EEOC Releases 2014 Enforcement and Litigation Data

The Equal Employment Opportunity Commission (EEOC) is responsible for enforcing various federal equal employment opportunity laws. Every year the EEOC releases information about its enforcement and litigation efforts during the previous fiscal year (FY), which runs from October 1st to September 30th. This data can be used to get a better understanding of potential employment-related liability exposures that continue to pose a significant risk to most employers.

In FY 2014, the EEOC received a total of 88,778 charges of workplace discrimination, which is lower than recent fiscal years. There were 93,727 charges filed in FY 2013 and 99,412 charges filed in FY 2012. According to the EEOC, this decrease is due in part to the government shutdown during the first quarter of FY 2014.

The EEOC obtained $296.1 million in total monetary relief through its pre-litigation enforcement program in FY 2014, which is also lower than recent fiscal years. The EEOC obtained $372.1 million in FY 2013 and $365.4 million in FY 2012. Monetary relief from cases litigated in FY 2014, including settlements, totaled $22.5 million.

The total number of charges filed in FY 2014 can be broken down as follows:

  • Retaliation under all statutes: 37,955 (42.8%)
  • Race (including racial harassment): 31,073 (35%)
  • Sex (including pregnancy and sexual harassment): 26,027 (29.3%)
  • Disability: 25,369 (28.6%)
  • Age: 20,588 (23.2 percent)
  • National Origin: 9,579 (10.8%)
  • Religion: 3,549 (4.0%)
  • Color: 2,756 (3.1%)
  • Equal Pay Act: 938 (1.1%) [Note: Sex-based wage discrimination can also be charged as sex discrimination under Title VII.]
  • Genetic Information Non-Discrimination Act: 333 (0.4%)

The states with the most charges filed in FY 2014 were:

  • Texas (8,035)
  • Florida (7,528)
  • California (6,363)
  • Georgia (4,820)
  • Illinois (4,487).
  • Pennsylvania (4,045)
  • North Carolina (4,017)

It’s interesting to note that of the 88,778 charges filed, 57,376 were closed because the EEOC determined there was no reasonable cause to believe that discrimination occurred based upon evidence obtained in investigation. This means that nearly 66% of employers had to endure an EEOC investigation despite the lack of reasonable cause to support a claim of discrimination. Since even baseless EEOC investigations can be expensive, employers should consider employment practices liability insurance to help cover the costs.

Employers can avoid the EEOC’s enforcement efforts by creating and enforcing a policy against discrimination and harassment. Employees must also be trained to prevent, detect and address any unlawful behavior. Training should cover all relevant topics, such as employment liabilities, sexual harassment for managers and employees, discrimination and harassment prevention and disability discrimination.

If you would like to learn more about controlling employment-related liabilities, check out The Human Equation’s library of online courses or contact us.

The Human Equation prepares all risk management and insurance content with the professional guidance of Setnor Byer Insurance and Risk.

Are You Protecting Customers’ Credit and Debit Card Data?

It’s hard to ignore the fact that data security breaches seem to be increasing in frequency and severity, particularly those involving credit and debit card data. Just ask Home Depot, Michaels Stores, Neiman Marcus, or their 50+ million customers whose payment card data may have been compromised in 2014. To reduce the chances of making the list in 2015, preventative measures must be taken by every business that accepts credit and debit card payments.

The PCI Security Standards Council developed the Payment Card Industry Data Security Standard (PCI DSS) to encourage and enhance cardholder data security. This standard includes 12 requirements.

Build and Maintain a Secure Network and Systems

  • Install and maintain a firewall to protect cardholder data.
  • Do not use defaults for system passwords or security parameters.

Protect Cardholder Data

  • Protect stored cardholder data.
  • Encrypt transmission of cardholder data.

Maintain a Vulnerability Management Program

  • Protect systems against malware and regularly update anti-virus software.
  • Develop and maintain secure systems and applications.

Implement Strong Access Control Measures

  • Restrict access to cardholder data to those who need to know.
  • Identify and authenticate system access.
  • Restrict physical access to cardholder data.

Regularly Monitor and Test Networks

  • Track and monitor all access to networks and cardholder data.
  • Regularly test security systems and processes.

Maintain an Information Security Policy

  • Maintain a policy that addresses information security for all personnel.

The PCI Security Standards Council also provides a number of tips and strategies to increase the security of payment card data, such as:

  • Never store Sensitive Authentication Data, such as the full track contents on the magnetic stripe or chip, card verification codes/values, or PINs.
  • Ask point-of-sale vendors about the security of payment card systems.
  • Do not store cardholder data that is not needed.
  • Consolidate and isolate cardholder data that is needed.

The Council notes that the PCI DSS provides minimum security requirements that may be enhanced by additional controls and practices. Various laws, rules or regulations may also require enhanced security measurers. For example, under the Fair and Accurate Credit Transaction Act (FACTA), electronically printed credit and debit card receipts given to customers cannot include a card’s expiration date or more than the last five digits of the card number.

Sometimes security measures aren’t enough to prevent a data security breach, so businesses should use insurance to manage their cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

A solid understanding of your insurance needs is the key to overcoming the quality versus cost argument. An experienced and reputable independent insurance agent can help you purchase insurance that is both economical and effective.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

Understanding Excepted Benefits Under the Affordable Care Act

Many employers offer benefits packages that provide employees with more than just health insurance coverage. Though some of these benefits, like pre-paid legal service plans, are clearly not health-related, others may provide employees with some health-related benefits. Does this mean they are subject to the Affordable Care Act’s health insurance market reforms? Not necessarily.

Certain types of benefits, due to their nature, are not subject to a number of health-related laws, including the Affordable Care Act, the Health Insurance Portability and Accountability Act, the Mental Health Parity Act and the Genetic Information Nondiscrimination Act. These are known as excepted benefits.

There are four categories of excepted benefits.

  1.         Benefits Excepted In All Circumstances

The following benefits, or any combination thereof, are considered excepted benefits in all circumstances:

  • Coverage only for accident (including accidental death and dismemberment)
  • Disability income coverage
  • Liability insurance, including general liability and automobile insurance
  • Coverage issued as a supplement to liability insurance
  • Workers’ compensation or similar coverage
  • Automobile medical payment insurance
  • Credit-only insurance (for example, mortgage insurance)
  • Coverage for on-site medical clinics
  1.         Limited Excepted Benefits

A number of benefits may be considered excepted benefits if they are provided under a separate policy, certificate or contract of insurance. They can also qualify as a limited excepted benefit if they are not an integral part of a group health plan, which means that participants may decline coverage or that claims for benefits are administered under a separate contract than claims for any other benefits under the plan.

One or more of the following benefits may qualify as a limited excepted benefit:

  • Limited-scope dental benefits
  • Limited-scope vision benefits
  • Long-term care benefits
  • Health flexible spending arrangements
  • Employee assistance programs (EAPs)
  1.         Noncoordinated Excepted Benefits

Coverage for only a specified disease or illness, such as a cancer-only policy, may qualify as a noncoordinated excepted benefit. Hospital indemnity or other fixed indemnity insurance may also qualify if it pays a fixed dollar amount per day (or per other period) of hospitalization or illness regardless of the amount of expenses incurred.

To qualify as a noncoordinated excepted benefit:

  • Benefits must be provided under a separate policy, certificate or contract of insurance;
  • There is no coordination between the benefits provided and an exclusion of benefits under any group health plan maintained by the same employer; and
  • Benefits are paid regardless of whether benefits are provided under any group health plan maintained by the same employer.
  1.         Supplemental Excepted Benefits

The following benefits may qualify as supplemental excepted benefits if they are provided under a separate policy, certificate or contract of insurance:

  • Medicare supplemental health insurance (Medigap or MedSupp insurance);
  • Coverage supplemental to the managed health care program established by the Department of Defense (TRICARE); and
  • Similar supplemental coverage specifically designed to fill gaps in primary coverage, such as coinsurance or deductibles, but which does not include coverage that becomes secondary or supplemental only under a coordination-of-benefits provision.

Excepted benefits must satisfy a number of specific requirements set forth in the federal regulations. Employers should consult a knowledgeable and licensed professional before taking action or making changes to their benefits packages.

If you would like more information about excepted benefits or would like to see how Setnor Byer Insurance & Risk can help with your employee benefits package, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Office Holiday Parties: Revel without Regret

Many employers consider a company-wide holiday celebration an excellent opportunity for employees to mingle socially and get to know one another better. It’s also a chance for senior management to interact with employees they rarely see throughout the year. Though holiday parties can create a positive work environment, increase employee morale and promote teamwork, they can also expose employers to a number of potentially significant risks.

Perhaps the most significant risks involve alcohol. What happens if an employee becomes intoxicated and causes damage to something or someone? Though liability is determined on a case-by-case basis, employers may face a greater chance of being held responsible if:

  • Attendance is, or is perceived to be, mandatory (e.g., everybody knows that being seen by the Vice President will enhance one’s chances of a promotion);
  • The employer pays for or provides the alcohol; or
  • The employer conducts business during the holiday party.

Employers can take steps to reduce their potential liability, such as:

  • Collect car keys from all who drink. Toward the close of the party, assign designated drivers or call taxis for anyone who is too impaired to drive. If the party is in a hotel, reserve a block of rooms for the inebriated to spend the night.
  • Appoint someone in a position of authority to monitor alcohol consumption; including making certain that no alcohol is served to minors.
  • Serve a limited amount of alcohol, controlled through “drink coupons.” (i.e., two drinks per person). Close the bar once dinner begins.
  • Send a memo to all employees prior to the party stating clearly that a) employees who arrive inebriated will not be allowed in; b) employees cannot bring their own alcohol; c) excessive drinking will not be tolerated; and d) intoxication and inappropriate behavior at the party will be grounds for discipline.
  • Do not permit supervisors or managers to buy alcoholic beverages for employees.
  • Hold the party at an off-site location and use professional bartenders to serve and monitor alcohol consumption.

There are other risks employers should consider when planning and holding the annual office holiday party, such as:

Discrimination and Harassment: Lines are often blurred during an office party, so they are often crossed. Conduct that is inappropriate at work may be considered appropriate at a party, such as engaging in intimate conversations or acts, giving a racy gift or telling an off-color joke. Employers may be held liable for unlawful harassment or discrimination that takes place during a holiday party, even if it’s off-premises and off-the-clock. Consider redistribution of the sexual harassment policy, and remind employees that a holiday party is no excuse for inappropriate behavior, which will not be tolerated.

Premises Liability: Employees are often allowed to bring spouses and significant others to the office holiday party. Every ‘plus one’ accompanied by an employee is a potential slip-and-fall victim. Employers must make sure the workplace is safe before the party and keep it safe during the party.

Workers’ Compensation: Employees are typically covered by workers’ compensation if they are injured in the course and scope of their employment. Though getting hurt at a holiday party wouldn’t seem to be work-related, an employee may be covered by workers’ compensation if attendance at the party is explicitly or implicitly required (or ‘encouraged’). Tell employees the holiday party is purely a voluntary social event, and mean it.

Employers should review their insurance policies before the party to make sure they are covered in the event something happens during the holiday party. General liability, employment practices liability and workers’ compensation insurance may cover some of the risks created by the office holiday party. However, other risks may require additional insurance coverage, such as a policy that covers one-time events, including alcohol-related liability, which may be available for a small additional premium.

If you would like more information about how Setnor Byer Insurance & Risk can help protect your business during the holidays and year round, please contact us.

A New Right of Access for Condominium Associations

Sometimes a condominium association needs to enter an owner’s unit, which is why Florida’s Condominium Act gives associations an irrevocable right of access. This right of access may only be used during reasonable hours to perform needed maintenance and repairs or to prevent damage to the common elements or to other units. However, Florida’s Condominium Act was amended on July 1, 2014 to expand an association’s right to access units that have been abandoned.

Under the new law, an association may enter an abandoned unit to:

  • Inspect a unit and adjoining common elements;
  • Make necessary repairs to a unit or to the common elements serving the unit;
  • Repair a unit if there is mold or deterioration;
  • Turn on utilities for a unit; or
  • Otherwise maintain, preserve or protect a unit and adjoining common elements.

When is a unit considered abandoned? Unless a unit owner provides the association with written notice to the contrary, a unit is presumed to be abandoned if:

  • The unit is the subject of a foreclosure action and no tenant appears to have resided in the unit for at least 4 continuous weeks; or
  • No tenant appears to have resided in the unit for 2 consecutive months, and the association is unable to contact or determine the whereabouts of the owner after reasonable inquiry.

Except in cases of emergency, an association must wait 2 days after giving the owner notice of its intent to enter the abandoned unit. This notice must be mailed or hand-delivered to the owner’s address of record and may be given electronically if the unit owner previously consented to receive electronic notices from the association.

Any expenses incurred by the association can be charged to the unit owner, and if a unit owner fails to pay, the association may use its lien authority to collect. An association may also ask a court to appoint a receiver to lease out an abandoned unit so that the rental income can be used to offset the association’s costs and expenses of maintaining, preserving and protecting the unit and the adjoining common elements, which can include:

  • The costs of receivership
  • Unpaid assessments
  • Interest
  • Administrative late fees and costs
  • Reasonable attorney fees

This expanded right of access to abandoned units applies even if the condominium documents, such as the bylaws or declaration, do not provide the authority to do so. Under the new law, the decision to enter an abandoned unit is at the association’s sole discretion. Nevertheless, associations should proceed cautiously to make sure all formalities are observed and to minimize the risk of a lawsuit by the unit owner.

Setnor Byer Insurance & Risk’s Condominium Program provides clients with access to various risk management services, such as Setnor Byer’s Risk Management Group and Unit Owners’ Report Line, as well as our affiliate’s online Board Member Education, which has been approved by the Division of Florida Condominiums, Timeshares, and Mobile Homes to satisfy Florida’s new board member education training.

If you would like to discuss how Setnor Byer Insurance & Risk can serve you and your association, please contact us.

Here We Go Again with Another Massive Data Security Breach

Before the dust could settle on Target’s data security breach, news of a potentially larger one has surfaced. On September 18, 2014, Home Depot confirmed that it suffered a data breach involving the debit and credit card information of approximately 56 million customers. Target’s breach involved approximately 40 million cards.

Home Depot’s breach involved payment card information for purchases made at U.S. and Canadian Home Depot stores from April to September, 2014. According to Home Depot, criminals used unique, custom-built malware not seen previously in other attacks to breach payment card systems. Though their investigation is ongoing, Home Depot said names, card numbers, expiration dates, cardholder verification values and service codes may have been compromised.

Seeing yet another large business with substantial resources suffer a massive data security breach should be more than enough to confirm that data security breaches can happen to any organization. Though preventing data breaches is becoming more difficult, businesses can take steps to reduce the risk.

A subsidiary of Reinsurer Munich Re recently held a presentation with cybersecurity experts and risk managers to show how cybercriminals choose their targets and access their systems. This presentation provided several key takeaways for businesses.

  • Businesses are not only viewed as targets by cybercriminals, but also as conduits to attack a business’s clients.
  • Businesses must identify any data that may be valuable to others, and keep only what is needed.
  • Most hackers use email and browsers to access a business’s systems.

The cybersecurity presentation identified 10 ways for businesses to prevent a data breach.

  • Outsource payment processing (point-of-sale, web payments) to take advantage of their sophisticated and dedicated security measures.
  • Separate social media from financial activity by using a dedicated device for online banking and a different device for email and social media.
  • Don’t reuse passwords and don’t trust websites to store them for you. Set up a two-factor authentication process that verifies identity by sending a secret code to your phone.
  • Train employees to protect sensitive and confidential information. Remind employees that most malicious attacks involve email, and that they should alert others when suspicious emails are received.
  • Identify risks by evaluating systems and networks, including email infrastructure and browser vulnerability. Learn how business associates (vendors, suppliers, partners) handle data security.
  • Mandate encryption for all data that is stored (at rest) and transmitted (in motion), and avoid the use of Wi-Fi networks if possible.
  • Use the latest web browser version that is available rather than relying on individual patches and updates.
  • Update operating systems to take advantage of built-in security improvements.
  • Secure routers connecting business computers to the Internet. Set strong administrator passwords and, if Wi-Fi is necessary, use a WPA2 password.
  • Encrypt backup data and store it off-site.

Home Depot is currently dealing with the consequences of its data security breach by investigating the breach, updating data security systems, notifying potential victims, providing free identity theft protection and adjusting its public relations to minimize the damage to its reputation. The costs of these efforts can be staggering. For businesses lacking the resources of the Target’s and Home Depot’s, these costs can be devastating.

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws. However, given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained.

If you would like to learn more about insuring against cyber risks, contact us.

If you would like to subscribe to our newsletters please click here.

What is a Grandfathered Group Health Plan?

Though the term ‘grandfathered’ is commonly used when discussing group health insurance under the Affordable Care Act (ACA), many people don’t know what it means. ‘Grandfathered’ is used to describe group health plans that are exempt from many of the ACA’s provisions. These exemptions were included in the ACA so groups that were happy with their health plans could keep them.

To be eligible for grandfathered status, a group health plan must have been in existence on March 23, 2010, which is the day the ACA became law. Plans starting after this date do not qualify for grandfathered status. Additionally, plans that have made significant changes since March 23, 2010 may lose their grandfathered status. For example, increased cost-sharing requirements, such as copayments and deductibles, decreased employer contributions, elimination of benefits, and changes in annual limits may cause a plan to lose its grandfathered status.

Grandfathered group health plans are exempt from many of the ACA’s provisions. For example, the following provisions do NOT apply to grandfathered plans.

  • Fair health insurance premiums: Under the ACA, health insurers may not charge discriminatory premium rates.
  • Guaranteed availability of coverage: Under the ACA, insurers must generally accept every employer group in the State that applies for coverage, though they can limit enrollment to annual open and special enrollment periods.
  • Guaranteed renewability of coverage: The ACA generally requires guaranteed renewability of coverage regardless of health status, utilization of health services, or any other related factor.
  • Comprehensive health insurance coverage: The ACA generally requires that insurers include coverage for defined essential benefits, provide a specified actuarial value, and comply with limitations on allowable cost sharing.
  • Coverage of preventive health: Under the ACA, group health plans must cover certain preventive services, immunizations, and screenings, without any cost sharing.
  • Prohibition on discrimination in favor of highly-compensated individuals: The ACA prohibits fully-insured group health plans from discriminating in favor of highly compensated individuals with respect to eligibility and benefits.
  • Patient protections: The ACA generally requires group health plans to permit an individual to select a participating primary care provider, to provide direct access to obstetrical or gynecological care without a referral.

Grandfathered group plans are not exempt from every provision of the ACA. There are a number of provisions that DO apply to grandfathered plans, such as:

  • Prohibition of preexisting condition exclusion or other discrimination based on health status: Under the ACA, group health plans may not impose a preexisting condition exclusion or discriminate based on health status.
  • Prohibition on excessive waiting periods: The ACA prohibits any waiting periods that exceed 90 days.
  • No lifetime or annual limits: The ACA generally prohibits group health plans from establishing lifetime limits and annual limits on the dollar value of benefits.
  • Extension of dependent coverage: Under the ACA, group health plans that provide dependent coverage are generally required to make such coverage available to children until age 26.
  • Prohibition on rescissions: Group health plans may not rescind health coverage except in the case of fraud or intentional misrepresentation.

The number of grandfathered group health plans is steadily decreasing. A 2013 study by the Kaiser Family Foundation found that 36 percent of those getting health coverage from an employer are enrolled in a grandfathered health plan, which is down from 48 percent in 2012 and 56 percent in 2011. The study also found that the number of employers offering grandfathered plans and the number of employees enrolling in them is also decreasing. This trend is expected to continue and more plans are expected to lose grandfathered status over time.

Very specific regulations govern grandfathered group health plans, so establishing and maintaining grandfathered status can be a complicated process. For example, grandfathered plans must disclose their status to participants and beneficiaries and must maintain any documents that are necessary to verify, explain or clarify a plan’s grandfathered status. Given the significance of the ACA’s grandfather exemptions, it’s important to seek guidance from reputable and experienced experts.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the ACA or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

My Friend Crashed My Car

At one time or another, most of you have let a friend borrow your car. Unfortunately, many of you probably weren’t thinking about insurance coverage as you handed over the keys. So what do you think, if your friend gets into an accident while driving your car, would your automobile insurance cover it?

As always, the first place to look is the insurance policy. Standard auto insurance policies have permissive use clauses that extend insurance coverage to those who had the owner’s permission to use the car. These clauses are intended to benefit and protect the general public and innocent victims of automobile accidents.

Though policy forms vary, permissive use (a/k/a omnibus) clauses are often incorporated into that part of the policy that identifies who is insured under the policy. For example, a policy may state that any person using the automobile is considered an ‘Insured Person’ if they have the owner’s permission to do so.

Permission to use an automobile can generally be either express or implied. Express permission must be of an affirmative character that is directly and distinctly stated, and clear and outspoken. Express permission cannot be merely implied or left to inference.

Implied permission, on the other hand, involves an inference arising from a course of conduct or relationship between the parties in which there is a mutual acquiescence or lack of objection which signifies permission. Implied permission is typically determined from the facts and circumstances in a particular case.

After establishing that the driver had permission to use the car, the next step is determining whether the driver’s use of the car was consistent with the owner’s permission. For example, if a car owner gave permission to drive to the local store, but the friend takes off on a cross-country trip, is this friend really driving with the owner’s permission?

There are generally three rules used by various states to determine whether a driver has exceeded the owner’s permission to use the car.

Conversion (Strict Construction) Rule: This rule requires that the automobile be used for a purpose reasonably within the scope of the permission given, during the time limits expressed and within the geographical limits contemplated by the owner and the driver. Any deviation, no matter how slight, will negate a driver’s permissive user status under the owner’s policy and there will be no coverage in the event of an accident. The friend cruising across the country would not be considered a permissive user in states adopting this rule.

Initial Permission Rule: Some states adopted the more liberal initial permission rule. Under this rule, if permission to use the automobile is initially given, the driver is considered to have the owner’s permission regardless of the manner in which the automobile is used. Since only the first use must be with the owner’s permission, any later deviations made by the driver, such as driving cross-country, are immaterial. For this reason, the initial permission rule is sometimes referred to as the ‘hell-or-high water’ rule.

Minor Deviation Rule: Some states have taken an intermediate approach by adopting the minor deviation rule. Under this rule, a driver can deviate from the scope of permission given by the owner and still be considered a permissive user as long as any deviation is not gross, substantial or major. In other words, this rule permits a slight deviation but condemns a major one. A material deviation, such as going cross-country, voids the initial permission, so if the friend gets in an accident in another state, he or she will not be considered a permissive user entitled to coverage under the owner’s auto insurance policy.

The next time a friend asks to borrow your car, take a minute to consider what might happen if there is an accident. As the owner of the car you will most likely be held liable for damages, so it’s a good idea to know whether you or your insurance company will be paying the bill.

If you have any questions or would like to discuss your insurance options, please contact us.

If you would like to subscribe to our newsletters please click here.

Understanding Business Insurance: What is BOP?

Many businesses take a piecemeal approach to buying insurance. One policy for property insurance, another for liability insurance, and so on. Unfortunately, this approach can be difficult and time consuming, particularly for small- and medium-sized businesses. For these businesses, a Business Owners Policy, a BOP, may be an attractive alternative.

A BOP is a pre-packaged bundle of coverages that insurance companies offer to eligible small- and medium-sized businesses. BOPs are designed to provide a number of essential insurance coverages in a convenient and cost effective manner. BOPs typically provide:

  • Property insurance to cover damage to buildings and contents;
  • Business income (business interruption) insurance to cover the loss of income resulting from a covered loss that Disrupts business operations; and
  • Liability insurance to protect against liability claims for bodily injury and property damage occurring on a business’s premises or arising out of its operations.

Depending on the insurance company, additional coverages may be included in a BOP, or added for an additional premium, such as:

  • Cyber Liability
  • Employment Practices Liability
  • Valuable Papers and Records
  • Personal and Advertising Liability
  • Liquor Liability
  • Equipment Breakdown
  • Sale and Disposal Liability coverage for self storage facilities

Though BOP eligibility requirements can vary significantly among insurance companies, BOPs are typically limited to small- and medium-sized businesses, which are generally those with fewer than 100 employees and annual revenues of less than $5 million. BOPs may also not be available to businesses operating in specific industries or those with highly specialized or high-risk operations.

Alternatively, BOPs may not be the solution for some businesses, even those that are eligible for them. For example, some businesses may require higher limits or broader coverage forms that are not available in a BOP. There are also a number of coverages that BOPs do not provide, such as workers compensation, commercial automobile and professional liability insurance. Even with a BOP, additional insurance policies may still be necessary.

Since BOPs are customized insurance products, it is important to note that coverage options and features (limits, exclusions, etc.) can vary significantly among insurers. Unfortunately, the lack of uniform eligibility requirements, coverage options and policy features makes it difficult to understand and compare the various BOP options that may be available. An experienced insurance agent should be consulted throughout the process.

If you would like to learn more about BOPs or the various options that may be available to insure your business, contact us.

If you would like to subscribe to our newsletters please click here.

Every Business Should be Worried about Cyber Liability

Regardless of industry, cyber attacks and data breaches expose businesses to potentially enormous losses and liabilities. According to a report by the Insurance Information Institute (III), the potential economic fallout from the cyber threat cannot be underestimated, particularly because the number of publicly disclosed data breaches soared from 449 in 2012 to 614 in 2013. This is likely why cyber risk cracked the top 10 list of global business risks in 2014.

According to the III report:

  • The majority of data breaches affected the medical/healthcare industry (43.8%) and business organizations (34.4%).
  • Business organizations accounted for the majority of records exposed by data breaches in 2013 (84%).
  • A report by PWC found that cyber crimes are considered a high-level threat.
  • Cyber attacks have become more frequent and increasingly costly for companies to resolve.
  • The average annualized cost of cyber crime is estimated to be $11.6 million per year.
  • Denial of service is the costliest cyber crime, followed by malicious insiders and web-based attacks.
  • The average time to resolve a cyber attack is 32 days, with an average cost of just over $1 million during this 32-day period.
  • Malicious or criminal attacks, such as malware infections, criminal insiders, phishing/social engineering and SQL injections, cause 42% of data breaches, followed by human error (30%) and system glitches (29%).
  • U.S. organizations have the highest lost business costs at an average of $3.3 million.
  • Businesses may be exposed to even greater risks from new technologies, such as cloud computing, which uses a network of remote servers over the Internet to store, manage and process data, rather than a local server.

The III report notes that upon experiencing a data breach, many businesses turn to their insurance policies to cover their loss. Unfortunately, many of these losses are not covered by traditional insurance policies. To protect against cyber threats, businesses need specific cyber insurance policies that provide a number of specialized coverages, such as:

  • Loss/corruption of data
  • Business income/interruption
  • Liability coverage (first- and third-party coverage)
  • Data breach coverage (including costs of complying with statutory notice requirements)
  • Cyber extortion
  • Crisis management
  • Identity theft

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.