Office Holiday Parties: Revel without Regret

Many employers consider a company-wide holiday celebration an excellent opportunity for employees to mingle socially and get to know one another better. It’s also a chance for senior management to interact with employees they rarely see throughout the year. Though holiday parties can create a positive work environment, increase employee morale and promote teamwork, they can also expose employers to a number of potentially significant risks.

Perhaps the most significant risks involve alcohol. What happens if an employee becomes intoxicated and causes damage to something or someone? Though liability is determined on a case-by-case basis, employers may face a greater chance of being held responsible if:

  • Attendance is, or is perceived to be, mandatory (e.g., everybody knows that being seen by the Vice President will enhance one’s chances of a promotion);
  • The employer pays for or provides the alcohol; or
  • The employer conducts business during the holiday party.

Employers can take steps to reduce their potential liability, such as:

  • Collect car keys from all who drink. Toward the close of the party, assign designated drivers or call taxis for anyone who is too impaired to drive. If the party is in a hotel, reserve a block of rooms for the inebriated to spend the night.
  • Appoint someone in a position of authority to monitor alcohol consumption; including making certain that no alcohol is served to minors.
  • Serve a limited amount of alcohol, controlled through “drink coupons.” (i.e., two drinks per person). Close the bar once dinner begins.
  • Send a memo to all employees prior to the party stating clearly that a) employees who arrive inebriated will not be allowed in; b) employees cannot bring their own alcohol; c) excessive drinking will not be tolerated; and d) intoxication and inappropriate behavior at the party will be grounds for discipline.
  • Do not permit supervisors or managers to buy alcoholic beverages for employees.
  • Hold the party at an off-site location and use professional bartenders to serve and monitor alcohol consumption.

There are other risks employers should consider when planning and holding the annual office holiday party, such as:

Discrimination and Harassment: Lines are often blurred during an office party, so they are often crossed. Conduct that is inappropriate at work may be considered appropriate at a party, such as engaging in intimate conversations or acts, giving a racy gift or telling an off-color joke. Employers may be held liable for unlawful harassment or discrimination that takes place during a holiday party, even if it’s off-premises and off-the-clock. Consider redistribution of the sexual harassment policy, and remind employees that a holiday party is no excuse for inappropriate behavior, which will not be tolerated.

Premises Liability: Employees are often allowed to bring spouses and significant others to the office holiday party. Every ‘plus one’ accompanied by an employee is a potential slip-and-fall victim. Employers must make sure the workplace is safe before the party and keep it safe during the party.

Workers’ Compensation: Employees are typically covered by workers’ compensation if they are injured in the course and scope of their employment. Though getting hurt at a holiday party wouldn’t seem to be work-related, an employee may be covered by workers’ compensation if attendance at the party is explicitly or implicitly required (or ‘encouraged’). Tell employees the holiday party is purely a voluntary social event, and mean it.

Employers should review their insurance policies before the party to make sure they are covered in the event something happens during the holiday party. General liability, employment practices liability and workers’ compensation insurance may cover some of the risks created by the office holiday party. However, other risks may require additional insurance coverage, such as a policy that covers one-time events, including alcohol-related liability, which may be available for a small additional premium.

If you would like more information about how Setnor Byer Insurance & Risk can help protect your business during the holidays and year round, please contact us.

Preventing Data Security Breaches

Every business must be able to identify the likeliest source of a data security breach so that they can also identify how to prevent it. Is it an executive’s laptop computer, the copy machine or the office’s wireless network? Could it be something else? Since the first step to preventing a data security breach is understanding the risk, it’s time to learn more about your business’s sensitive data.

Effective data security starts by assessing the kind of information a business has and identifying who has access to it. Evaluating data security vulnerabilities requires an understanding of how sensitive data moves into, through, and out of a business, and who has or could have access to it. Here are some tips from the Federal Trade Commission.

Take Inventory

Take an inventory of all devices and equipment capable of storing sensitive data, such as laptop computers, mobile devices, flash drives, off-site servers, disks and digital copiers. Do employees work from home? If so, add their home computers to the list.

The type and location of sensitive data should also be inventoried. Don’t stop with the office’s filing cabinets and computer systems. Sensitive data may also be received from other sources, such as websites, contractors or call centers. Every possible source and destination for sensitive data must be considered.

Track Sensitive Data

It is important to know how the business obtains, stores, shares and disposes of sensitive data. Every department should be consulted, including sales, information technology, human resources and accounting. Don’t forget about contractors and other third-party service providers.

This process should provide a business with a thorough understanding of:

  • Who provides sen­sitive data? Does it come from customers, credit card companies, banks or other financial institutions, credit bureaus, job applicants, contractors, third-party service providers?
  • How is sensitive data received? Does it come via phone, fax, mail or email? Is there a website designed to request and receive sensitive data? Are there any other possible entry points?
  • What kind of sensitive data is collected? Do business operations require or permit collecting financial information (credit cards, bank accounts, credit reports), personally identifying information (drivers’ licenses, social security numbers) or medical information?
  • Where is sensitive data stored? Is it kept on disks, tapes, laptops, smartphones, tablets or other mobile devices? Employees’ personal computers or mobile devices? Where are data backups and copies stored?
  • Who can access sensitive data? Is access to sensitive data limited to only those who need it? Are there security measures in place? Is sensitive data protected against unauthorized access by contractors or other third-party service providers?

Throughout this process, pay particular attention to certain kinds of sensitive data. Identity thieves typically look for social security numbers, credit card and other financial information.

Organizations should also consider protecting against data security breaches with insurance.Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to subscribe to our newsletters please click here.

Finding Safe Harbor from the Employer Mandate

Under the Affordable Care Act’s Employer Shared Responsibility provisions, “large” employers with at least 50 full-time equivalent employees may be subject to an annual $2,000 or $3,000 penalty (tax) per qualifying employee. An employer may avoid the penalty by offering health coverage to at least 95% of its full-time employees (and dependents) under an “affordable” plan that provides “minimum value.”

A plan will generally satisfy the “minimum value” requirement if it covers at least 60% of health care costs. To be considered “affordable,” the employee’s required contribution for employee-only coverage cannot be more than 9.5% of the employee’s household income for the taxable year.

In the context of determining whether a plan satisfies the affordability requirement, the Internal Revenue Service recognized the likely inability of employers to ascertain the household income for each of its employees. As a result, the proposed regulations recently published by the IRS allow employers to take advantage of three safe harbor provisions.

Form W-2 Safe Harbor

Application of the Form W-2 Safe Harbor, which is determined after the calendar year on an employee-by-employee basis, takes into account the employee’s Form W-2 wages and the employee contribution.

An employer will not be assessed a penalty for an employee if the required annual contribution for the employer’s cheapest employee-only coverage plan is not more than 9.5% of that employee’s Form W-2 wages from the employer. If an employee is not offered coverage for an entire calendar year, the Form W-2 wages can be adjusted to reflect the period for which coverage was offered.

To avoid manipulation, the proposed regulations provide that the employee’s required contribution must remain consistent during the calendar year and that an employer cannot make discretionary adjustments to the required employee contribution for a pay period.

Rate of Pay Safe Harbor

Under the Rate of Pay Safe Harbor, an employer:

  • takes the rate of pay for each hourly employee who is eligible for coverage under the plan as of the beginning of the plan year; and
  • multiplies that rate by 130 hours (the benchmark for monthly full-time status) to compute the employee’s monthly wages.

If the employee’s monthly contribution amount for the cheapest employee-only coverage plan is not more than 9.5 percent of the computed monthly wages, then the coverage is considered affordable. For salaried employees, the monthly salary would be used to determine affordability.

The Rate of Pay Safe Harbor allows employers to prospectively determine affordability without having to analyze every employee’s wages and hours. However, it may only be used for those employees who did not have their hourly wages or monthly salaries reduced by the employer during the year.

Federal Poverty Line Safe Harbor

Under the Federal Poverty Line (FPL) Safe Harbor, coverage is considered affordable if the employee’s cost for the cheapest employee-only coverage plan is not more than 9.5% of the FPL for a single individual. Under the regulations, employers may use the most recently published poverty guidelines for the first day of the plan year.

These safe harbors are optional. Large employers may use one or more of these for all employees or for any reasonable category of employees, provided they are used uniformly and consistently for all employees in a category.

The IRS will be accepting comments on these proposed regulations until March 18, 2013.

At Setnor Byer Insurance & Risk, we are committed to guiding you through what is sure to be a bumpy ride. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Your Business from Cyber Liability Risks

Almost every business relies on computers, networks and electronic data to support their business operations and serve their customers. What most business owners don’t realize is the substantial exposure associated with their use of electronic platforms and the data those platforms host. Today, Cyber Liability insurance is available to business owners for the exposures associated with their use of electronic platforms.

Most businesses are not aware that standard Commercial General Liability policies do not contemplate these types of claims, leaving companies with significant gaps in coverage for cyber-related perils. Any business that collects or handles confidential information, stores client data, uses email, generates revenue online, relies on the internet for transactions or uses a network to conduct its business is in need of this important coverage.

Cyber Liability insurance is designed to protect the insured against direct and indirect loss to the Company’s assets as well as third party claims of negligence. Losses can be caused by hazards such as the transmission of virus/malicious code, denial of service attacks, physical theft of a computer/device, accidental release of an insured’s confidential data and attacks by hackers. First party coverage under the Cyber Perils policy includes:

  • Loss of data
  • Loss of business income
  • Electronic theft
  • Cyber extortion
  • Security event costs

Third party claims of negligence can include allegations that an insured:

  • Permitted the unauthorized disclosure of confidential information
  • Failed to secure a Network against attack
  • Committed an act of defamation

Of particular interest to many businesses are data breach security concerns. Recent studies have shown that over 70 percent of all data security breaches are experienced by small to medium sized businesses and the cost of a breach can be staggering. The average cost for a data breach claim is over two million dollars. These damages include the cost of data reconstruction, customer/client notification and credit monitoring. This leaves small businesses most at risk because they are unlikely to have the time and resources necessary to handle a data breach security event.

Given the variety and complexity of these occurrences, an experienced insurance agent should be consulted to ensure that proper coverage is obtained and that no gaps remain. If you would like to learn more about insuring against data security breaches, contact us.

Florida’s New-Look Self-Storage Facility Act: Are You Ready?

In April 27, 2012, a bill amending Florida’s Self-Storage Facility Act (Act) was signed into law by Governor Rick Scott. The bill primarily implements changes to the notice requirements related to enforcing an owner’s lien against items stored in a self storage facility. According to the Self Storage Association, these changes could save Florida’s self storage industry more than $4 million annually.

Additionally, the bill provides that applications and rental agreements must include a provision disclosing whether an applicant is a member of the uniformed services. Consistent with the protection afforded some military personnel by the Servicemembers Civil Relief Act (SCRA), this new requirement is intended to help servicemembers avoid foreclosure of their stored property during a period of military service.

The bill, which becomes effective July 1, 2012:

  • Expands the definition of last known address to include the street address, post office box, or e-mail address provided by the tenant in a rental agreement or in a subsequent written change of address notice;
  • Deletes a provision which may have required a tenant to provide a new address to an owner by certified mail;
  • Removes the requirement that a tenant be notified of the owner’s claim by certified mail, and allows written notice of a pending sale of property to be delivered in person, by e-mail, or by first-class mail along with a certificate of mailing;
  • Provides that if the owner notifies the tenant by e-mail, a response, return receipt, or delivery confirmation from the tenant’s last known e-mail address is required for the notice to be effective; otherwise, the owner must send notice of the sale to the tenant’s last known address by first-class mail along with a certificate of mailing, before proceeding with the sale;
  • Deletes a requirement that a notice sent by mail must be “registered” in order for the notice to be presumed delivered when deposited with the U.S. Postal Service, thereby making any notice sent by mail, registered or not, is presumed delivered when deposited with the U.S. Postal Service;
  • Removes a reference to certified mail, thereby permitting an owner to notify the tenant or secured lienholders of any balance remaining from the proceeds of a sale of property by first-class mail along with a certificate of mailing; and
  • Requires contract rental agreements or applications for a rental agreement to contain a provision disclosing whether the applicant is a member of the uniformed services.

To take advantage of these revisions, owners and operators of self storage facilities should make every effort to obtain each tenant’s email address. Importantly, procedures should be implemented to ensure tenants’ email addresses are kept current. Those failing to do so will be unable to enjoy the benefits provided under the amended law.

Regardless of whether a self storage facility takes advantage of the new notice procedures, the new requirement for determining a tenant’s military status cannot be ignored. Far too many self storage facilities fail to determine whether a tenant is in the military service, and, consequently, they do not know whether the SCRA applies to any particular tenants.

Ignorance in this respect will inevitably result in violations of the SCRA, which can prove costly and embarrassing. Though some may find determining military status burdensome, in reality, this new requirement will benefit self storage facilities as much as their military tenants.

Oftentimes, there is a period of uncertainty following the enactment of a new law because many are unsure of precisely what is now required or permitted. Fortunately, the changes to the Act are fairly straightforward, so extensive confusion is not anticipated. Nevertheless, those who own or operate a self storage facility in Florida would be wise to seek advice if there are any doubts as to how the new law will affect their operation.

Setnor Byer Insurance & Risk’s Self-Storage Insurance Program and Risk Management Group work closely with self-storage facilities throughout Florida and nationwide to profile risks, compare coverage options, and match our clients with an insurance program that meets their needs.

If you have any questions about the amendments to Florida’s Self-Storage Facility Act, or if you would like discuss how our programs can help you, please contact us.

Controlling Slip-and-Fall Liability: Tips for Self-Storage Facility Operators

Self-storage operators are not immune to slip-and-fall liability. While the volume of foot traffic at a self-storage facility may not reach that of other types of businesses, customers must still enter the premises to store, access and retrieve their property. As a result, an exposure to this type of liability exists, and facility operators must take this risk seriously.

Slips and falls are typically caused by transitory foreign substances, meaning any liquid or solid substance or object that doesn’t belong on the floor. Many believe the hazards caused by these items are more likely to occur in restaurants or grocery stores where spilled foods or beverages create dangerous conditions. However, the likelihood of transitory foreign substances shouldn’t be overlooked in a self-storage setting where customers store and move various items that, if not properly cleaned, can create a dangerous condition in the common areas. Consider these scenarios:

  • A tenant spills an oily substance on the floor when moving automotive parts out of his unit; another tenant then slips on that spot and falls, hurting his back.
  • A tenant’s friend slips in a puddle of water that accumulated in the common area when another tenant propped a door open during a rainstorm and forgot to close it upon leaving.

In light of this risk, self-storage operators must know their duties under the law with regard to protecting those on their premises from hazardous conditions, as well as protecting their business against any potential lawsuits.

Follow the Law

Slip-and-fall cases are traditionally based on the principle that a business owner invites others to enter the premises for the purpose of conducting business with him. Legally speaking, this person is considered an invitee and, under common law, a business owner owes a legal duty to protect him from hazardous conditions.

The general duty can be restated in the following manner: A possessor of land (in this case, a self-storage operator) is subject to liability for physical harm caused to his invitees (tenants and visitors) by a condition on the land only if:

  • He knows or by the exercise of reasonable care would discover the condition, and should realize that it involves an unreasonable risk to such invitees.
  • He should expect that they will not discover or realize the danger, or will fail to protect themselves against it.

It’s important to note each state’s common law may have its own peculiarities with respect to defining the precise duty owed by the business owner. Additionally, some state statutes may modify not only respective duties, but methods of proving slip-and-fall cases in court.

For example, a new Florida statute provides that it’s the claimant’s obligation to prove the property owner had knowledge of the hazardous condition. This statute was enacted to legislatively overrule a Florida Supreme Court case that essentially gave claimants the benefit of a rebuttable presumption. As a result, in such jurisdictions, self-storage facilities are no longer on the hot seat in terms of overcoming negative presumptions.

In the context of a transitory foreign substance, such as leaked oil or a puddle of water that has not been cleaned up properly, it’s fair to assume that, in many cases, the substance will create an unreasonable risk to individuals who would not discover it unless brought to their attention, thereby typically satisfying the second element. Similarly, if the self-storage facility failed to clean up the slippery substance, or otherwise failed to warn tenants and visitors of the dangerous condition despite knowing of its existence, it’s fair to say the third element would also be satisfied.

That leaves the first element: Whether the self-storage operator knows of, or by the exercise of reasonable care would discover, the dangerous condition. Although proving knowledge of a hazardous condition can be problematic in some cases, the stickiest issue is usually the determination of whether the self-storage operator should have discovered the dangerous condition before it caused injury to a tenant or visitor. This issue implicates the duty to inspect the premises, which generally requires the business owner to exercise reasonable care to discover dangerous conditions.

Unfortunately, reasonable care is not a fixed concept with defined characteristics. Precisely what’s considered reasonable in any given situation depends on the circumstances, so that behavior constituting reasonable care in one case may be considered negligent in another. It’s this dependence on external factors that precludes a universal, one-size-fits-all approach to meeting one’s duty to exercise reasonable care.

Be Proactive

In the absence of clear-cut standards of behavior, what can a self-storage operator do to defend against slip-and-fall liability? In the context of discovering a hazardous transitory foreign substance, he may exercise reasonable care by inspecting the premises to identify and remedy any dangerous conditions. However, the extent to which the premises must be inspected depends on the particular facts and circumstances.

For example, reasonable care demands more frequent inspections of the common areas during periods of elevated activity. Similarly, areas within the facility that experience increased traffic, such as the office, should also receive increased scrutiny.

There are also other factors that may help define the extent to which the premises must be inspected. Is there a tenant with a history of handling slippery substances or not cleaning up after himself? Is there a particular time of day or year when the facility is more likely to be left in disarray? Is there an area that accumulates water or other transitory foreign substances? Answering these questions could reveal previously unidentified risks.

After considering conditions unique to your facility, including any relevant history and experience, you can make some conclusions on what’s reasonable. For example, would a jury agree it was reasonable to inspect the common areas, such as the office or parking lot, twice a day or twice a month? Was it reasonable to conclude that an area with a history of flooding did not require additional inspections after a rainstorm? Was it reasonable to not require additional inspections of the area next to units occupied by tenants who routinely work on their cars?

While undertaking this secondary level of analysis will not guarantee protection against slip-and-fall liability, it can assist in the development of inspection-related policies and procedures geared toward protecting tenants and guests from any hazardous conditions which should’ve been discovered by exercising reasonable care.

Finally, once you have inspection-related policies and procedures in place, including those recommended by your attorney or required by applicable law, you need to communicate them to your staff. Supervisors must remain attentive to ensure the policies and procedures are strictly followed and documented. Employees should know their failure to follow these policies and procedures could result in disciplinary action.

Though often overlooked, self-storage facilities have a duty to exercise reasonable care to discover dangerous conditions before an injury occurs. It’s in precisely this circumstance that many operators find they’ve failed in their duty and, consequently, land in a courtroom. Those who fail to understand and adhere to this duty before a slip-and-fall occurs, may have to endure the unfortunate experience of having a jury decide what was overlooked afterward.

Converting a Safe Workplace into Lower Workers’ Compensation Insurance Premiums

In many states, including Florida, workers’ compensation insurance rates are set by the state, which means that regardless of which insurance company ultimately provides the insurance, the rates remain the same. Therefore, unlike with other types of insurance, consumers are limited in their ability to go bargain shopping for workers’ compensation insurance. However, this lack of bargaining power does not necessarily mean that employers are powerless to reduce their premiums. There is one way employers can lower the cost of their workers’ compensation insurance: maintain a safe working environment.

Workers’ compensation insurance provides indemnity and medical benefits to employees who are injured on the job. Each time an employee files a workers’ compensation claim, the insurance company must make a payment on the claim. Needless to say, insurance companies prefer insuring safe, or safer, workplaces because there are presumably fewer claims to pay, thereby increasing the company’s profits.

Thus, in an effort to encourage employers to maintain a safe working environment and to reward those that successfully do so, experience modification ratings are used to adjust an employer’s workers’ compensation premiums. Those employers who experience fewer or no claims are rewarded with a credit toward their premiums, while those employers who experience a higher number of claims may face increased premiums.

Determining an employer’s experience modification rating, or experience mod, involves fairly detailed and complex calculations which are designed to tailor the final premium cost to the employer’s actual claims experience. In short, the experience mod compares an employer’s actual workers’ compensation claims experience, typically over a three year period, with that of other employers operating in the same type of business with a similar number of employees.

If an employer’s claims experience is consistent with the industry average, then the experience mod is 1.0, which when multiplied by the base premium, will not serve to increase or decrease the premium. However, if an employer’s claims experience is 25% better than the industry average, then the experience mod will be .75, which when multiplied by the base premium, will decrease the premium by 25%. Alternatively, if an employer’s experience is 25% worse than the industry average, then the experience mod will be 1.25, which will operate to increase the premium by 25%. Therefore, by maintaining a safe workplace, employers can significantly reduce their workers’ compensation premiums.

In addition to having this basic understanding of the experience modification rating process, it is helpful to know some of the features of the rating process so an employer can tailor its safety and loss control procedures to maximize the benefits afforded by the experience mod.

For example, since the cost of a specific workplace injury is statistically less predictable than the likelihood of an occurrence of an injury, the experience mod places greater weight to accident frequency than it does to accident severity. In other words, an employer having one loss totaling $100,000 compared to an employer having 10 losses totaling $100,000 will have a better experience mod. This is because the employer suffering one loss is seen as the more stable risk. And, given the unpredictability of the total cost of an injury, the experience mod calculation takes into consideration the possibility that any single injury could have astronomical costs, thereby making a higher frequency of claims a greater risk than a single, expensive claim. Since a workplace with a higher frequency of claims involves a greater risk, the experience mod will operate to make the premiums higher.

Employers should also know that medical-only claims do not have as much of an impact on the experience modification as do indemnity claims. Since the calculation reduces the value of medical-only claims by 70%, employers are not necessarily penalized when they occur. Moreover, the existence of open claims, or claims that have not yet been resolved, can negatively impact the experience mod, so employers benefit from getting claims resolved and closed.

In addition to adjusting an employer’s experience mod, some insurance companies may reward employers by offering payments, typically called dividends, to insureds that eliminate or otherwise limit the number of claims filed by their employees. These dividends, which are generally reserved for the most attractive risks, are usually based on a sliding scale wherein the amount of the dividend decreases as the number of claims increases. However, it is important not to get too caught up in the most generous dividend percentage. For example, if an employer has a history of at least four workplace injuries per year, then it is unrealistic to focus on the dividend percentage that is available only to those insureds experiencing no injuries. The best approach is to compare dividend percentages that comport with an employer’s specific claims history.

Understanding all the aspects of the workers’ compensation experience modification rating system, including the manner in which it can be addressed to achieve the maximum benefit, can be overwhelming. That is why it is important to utilize the services of an insurance agent who is familiar with not only the ins-and-outs of the experience mod rating system, and available dividend plans, but who can also provide information regarding loss control and workplace safety.

Despite the lack of competitive premiums in some states, maintaining a safe work environment remains the best way to reduce the cost of workers’ compensation insurance. By understanding the nature of the workplace, including procedures which may be incorporated to reduce the number of claims, the right insurance agent can work with the insurance company to ensure claims are treated appropriately in order to take advantage of the benefits afforded by the experience modification rating system.

If you would like more information about obtaining workers’ compensation insurance for your organization, contact us.

Did You Know? Employee Dishonesty

Did you know that eight out of ten crimes against businesses are carried out by employees? Workplace fraud and employee theft are more prevalent than ever: It is estimated that the average American business loses six percent of its total annual revenues due to some form of employee fraud. Small businesses are particularly vulnerable to occupational fraud and abuse because they usually cannot afford extensive safeguards against these risks, nor can small firms easily absorb the large losses to which employee fraud and theft can lead.

Most business owners prefer to think of their employees as loyal, trustworthy and honest, and are unwilling to accept the reality that those whom they regard as “family” might be stealing from them. But there are many reasons why an employee may be tempted to defraud an employer, not the least of which is financial pressure on the employee. Also, a dishonest employee may attempt to rationalize a crime with such excuses as “The company will never miss this money” or “This isn’t really stealing because I’m not being compensated as I deserve.”

Typically, losses attributable to employee fraud can range from relatively small, one-time thefts to long-term schemes that go undetected for years. Statistics indicate that the average length of time that an employee fraud goes undetected is eighteen months, during which time an employer can lose enormous sums of money. That’s why early detection of employee fraud is vital. To protect against this ever-present risk, companies would be wise to establish loss prevention programs that include training in fraud prevention and detection for all managers.

Additionally, sound controls must be in place to prevent employee fraud, with thorough reviews of these loss control practices occurring regularly.

But no loss prevention program is foolproof, which is why all companies ought to obtain separate employee dishonesty insurance coverage. Under virtually all commercial property policies, employee dishonesty coverage, also known as employee theft coverage, is a standard exclusion. But employee dishonesty insurance is specifically designed to protect an employer from financial loss due to the fraudulent activities of an employee or group of employees, including such employee-driven crimes as embezzlement and internal theft. No business owner wants to believe that employee dishonesty insurance is necessary, yet without such coverage, a business is severely exposed to potentially devastating losses. That’s why no business insurance program is complete without appropriate employee theft coverage.

To learn more about how you can protect your business from employee dishonesty, contact us.

The Downside and Economic Risk of Email, Web and Other Digital Communications

The ease with which a brick and mortar business can transform into an e-commerce operation, at least to some degree, can be startling. What was once accomplished face-to-face is now done virtually. What was once kept in a filing cabinet is now stored on electronic databases. Pens and stamps have been replaced by PINs and clicks. In the blink of an eye, even those who swore they would never do business in the cyber-world are now making considerable efforts to expand their business by establishing a virtual presence.

Even those who do not consider their business to be a typical online operation are finding that more and more of their processes are being done electronically. Those who would readily dismiss the suggestion that their operation is technology-based routinely rely on the Internet, email, computers, networks, databases, online storefronts, and even their own websites to conduct and expand their business.

Since such a transformation in business practices often leads to new liability and damage exposures that were previously nonexistent, it is not uncommon for businesses to find that they have outgrown their insurance coverage. This is understandable since those charged with managing risk typically focus on the traditional exposures ordinarily covered by an organization’s general property and liability insurance policies. Unfortunately, in the context of risks associated with the use of technology in commerce, these policies do not offer the protection required to keep pace with developing business practices.

The risks associated with the use of technology in commerce can be significant, and if they are not properly mitigated and insured against, the consequences may be devastating. Thus, it is important for every business to conduct an audit of potential risk exposures stemming from the use of technology.

A business may be exposed to unique risks if it:

  • Generates revenue online;
  • Advertises online;
  • Maintains a website;
  • Deals with clients, customers, suppliers, partners, etc, online;
  • Relies on computers and networks to conduct business;
  • Stores and uses valuable or confidential personal information on internal or external networks or servers;
  • Outfits its sales or support staff with portable devices, such as laptops or PDA’s; or
  • Uses a computer network to control production, inventory, delivery, etc.

Perhaps the most surprising part of this list is that an operation does not need to conform to the stereotypical dot.com image in order to be exposed to traditional dot.com-like risks. The nearly universal integration of technology into the business world means that virtually every organization faces at least some technology-based exposures.

These exposures can be broadly categorized as first-party and third-party risks. First-party risks include liabilities involving data recovery, business income, denial of service, virus or hacker sabotage, and theft of system resources. Third-party risks include liabilities involving theft or disclosure of data, damage or loss to someone else’s data, media liability for website content, privacy liability, network security, malicious sabotage, malicious virus, and administrative errors.

If one of these risks comes to pass, it can be extremely expensive. For example, many states, including Florida, New York, and California have enacted laws requiring businesses to notify their customers in the event of a breach of security involving computerized personal information, such as names, social security numbers, driver’s license numbers, and account or credit card numbers. A business that stores such information electronically is at risk of having to comply with these statutes even if the business has absolutely no online retail components. The loss of a salesperson’s laptop computer containing such information may require a business to initiate the required notice protocols, the expense of which may be debilitating.

While businesses can take steps to minimize exposures, it is unlikely that any efforts will operate to completely insulate an organization from the possibility of loss. Therefore, businesses should obtain insurance that is specially designed to meet specific operations and risks. There are many insurance products which can be tailored to match exposures to coverages. Given the scope of the risk exposure, good business judgment demands that an organization look into updating their insurance coverage to cover all of their risks, not just the traditional ones.

If you would like to learn more about how we can help you obtain the necessary insurance to cover your business, please contact us.

Is Crime On Your Menu? If So, Take It Off

You’ve often heard that crime doesn’t pay, but you should be aware that it can be quite costly when it occurs at your place of business.

According to the Federal Bureau of Investigation, approximately 1.5 million violent crimes occurred in the United States in 2007. Usually, it is the criminal justice system that metes out punishment to perpetrators, most often in the form of incarceration; occasionally, however, a victim may file a civil lawsuit to recover money damages from a perpetrator. In any event, it might seem that violent crimes generally involve only victims and assailants.

But that is not necessarily so. The dynamic may be significantly altered if the crime takes place on the premises of a food service establishment. Why? Because food service establishments, as possessors of land, owe a duty to their patrons to protect them from hazardous conditions, including the risk of suffering a criminal attack, on their premises. In fact, under certain circumstances, a food service establishment may be held liable to a victim of a crime that occurs at their establishment if it is determined that the establishment has failed to protect victims from perpetrator[s].

Notwithstanding jurisdictional variations, it is generally the case that a possessor of land who holds it open to the public for a business purpose may be held liable to those members of the public for physical harm that is caused by a third person’s intentional, harmful act when that act takes place while individuals are upon the land for a business purpose. In other words, a food service establishment may be held liable for harm that is inflicted on patrons during a crime that takes place on the establishment’s premises.

An establishment’s liability could be triggered when a patron suffers physical harm during a crime if the harm is caused by the failure of the food service establishment to exercise reasonable care:

  • To discover that such harmful acts are being done or are likely to be done; or
  • To give a warning adequate to enable the patrons to avoid the harm, or otherwise to protect them from it.

In interpreting this duty, courts have noted that since a possessor of land is not necessarily an insurer of its patrons’ safety, the possessor of land is ordinarily under no duty to exercise any care until it knows or has reason to know that the criminal acts of a third person are occurring or are about to occur. In other words, a possessor of land has a duty to take reasonable precautions to protect patrons from foreseeable criminal attacks. Whether or not a criminal attack is foreseeable often turns on the frequency with which crimes have occurred at an establishment.

One method of establishing foreseeability is to prove that the possessor of land had actual or constructive knowledge of a particular assailant’s inclination toward violence. Another method is to prove that the possessor had actual or constructive knowledge of a dangerous condition on the premises that was likely to cause harm to a patron. If the place or character of the business, or its experience with crime on the premises, is such that the establishment should reasonably anticipate criminal conduct on the part of third persons, either generally or at some particular time, the establishment may be under a duty to take precautions against it, and to provide reasonably sufficient personnel to afford reasonable protection to patrons. Simply put, if a criminal attack on a patron is foreseeable, then the food service establishment has a duty to protect its patrons.

It is also important to note that this duty to protect has often been extended to ensuring the safety of the parking area and to providing a safe and suitable means of ingress and egress. In appropriate circumstances, this duty may require the implementation of safety and security measures that include employing on-site security personnel, installing video surveillance equipment, and erecting a fence to protect the parking and the entrance areas. Whether an establishment’s protective measures are deemed “reasonable” will depend to a significant degree on the circumstances.

The statistics prove that anyone can be a victim of crime. Nevertheless, people often believe that it happens only to someone else. While this perception may provide some level of comfort as you go about your everyday life, such thinking does not reflect sound business judgment. In the event you fail to do everything in your power to mitigate patrons’ risk of being victims of crime on your premises, you may find that you have also been the victim of a crime – even though it really did happen to someone else.