department and advised on departmental and operational changes for improved function within the hospital.
  • Develops and enhances credentialing and peer review processes for hospitals and physician groups.
  • Advises hospitals and large physician practices on informed consent, release of information patient information, affiliation agreements, and privileging of peer review and quality review activities. 

Recognitions

  • Sessions, LynnChambers USA: Healthcare in Texas (2014)
  • Burton Award: Distinguished Writing Award for "Anatomy of Healthcare Data Breach" (2013)
  • American Leadership Forum: Senior Fellow
  • Texas Bar Foundation: Fellow
  • Texas Super Lawyers "Rising Star" (2005)
  • Rice University, Jesse H. Jones School of Management Executive Education: Executive Education in Medical and Healthcare Management Certification
  • Texas Children's Hospital: Advanced Quality Improvement and Patient Safety Certification
  • Development Dimensions International: Strategic Leadership

Memberships

  • American Health Lawyers Association
  • AHLA Enterprise Risk Management Task Force: Vice Chair
  • American Society for Healthcare Risk Management
  • Risk and Insurance Management Society
  • American Bar Association
  • Houston Bar Association

Alerts

Articles

Community

  • Children at Risk: Board of Directors, Chair of Development
  • Immunization Partnership: Board of Directors

Services

Industries

Prior Positions

  • Texas Children's Hospital: Director and In-House Counsel (2004 to 2011)

Admissions

  • U.S. District Court, Southern District of Texas
  • U.S. District Court, Northern District of Texas
  • U.S. District Court, Eastern District of Texas
  • Texas, 1993

Education

  • J.D., Baylor University Law School, 1993, Order of Barristers
  • B.A., Texas A&M University, 1989

Blog

In The Blogs

Previous Next
Data Privacy Monitor
Utilities, Oil and Gas Companies Feeling Drained by “Energetic Bear”
July 22, 2014
The following was authored by Mary Guzman, Senior Vice President, InfoSec Practice Leader with McGriff, Seibels & Williams, Inc. There is much going on in the cyber world related to energy and utility companies.  As has long been...
Read More ->
Data Privacy Monitor
Industry Thought Leader Tanya Forsheit Joins BakerHostetler’s Nationally Renowned Privacy Team
July 21, 2014
InfoLawGroup Founding Partner and IAPP Certified Information Privacy Professional is sixth major practice addition in 2014 LOS ANGELES, July 21, 2014—BakerHostetler is proud to announce that Partner Tanya Forsheit has joined the firm’s...
Read More ->
Data Privacy Monitor
New York Attorney General Report Shows the Number of Data Breaches is on the Rise and Recommends Steps to Take for Protecting Against Them
July 18, 2014
On July 15, 2014, the New York Attorney General issued a report examining the growing number and costs of data breaches in the state of New York.  The report titled, “Information Exposed: Historical Examination of Data Security in New York...
Read More ->
Data Privacy Monitor
Florida Gives Breach Notification Statute More Teeth
June 30, 2014
On June 20, 2014, Florida Governor Rick Scott signed the Florida Information Protection Act of 2014 (“FIPA”), which will repeal Florida’s current breach notification statute at Fla. Stat. § 817.5681 and replace it with a new statute at...
Read More ->
Data Privacy Monitor
Health System Investigated for Leaving PHI in Doctor’s Driveway – Settles with OCR for $800K
June 25, 2014
While OCR enforcement activity has focused on a covered entity’s safeguarding of ePHI, organizations cannot forget about PHI in non-electronic form.  To settle potential violations of the HIPAA Privacy Rule, Parkview Health System, Inc...
Read More ->