Showing posts with label Ethics. Show all posts
Showing posts with label Ethics. Show all posts

Safeguarding Injured Workers From Cybersecurity Breaches


Under new Federal proposals, injured workers will be protected from cybersecurity breaches. The impact will be greater responsibilities and costs for law firms and, employers and their insurance companies.

Workers' Compensation stakeholders will be required to maintain better cyber hygiene, have better application update procedures and establish an adequate plan to respond to  breaches. Client and governmental agencies will require more secure networks and procedures for handling data transmission, access, and storage.

Hacking is an increasing concern for workers' compensation stakeholders. Some of the attacks by nation states are difficult to contain. Other attacks, by criminal ventures and amateurs, are less invasive. All the attacks can be hazardous, disruptive and costly. In the future, they will probably advance from the invasion of Personal Protective Information (PPI) to industrial ("Internet of Everything"), and national attacks, ie. WannaCry, and WannaCry (2nd wave).  See also, Envisioning the Hack That Could Take Down New York City  NYMag June 10, 2016  and "A Cyberattack "the World Isn't Ready For," NY Times, June 25, 2017.

The scope of potential exposure to injured workers is enormous. It extends from the hypothetical breach of a cardiovascular  (ie. medical device security) implant portrayed on the television series, Homeland, to real-world breaches of Personal Protected Information (PPI). An example of which is the breach of 32,599 patient records resulting in a $4.124 million class action settlement. Columbia Cas. Co. v. Cottage Health System, 2015 WL 4497730 July 15, 2015 Not Reported in F.Supp.3d. "The Court, therefore, DISMISSES the Complaint WITHOUT PREJUDICE, so that the parties may pursue alternative dispute resolution under the terms of the policy." The cybersecurity policy contained an exclusion for "failure to follow minimum required practices." See also the press releases from the NY State Attorney General.

Insurance carriers are not immune from liability as a result of cybersecurity data breaches. A $115 Million proposed class action settlement as a result of a cybersecurity attack on health insurer Anthem, Inc. has been announced. It is the largest data breach settlement in history,

More specifically, a recent American Bar Association opinion mandates that attorneys must take reasonable cybersecurity measures to protect client data. ABA Formal Opinion 477 (May 11, 2017). 

National regulation initiatives have been given a mandate through Presidential Executive Orders. Presidential Executive Order on Improving Critical Infrastructure Cybersecurity 13636 February 13, 2013 and Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure  May 11, 2017. An Introduction to Data Security  (NIST) June, 2017. Digital Idenity Guidlines 800-63 Rev 3, (NIST) June, 2017.

The National Institute of Standards and Technology (NIST) has initiated a "Framework for Improving Critical Infrastructure Cybersecurity." This voluntary model is rapidly gaining acceptance throughout industry and government.

A Federal statutory cause of action has evolved under the Defense of Trade Secrets Act. 18 USC §1836, et. seq., as well as the Cybersecurity Act of 2015. See also, Cybersecurity Enhancement Act of 2014  P.L.113-274 .

The recent initiatives in electronic security were highlighted at the recent NJ ICLE 2nd Annual Cyber Security Conference. The Presidential initiatives operationalized by National Institutes of Standards and Technology. The Cybersecurity Framework: Implementation Guidance for Federal Agencies - Draft NISTIR 8170 (NIST) May 12, 2017 Comment period through June 30, 2017 . Cybersecurity Framework Workshop 2017 , Addressing Gaps in Cybersecurity: OCR Releases Crosswalk Between HIPAA Security Rule and NIST Cybersecurity Framework  February 23, 2016.

The NIST Framework is being integrated into the infrastructure by the Executive Branch. Adoption and integration is anticipated by Health and Human Services  (HHS) (HIPAA-Office of Civil Rights), and Securities and Exchange Commission (SEC), Food and Drug Administration (FDA).
"An overriding question remains whether lawyers will be able to effectively protect their client’s confidentiality interests at any cost. Clients are becoming more sophisticated and they now demand that law firms adhere to security standards that will prevent a breach and if a breach occurs that the law firm will take adequate action to provide notice and, mitigate the potential damage."
"The ethical responsibility of lawyers, in most jurisdictions, is to take reasonable care to protect the personal information of clients in accordance with well-defined constitutional, statutory and administrative regulations, ethics opinions and the common law phraseology of the Restatement of Torts." See, Cybersecurity is an imminent and costly threat to lawyers and their clients.
Cybersecurity in workers' compensation remains in its infancy.  Cybersecurity is again placing the Federal government yet again in the lead on privacy and confidentiality as workers' compensation moves along the Path to Federalization. Going forward, increased regulation and stricter controls will safeguard injured workers.

This article is based on my presentation on Cybersecurity  at the NJ ICLE seminar on Hot Topics in Workers' Compensation Law 2016. The 2017 supplement to the treatise Workers' Compensation Law provides extensive and expanded coverage on this topic.

Jon L. Gelman of Wayne NJ is the author of NJ Workers’ Compensation Law (West-Thomson-Reuters) and co-author of the national treatise, Modern Workers’ Compensation Law (2017 West-Thomson-Reuters). 

For over 4 decades the Law Offices of Jon L Gelman  1.973.696.7900  jon@gelmans.com  has been representing injured workers and their families who have suffered occupational accidents and illnesses.

Updated: 06/29/17 06:30 am

Chaos for Workers' Compensation Programs--The Elimination of Social Security Numbers?

The Centers for Medicare & Medicaid Services (CMS) is readying a fraud prevention initiative that removes Social Security Numbers (SSN) from Medicare cards to help combat identity theft and safeguard taxpayer dollars. The question remains whether the elimination will cause chaos in state workers' compensation programs since the SSNs have historically been utilized as personal identifiers.


For decades private and public insurance systems have relied upon SSN as a major identifier for benefits delivery and record keeping programs. The change surely is going to increase industry costs for the actual conversion process and create some bumps in the road going forward. Workers and their attorneys may also experience inconvenience in initially obtaining benefits and researching prior records. Furthermore, investigatory resources will suffer the burden additional costs in an attempt to convert information and have it readily available on demand. A critical issue remains for lawyers who handle this data and their ethical responsibility to maintain confidentiality.

CMS has rationalized that the new cards will use a unique, randomly-assigned number called a Medicare Beneficiary Identifier (MBI), to replace the Social Security-based Health Insurance Claim Number (HICN) currently used on the Medicare card. CMS will begin mailing new cards in April 2018 and will meet the congressional deadline for replacing all Medicare cards by April 2019. Today, CMS kicks-off a multi-faceted outreach campaign to help providers get ready for the new MBI.

“We’re taking this step to protect our seniors from fraudulent use of Social Security numbers which can lead to identity theft and illegal use of Medicare benefits,” said CMS Administrator Seema Verma. “We want to be sure that Medicare beneficiaries and healthcare providers know about these changes well in advance and have the information they need to make a seamless transition.”

Providers and beneficiaries will both be able to use secure look up tools that will support quick access to MBIs when they need them. There will also be a 21-month transition period where providers will be able to use either the MBI or the HICN further easing the transition

CMS testified on Tuesday, May 23rd before the U.S. House Committee on Ways & Means Subcommittee on Social Security and U.S. House Committee on Oversight & Government Reform Subcommittee on Information Technology, addressing CMS’s comprehensive plan for the removal of Social Security numbers and transition to MBIs.

Personal identity theft affects a large and growing number of seniors. People age 65 or older are increasingly the victims of this type of crime. Incidents among seniors increased to 2.6 million from 2.1 million between 2012 and 2014, according to the most current statistics from the Department of Justice. Identity theft can take not only an emotional toll on those who experience it, but also a financial one: two-thirds of all identity theft victims reported a direct financial loss. It can also disrupt lives, damage credit ratings and result in inaccuracies in medical records and costly false claims.

Work on this important initiative began many years ago, and was accelerated following passage of the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA). CMS will assign all Medicare beneficiaries a new, unique MBI number which will contain a combination of numbers and uppercase letters. Beneficiaries will be instructed to safely and securely destroy their current Medicare cards and keep the new MBI confidential. Issuance of the new MBI will not change the benefits a Medicare beneficiary receives.

CMS is committed to a successful transition to the MBI for people with Medicare and for the health care provider community. CMS has a website dedicated to the Social Security Removal Initiative (SSNRI) where providers can find the latest information and sign-up for newsletters. CMS is also planning regular calls as a way to share updates and answer provider questions before and after new cards are mailed beginning in April 2018.


…
Jon L. Gelman of Wayne NJ is the author of NJ Workers’ Compensation Law (West-Thomson-Reuters) and co-author of the national treatise, Modern Workers’ Compensation Law (West-Thomson-Reuters). 

For over 4 decades the
Law Offices of Jon L Gelman  1.973.696.7900  jon@gelmans.com  has been representing injured workers and their families who have suffered occupational accidents and illnesses.


The Security of Metadata in Workers' Compensation Claims

Metadata Ethics Opinions Around the U.S.
Source: aba.org

Confidentiality is a crucial element in workers' compensation matters and the removal of metadata in electronically transmitted documents are a critical factor in the process of maintaining the level of security embraced by the system. Metadata is all hidden data in a PDF file, including text, metadata, annotations, form fields, attachments, and bookmarks.


"....Metadata is loosely defined as "data about data." More specifically, the term refers to the embedded stratum of data in electronics file that may include such information as who authored a document, when it was created, what software was used, any comments embedded within the content, and even a record of changes made to the document.

"While metadata is often harmless, it can potentially include sensitive, confidential, or privileged information. As such, it presents a serious concern for attorneys charged with maintaining confidentiality -- both their own and their clients. Professional responsibility committees at several bar associations around the country have weighed in on attorneys' ethical responsibilities regarding metadata, but the opinions vary significantly. Source: The American Bar Association

The NJ Supreme Court announced yesterday, in an Administrative Determination,  that all documents in electronic format should be "scrubbed" of metadata.

"The Court addressed an important ethical question raised by New Jersey practitioners in the context of their contemporary practice: whether a lawyer who receives an electronic document may, consistent with the rules governing attorney ethics, review metadata in that document. “Metadata” is embedded information in electronic documents that is generally hidden from view in a printed document. Metadata may reflect such information as the author of a document, date(s) on which the document was revised, tracked revisions, and comments inserted in the margins, among other things. This embedded electronic information may include privileged information or other potentially objectionable, private or proprietary information. Following a careful review, the Court adopts the recommendations of the Working Group on Ethical Issues Involving Metadata in Electronic Documents, and makes a number of amendments to the Court Rules regarding electronic documents and metadata. The measures are designed to protect sensitive client data, clarify attorneys’ professional obligations, and foster education programs so that the legal community may be better equipped to meet the unique challenges inherent in exchanging documents electronically -- a modern reality that is ubiquitous in the contemporary practice of law.

“Metadata” is embedded information in electronic documents that is generally hidden from view in a printed copy of a document. It is generated when documents are created or revised on a computer. Metadata may reflect such information as the author of a document, the date or dates on which the document was revised, tracked revisions to the document, and comments inserted in the margins. It may also reflect information necessary to access, understand, search, and display the contents of documents created in spreadsheet, database, and similar applications. This embedded electronic information may include privileged information, information subject to the work product privilege, information that has not been requested in discovery, information that has been requested in discovery but is subject to an objection on which a court has not yet ruled, non-discoverable information, and private or proprietary information. Some metadata is of little or no use to a party or counsel in a litigated dispute or transactional matter. Other metadata is directly material to a factual or legal issue. If the sender has not affirmatively minimized (“scrubbed” or “stripped”) metadata in the document, some information may be revealed by simple computer keystrokes, while other metadata may be “mined” by the use of sophisticated computer software.


Professional programs are available to remove Metadata from electronic documents. See,
Sanitization—Remove hidden data from PDF files with Adobe® Acrobat® XI