Lynn Sessions

Partner

Houston
T 713.646.1352  |  F 713.751.1717

"The 'very knowledgeable' Lynn Sessions…[is able to] 'get to the short and sweet - she gets right to the point, which is extraordinarily beneficial to us.'"

— Chambers USA 2015

With more than 20 years of working with healthcare industry clients, Lynn Sessions focuses her practice on healthcare operations and regulatory work, with an emphasis on healthcare privacy and data security, breach response, and HIPAA compliance. Having previously served as in-house counsel and director of several departments at a nationally ranked children's hospital, Lynn collaborates closely with healthcare clients and approaches her legal representation from a client's perspective. 

Lynn is a frequent speaker on a range of topics affecting health industry clients, including HIPAA compliance, data breach response, cyber and network security, enterprise risk management, EMTALA, handling adverse patient events and insurance and risk financing. Lynn is also a regular contributor to BakerHostetler's Data Privacy Monitor blog, available at www.dataprivacymonitor.com, as well as the Health Law Update.

Select Experience

Privacy and Data Security 

  • Has handled more than 300 healthcare data breaches, including several of the largest breaches reported to date. In her representation, Lynn provides counsel to health care providers and other covered entities on breach analysis, breach response, crisis management with patients, media and employees, and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.

Operations and Regulatory Practice 

  • Regularly advises hospitals on Emergency Medical Treatment and Active Labor Act (EMTALA).
More »

Experience

Privacy and Data Security 
  • Has handled more than 300 healthcare data breaches, including several of the largest breaches reported to date. In her representation, Lynn provides counsel to health care providers and other covered entities on breach analysis, breach response, crisis management with patients, media and employees, and regulatory notification obligations to the Office for Civil Rights (OCR) and state attorneys general.
  • Has responded to more than 75 post-breach investigations from the OCR and state attorneys general arising from large and small data breaches reported by covered entities and has successfully defended healthcare organizations in these investigations.
  • Represents educational institutions regarding data breaches, including breach analysis, breach response, crisis management, and regulatory report.
  • Advises clients on HIPAA compliance, including preparation of policies and procedures, notice of privacy practices, business associate agreements, and incident response plans. Works with healthcare organizations post-data breach to strengthen safeguards under HIPAA and implementation of corrective action plans.
  • Advises with large non-healthcare employers on HIPAA issues for their self-insured health plans and onsite provider clinics on HIPAA compliance, including policies and procedures, business associate arrangements, and sharing of employee information.  
Operations and Regulatory Practice 
  • Regularly advises hospitals on Emergency Medical Treatment and Active Labor Act (EMTALA).
  • Conducted an audit of a top children’s hospital's risk management department and advised on departmental and operational changes for improved function within the hospital.
  • Develops and enhances credentialing and peer review processes for hospitals and physician groups.
  • Advises hospitals and large physician practices on informed consent, release of information patient information, affiliation agreements, and privileging of peer review and quality review activities. 

Recognitions

  • Chambers USA: Healthcare in Texas (2014 to 2016)
  • Burton Award: Distinguished Writing Award for "Anatomy of Healthcare Data Breach" (2013)
  • American Leadership Forum: Senior Fellow
  • Texas Bar Foundation: Fellow
  • Texas Super Lawyers "Rising Star" (2005)
  • Rice University, Jesse H. Jones School of Management Executive Education: Executive Education in Medical and Healthcare Management Certification
  • Texas Children's Hospital: Advanced Quality Improvement and Patient Safety Certification
  • Development Dimensions International: Strategic Leadership

Memberships

  • American Health Lawyers Association
  • AHLA Enterprise Risk Management Task Force: Vice Chair
  • American Society for Healthcare Risk Management
  • Risk and Insurance Management Society
  • American Bar Association
  • Houston Bar Association

News

Press Releases

Alerts

Articles

Community

  • Children at Risk: Board of Directors, Chair of Development
  • Immunization Partnership: Board of Directors

Services

Industries

Prior Positions

  • Texas Children's Hospital: Director and In-House Counsel (2004 to 2011)

Admissions

  • U.S. District Court, Southern District of Texas
  • U.S. District Court, Northern District of Texas
  • U.S. District Court, Eastern District of Texas
  • Texas

Education

  • J.D., Baylor Law School, 1993, Order of Barristers
  • B.A., Texas A&M University, 1989

Blog

In The Blogs

Previous Next
Data Privacy Monitor
Privacy Shield to Open for Business August 1
By Jenna N. Felz
July 20, 2016
After more than two years of negotiations, on July 12, 2016, the European Commission formally adopted the EU-U.S. Privacy Shield (the “Privacy Shield”) framework as a valid mechanism for transfers of personal data from the EU to the U.S...
Read More ->
Data Privacy Monitor
$90 Million Cyber Thefts From SWIFT Network Raise Security and Legal Issues
July 7, 2016
In February 2016, attackers stole $81 million from the Bangladesh central bank’s account at the New York Federal Reserve Bank by hacking into the Bangladesh bank’s computer network and sending fraudulent messages through the Society for...
Read More ->
Data Privacy Monitor
Business Associates in the Crosshairs: Catholic Health Care Services Settles for $650,000 for Failure to Safeguard PHI
By Suchismita Pahi
July 7, 2016
Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS) recently agreed to enter into a $650,000 resolution agreement and a two-year corrective action plan (CAP) with the Office for Civil Rights (OCR). CHCS provides...
Read More ->
Data Privacy Monitor
Mobile Ad Co Settles with FTC Over Allegations of Deceptive Geolocation Tracking And Children's Privacy Violations for $4 Million
By Alan L. Friel
June 29, 2016
On June 22, 2016, mobile advertising company, InMobi Private Ltd. settled with the Federal Trade Comission (“FTC” or “Commission”) claims of violations of Section 5 of the FTC Act, and the Children’s Online Privacy Protection Act and Rule...
Read More ->
Data Privacy Monitor
Privacy Shield Developments and UK Data Transfers Post-Brexit
By Jenna N. Felz
June 28, 2016
With the UK’s Brexit referendum dominating the news out of Europe over the past week, it may have been easy to miss a key development in the continuing Privacy Shield negotiations. On Friday, June 24, news outlets reported that U.S...
Read More ->