Cybersecurity Tips for Small Businesses

When it comes to data security breaches, things aren’t getting any better. According to Risk Based Security’s 2019 MidYear QuickView Data Breach Report, more than 3,800 data security breaches were reported in the first six months of 2019. More than 4.1 billion records were compromised. When compared to midyear 2018, the number of reported breaches is up 54%. The number of exposed records is up 52%.

Breaches involving big businesses make the headlines, but small businesses are at risk too. According to the Federal Communications Commission, every small business needs a cybersecurity strategy to protect their business, their customers and their data from constantly growing and evolving cybersecurity threats. The FCC has the following tips for small businesses.

Train Employees. Educate employees about data security. Establish basic security practices, policies and Internet use guidelines that include specific penalties for violations.

Protect Data, Devices and Networks. Using the latest security software, web browsers and operating systems can help defend against viruses, malware and other threats. Set antivirus software to run a scan after each update. Install other key software updates as soon as they are available.

Protect Mobile Devices. Mobile devices, particularly those with sensitive data or network access, can create significant security risks. Require employees to password-protect devices, encrypt data and install security apps to protect data on public networks. Implement and enforce reporting procedures for lost or stolen equipment.

Backup Sensitive Data. Require regular backups of critical data, including documents, spreadsheets, databases, financial files, human resources files and accounting files. Backup data automatically if possible, or at least weekly. Store backups offsite or in the cloud.

Secure Wi-Fi Networks. Make sure networks are secure, encrypted and hidden. Network names should not be broadcast. Routers should be password protected.

Limit Access and Authority. Employees should only have access to data needed to do their jobs. Employees should not be able to install any software without permission.

Passwords and Authentication. Require employees to use unique passwords and change passwords every three months. Consider implementing multi-factor authentication that requires additional information beyond a password to gain access.

Data security threats have become a constant concern for small businesses. Implementing, maintaining and updating security policies and procedures is important, but it’s not always enough. Small and medium-sized businesses should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Every Small Business Needs a Cyber Security Strategy

Did you know that more than 50 percent of small and medium-sized businesses (SMBs) experienced a cyber-attack in the previous year? Cybercriminals tend to be opportunistic. They target the unprepared. Unfortunately, far too many SMBs don’t have a plan to prevent or respond to cyber-attacks.

SMBs can significantly reduce the likelihood of falling victim to cybercriminals by preparing a cyber security strategy. Let’s look at the essential elements of an effective strategy.

Prevention. The primary goal of every cyber security strategy should be prevention. An effective prevention strategy requires:

Detection. SMBs must be able to detect cyberattacks when they happen. An effective detection strategy requires:

  • Technology. Cyberattacks are so sophisticated that SMBs need quality intrusion detection systems that are routinely updated to remain current with evolving threats.
  • Real-Time Alerts. Tracking attacks provides data that can be used to generate real-time alerts.
  • Documentation. Records make it easier to evaluate attack trends and characteristics and update strategies accordingly.

Mitigation. A rapid response to a cyberattack is critical to limiting the damage. An effective mitigation strategy includes:

  • Response Plans. Once an attack is detected, SMBs must be ready to contain, assess and respond to the threat. A response plan should specifically identify personnel and designate responsibilities in the event of an attack.
  • Periodic Evaluations. Remediation and mitigation strategies must be reviewed and updated periodically to remain current with constantly evolving cyber threats.

Insurance. Preparation is important, but it isn’t always enough. SMBs should have Cyber Perils Insurance Coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Did You Know…Data Breaches Exposed More Than 18 Million Records PER DAY?

It looks like 2018 is going to be a record year for data breaches…in a bad way. Gemalto, a global digital security provider, released its Breach Level Index for the first half of 2018. It revealed a mix of good, bad and ugly. When compared to the first half of 2017, the number of data breaches worldwide actually went down. Unfortunately, the number of lost, stolen or compromised data records went up. Now for the ugly. This number went up 72 percent!

During the first six months of 2018, there were 944 data breaches worldwide, nearly 60 percent occurred in North America. As a result of these breaches, more than 3.3 billion data records were compromised or exposed. That works out to 18.5 million records per day. Nearly three quarters of a million records per hour!

According to the Breach Level Index:

  • More than 76 percent of the records breached involved social media, including breaches at Facebook (2.1 billion records) and Twitter (336 million records).
  • Malicious outsiders caused 56 percent of the data breaches.
  • Attacks by malicious insiders fell by 60 percent.
  • 879 million data records were lost by accident.
  • Identity theft remains the leading type of data breach.
  • The number of records stolen through identity theft breaches increased by 757 percent.
  • Financial access incidents decreased in frequency but increased in severity.
  • The healthcare industry experienced the most data breaches of any industry (27 percent).
  • 20 percent of all breaches had an unknown number of compromised data records.
  • Only one percent of the compromised data records were encrypted.

Data security has become a universal concern. Every business is at risk. None are immune. This explains the growing popularity of cyber liability insurance policies. Businesses can purchase Cyber Perils coverage to protect against various cyber threats and liability exposures, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats and data security breaches.

Do Standard Crime Insurance Policies Cover Business Email Compromise (BEC) Attacks?

Business Email Compromise (BEC) attacks are sophisticated scams that commonly use social engineering, phishing and spoofing to compromise legitimate business e-mail accounts. In 2017, the FBI reported receiving 15,690 BEC complaints with BEC losses topping $675 million. The FBI warns small, medium and large businesses alike that constantly expanding and evolving BEC attacks put them all at risk.

Businesses can and should take preventative measures to protect against BEC attacks, but what happens when they fail? Are BEC attacks considered a type of Computer Fraud that is covered under a standard crime insurance policy? Well…it depends.

Losses and claims associated with BEC attacks are relatively new. Standard crime insurance policies are not. Like Über and Airbnb, BEC attacks don’t fit neatly into standard insurance policies, so coverage isn’t always clear. As expected, this coverage confusion produced coverage disputes that became coverage lawsuits.

Lawsuits can provide clarity because they require courts to interpret and apply specific insurance policies and provisions. But, that’s not necessarily the case with BEC attacks because some federal appellate courts don’t necessarily agree on whether a BEC attack constitutes Computer Fraud under a standard crime policy.

Since coverage isn’t obvious one way or the other, courts must dig deep into the policy and relevant case law to determine whether coverage exists. As the following cases illustrate, this can create conflicting case law.

Apache Corporation (5th Circuit 2016). A BEC attack was part of a scam to change the account number used to pay a legitimate vendor. Apache was unaware of the fraud until the vendor told them payments were overdue. By then, approximately $7 million had been diverted to the fraudulent account.

The Fifth Circuit ruled that Apache’s losses are not covered because the BEC attack was merely incidental to an overall scheme to defraud. According to the court, most fraudulent schemes involve some form of computer-facilitated communication, and interpreting Computer Fraud to include any fraudulent scheme that uses email would convert a crime policy’s computer-fraud provision into one for general fraud. Regrettably, the court concluded, Apache sent payment for a legitimate invoice to the wrong bank account.

American Tooling Center (6th Circuit 2018). American Tooling filed a Computer Fraud claim after a BEC attack tricked the Treasurer to wire $834,000 to a fraudulent account. The Sixth Circuit ruled that American Tooling’s losses are covered because the BEC attack constituted Computer Fraud under the crime insurance policy.

According to the court, an impersonator used a computer to send fraudulent emails that fraudulently caused American Tooling to transfer money to the impersonator. The Computer Fraud provision, the court noted, does not require that the fraud cause any computer to do anything. The court said that if the insurance company wanted to limit Computer Fraud coverage to hacking or unauthorized computer access it could have done so in the policy.

These cases didn’t involve identical facts or policy forms, yet they reveal potentially significant conceptual differences about the nature of BEC attacks and the scope of Computer Fraud coverage. Though the circumstances were quite similar, the outcomes were very different.

As a result, determining whether a BEC attack is covered under a standard crime policy may depend, at least in part, on where it occurred. This can make it difficult for businesses to effectively evaluate, mitigate and insure against the serious risk posed by BEC attacks.

Please contact us if you would like more information about insurance specifically designed to protect against cyber threats.

To receive regular insurance and risk management informational updates, please subscribe to our newsletter.

Workers’ Compensation 101: What Does Employers Liability Insurance Cover?

Did you know that a standard workers’ compensation insurance policy has more than one part? It’s true, check for yourself. Part One Workers Compensation Insurance provides indemnity and medical benefits that employers are legally required to provide employees who are injured on the job. You probably knew that already.

But, if you keep reading, you will see that Part One is followed by…Part Two Employers Liability Insurance. What could that possibly cover?

Part Two of a standard workers’ compensation policy covers employers for liability arising out of an employee’s work-related injury, death or disease that is not otherwise covered under a state’s workers’ compensation laws. Unless otherwise excluded under the policy, Employers Liability Insurance will typically respond to a variety of claims that stem from an employee’s work-related injury, including the following common claims.

Third-Party Over. Despite providing workers’ compensation insurance, an employer may end up being held indirectly liable for an employee’s workplace injury. Third-party over claims occur when: 1) an employee sues a third-party to recover damages for their workplace injury; and 2) that third-party then turns around and attempts to hold the employer responsible for the employee’s lawsuit.

For example, assume an employee injured by workplace machinery sues the machine’s manufacturer for damages. A third-party over situation would occur if the manufacturer tries to recover money it paid to the employee by suing the employer for negligently failing to maintain the machinery.

Loss of Consortium. Consortium generally refers to one spouse’s legal right to the company, affection, assistance, service, companionship and marital relations of the other spouse. The spouse of an injured employee may bring a claim for care and loss of services.

Consequential Bodily Injury. An injured employee’s spouse, child, parent or sibling may sue the employer for their own bodily injuries that are a direct consequence of the bodily injury suffered by the employee. Examples may include a spouse who develops migraine headaches or a parent who has a stroke induced by the stress caused by their child’s workplace injury.

Dual-Capacity. Depending on the circumstances, an injured employee may be able to sue their employer in a nonemployment-related capacity. For example, an employer may be sued as the manufacturer of the machinery that injured the employee or the landlord that failed to adequately maintain the premises.

Employers Liability Coverage is automatically included in standard workers’ compensation policies available in most states. But, North Dakota, Ohio, Washington and Wyoming only allow workers’ compensation insurance purchased from a compulsory state fund. Employers in these ‘monopolistic’ states must purchase stop-gap coverage, which is essentially an Employers Liability Coverage endorsement added to a General Liability policy.

Please contact us if you have any questions about Worker’s Compensation and Employers Liability Insurance Coverage. You can subscribe to our newsletter to receive regular insurance and risk management informational updates.

Is That REALLY a Service Animal?

Are you ready to RRRUUMMMBLE? In this corner, we have a “No Pets Allowed” policy. And, in this corner, we have a patron with a service animal. Who wins? The answer is important because a number of laws protect individuals with disabilities, including the Americans with Disabilities Act. To avoid costly violations, businesses (and their employees!) need to know how to deal with service animals.

Title III of the ADA generally prohibits disability discrimination by public accommodations. ADA regulations issued by the Department of Justice generally require public accommodations to modify policies, practices or procedures to permit the use of a service animal by an individual with a disability. [Modifications that conflict with legitimate safety requirements or fundamentally alter the nature of goods or services provided to the public are not required.]

The ADA broadly defines public accommodation to include a wide-range of private entities that conduct operations affecting commerce. So, there’s a good chance that this requirement applies to your business.

What is a Service Animal?

A service animal is defined as any dog that is individually trained to do work or perform tasks for the benefit of an individual with a disability, including a physical, sensory, psychiatric, intellectual or other mental disability. The work or tasks performed by a service animal must be directly related to the individual’s disability, such as:

  • Assisting individuals who are blind or deaf;
  • Providing physical support or stability to individuals with mobility disabilities; and
  • Helping persons with psychiatric and neurological disabilities.

Dogs that provide emotional support, well-being, comfort or companionship are not considered service animals because they are not individually trained to perform a specific job or task. Other species of animals, whether wild, domestic, trained or untrained, are not service animals for the purposes of this definition.

Fun Fact: In some cases, a public accommodation may be required to let an individual with a disability use a trained miniature horse. Seriously.

What can you ask someone with a Service Animal?

If it’s obvious that an animal is trained to do work or perform tasks for an individual with a disability, you’re generally not allowed to ask anything. This would be the case if a dog is observed guiding someone who is blind or pulling someone’s wheelchair. If it’s not obvious, then you’re allowed to ask two, and only two, specific questions.

  • Is the animal required because of a disability? (But, you cannot ask about the nature or extent of a person’s disability.)
  • What work or task has the animal been trained to perform?

You cannot require or request proof that a dog has been certified, trained or licensed as a service animal, which doesn’t really matter because anyone can buy certification and registration documents online. It also doesn’t matter because these documents do not convey any rights under the ADA and are not recognized by the DOJ as proof that a dog is a service animal.

A growing number of states have actually passed laws in response to people lying about service animals. For example, in 2015, Florida made it a crime to knowingly and willfully misrepresent yourself as being qualified to use a service animal

Here are a few other things worth knowing about service animals.

  • Service animals don’t need to be professionally trained.
  • Service animals that are not housebroken or out of control can be asked to leave.
  • Any breed of dog can be a service animal.
  • Restaurants and bars are not required to permit service animals on chairs or tables.
  • State-specific laws, which can vary significantly, may also govern the use of service dogs in public accommodations.

Things can go very wrong very fast when service animals are not handled properly. They often require a delicate touch. Businesses that don’t know or follow the law governing service animals face potentially devastating reputational and financial harm.

Please contact us if you would like more information about insurance designed to protect your business…just in case.

To receive regular insurance and risk management informational updates, please subscribe to our newsletter.

Fair Labor Standards Act: Wage & Hour Law Update

What is the most recent development involving Fair Labor Standards Act? Here’s a hint. It’s not the highly-publicized rise and fall of those new white-collar overtime exemption regulations. In fact, quite a bit has happened since the Department of Labor officially abandoned its fight for new white-collar regulations in late 2017.

Opinion Letters

In June 2017, the DOL announced that it would reinstate the issuance of written opinion letters to help employers and employees better understand the FLSA. These letters provide the Wage and Hour Division’s official opinion of how the FLSA applies in the specific circumstances described by the person requesting the opinion.

On January 5, 2018, the DOL made good on its promise when it re-issued seventeen FLSA-specific opinion letters, the first in nearly a decade. These letters were originally prepared in 2009 by the departing Bush administration and quickly withdrawn under the new Obama administration. Then, on April 12th, the DOL issued two new FLSA-specific opinion letters.

This new round of opinion letters covers various topics, including:

  • Compensability of frequent rest breaks required by a serious health condition;
  • Compensability of travel time;
  • Calculation of salary deductions;
  • Salary deductions for full-day absences based on hours missed; and
  • Year-end non-discretionary bonuses.

Opinion letters are significant because they can provide an affirmative defense for actions that may otherwise be unlawful under the FLSA. An employer may avoid liability for actions:

  • Taken in good faith; and
  • In conformity with and in reliance on any written regulation, order, ruling, approval or interpretation of the DOL’s Wage and Hour Division.

Tipped Employees

In December 2017, the DOL proposed new tip regulations. Under the FLSA, employers can credit tips toward their minimum wage obligation. This “tip credit” is equal to the difference between the cash wages it pays the employee (which must be at least $2.13 per hour) and the $7.25 per hour Federal minimum wage.

Under current regulations, employees must be allowed to keep all of their tips, except for tips distributed through a tip pool. However, the tip pool must be limited to employees who customarily and regularly receive tips, like servers, bartenders and bussers. This restriction applies regardless of whether an employer claims a tip credit.

The proposed regulations remove this restriction for employers that do not take a FLSA tip credit and pay a direct cash wage of at least the full Federal minimum wage. The proposed regulations do not change the rules for employers that do claim a tip credit.

Under the proposed regulations, employers who do not take a tip credit would be allowed to share tips with back-of-house workers and other employees who do not customarily and regularly receive tips. According to the DOL, this lets employers reduce wage disparities among employees who all contribute to a customer’s experience, and also incentivizes all employees to improve customers’ experience.

The period for public comment on the proposed regulations ended February 5, 2018, so we can only wait to see what the DOL does next.

The rapidly changing FLSA can put employers at serious risk. Adjusting to change takes time, but violations can happen in the blink of an eye. Employers should consider Employment Practices Liability Insurance to protect against various employment-related claims, including limited coverage for wage and hour claims.

Please contact us if you would like to learn more about protecting your business with employment practices liability insurance.

To receive regular updates about developments which may affect your business, subscribe to Setnor Byer Insurance & Risk’s weekly risk management news brief.

How Can You Limit the Damage Caused by Identity Theft?

What’s worse than filing your taxes? Finding out that your return was already filed and your refund check was already cashed. Yep, that’s definitely worse. Unfortunately, tax season has become the time of year when many first discover that their identities have been stolen.

According to Javelin Strategy & Research’s 2017 Identity Fraud Study, there were 15.4 million U.S. victims of identity theft in 2016, which is 16 percent higher than 2015. It was the highest rate since Javelin began tracking identity fraud in 2003.

So, what should you do if your identity has been stolen? According to the Federal Trade Commission (FTC), you must take immediate action to limit the damage.

What to do right away.

Contact the fraud department of each company (retailer, bank, etc.) where you know fraud occurred. Explain that someone stole your identity and ask them to close or freeze the accounts so no one can add new charges unless you agree. Change logins, passwords and PINS for your accounts.

Contact one of the three credit bureaus to place a free 90-day fraud alert. That company must tell the other two. A fraud alert makes it harder for someone to open new accounts in your name. When you have an alert on your report, a business must verify your identity before it issues new credit in your name.

Get your credit reports from Equifax, Experian and TransUnion. Review your reports and note any accounts or transactions you don’t recognize.

Report identity theft to the FTC. The FTC will create an Identity Theft Report and recovery plan. An identity theft report proves to businesses that someone stole your identity. It also guarantees you certain rights.

File a report with your local police department. Tell the police someone stole your identity and that you need to file a report. Ask for a copy of the police report.

What to do next.

Close new accounts. Ask the fraud department of each business where an account was opened to close the account. Request a confirmation letter and keep a record of who you contacted and when.

Remove fraudulent charges from your accounts. Let the fraud department know which charges are fraudulent and ask that they be removed from your account. Request a confirmation letter and keep a record of who you contacted and when.

Correct your credit report. Write each of the three credit bureaus. Identify what information on your report came from identity theft and ask them to block that information. You have the right to block fraudulent information so that it won’t show up on your credit report and companies can’t try to collect the debt from you. If you have an Identity Theft Report, credit bureaus must honor your request to block this information.

Consider an extended fraud alert or credit freeze. Both can help prevent further misuse of your personal information, but there are important differences between the two. For example, an extended fraud alert allows access to your credit reports as long as steps are taken to verify your identity. A credit freeze stops all access until it’s removed. Though fraud alerts are free to place and remove, there may be small fees associated with credit freezes.

Protective measures to protect against identity theft are important, but they’re not always enough. However, there is insurance that is specifically designed to protect both individuals and businesses against identity thieves and hackers. For example, identity theft coverage can help individuals cover the cost of clearing their name. Cyber Liability and Security Breach (Cyber Perils) coverage can protect businesses against various cyber threats, including the cost of complying with data breach notice laws.

Please contact us if you would like more information about insurance specifically designed to protect against identity theft.

Additional information is also available in our weekly Risk Management Newsletters.

Risk Transfers: Indemnification and Additional Insured Status

Risk allocation involves identifying who is responsible for what and for how much. In some cases, a contract requires one party to assume the liability of another party. These risk transfers are commonly found in construction and landlord/tenant agreements, and are becoming common practice in other industries as well.

Assuming responsibility for the acts of another is obviously a big deal. So it’s important to know the nature and extent of the risk being assumed, and to have a plan to pay in the event of a loss. At a minimum, this requires an understanding of indemnification and Additional Insured status.

Indemnification

An indemnification provision requires one party (the indemnitor) to assume the liability of another party (the indemnitee). In the event of a loss that is specified in the contract, the indemnitor agrees to compensate the indemnitee for their loss. It is important to understand that these provisions commonly require the indemnitor to assume liability that would not otherwise exist.

For example, construction contracts routinely include broad indemnification provisions that transfer liability for not only bodily injury or property damage, but also for pollution, design flaws, delays, and other perils not typically understood or contemplated by the indemnitor. Therefore, the indemnitor must understand all the risks being assumed.

Additional Insured Status

Insurance coverage may be available to cover those risks assumed (or transferred) by the indemnification agreement, and indemnitors may purchase insurance to finance these risks. On the other hand, indemnitees often request or require their indemnitors to not only purchase insurance, but to also name them as an Additional Insured on the policy so they can have direct access to benefits under the indemnitor’s policy.

Though Additional Insured status can be used to finance indemnification obligations, it is important to know that there are limitations. For example,

  • Additional Insured status only protects against losses covered by the insurance policy, regardless of what the indemnification agreement requires.
  • Indemnitees must satisfy the policy’s requirements, such as meeting the definition of an Additional Insured and having a written contract.
  • An indemnitee’s protection may be compromised by shared coverage limits and a lack of control over the terms and conditions of an indemnitor’s policy.
  • Certificates of Insurance cannot be used to create or modify coverage under an insurance policy, regardless of what they say.

Perhaps the most common and potentially costly problem occurs when an indemnitor assumes a risk that is not covered by their insurance. For example, a plumber agrees to indemnify a general contractor for economic damages caused by the plumber’s delay in completing the work. The plumber takes a week longer than expected to finish the job. The general contractor hires additional workers to make up for the lost week and sends the bill for the extra labor to the plumber. Under the indemnification agreement, the plumber must pay for the extra workers. Unfortunately, since there was no bodily injury or property damage to trigger coverage under the plumber’s general liability insurance policy, the plumber must pay the cost himself. Remember that Additional Insured status cannot be used to cover indemnification obligations that are broader than the insurance coverage.

Before signing on the dotted line, ask the following questions:

  • What are the terms and implications of the indemnification provision?
  • Is the indemnitor required to obtain additional insured status for another?
  • Is the language of the additional insured endorsement adequate, covering the indemnitor’s responsibilities or must additional measures be taken to ensure that contractual obligations are properly financed?

Given their significance and complexity, these questions should be discussed with your insurance agent or attorney.

Please contact us if you would like to speak with one of our Risk Management Professionals.

You can also receive additional information by subscribing to our weekly Risk Management Newsletters.

Florida Workers’ Compensation Insurance Rates Increasing 14.5 Percent

In a previous article, we discussed the possibility that Florida employers may soon be paying substantially more for workers’ compensation insurance. Unfortunately, this possibility has become a reality.

On October 5, 2016, the Florida Office of Insurance Regulation (OIR) issued a final order approving an overall statewide workers’ compensation insurance rate level increase of 14.5 percent. This rate increase was prompted by the National Council on Compensation Insurance (NCCI), which is a licensed rating organization authorized to submit workers’ compensation insurance rate filings on behalf of Florida insurance companies.

On June 30, 2016, NCCI submitted an amended rate filing to the OIR requesting:

  • A 19.6 percent rate increase;
  • To be effective October 1, 2016;
  • For all new, renewal and outstanding policies.

After holding a public hearing and disapproving NCCI’s proposed rate increase, but conditionally approving a modified rate increase, the OIR finally approved:

  • A 14.5 percent rate increase;
  • That will be effective December 1, 2016;
  • For new and renewal policies (rates will not change for current in-force policies).

According to the OIR, this rate increase is justified by three recent legal developments that have affected Florida’s workers’ compensation system.

  1. The Castellanos Case. Attorney’s fees in workers’ compensation cases are governed by a statutory fee schedule. Under this mandatory schedule, attorney’s fees must be a fixed percentage of the workers’ compensation benefits secured on behalf of an injured worker. For example, attorney’s fees must equal 20 percent of the first $5,000 of benefits secured and 15 percent of the next $5,000.

On April 28, 2016, this statutory fee schedule was deemed unconstitutional by the Supreme Court of Florida. Without this statutory cap, attorneys may be entitled to collect more fees than before.

  1. The Westphal Case. On June 9, 2016, the 104-week statutory limitation on temporary total disability benefits was deemed unconstitutional by the Supreme Court of Florida. According to the Court, injured workers who have not yet reached maximum medical improvement before their 104 weeks of temporary total disability benefits end do not have a reasonable alternative to tort litigation.

This, the Court held, effectively denies these workers of their constitutional right of access to courts. As a result of the Court’s ruling, injured workers may now collect temporary total disability benefits for up to 260 weeks.

  1. Updated Health Care Provider Reimbursement Manual (HCPRM). The Florida Workers’ Compensation HCPRM sets out the policies, guidelines, codes and maximum reimbursement allowances for services and supplies furnished by health care providers under the workers’ compensation statutes. The most recently updated manual, which includes higher allowances, became effective July 1, 2016.

According to the OIR, the decision to approve an overall combined average statewide rate increase of 14.5 percent was made after a thorough review of NCCI’s rate filing and careful consideration of hundreds of public comments and testimony received from interested stakeholders. Since workers’ compensation insurance rates are set by the OIR, Florida employers affected by this decision will not be able to avoid the rate increase.

However, there are ways for employers to lower workers’ compensation insurance costs, such as promoting employee safety and maintaining a safe work environment.

Please contact us if you would like more information about controlling workers’ compensation insurance costs.

Additional information is also available in our weekly Risk Management Newsletters.