Counting Employees under the Affordable Care Act’s Pay-or-Play Provisions

Employers subject to the Affordable Care Act’s Employer Shared Responsibility provisions may be assessed a penalty if they do not offer affordable health coverage that provides a minimum level of coverage to their full-time employees and their dependents. Whether an employer is subject to these pay-or-play provisions depends on the number of people it employs. When counting employees, however, there are specific rules that must be followed.

An employer is generally considered an “Applicable Large Employer” subject to the pay-or-play provisions if it employed an average of at least 50 full-time employees, including full-time equivalent employees (FTEs), on business days during the preceding calendar year. To determine whether an employer is considered an Applicable Large Employer for a calendar year:

  • Add the total number of full-time employees for each calendar month in the preceding calendar year, and the total number of Full Time Equivalent employees for each calendar month in the preceding calendar year.
  • Divide the sum by 12.
  • If the result is not a whole number, round it down to the next lowest whole number

If the result of this calculation is less than 50, the employer is not considered an Applicable Large Employer for the current calendar year. If the result is 50 or more, the employer is an Applicable Large Employer for the current calendar year.

[Note that transition relief was provided to qualifying employers with an average of 50-99 full-time and full-time equivalent employees on business days during 2014, so that they will not be assessed a penalty in 2015.]

The first step to counting employees is identifying full-time and full-time equivalent employees. A full-time employee, with respect to a calendar month, is an employee who works an average of at least 30 hours per week, or 130 hours in a calendar month. A full-time equivalent employee isn’t an actual person. Rather, it’s a term used to describe the combination of all non-full-time employees who are counted as the equivalent of a full-time employee.

The number of FTEs for each calendar month in the preceding calendar year is determined by calculating the aggregate number of hours of service for that calendar month for non-full-time employees (but not more than 120 hours of service for any employee) and dividing that number by 120. Fractions may be rounded to the nearest one hundredth.

For example, assume that during each calendar month of 2015, Employer W has 25 employees averaging 35 hours of service per week and 40 employees each of whom averages 90 hours of service per calendar month. Each of the 25 employees averaging 35 hours of service per week count as one full-time employee, so Employer W has 25 full-time employees for each calendar month in 2015.

To determine the number of FTEs for each calendar month, combine the hours of service of the 40 non-full-time employees (40 employees x 90 hours) and divide that number by 120. This calculation (40 x 90 = 3,600, and 3,600 / 120 = 30) shows that Employer W has 30 FTEs for each calendar month in 2015. Since Employer W had 55 full-time and full-time equivalent employees during each calendar month in 2015, Employer W will be considered an Applicable Large Employer for 2016.

The regulations contain a number of specific rules, methods and exceptions that must be considered when counting employees. For example, in some cases an employer may not have to include seasonal workers when counting employees. Given the complexity of some of these rules, methods and exceptions, employers should consult with an attorney to make sure they’ve counted correctly.

At Setnor Byer Insurance & Risk, we are committed to guiding you through the changes coming in 2014. Check back with us periodically for future informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

SEC Commissioner Emphasizes the Importance of Cyber Insurance

Cyber risks are a growing concern among businesses of all kinds. In a recent speech given at the New York Stock Exchange, SEC Commissioner Luis A. Aguilar emphasized that cyber security should be a number one priority of businesses and regulators alike and warned companies, and more specifically their directors, to “take seriously their obligation to make sure that companies are appropriately addressing those risks.”

The New York Stock Exchange’s Governance Services Department hosted the Cyber Risks and the Boardroom Conference where Commissioner Aguilar expounded on the responsibility of corporate directors to consider and address the risk of cyber-attacks. The commissioner made it clear that despite all efforts to prevent a cyber-attack, companies should prepare “for the inevitable cyber-attack and the resulting fallout.”

In 2014, there have been high-end data breaches of large companies, with data, personal records and financial information stolen and sold on the black market before the company has even discovered a breach occurring. In May, eBay discovered that hackers had infiltrated their system and stole personal records of 233 million users.

Domino’s Pizza was also hacked, with over 600,000 Belgian and French customers’ records affected. These hackers demanded $40,000 in ransom from the pizza chain in exchange for not selling the data, which included names, addresses, emails, and phone numbers.

Just last week, August 5, 2014, the largest data breach in history occurred when a Russian crime ring stole more than 1.2 billion Internet usernames and passwords.

While many companies are concerned about the threat of cyber-attacks, and have implemented security protocols to reduce them, it is clear to security experts that all vulnerabilities are nearly impossible to eliminate. For this reason, a growing segment of companies that collect personal data are including Data Breach and Cyber Peril insurance in their risk financing strategy. These insurance contracts are complex and vary by insurer, but are worth considering given the financial costs associated with notification expenses, litigation and harm to one’s reputation.

If you have any questions or would like to discuss your insurance options, please contact us.

If you’d like to subscribe to our weekly newsletters please click here

Settling Insurance Claims: Good Faith or Bad Faith?

Insurance companies have a general duty of good faith when settling the claims of their policyholder. This duty of good faith can come from statute, common law, or both. For example, in addition to having a common law duty of good faith, insurance companies in Florida have a statutory duty to act fairly and honestly toward their insureds. Insurance companies that fail to act in good faith may end up in court defending a claim for bad faith.

Contrary to what many believe, it’s not bad faith for an insurance company to deny a claim that is not covered under a policy or to defend a claim subject to a reservation of rights. So what does it mean to act in good faith? According to one court, the duty of good faith requires insurance companies to investigate the facts, give fair consideration to settlement offers that are not unreasonable, and settle, if possible, where a reasonably prudent person, faced with the prospect of paying the total recovery, would do so.

Those damaged by an insurance company’s failure to act in good faith may be able to sue the insurance company for bad faith. Bad faith claims can be first-party or third-party.

A first-party bad faith claim occurs when an insurance company is sued by its insured for refusing to settle the insured’s own claim in good faith. First-party claims typically involve allegations that the insurer improperly denied coverage, underpaid a loss or delayed payment without adequate justification. A common example of a first-party bad faith claim is when an insured is involved in an accident with an uninsured motorist and does not reach a settlement with his or her own uninsured motorist liability carrier for costs associated with the accident.

A third-party bad faith claim arises when an insured is exposed to liability in excess of insurance coverage because the insurer failed in good faith to settle a third party’s claim against the insured within policy limits. Third-party bad faith claims often arise in situations where there is clear liability on the part of the insured, severe injury to the third party, and minimal policy limits available.

Assume, for example, an insured with $100,000 of automobile liability coverage runs a red light and injures a pedestrian. Despite the pedestrian’s significant injuries and the insured’s clear fault, the insurance company rejects the pedestrian’s reasonable $90,000 settlement offer. The pedestrian goes to court and is awarded $200,000 in damages. By failing to act in good faith and settle the case within the $100,000 policy limit, the insured is liable for the excess judgment amount of $100,000.

In this example, the insured could file a third-party bad faith claim against its insurance company. The injured pedestrian may also be able to sue the insurance company, either directly if permitted by applicable law, or through an assignment of the insured’s rights. Note that in some jurisdictions insurance companies are entitled to notice before a lawsuit can be filed. In Florida, for example, those wanting to file a bad faith claim must give the insurance company 60-days’ notice before filing a lawsuit.

The claims settlement process can be long, complicated and stressful, even when the insurance company is handling the process in good faith. Since bad faith claims, particularly those involving third parties, can be very complex, it helps to have a reputable and experienced insurance agent to guide you through the claims process.

If you have any questions or would like to discuss your insurance options, please contact us.

If you would like to subscribe to our newsletters please click here.

A Contract’s Fine Print: Find the Devil in the Details

Contracts are an essential part of doing business. Regardless of size or industry, contracts with customers, vendors, suppliers, service providers or independent contractors are an important part of a business’s operations. While good contracts can help manage risk and maintain good working relationships, bad contracts can be incredibly harmful. This is why every business must proceed cautiously when negotiating and signing contracts.

Ideally, an attorney will be consulted when negotiating or signing contracts. The reality, however, is that many businesses handle their own contracts. Though it may be easy for some to identify and understand a contract’s main provisions, like cost, volume, part numbers, etc., the devil is in the details, which, in the case of contracts, is the fine print.

Every provision in a contract has a purpose, including those found in the fine print. Despite being underemphasized, they are often important when defining a contractual relationship, particularly when things go wrong. The following provisions, for example, are not only commonly used, but commonly overlooked.

Forum (Jurisdiction) Selection: A contract may require that any lawsuits involving the contract be filed in a specific forum or jurisdiction (county, state, country). This may not be a problem if a business is located in the jurisdiction specified in the contract. However, it may be a huge problem if, for example, a Florida business is required to file a lawsuit in Alaska. Despite having the legal right to enforce the contract, the increased complexity and cost of filing a lawsuit in another jurisdiction makes it practically impossible for many businesses to do so, particularly when relatively small amounts of money are involved.

Choice of Law: Similar to a forum selection clause, a choice of law provision specifies which state’s law will be used to interpret and enforce the contract. These clauses can be significant because laws may vary from state to state. For example, one state may have more favorable consumer protection laws, while another makes it more difficult to recover damages. It is important to know if and how a choice of law provision may affect any contractual rights or remedies.

Integration (Merger) Clause: Contracts typically contain a provision stating that the contract represents the full and final agreement and supersedes any other agreements, oral or written. With an integration clause, any verbal or written conversations, brochures, promises, representations or statements that are not included in the contract are not part of the contract. This may become an issue when a business is not receiving what the salesperson promised before signing the contract. Expectations, obligations and requirements must be included in the contract to be enforceable under the contract.

Assignment: A contract may allow one or both parties to assign their rights, duties or obligations to a third party. This can create a problem if there is an expectation that a specific person or company will be performing under the contract. If, for example, a business wants only a specific vendor to do a job, the contract must state that the vendor cannot assign its obligations under the contract to someone else. Otherwise, a business may find that the person they contracted with isn’t the person they end up working with.

Evergreen Clause: Contracts are typically entered into for a specific period of time (term). A contract with an evergreen clause will automatically renew for a new term unless notice of termination is given by either party, usually within a specific period of time. For example, a one year contract will automatically renew for another year unless written notice of termination is given at least 60 days before the end of the yearly term. Businesses that fail to discover and comply with an evergreen clause may be stuck in a contract they no longer need or want.

Dispute Resolution: Contracts may require that disputes be resolved through arbitration rather than by filing a lawsuit. Depending on the nature of the contract, this requirement can significantly affect the resolution of disputes and the apportionment of damages.

Indemnification Clause: Indemnification clauses are used to allocate risk and responsibility among the parties to a contract by requiring one party to compensate the other for specific liabilities or losses arising out of the contract. Since these clauses commonly require a party to assume liability that would not otherwise exist, they must be reviewed carefully and understood completely. Indemnification clauses often end up being the most significant provision in a contract when something goes wrong.

Insurance Requirements: Many contracts include specific insurance requirements. For example, a contract may require a party to have general liability or workers’ compensation insurance, or it may require that one party be given Additional Insured status under the other party’s insurance policies. Contracts often require proof of insurance before work can begin or payment is made. It is important to identify and comply with any contractual insurance requirements.

Despite the benefits of using an attorney to negotiate and review contracts, particularly complex or high-value contracts, many businesses take a do-it-yourself approach. Nevertheless, given the increased risk of harm caused by bad contracts, businesses should never sign a contract without reading and understanding every provision, including those in fine print.

If you have any questions or would like to discuss how Setnor Byer Insurance & Risk can help identify and protect against various business risks, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Is Your Self Storage Facility Prepared for the Next Disaster?

Preparation is the key to surviving a natural or human-caused disaster. Nevertheless, a survey by the Ad Council found that 62% of respondents did not have an emergency plan in place for their business. Since up to 40% of businesses affected by a natural or human-caused disaster never reopen, self storage facilities intent on surviving the next disaster must be prepared.

Natural or human-caused disasters can affect a self storage facility’s operations and finances by disrupting critical business functions and processes. During and after a disaster, a self storage facility may experience:

  • Lost or delayed sales and income
  • Increased expenses
  • Customer dissatisfaction
  • Repair and replacement costs

To prevent or limit the damage from a disaster, the Federal Emergency Management Agency (FEMA) recommends developing a preparedness program using these five steps.

Program Management. An effective preparedness program requires leadership, commitment and financial support. Beyond any applicable laws or regulations that may establish minimum standards, each self storage facility must determine how much risk it can tolerate and take steps to minimize the likelihood of exceeding that risk.

A preparedness policy should be developed by management and distributed to staff. The policy should define roles and responsibilities. Select employees should be given the authority to develop the program and keep it current. The policy should also define the general goals and objectives of the preparedness program, such as:

  • Protecting the life and safety of employees, tenants, visitors, etc.
  • Protecting facilities, physical assets and electronic information
  • Minimizing interruptions or disruptions of business operations
  • Protecting the facility’s brand, image and reputation

Planning. Preparing for a disaster requires planning. During the planning process, self-storage facilities should consider all threats, not just those that are most likely to occur. Special attention should be given to threats that are classified as probable and threats that could cause injury, property damage or business disruption.

Implementation. Implementation of a preparedness program includes identifying and assessing resources, writing plans and developing a system to manage incidents. An effective preparedness program should address:

  • Resource and incident management
  • Emergency response
  • Crisis communications
  • Business continuity
  • Information technology
  • Training

Testing and Exercises. An effective preparedness program requires testing and exercises to:

  • Train personnel
  • Reinforce knowledge of procedures, facilities, systems and equipment
  • Improve individual and organizational performance
  • Identify strengths
  • Reveal weaknesses and gaps

Program Improvement. Self storage facilities must take advantage of every opportunity to improve their preparedness program. After an actual incident, a critique should be conducted to assess effectiveness. Lessons should also be learned from incidents occurring elsewhere.

An effective preparedness program can control a number of risks associated with natural or human-caused disasters. An effective insurance program is needed to protect against those risks that cannot be controlled. Since self storage facilities face unique risks, it helps to have an insurance program that is specifically designed for the self storage industry.

If you would like more information about protecting your self storage facility, please contact.

A Narrow View of Cyber Risks Can Leave You Overexposed

Recent, high-profile incidents show that every business is at risk of suffering a data security breach, regardless of size, resources or sophistication. To combat the risk, many organizations are taking steps to identify and secure organizational vulnerabilities, such as wireless networks, laptop computers, and even the office copy machine. However, a report by Zurich Insurance and the Atlantic Council suggests organizations must look beyond their own operations to truly recognize their exposure to cyber risks.

Businesses are increasingly using the internet and information technology functions to expand their operations and create opportunities. They are also increasing their exposure to external cyber risks that are often beyond their control. This is why businesses need to expand their horizon when evaluating and managing cyber risks. According to the report, businesses must consider these seven aggregations of cyber risk to fully understand their exposure.

  • Internal IT Enterprise: Risks associated with an organization’s internal IT (hardware, software, servers, processes).
  • Counterparties and Partners: Risks from dependence on or interconnection with outside organizations.
  • Outsource and Contract: Risks from contractual relationships with third-parties (IT and cloud providers, legal, accounting).
  • Supply Chain: Risks to supply chains in the IT sector and cyber risks to traditional supply chains and logistics.
  • Disruptive Technologies: Risks caused by unseen effects from, or disruptions to new technologies (smart grids, embedded medical devices, driverless cars), or existing but poorly understood technologies (internet, networks).
  • Upstream Infrastructure: Risks from disruptions to infrastructure relied on by economies and societies (electricity, telecommunications, financial systems).
  • External Shocks: Risks from incidents outside the system (international conflicts, acts of terrorism, malware pandemic).

Despite the external risks resulting from increased outsourcing and interconnectivity, businesses are urged to continue taking steps to control their internal cyber risks. According to the report, there are a relatively small number of actions that every organization can take to protect against most cyber risks, such as:

  • Implementing applicationwhite-listing to prevent systems from running programs that have not been pre-approved, such as malicious software
  • Using standard secure system configurations to keep systems simple and easier to defend.
  • Installing patch software for systems and applications within 48 hours of being released by the software manufacturers
  • Controlling administrative privileges to only those who need it and can be trusted with it

The report also recommends that businesses:

  • Expand their risk horizon to consider the seven aggregations of risk
  • Have cyber insurance, particularly for third-party risks associated with data breaches or business interruption
  • Deal with cyber risks at the board-level

Finally, the report states that resiliency is the key in a world where the number of cyber risks is increasing and the ability to control them is decreasing. To survive cyber threats and limit their impact, the report recommends that every business:

  • Incorporate redundancies in critical systems
  • Implement incident response and business continuity plans
  • Utilize scenario planning and exercises to stay prepared

As we have seen, nothing is foolproof, so businesses should use insurance to protect against cyber risks. There are a number of cyber liability products that protect against privacy injuries, such as identity theft, and that cover the cost of complying with various data breach notice laws.

Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against cyber risks, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

Shopping for Homeowners Insurance Video from Tower Hill® Insurance

For most people, their biggest purchase is their home. Following the four must-dos for shopping for homeowners insurance can help you find the best value and the best protection for your home:

  • Get advice from a professional agent who will take the time to guide you through the selection process
  • Shorten your list to the best companies, those with a great reputation for financial strength, claims handling, and customer service.
  • Compare multiple quotes for similar coverages, and ask your agent to explain any differences in coverages.
  • Tailor your policy to your wants and needs, as well as your tolerance for risk. Make sure price is not the primary factor.

The video below does a great job discussing these items in further detail.

https://youtu.be/us4P2QNnI70

If you would like to learn more about this coverage please contact us.

Summary Plan Descriptions under ERISA

The Employee Retirement Income Security Act (ERISA) is a federal law that sets minimum standards for most voluntarily established employee pension and welfare plans in the private sector. To protect individuals in these plans, ERISA requires plan administrators, which are oftentimes the employers, to provide plan participants and their beneficiaries with a Summary Plan Description (SPD).

SPDs are used to give plan participants and beneficiaries important information about pension plans, like 401(k) and profit sharing plans, and welfare plans, like group health, disability and pre-paid legal plans. SPDs provide information about the plan, what benefits are available under the plan, the rights of participants and beneficiaries under the plan, and how the plan works.

SPDs must generally be given to each plan participant and each beneficiary receiving benefits under the plan within 90 days after first becoming covered by the plan. Under ERISA, SPDs must generally:

  • Identify the plan name, plan number and employer identification number (EIN)
  • Describe the type of plan (ex. 401(k), profit sharing, group health, disability)
  • Describe the type of plan administration
  • Provide contact information for the plan administrator and service of process
  • Describe the plan’s eligibility requirements
  • Describe circumstances which may result in disqualification, ineligibility, denial, loss, forfeiture, suspension or reduction of benefits
  • State the date of the plan’s fiscal year
  • Describe the procedures governing claims for benefits, applicable time limits and remedies if claims are denied
  • Describe provisions governing termination of the plan
  • A statement of rights available to plan participants under ERISA

SPDs for employee pension plans must include additional information, such as:

  • The plan’s normal retirement age
  • A description of benefits, eligibility, vesting and accrual
  • A statement about whether the plan is covered by termination insurance from the Pension Benefit Guaranty Corporation
  • Source of contributions to the plan and the methods used to calculate contributions amounts

Similarly, SPDs for employee welfare plans must also include additional information, such as information about:

  • Cost-sharing provisions, including costs of premiums, deductibles, coinsurance and copayment requirements
  • Annual or lifetime caps or limits on benefits
  • Coverage for preventive services
  • Coverage for drugs, medical tests, devices and procedures
  • The use of network providers, the composition of provider networks and whether, and under what circumstances, coverage is provided for out-of-network services
  • Conditions or limits on the selection of primary care providers or providers of specialty medical care
  • Conditions or limits applicable to obtaining emergency medical care
  • Preauthorization requirements or utilization review as a condition to obtaining a benefit or service

Since comprehension is the key, SPDs must follow strict style and formatting requirements. For example:

  • SPDs must be written in a manner calculated to be understood by the average plan participant
  • SPDs must be sufficiently comprehensive to apprise the plan’s participants and beneficiaries of their rights and obligations under the plan
  • SPDs must not be formatted in a way that misleads, misinforms or fails to inform participants and beneficiaries
  • Advantages and disadvantages of the plan must be presented without either exaggerating the benefits or minimizing the limitations
  • Exceptions, limitations, reductions, and restrictions of plan benefits cannot be minimized, rendered obscure or otherwise made to appear unimportant (style, caption, printing type and prominence must be the same as that used to describe plan benefits)

In fulfilling these requirements, plan administrators must consider the level of comprehension and education of typical participants in the plan and the complexity of the terms of the plan. In most cases, this will usually require limiting or eliminating technical jargon and long, complex sentences, and using clarifying examples, illustrations, clear cross references and a table of contents.

Unlike the general descriptions provided in this article, the SPD requirements are highly technical and very specific. To avoid violations, employers must confirm strict compliance with ERISA’s SPD requirement. If you have questions about your employee welfare plans, or if you would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Loss of Business Income Caused by Civil Authority Action

Public safety concerns may prompt civil authorities to take action to protect people and property. For example, a governor can issue a mandatory hurricane evacuation, a mayor can close roads during inclement weather, the police can enforce curfews during riots, or a fire department can restrict access to a neighborhood during a gas leak. Though these actions may be good for public safety, they may be bad for business.

In some cases, a Business Interruption policy’s Civil Authority coverage may offset income losses suffered during a civil authority action. Business Interruption, also known as Business Income, is a type of commercial insurance that protects against loss of income when a covered loss causes a business to reduce or suspend its operations. Civil Authority coverage is an additional protection that may be included in a Business Interruption policy.

A typical Civil Authority clause states: We will pay for the actual loss of Business Income you sustain and necessary Extra Expense caused by action of civil authority that prohibits access to the described premises due to direct physical loss of or damage to property, other than at the described premises, caused by or resulting from any Covered Cause of Loss.

Under this framework, the Civil Authority provision will not provide coverage unless all four of the following conditions are met.

  • The loss of business income must be caused by the civil authority action. There must be a direct relation between a civil authority action and a loss of income.
  • The civil authority action must prohibit access to the insured business. Courts have held that access must be completely prohibited in order to satisfy this requirement. A civil authority action that makes travel to an insured’s business difficult or inconvenient is not enough to trigger Civil Authority coverage.
  • The civil authority action must be caused by direct physical loss of or damage to property away from the insured’s premises. Unlike Business Interruption coverage, which requires loss or damage to the insured’s property, Civil Authority coverage requires loss or damage to property somewhere else. For example, an explosion at a nearby warehouse causes the fire department to shut down the area surrounding an insured business for two weeks.
  • It’s worth noting that claims for Civil Authority coverage often fail to meet this requirement because the decision to take civil authority action is not caused by direct property damage, but by the desire to prevent it. Courts have denied coverage for losses caused by civil authority actions that were designed to prevent future damage rather than address existing property damage, such as pre-hurricane evacuation orders and curfews imposed to prevent looting and rioting. According to one court, Civil Authority coverage is designed to address situations involving civil authority action that is taken after damage occurs.
  • The loss or damage to property away from the insured’s premises must be caused by or result from a loss that is covered under the insured’s policy. A business without hurricane insurance, for example, would not be covered if a civil authority action was caused by hurricane wind damage.

Though many aspects of Civil Authority coverage are relatively standard, there are some variations among insurers and policy forms. For example, some policies provide that coverage will not begin until 24 hours after the civil authority action was taken, and others require 72 hours. The duration of Civil Authority coverage may also be different.

Given the complexity of Civil Authority coverage under a Business Interruption policy, an experienced and reputable insurance agent should be consulted to help identify needs and evaluate options.

If you have any questions or would like to speak with one of our Risk Management Professionals, please contact us.

If you would like to subscribe to our newsletters please click here.

Florida’s New Data Breach Notice Law

Florida has a new law to combat the recent surge of data security breaches involving sensitive personal information. On July 1, 2014, Florida’s current data breach notification statute will be replaced by the Florida Information Protection Act of 2014 (Act). Though similar to Florida’s current statute, the Act makes some significant changes that businesses must incorporate into their data security practices and procedures.

Under the Act, sole proprietors, partnerships, corporations, trusts, estates, cooperatives, associations and other commercial entities that acquire, maintain, store or use personal information (Covered Entities) are required to take reasonable measures to protect and secure such personal information. The Act broadens the definition of Personal Information to include:

  • An individual’s first name or first initial and last name in combination with that individual’s social security number, driver license or identification card number, passport number, military identification number, or other similar number issued on a government document used to verify identity. (Broader)
  • Financial account, credit and debit card numbers, in combination with any security code, access code or password.
  • Information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional. (New)
  • An individual’s health insurance policy number or subscriber identification number and any unique identifier used by a health insurer to identify the individual. (New)
  • A user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account. (New)

Like the current statute, Personal Information does not include information that is encrypted, secured or modified by any other method or technology that removes personally identifying elements or that otherwise renders the information unusable.

In the event of a breach, Covered Entities must follow one or more of the Act’s various notice requirements. The Act generally defines a breach as unauthorized access of electronic data containing personal information. Covered Entities must notify each individual in Florida whose Personal Information was, or is reasonably believed to have been, breached no later than 30 days after the Covered Entity determines that a breach occurred or has reason to believe a breach occurred. Under the current statute, Covered Entities had 45 days to provide notice.

This notice, which may be sent by mail or e-mail, must include:

  • The date, estimated date or estimated date range of the breach
  • A description of the Personal Information that was or may have been accessed during the breach
  • Contact information that individuals can use to inquire about the breach

If a Covered Entity is required to notify more than 1,000 individuals at a single time, the Covered Entity must also provide notice to all national consumer reporting agencies. If a breach affects 500 or more individuals in Florida, the Department of Legal Affairs must be notified no later than 30 days after the Covered Entity determines that a breach occurred or had reason to believe a breach occurred. This is a new notice requirement.

If a Covered Entity uses a third-party vendor to maintain, store or process Personal Information, then that third-party agent must notify the Covered Entity no later than 10 days after the third-party agent determines that a breach occurred or had reason to believe a breach occurred. Though a third-party agent may provide the required notices, the Covered Entity is ultimately responsible for compliance with the Act.

The Act also requires Covered Entities and their third-party agents to take all reasonable measures to dispose, or arrange for the disposal, of customer records containing Personal Information within its custody or control when they are no longer retained. Disposal shall involve shredding, erasing, or otherwise modifying the records to make Personal Information unreadable or undecipherable through any means.

Unlike the general descriptions provided in this article, the Act is highly technical and very specific. Though the Act does not create a private cause of action, civil penalties of up to $500,000 should be enough motivation for Covered Entities to learn more about Florida’s new law and ways to limit the new risks with insurance.

If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to subscribe to our newsletters please click here.