Every Business Should be Worried about Cyber Liability

Regardless of industry, cyber attacks and data breaches expose businesses to potentially enormous losses and liabilities. According to a report by the Insurance Information Institute (III), the potential economic fallout from the cyber threat cannot be underestimated, particularly because the number of publicly disclosed data breaches soared from 449 in 2012 to 614 in 2013. This is likely why cyber risk cracked the top 10 list of global business risks in 2014.

According to the III report:

  • The majority of data breaches affected the medical/healthcare industry (43.8%) and business organizations (34.4%).
  • Business organizations accounted for the majority of records exposed by data breaches in 2013 (84%).
  • A report by PWC found that cyber crimes are considered a high-level threat.
  • Cyber attacks have become more frequent and increasingly costly for companies to resolve.
  • The average annualized cost of cyber crime is estimated to be $11.6 million per year.
  • Denial of service is the costliest cyber crime, followed by malicious insiders and web-based attacks.
  • The average time to resolve a cyber attack is 32 days, with an average cost of just over $1 million during this 32-day period.
  • Malicious or criminal attacks, such as malware infections, criminal insiders, phishing/social engineering and SQL injections, cause 42% of data breaches, followed by human error (30%) and system glitches (29%).
  • U.S. organizations have the highest lost business costs at an average of $3.3 million.
  • Businesses may be exposed to even greater risks from new technologies, such as cloud computing, which uses a network of remote servers over the Internet to store, manage and process data, rather than a local server.

The III report notes that upon experiencing a data breach, many businesses turn to their insurance policies to cover their loss. Unfortunately, many of these losses are not covered by traditional insurance policies. To protect against cyber threats, businesses need specific cyber insurance policies that provide a number of specialized coverages, such as:

  • Loss/corruption of data
  • Business income/interruption
  • Liability coverage (first- and third-party coverage)
  • Data breach coverage (including costs of complying with statutory notice requirements)
  • Cyber extortion
  • Crisis management
  • Identity theft

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Affordable Care Act Implementation in 2014

As 2013 comes to an end, many are making plans and resolutions for the New Year. 2014 is also a big year for the Affordable Care Act, as many of the Act’s provisions go into effect, such as:

Individual Mandate. Under the Act, most individuals who can afford basic health coverage will be required to obtain such coverage or pay a penalty to help offset the costs of caring for uninsured Americans. Various exemptions to the individual mandate are available, including one if affordable coverage is not available.

Employer Mandate. Beginning in 2014, large employers who failed to offer qualifying health care coverage to their employees may have been required to pay a penalty (tax). However, enforcement of this provision has been postponed from January 1, 2014 to January 1, 2015.

Health Insurance Marketplace (Exchanges). Starting in 2014, individuals and small businesses can shop for and buy qualified health benefit plans on the Health Insurance Exchanges. These new marketplaces are designed to offer consumers with various options for health plans that meet certain benefits and cost standards.

Essential Health Benefits. The Act creates essential health benefits packages that provide coverage for specific services. These packages are separated into four categories that vary based on the proportion of plan benefits they cover.

Elimination of Annual Coverage Limits. The Affordable Care Act prohibits new plans and existing group plans from imposing annual dollar limits on the amount of coverage an individual may receive.

Ban on Discrimination Due to Pre-Existing Conditions or Gender. In 2014, insurance companies cannot refuse to sell coverage or renew policies because of an individual’s pre-existing conditions. Also, in the individual and small group market, the law eliminates the ability of insurance companies to charge higher rates due to gender or health status.

Protection for Clinical Trials. Insurers will be prohibited from dropping or limiting coverage because an individual chooses to participate in a clinical trial. This protection applies to clinical trials that treat cancer or other life-threatening diseases.

Increasing Small Business Tax Credit. The Affordable Care Act’s second phase of the small business tax credit for qualified small businesses and small non-profit organizations starts in 2014. The credit is up to 50% of the employer’s contribution to provide health insurance for employees. There is also up to a 35% credit for small non-profit organizations.

Individual Tax Credits. Starting in 2014, tax credits will become available for people with income between 100% and 400% of the poverty line who are not eligible for other affordable coverage. The tax credit can be advanced, so it can lower premium payments each month. It’s also refundable, so moderate-income families can receive the full benefit of the credit. Individuals may also qualify for reduced cost-sharing (copayments, co-insurance, and deductibles).

Access to Medicaid. Americans who earn less than 133% of the poverty level (approximately $14,000 for an individual and $29,000 for a family of four) will be eligible to enroll in Medicaid. States may receive 100% federal funding for the first three years to support this expanded coverage, phasing to 90% federal funding in subsequent years.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you would like to subscribe to our newsletters please click here.

Learn more about our Affordable Care Act Program.

Shopping for Insurance: Quality versus Cost

People typically purchase insurance because they have to, not because they want to. For the most part, consumers are happy to obtain the minimum required insurance coverage at the lowest price they can find. That is, until a claim comes along. Only then do they discover that buying the cheapest insurance available wasn’t such a bargain after all.

The quality versus cost argument is nothing new especially when it comes to insurance. Consumers who pay less tend to get less, whether in the form of coverages, limits or financial security. And, when people choose cost over quality, it usually means they are uninformed about what they really need.

As a full-service independent insurance agency, it is our job to help our clients understand their insurance needs. We evaluate, compare and quote various options from multiple insurance companies so that our clients have the right information before making a decision. Though many still choose cost over quality, it is important that they understand what they may be sacrificing.

Low Premiums

Would you rather have automobile insurance that protects you from damage caused by someone who is uninsured or underinsured? Uninsured Motorist Coverage is commonly excluded from a policy to reduce the premium. Rejecting GAP coverage or electing non-stacked coverage are other ways to save money. But these choices come with a risk. When shopping for insurance it’s better to determine what coverage is desired, see how much that coverage would cost, and work with an independent insurance agent to help get the coverage you need at a cost you can afford.

Financial Stability

Although cost is important, the financial strength of an insurance company may be more important. Financially weak insurance companies are more likely to become insolvent or go bankrupt, which means that their policyholders are less likely to get their claims paid. Though purchasing insurance from a financially weak company may be cheaper, how valuable is the money saved on premium if there is no money to pay a claim? An independent insurance agent can help you evaluate the financial stability of the insurance companies you are considering.

Customer Service

Insurance companies don’t typically assign an agent to their customers. Each time you call you speak to a different person which means you have to explain your situation over and over. Look for an agent that offers personalized service. Those are the agents who are willing to go the extra mile to get you what you need. For example, at Setnor Byer Insurance & Risk, our commercial clients enjoy complimentary access to our risk management services to help them manage the risks associated with owning a business.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like more information about our insurance products, please contact us.

If you would like to subscribe to our newsletters please click here.

Getting Rid of Consumer Report Information with the Disposal Rule

Businesses commonly use consumer reports when deciding whether to make a job offer or extend a line of credit. In the wrong hands, consumer reports may also be used to commit fraud and identity theft. This is why the Federal Trade Commission (FTC) enacted the Disposal Rule.

The authority for the Disposal Rule comes from the Fair and Accurate Credit Transactions Act (FACTA), which requires proper disposal methods by those who use consumer information from consumer reports for business purposes. As required by FACTA, the FTC’s Disposal Rule requires the use of reasonable disposal measures to protect against unauthorized access to or use of consumer information. Individuals and businesses of any size that use consumer reports for business purposes must comply with this rule

The Disposal Rule applies to consumer reports or information that comes from consumer reports. Under the Fair Credit Reporting Act, consumer reports include information obtained from a consumer reporting company that is used or expected to be used for various reasons, such as establishing a consumer’s eligibility for credit, employment or insurance. Credit reports and credit scores are consumer reports. Reports with information relating to employment, check writing history, insurance claims, residential or tenant history and medical history are also consumer reports.

The Disposal Rule, which simply requires reasonable disposal measures to prevent unauthorized access to or use of consumer information, is designed to be flexible. The rule allows organizations and individuals to determine what measures are reasonable by considering the sensitivity of the information, the costs and benefits of different disposal methods and changes in technology.

Under the rule, reasonable measures may include:

  • burning, pulverizing or shredding of papers containing consumer information so that the information cannot practicably be read or reconstructed.
  • destroying or erasing electronic media containing consumer information so that the information cannot practicably be read or reconstructed.
  • after due diligence, hiring a third party to properly dispose the consumer information. Due diligence could include reviewing an independent audit of the disposal company’s operations and/or its compliance with this rule, checking references, requiring certification by a recognized trade association or taking other appropriate measures to determine the competency and integrity of the disposal company.

According to the FTC, these examples are illustrative only and are not exclusive or exhaustive methods for complying with the Disposal Rule.

The Disposal Rule is but one aspect of protecting against a data security breach. Organizational protective measures should cover everything from the wireless network to the copy machine, and should also include insurance.

Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given their complexity, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Final Rules Issued for Mental Health Parity and Addiction Equity Act

The Departments of Labor, Health and Human Services and the Treasury issued final rules implementing the Paul Wellstone and Pete Domenici Mental Health Parity and Addiction Equity Act of 2008 (Act). Though interim final rules implementing the Act were published and became effective in 2010, these final rules will become effective 60 days after their November 13, 2013 publication date.

Under the Act, group health plans and group and individual health insurance coverage are required to treat mental health and substance use disorder benefits on par with medical/surgical benefits. Though the Act does not require group health plans to provide mental health benefits or substance use disorder benefits, if they are provided, financial requirements and treatment limitations cannot be more restrictive for mental health and substance use disorders than they are for medical/surgical benefits.

Financial requirements include deductibles, copayments, coinsurance and out-of-pocket maximums, but do not include aggregate lifetime or annual dollar limits. Treatment limitations include limits on the frequency of treatment, number of visits, days of coverage, days in a waiting period, and other similar limits on the scope or duration of treatment.

According to a press release issued by the administration, the final rules include specific consumer protections, such as:

  • Ensuring that parity applies to intermediate levels of care received in residential treatment or intensive outpatient settings;
  • Clarifying the scope of transparency required by health plans, including the disclosure rights of plan participants, to ensure compliance with the law;
  • Clarifying that parity applies to all plan standards, including geographic limits, facility-type limits and network adequacy; and
  • Eliminating an exception to the existing parity rule that was determined to be confusing, unnecessary and open to abuse.

Health and Human Services Secretary Kathleen Sebelius said, “This final rule breaks down barriers that stand in the way of treatment and recovery services for millions of Americans. Building on these rules, the Affordable Care Act is expanding mental health and substance use disorder benefits and parity protections to 62 million Americans. This historic expansion will help make treatment more affordable and accessible.”

The final rules generally apply to group health plans and health insurance issuers offering group health insurance coverage for plan years beginning on or after July 1, 2014; however, they do not apply to small employers with between 2 and 50 employees. Since the Affordable Care Act extended the Act to grandfathered and non-grandfathered individual health insurance coverage, the final rules apply to individual coverage with policy years beginning on or after July 1, 2014.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the constantly changing health care reform landscape. Check back with us periodically for future informational updates.

If you have specific questions about the Mental Health Parity and Addiction Equity Act or the Affordable Care Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you would like to subscribe to our newsletters please click here.

IRS Modifies “Use-or-Lose” Rule for Flexible Spending Accounts (FSAs)

On October 31, 2013, the Internal Revenue Service (IRS) modified the longstanding cafeteria plan “use-or-lose” rule for health Flexible Spending Accounts/Arrangements (FSAs). Under this rule, unused FSA account balances are forfeited at the end of the plan year. Now, up to $500 of unused money may be carried over to the next plan year.

A cafeteria plan FSA, which is offered with other employer-established benefits, reimburses employees for qualified medical expenses. FSAs are usually funded by employees through voluntary salary reductions of up to $2,500 per year, though employers may also contribute. FSA contributions are not included in an employee’s income and reimbursements for qualified medical expenses are not taxed.

For nearly 30 years, FSAs have been subject to the “use-or-lose” rule. However, last year the IRS asked whether the rule should be modified to provide greater flexibility. The overwhelming response was yes. The reasons for increased flexibility include:

  • Difficulties in predicting future medical expenditures
  • Minimizing incentives for unnecessary spending to avoid forfeiture
  • The possibility that lower paid employees are reluctant to participate in FSAs because even modest forfeitures can be significant
  • Easing and simplifying the administration of FSAs

Under the new rule for cafeteria plan FSAs, employers may allow employees to carryover up to $500 of unused FSA money to the next plan year. Any amounts carried over may be used to pay or reimburse medical expenses incurred during that entire plan year. Employers have the option, not the obligation, to let employees carryover unused FSA money. And, since $500 is the maximum amount that can be carried over, employers may choose a lower amount.

Currently, cafeteria plans are allowed to have a “grace period” of up to two months and 15 days after the plan year during which participants may use remaining FSA money from the previous plan year to pay expenses incurred during the grace period. Since this is a popular feature among many plans, it is important to note that plans may provide employees with a carryover option OR a grace period. A health FSA cannot have both.

Employers wishing to utilize the new carryover option must amend their cafeteria plan. The amendment must be adopted on or before the last day of the plan year and may, in some cases, be effective retroactively to the first day of that plan year. Plans must also be amended to eliminate any grace period by no later than the end of that plan year, though the IRS notes that this may be subject to “non-code legal constraints.”

Given the complexity of providing and managing cafeteria plans, as well as the liability for getting it wrong, employers should consult with appropriate professionals to make sure their plans meet their minimum needs and provide maximum benefits.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Are You Ready for Halloween’s Scary Treats?

Halloween is here! Get ready for the costumes, parties, pranks, trick-or-treaters, candy and…the risk. Every year we are reminded how quickly Halloween celebrations can go wrong. Since cancelling Halloween is not an option, it is important to identify risks that can be controlled and insure against those that cannot.

Vehicle-Pedestrian Accidents

A study by the Centers for Disease Control and Prevention found that the number of childhood pedestrian deaths increased fourfold among children on Halloween. The following tips can limit the likelihood of being involved in a vehicle-pedestrian accident.

  • Slow down and be alert. Children may move in unpredictable and unsafe ways.
  • Take extra time at intersections. Pay attention to medians and curbs.
  • Enter and exit driveways slowly and carefully.
  • Eliminate distractions, such as cell phones and music.
  • Turn headlights on earlier in the day

Standard auto insurance policies would typically provide coverage for damage and liability resulting from a vehicle-pedestrian accident, subject to any policy exclusions.

Slips, Trips and Falls

Whether they are trick-or-treaters or party guests, people typically have more visitors than usual on Halloween. This means a higher risk of slip, trip and fall accidents and liability. To prevent accidents:

  • Keep areas well-lit.
  • Remove all objects that could cause children or guests to slip, trip or fall.
  • Make sure Halloween decorations don’t create a hazard.
  • Repair any broken walkways, sidewalks, driveways, paths and steps.
  • Warn visitors of, and clearly mark, any hazards that cannot be removed or repaired.
  • Keep pets inside and away from guests and trick-or-treaters.

If a guest is injured, standard homeowners’ and renters’ policies will typically provide coverage in the event of a lawsuit. These policies may also provide an injured guest with medical coverage, which may help avoid a lawsuit.

Fire

The National Fire Protection Association says that Halloween ranks among the top 5 days of the year for candle-related fires. The NFPA also found that decorations, like jack-o-lanterns, are often the items first ignited in home fires. To prevent fires:

  • Don’t leave candles unattended and keep them away from flammable materials.
  • Make sure decorations and costumes are flame resistant.
  • For decorations requiring electricity, make sure plugs, wires and cords are not damaged and are used properly.

Fires caused by candles or decorations will typically be covered under standard homeowners’ and renters’ policies.

Vandalism

Homes and vehicles are often damaged by mischievous or malicious trick-or-treaters. To limit the risk:

  • Keep areas well-lit.
  • Move items indoors or to another location.

Vandalism damage that exceeds the deductible will typically be covered under standard homeowners’ and renters’ policies. If a car is vandalized, the comprehensive portion of an auto insurance policy should cover the damage.

If you would like more information about identifying and insuring against various risks, please contact us.

If you would like to subscribe to our newsletters please click here.

Data Security Breaches Can Happen to You

When it comes to data security breaches, many organizations say, “That could never happen to us.” Unfortunately, the increasing frequency of data security breaches means that many of these organizations are wrong. Don’t believe it? Let’s take a look at a few recent security breaches.

Hacking

In October 2013, the multi-billion dollar company, Adobe Systems, Inc., suffered a data security breach that compromised nearly 3 million records. Hackers were able to access customers’ IDs, encrypted passwords, names, encrypted credit or debit card numbers, expiration dates and other information related to their orders.

Laptop Computer

In October 2013, a Wisconsin hospital suffered a data breach when a laptop computer with unencrypted data was stolen out of an employee’s car. As a result, patients may have had their names, dates of birth, medical record and account numbers, providers, departments of service, bed and room numbers, dates and times of services, visit histories, complaints, diagnoses, procedures, test results, vaccines and medications exposed.

Employee Theft

In September 2013, a dishonest hospital employee in Florida accessed patient names, social security numbers, dates of birth and addresses. Even though the employee was fired and will be facing criminal prosecution, this information may have been used to file fraudulent tax returns.

Email Error

In September 2013, Columbia University Medical Center suffered a data security breach when an Excel file containing sensitive medical student information was accidentally attached to an email that was sent to students, faculty and staff.

Programming Error

In September 2013, a financial services firm suffered a data breach when a programming error allowed customers’ names, social security numbers and addresses to be viewed on the firm’s unrestricted website.

These recent incidents show that data security breaches can happen to any organization. This means that every organization must be proactive in protecting against data security breaches. Though protective measures should cover everything from the wireless network to the copy machine, organizations should also consider protecting against data security breaches with insurance.

Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.

Self Storage Facilities: Protecting the Bottom Line

Most businesses rely on their facilities to manufacture products or provide services. In the self storage industry, the facilities typically are the product. If property loss or damage is not fixed quickly, the business may fail. Though most believe their self storage facilities are adequately insured against property loss or damage, many overlook Ordinance and Law coverage. This oversight can be the downfall of any self storage facility.

Ordinance and Law insurance is designed to pay the extra expense of rebuilding to comply with ordinances or laws, such as building codes, which did not exist when the building was originally constructed. Since the costs of improving a structure to bring it up to code are specifically excluded under most property policies, this coverage can be quite valuable.

An insured’s obligation to rebuild according to current and stricter codes is often triggered when an insured building experiences a covered loss, such as a fire or hurricane. Unfortunately, many insureds first learn of this additional obligation and expense after they experience a property loss. To avoid the burden of these additional rebuilding costs, self storage facilities can add Ordinance and Law coverage to their current property insurance policies. Doing so will generally cover:

  • Loss to the undamaged portion of the building;
  • Increased demolition costs; and
  • Increased costs of construction.

Since rebuilding according to current building codes may suspend operations for an extended period of time, self storage facilities can purchase Business Interruption insurance to cover reductions in net income caused by an inability to continue business operations. Since payroll, mortgage/rent payments, money owed to suppliers, taxes, and other continuing expenses must be met, Business Interruption insurance may provide badly needed capital when operations are suspended.

Combining Ordinance and Law coverage with Business Interruption coverage, self storage facilities increase the likelihood of surviving not only the initial property loss, but a protracted suspension of operations resulting from the obligation to rebuild in accordance with current building codes.

While the decision to obtain Ordinance and Law and Business Interruption coverage should be easy, understanding specific policy provisions and terms can be difficult. Since there may be variations among different policy forms, it is important that you consult with an experienced insurance agent to discuss your options.

If you would like more information about protecting your self storage facility or obtaining Ordinance and Law and Business Interruption insurance coverage, please contact us.

If you would like to subscribe to our newsletters please click here.

No Penalty for Noncompliance with ACA’s Notice of Coverage Options

On September 11, 2013, the United States Department of Labor announced that employers will not be fined or penalized under the Affordable Care Act for failing to provide employees with notice about coverage options available through the ACA’s Health Insurance Marketplace (Exchanges). This comes just weeks before the October 1, 2013 deadline for employers to begin providing the notice to their employees.

The announcement, which was posted on the DOL’s website as a “FAQ on Notice of Coverage Options,” states:

Q: Can an employer be fined for failing to provide employees with notice about the Affordable Care Act’s new Health Insurance Marketplace?

  1. No. If your company is covered by the Fair Labor Standards Act, it should provide a written notice to its employees about the Health Insurance Marketplace by October 1, 2013, but there is no fine or penalty under the law for failing to provide the notice.

A day later, the U.S. Small Business Administration posted similar information on its website.

This announcement comes as a surprise to those who assumed that noncompliance would be met with a fine or penalty. Though the ACA’s employer notice requirement does not contain a specific penalty provision, many assumed that the ACA’s general penalty of $100 per day would apply. And, since news of the DOL’s position came informally through its website rather than the formal regulatory process, some believe that fines or penalties for noncompliance remain a possibility in the future.

This new development has understandably left many employers unsure about how to deal with the ACA’s employer notice requirement. Though it is still the law, the DOL’s announcement has undoubtedly left many wondering whether a requirement can really exist without consequences.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the constantly changing health care reform landscape. Check back with us periodically for future informational updates about the Affordable Care Act.

If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, view our health product page.

If you would like to subscribe to our newsletters please click here.