Skip to Main Content
Professional Photo
Professionals

Alisa L. Chestler, CIPP/US, QTE

Shareholder

Alisa Chestler concentrates her practice in privacy, security and information management issues; health information and technology; and corporate transactions matters.

Featured Videos


The Cyber Risk Allocation Paradigm is Changing: Cyber Insurance's Evolving Issues September 23, 2021
Cyber Threats: Key Considerations for Employers July 27, 2021

Featured Experience


Assisted large hospital system in identifying cybersecurity issues and negotiation of asset purchase agreement and closing conditions.

Counseled emerging company on privacy and security issues prior to initial capital raise.

Represented an academic medical center in negotiating a $400 million electronic medical record software license and implementation services agreement with Epic Systems.

2016

Professional Biography


Ms. Chestler serves as the chair of the Data Protection, Privacy and Cybersecurity Team at Baker Donelson. She concentrates her practice in privacy, security and information management issues including compliance, contract negotiation and corporate transactions matters. She joined Baker Donelson after a distinguished career as in-house counsel and privacy officer to several large public and private companies. Ms. Chestler is a Certified Information Privacy Professional: United States (CIPP/US) and has also attained certification as a Qualified Technology Expert (QTE).

Ms. Chestler serves as a trusted advisor to clients and routinely counsels clients on their technology and data strategy with a strong base in digital health, life science and general health care. She routinely counsels clients on technology, data privacy and security matters that arise from federal and state laws, including HIPAA, the California Consumer Privacy Act (CCPA), GLB, FCRA/FACTA, FERPA, state data breach laws and the Payment Card Industry (PCI-DSS) requirements. Ms. Chestler also counsels clients on global data protection laws, including the General Data Protection Regulation (GDPR) and the Personal Information Protection and Electronic Documents Act (PIPEDA). She has significant experience assisting companies in developing comprehensive privacy and security programs and working with management to identify risk management issues, many times in anticipation of corporate transactions. She assists clients in identifying, evaluating and managing risks associated with privacy and information security practices of companies and third party service providers. Ms. Chestler also counsels clients regarding incident response programs including the development of the incident response plan, investigation and response.

Ms. Chestler drafts and negotiates technology agreements including Master Services Agreements (MSAs), software license agreements, Software as a Service (SaaS) agreements, and professional services agreements.

Ms. Chestler routinely assists clients in complex health information and technology issues including the negotiation of complex information technology and partnership agreements, including health information exchange (HIE) participation, EHR negotiation, data use agreements, blockchain, artificial intelligence (AI), adoption and compliance with HITECH and meaningful use requirements, and the interoperability and information blocking regulations. She assists digital health and consumer application companies in navigating the complexities of health care technology strategy, agreements and compliance concerns. Follow her on Twitter @alchestler.

  • Assisted large hospital system in identifying cybersecurity issues and negotiation of asset purchase agreement and closing conditions.

  • Counseled emerging company on privacy and security issues prior to initial capital raise.

  • Represented an academic medical center in negotiating a $400 million electronic medical record software license and implementation services agreement with Epic Systems.

  • Strategic and legal counseling for international consumer application entrance into health market.

  • Listed in Washington, D.C. Super Lawyers in the area of Health Care (2012 – 2023); Technology Transactions (2023)
  • Member – American Health Law Association
    • Health Information and Technology Practice Group – Chair (2018 – Present)
    • Health Information and Technology Practice Group – Vice Chair (2015 – 2018)
    • Health Information and Technology Practice Group – Leadership Development (2014 – 2015)
  • Member – International Association of Privacy Professionals
  • Member – Health Care Compliance Association 
  • Chair – Compliance Committee, The Care Continuum Alliance (2009 – 2013)
  • Member – American Health Information Management Association
    • Practice Council on Health Information Exchange (2012 – 2014)
  • Moderator – "Privacy and Security Risk Management: Securing Your Enterprise and Beyond," 2022 Baker Donelson Long Term Care Symposium (November 2022)
  • "Don't Let a Cyber Quarantine Wreck Your Transaction/Reps and Warranties and Risk Analysis: A Growing Trend," AHLA Health Law Transactions Meeting (April 2022)
  • "Tenth Annual Tennessee Hospitality & Tourism Association Law Symposium" (August 2021)
  • "The Law & Cyber Security: What Those in Trucking Need to Know," American Trucking Association (July 2020)
  • "Unblocking Information - Industry Collaboration on Interoperability Model Contract Terms," AHLA Annual Meeting (July 2020)
  • "Corporate Counsel 2020: How to Cyber-Proof Your Transaction - Privacy and Security Considerations," Tennessee Bar Association (May 2020)
  • "Avoiding Cyber-Collisions- Don't Let Cyber Issues Wreck Your Transaction," AHLA Transactions Meeting (April 2020)
  • The CFO Leadership Council – Nashville Chapter (January 2020)
  • "Crafting a Company's Privacy Regime to Meet Global Requirements," Georgetown Law 16th Annual Advanced eDiscovery Institute, Washington, D.C. (November 2019)
  • "How the C-Suite, Board, & CISO Can Communicate Better," Cybercon 2019 (September 2019)
  • "Cyberproof Your Transaction – Avoid Letting Cyber Issues Derail Your Transaction," 2019 AHLA Transactions Conference (May 2019)
  • "AHLA Physicians and Hospitals Law Institute" (February 2019)
  • "Wrap It Up" (December 2018)
  • Moderator – "Whose Document Is It Anyway? – Possession of Documents in the Digital Age," 2018 Long Term Care Symposium (November 2018)
  • "Cyber Security," 68th Annual Southeastern Association of Tax Administrators Conference, Nashville, Tennessee (July 2018)
  • "Get the 411– Keeping the Information Technology Elements of Your Transactions Online," AHLA Health Care Transactions Conference, Nashville, Tennessee (May 2018)
  • Panelist – "Code Talkers and Cyber Security – What Do They Have in Common?," Tennessee HIMSS Cybersecurity Breakfast, Nashville, Tennessee (October 2017)
  • "What's Now and What's Next in the Telehealth Industry: Utilize Technological Advances to Minimize Risk," Bloomberg BNA, Washington, D.C. (September 2017)
  • "Blockchain, IoT. . . Around the World in Health Information Technology," AHLA Annual Meeting, San Francisco, California (June 2017)
  • Panelist – "Business Case for Cybersecurity | Managing the Risk of Insecurity," Nashville Cybersecurity Conference (June 2017)
  • "Welcome to the Future: Telemedicine and HIPAA HITECH ," 2016 Long Term Care Symposium (November 2016)
  • Moderator – "Healthcare & Interoperability: What does interoperability mean to health care? Why is it so crucial to the next level of providing safe and effective health care?," 2016 SEUS-CP Conference, Nashville, Tennessee (May 2016)
  • Panelist – "Why U.S. – Turkey Partnerships? Opportunities and Challenges," U.S. – Turkey Investment Partnership Summit (February 2016)
  • "Commercial and Government Procurement/RFP Process," Israel Defense Cybersecurity Conference (January 2016)
  • "HIT or Miss? Legal and Ethical Concerns for Implementation of Health IT," Nashville Council of Health Care Attorneys CLE Program (November 2015)
  • "The Rise of Health Care Technology: ERM Implications for the New Normal," American Health Law Association, Enterprise Risk Management Task Force Educational Webinar (October 2015)
  • Panelist – "Under Disruption: Why Health IT is Out of Control," Summit of the Southeast, Tennessee HIMSS Annual Meeting (September 2016)
  • "EHR Standards: HIE, Meaningful Use, and Patient Portals: What Your Lawyers Are Worried About," American Health Information Management Association National Convention (September 2015)
  • Moderator – "U.S. Federal Policy and Cyber Legislation and Regulation: What It Means for Your Business," and "Cybersecurity: Business Challenges and the Future," Securing Your Future: Staying Ahead of Developments in Cybersecurity and Its Impact on Technology, Advanced Manufacturing, Logistics, Health Care and Energy, Atlanta, Georgia (August 2015)
  • Moderator – "The Role of State Governments in Cybersecurity," Securing Your Future: Staying Ahead of Developments in Cybersecurity and its Impact on Technology, Advanced Manufacturing, Logistics, Health Care and Energy, Atlanta, Georgia (August 2015)
  • Panelist – "Fighting Hack Attacks and Data Breaches: A Booming Climate for Investors," Securing Your Future: Staying Ahead of Developments in Cybersecurity and Its Impact on Technology, Advanced Manufacturing, Logistics, Health Care and Energy, Atlanta, Georgia (August 2015)
  • Panelist – "Defending the Grid: Latest Threats and How They Can Be Avoided," Securing Your Future: Staying Ahead of Developments in Cybersecurity and Its Impact on Technology, Advanced Manufacturing, Logistics, Health Care and Energy, Atlanta, Georgia (August 2015)
  • Moderator – "Cyber Liability Coverage and Insurance," Securing Your Future: Staying Ahead of Developments in Cybersecurity and Its Impact on Technology, Advanced Manufacturing, Logistics, Health Care and Energy, Atlanta, Georgia (August 2015)
  • Panelist – "The Background Singers: How Other Industries Affect Hotels," 2015 Hotel Data Conference (August 2015)
  • "Health Care Technology: New Regulations and Impact of HIPAA," Nashville Bar Association CLE Program (August 2015)
  • "Data Security and Privacy Essentials for an Unsecure World" (October 2014)
  • Moderator – "Part III: HIT and Data Sharing Issues for the ACO," Accountable Care Organization Bootcamp Webinar Series (March 2013)

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept