Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Safeguarding Injured Workers From Cybersecurity Breaches


Under new Federal proposals, injured workers will be protected from cybersecurity breaches. The impact will be greater responsibilities and costs for law firms and, employers and their insurance companies.

Workers' Compensation stakeholders will be required to maintain better cyber hygiene, have better application update procedures and establish an adequate plan to respond to  breaches. Client and governmental agencies will require more secure networks and procedures for handling data transmission, access, and storage.

Hacking is an increasing concern for workers' compensation stakeholders. Some of the attacks by nation states are difficult to contain. Other attacks, by criminal ventures and amateurs, are less invasive. All the attacks can be hazardous, disruptive and costly. In the future, they will probably advance from the invasion of Personal Protective Information (PPI) to industrial ("Internet of Everything"), and national attacks, ie. WannaCry, and WannaCry (2nd wave).  See also, Envisioning the Hack That Could Take Down New York City  NYMag June 10, 2016  and "A Cyberattack "the World Isn't Ready For," NY Times, June 25, 2017.

The scope of potential exposure to injured workers is enormous. It extends from the hypothetical breach of a cardiovascular  (ie. medical device security) implant portrayed on the television series, Homeland, to real-world breaches of Personal Protected Information (PPI). An example of which is the breach of 32,599 patient records resulting in a $4.124 million class action settlement. Columbia Cas. Co. v. Cottage Health System, 2015 WL 4497730 July 15, 2015 Not Reported in F.Supp.3d. "The Court, therefore, DISMISSES the Complaint WITHOUT PREJUDICE, so that the parties may pursue alternative dispute resolution under the terms of the policy." The cybersecurity policy contained an exclusion for "failure to follow minimum required practices." See also the press releases from the NY State Attorney General.

Insurance carriers are not immune from liability as a result of cybersecurity data breaches. A $115 Million proposed class action settlement as a result of a cybersecurity attack on health insurer Anthem, Inc. has been announced. It is the largest data breach settlement in history,

More specifically, a recent American Bar Association opinion mandates that attorneys must take reasonable cybersecurity measures to protect client data. ABA Formal Opinion 477 (May 11, 2017). 

National regulation initiatives have been given a mandate through Presidential Executive Orders. Presidential Executive Order on Improving Critical Infrastructure Cybersecurity 13636 February 13, 2013 and Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure  May 11, 2017. An Introduction to Data Security  (NIST) June, 2017. Digital Idenity Guidlines 800-63 Rev 3, (NIST) June, 2017.

The National Institute of Standards and Technology (NIST) has initiated a "Framework for Improving Critical Infrastructure Cybersecurity." This voluntary model is rapidly gaining acceptance throughout industry and government.

A Federal statutory cause of action has evolved under the Defense of Trade Secrets Act. 18 USC §1836, et. seq., as well as the Cybersecurity Act of 2015. See also, Cybersecurity Enhancement Act of 2014  P.L.113-274 .

The recent initiatives in electronic security were highlighted at the recent NJ ICLE 2nd Annual Cyber Security Conference. The Presidential initiatives operationalized by National Institutes of Standards and Technology. The Cybersecurity Framework: Implementation Guidance for Federal Agencies - Draft NISTIR 8170 (NIST) May 12, 2017 Comment period through June 30, 2017 . Cybersecurity Framework Workshop 2017 , Addressing Gaps in Cybersecurity: OCR Releases Crosswalk Between HIPAA Security Rule and NIST Cybersecurity Framework  February 23, 2016.

The NIST Framework is being integrated into the infrastructure by the Executive Branch. Adoption and integration is anticipated by Health and Human Services  (HHS) (HIPAA-Office of Civil Rights), and Securities and Exchange Commission (SEC), Food and Drug Administration (FDA).
"An overriding question remains whether lawyers will be able to effectively protect their client’s confidentiality interests at any cost. Clients are becoming more sophisticated and they now demand that law firms adhere to security standards that will prevent a breach and if a breach occurs that the law firm will take adequate action to provide notice and, mitigate the potential damage."
"The ethical responsibility of lawyers, in most jurisdictions, is to take reasonable care to protect the personal information of clients in accordance with well-defined constitutional, statutory and administrative regulations, ethics opinions and the common law phraseology of the Restatement of Torts." See, Cybersecurity is an imminent and costly threat to lawyers and their clients.
Cybersecurity in workers' compensation remains in its infancy.  Cybersecurity is again placing the Federal government yet again in the lead on privacy and confidentiality as workers' compensation moves along the Path to Federalization. Going forward, increased regulation and stricter controls will safeguard injured workers.

This article is based on my presentation on Cybersecurity  at the NJ ICLE seminar on Hot Topics in Workers' Compensation Law 2016. The 2017 supplement to the treatise Workers' Compensation Law provides extensive and expanded coverage on this topic.

Jon L. Gelman of Wayne NJ is the author of NJ Workers’ Compensation Law (West-Thomson-Reuters) and co-author of the national treatise, Modern Workers’ Compensation Law (2017 West-Thomson-Reuters). 

For over 4 decades the Law Offices of Jon L Gelman  1.973.696.7900  jon@gelmans.com  has been representing injured workers and their families who have suffered occupational accidents and illnesses.

Updated: 06/29/17 06:30 am

Chaos for Workers' Compensation Programs--The Elimination of Social Security Numbers?

The Centers for Medicare & Medicaid Services (CMS) is readying a fraud prevention initiative that removes Social Security Numbers (SSN) from Medicare cards to help combat identity theft and safeguard taxpayer dollars. The question remains whether the elimination will cause chaos in state workers' compensation programs since the SSNs have historically been utilized as personal identifiers.


For decades private and public insurance systems have relied upon SSN as a major identifier for benefits delivery and record keeping programs. The change surely is going to increase industry costs for the actual conversion process and create some bumps in the road going forward. Workers and their attorneys may also experience inconvenience in initially obtaining benefits and researching prior records. Furthermore, investigatory resources will suffer the burden additional costs in an attempt to convert information and have it readily available on demand. A critical issue remains for lawyers who handle this data and their ethical responsibility to maintain confidentiality.

CMS has rationalized that the new cards will use a unique, randomly-assigned number called a Medicare Beneficiary Identifier (MBI), to replace the Social Security-based Health Insurance Claim Number (HICN) currently used on the Medicare card. CMS will begin mailing new cards in April 2018 and will meet the congressional deadline for replacing all Medicare cards by April 2019. Today, CMS kicks-off a multi-faceted outreach campaign to help providers get ready for the new MBI.

“We’re taking this step to protect our seniors from fraudulent use of Social Security numbers which can lead to identity theft and illegal use of Medicare benefits,” said CMS Administrator Seema Verma. “We want to be sure that Medicare beneficiaries and healthcare providers know about these changes well in advance and have the information they need to make a seamless transition.”

Providers and beneficiaries will both be able to use secure look up tools that will support quick access to MBIs when they need them. There will also be a 21-month transition period where providers will be able to use either the MBI or the HICN further easing the transition

CMS testified on Tuesday, May 23rd before the U.S. House Committee on Ways & Means Subcommittee on Social Security and U.S. House Committee on Oversight & Government Reform Subcommittee on Information Technology, addressing CMS’s comprehensive plan for the removal of Social Security numbers and transition to MBIs.

Personal identity theft affects a large and growing number of seniors. People age 65 or older are increasingly the victims of this type of crime. Incidents among seniors increased to 2.6 million from 2.1 million between 2012 and 2014, according to the most current statistics from the Department of Justice. Identity theft can take not only an emotional toll on those who experience it, but also a financial one: two-thirds of all identity theft victims reported a direct financial loss. It can also disrupt lives, damage credit ratings and result in inaccuracies in medical records and costly false claims.

Work on this important initiative began many years ago, and was accelerated following passage of the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA). CMS will assign all Medicare beneficiaries a new, unique MBI number which will contain a combination of numbers and uppercase letters. Beneficiaries will be instructed to safely and securely destroy their current Medicare cards and keep the new MBI confidential. Issuance of the new MBI will not change the benefits a Medicare beneficiary receives.

CMS is committed to a successful transition to the MBI for people with Medicare and for the health care provider community. CMS has a website dedicated to the Social Security Removal Initiative (SSNRI) where providers can find the latest information and sign-up for newsletters. CMS is also planning regular calls as a way to share updates and answer provider questions before and after new cards are mailed beginning in April 2018.


…
Jon L. Gelman of Wayne NJ is the author of NJ Workers’ Compensation Law (West-Thomson-Reuters) and co-author of the national treatise, Modern Workers’ Compensation Law (West-Thomson-Reuters). 

For over 4 decades the
Law Offices of Jon L Gelman  1.973.696.7900  jon@gelmans.com  has been representing injured workers and their families who have suffered occupational accidents and illnesses.


Just Published: 2017 Update - Gelman on Workers' Compensation Law

Just Published: 2017 Update - Gelman on Workers' Compensation Law

Jon Gelman’s, newly revised and updated 2017 treatise on Workers’ Compensation Law is now available from  by West Group of Egan, MN within the next few weeks. The treatise is the most complete work available on NJ Workers’ Compensation law and integrated with WESTLAW™, the "most prefered online legal research service.'"
  • The recent NJ Supreme Court case involving the jurisdictional issue of employment status is reviewed. This supplement reviews the analysis and mandates of the Court concerning the appropriate forum to resolve the concurrent jurisdiction issues. Other new case law, including dual employment status and its application to the Exclusivity Rule is discussed.
  • A revised chapter has been added that discusses the responsibilities of a workers’ compensation attorney and ethical considerations while handing claims. The material includes how to identify and protect the client’s interest of protected personal in-formation confidentiality. Additionally, it reviews potential cybersecurity threats in light of the increased technology advancement of the practice and what attorneys should do to protect against and respond to the cyber attacks.
  • This supplement analyzes the newly enacted expanded World Trade Center Health Program and the integration with workers’ compensation benefits.
  • The section on cancer and the complex smoking defense has been expanded and updated. It now includes a review of current case law and literature encompassing the health effects of environmental tobacco smoke.
  • Recent decisions concerning The Federal Influenced and Corrupt Organizational Acts (RICO) and workers’ compensation insurance companies, medical providers, and self-insured are discussed. The current Federal Court decisional activity involving NJ operating pharmaceutical distributors is reviewed.
  • The new Centers for Medicare and Medicaid Centers (CMS) Secondary Payer Act Secondary Payer Act (MSP) offset procedures and adopted regulations, implementing The SMART Act are presented in this supplement. The rules for both beneficiary and applicable plans to process and to perfect an appeal, are reviewed. The method and manner of reporting, and communication, with the newly established CMS Commercial Repayment Center (CRC) for workers’ compensation conditional payment is reviewed. Additionally, the newly established procedures and formats for Workers’ Compensation Medicare Set-Aside Arrangements (WCMSA) are discussed.
  • Newly proposed rules by the Occupational Safety and Health Administration (OSHA) concerning beryllium are reviewed. Additionally, a list of New Jersey Covered Facilities under the Energy Employees Occupational Illness Compensation Program is provided.
  • The NJ Supreme Court decision involving “The Coming and Going Rule” and its application to parking lot cases is discussed. Cardiovascular disability claims are analyzed in accordance with the NJ Supreme Court’s recent decision involving what constitutes “work effort” that would trigger a compensable event.
  • The application of the Fraud Prevention Act as a mechanism to bar compensability when information is withheld is reviewed in this supplement. The synergy between tort law and the Workers’ Compensation Act, as expressed in recent case law, is discussed. The recent decision involving the determination of employment status and independent contractors is incorporated in this material.
  • New procedures regarding contacting insolvent entities administered by the NJ Product-Liability Insurance Guaranty Association are outlined. The recent Court ruling involving temporary disability benefits and third-party action liens are included in this supplement.
  • The new Life Tables are included in this material. The updated Centers for Medicare and Medicaid Services reporting requirements for recoveries for environmental hazards and ingestion of particular substances are discussed.
  • The utilization of new procedures for medical provider benefit recovery, motions for emergent medical treatment, counsel fees, and methods to correctly respond to the Court and notice requirements for hearing notice listings are described in this supplement.

Gelman on Workers’ Compensation Law is exclusively integrated into the entire world-wide leading legal research network of West Group-Reuters-Thomson publications.

It is now available, in print, on CD-Rom and online via Westlaw™ and WestlawNext™. [Westlaw Database Identifier NJPRAC].

Now also available an an electronic edition/tablet edition as a ProView™ edition.

Click here now to order your copy.

Jon L. Gelman is nationally recognized as an author, lecturer and skilled trial attorney in the field of workers’ compensation law and occupational/environmental disease litigation. Over a career spanning more than three decades he has been involved in complex litigation involving thousands of clients challenging the mega-industries of: asbestos, tobacco and lead paint. Gelman is the author NJ Workers’ Compensation Law (West-Thompson) and co-author of the national treatise, Modern Workers’ Compensation Law (West-Thompson). He is the former Vice-President of The Workers Injury Law & Advocacy Group (WILG), a charter member of The College of Workers' Compensation and a member of The National Academy of Social Insurance (NASI). Lawyers. Jon is a founder of the Nancy R. Gelman Foundation Inc., which seeks to fund innovative research to cure breast cancer. He is also an avid photographer.