Lynn Sessions

Partner

Houston
T +1.713.646.1352
F +1.713.751.1717

"She's incredibly levelheaded, she's very, very smart – she knows the privacy space inside and out and gives us really great guidance."

— Chambers USA 2017

Overview

With more than 20 years of working with healthcare industry clients, Lynn Sessions focuses her practice on healthcare operations and regulatory work, with an emphasis on healthcare privacy and data security, breach response, and Health Insurance Portability and Accountability Act (HIPAA) compliance. Having previously served as in-house counsel and director of several departments at a nationally ranked children’s hospital, Lynn collaborates closely with healthcare clients and approaches her legal representation from a client’s perspective. 

Lynn is a frequent speaker on a range of topics affecting health industry clients, including HIPAA compliance, data breach response, cyber and network security, enterprise risk management, the Emergency Medical Treatment and Labor Act (EMTALA), handling adverse patient events, and insurance and risk financing. Lynn is also a regular contributor to BakerHostetler’s “Data Privacy Monitor” blog, available at www.dataprivacymonitor.com, as well as the Health Law Update.

Select Experience

Privacy and Data Security 

  • Has handled more than 300 healthcare data breaches, including several of the largest breaches reported to date. In her representation, provides counsel to healthcare providers and other covered entities on breach analysis; breach response; crisis management with patients, media and employees; and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.

Operations and Regulatory Practice 

  • Regularly advises hospitals on EMTALA.
  • Conducted an audit of a top children’s hospital’s risk management department and advised on departmental and operational changes for improved function within the hospital.
More »

Experience

Privacy and Data Security 
  • Has handled more than 300 healthcare data breaches, including several of the largest breaches reported to date. In her representation, provides counsel to healthcare providers and other covered entities on breach analysis; breach response; crisis management with patients, media and employees; and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.
  • Has responded to more than 75 post-breach investigations from the OCR and state attorneys general arising from large and small data breaches reported by covered entities, and has successfully defended healthcare organizations in these investigations.
  • Represents educational institutions regarding data breaches, including breach analysis, breach response, crisis management and regulatory reports.
  • Advises clients on HIPAA compliance, including preparation of policies and procedures, notice of privacy practices, business associate agreements, and incident response plans. Works with healthcare organizations post-data breach to strengthen safeguards under HIPAA and implement corrective action plans.
  • Advises with large non-healthcare employers on HIPAA issues for their self-insured health plans and with on-site provider clinics on HIPAA compliance, including policies and procedures, business associate arrangements, and sharing of employee information. 
Operations and Regulatory Practice 
  • Regularly advises hospitals on EMTALA.
  • Conducted an audit of a top children’s hospital’s risk management department and advised on departmental and operational changes for improved function within the hospital.
  • Develops and enhances credentialing and peer review processes for hospitals and physician groups.
  • Advises hospitals and large physician practices on informed consent, release of patient information, affiliation agreements and privileging of peer review and quality review activities. 

Recognitions and Memberships

Recognitions

  • Chambers USA
    • Nationwide Privacy & Data Security (2017)
    • Healthcare in Texas (2014 to 2017)
  • National Law Journal "Cybersecurity Trailblazer" (2016)
  • Burton Award: Distinguished Writing Award for "Anatomy of Healthcare Data Breach" (2013)
  • American Leadership Forum: Senior Fellow
  • Texas Bar Foundation: Fellow
  • Texas Super Lawyers "Rising Star" (2005)
  • Rice University, Jesse H. Jones School of Management Executive Education: Executive Education in Medical and Healthcare Management Certification
  • Texas Children's Hospital: Advanced Quality Improvement and Patient Safety Certification
  • Development Dimensions International: Strategic Leadership

Memberships

  • American Health Lawyers Association
  • AHLA Enterprise Risk Management Task Force: Vice Chair
  • American Society for Healthcare Risk Management
  • Risk and Insurance Management Society
  • American Bar Association
  • Houston Bar Association

Community

  • Children at Risk: Board of Directors, Chair of Development
  • Immunization Partnership: Board of Directors

Prior Positions

  • Texas Children's Hospital: Director and In-House Counsel (2004 to 2011)

Admissions

  • U.S. District Court, Southern District of Texas
  • U.S. District Court, Northern District of Texas
  • U.S. District Court, Eastern District of Texas
  • Texas

Education

  • J.D., Baylor Law School, 1993, Order of Barristers
  • B.A., Texas A&M University, 1989

Blog

In The Blogs

Previous Next
Data Privacy Monitor
SEC Cybersecurity Risk Alert Emphasizes Proactive Compliance and Ongoing Vigilance
By Jonathan A. Forman, Melinda L. McLellan
August 16, 2017
On August 7, 2017, the Securities and Exchange Commission (SEC) released its latest cybersecurity risk alert, detailing findings from the examination of 75 broker-dealers, investment advisers and investment companies carried out by its...
Read More ->
Data Privacy Monitor
FINRA Video Series Highlights Broker-Dealers’ Common Cybersecurity Deficiencies
August 10, 2017
In a series of three video programs published on the FINRA website in recent weeks, FINRA provided guidance on common deficiencies it has been seeing in its cybersecurity examinations of member firms, and recommended a number of measures...
Read More ->
Data Privacy Monitor
Are Industrial Control Systems the Linchpin for Critical Infrastructure Cybersecurity?
August 7, 2017
Over the past few months, news headlines around the globe have been littered with reports of cyberthreats to the critical infrastructure of countries of all sizes. What were once just ominous theories of catastrophic cyberattacks crippling...
Read More ->
Data Privacy Monitor
FTC Announces Internal Process Reforms in Connection with Civil Investigative Demands
July 27, 2017
Has your company or client been served with a Civil Investigative Demand (CID)? Overwhelmed? Don’t despair – the future may be brighter, as the Federal Trade Commission (FTC) is now offering more clarity regarding its CID document requests...
Read More ->
Data Privacy Monitor
Oregon Expands Deceptive Trade Practices Act to Include Misrepresentations About PI Usage
July 26, 2017
Effective January 1, 2018, Oregon will join Pennsylvania and Nebraska in expanding its definition of deceptive trade practices to explicitly include a material misstatement regarding the use of personal information. House Bill 2090 applies...
Read More ->