Protecting Sensitive Data: How Secure is Your Wireless Network?

In previous articles we discussed how laptop computers and the office copy machine increase the risk of data security breaches. Another significant risk to an organization’s sensitive data is the wireless network. Since today’s workplaces are increasingly “going wireless,” the Federal Trade Commission recommends taking the following steps to protect wireless networks.

Understand how a wireless network works. Going wireless generally requires connecting an internet access point to a wireless router, which sends a signal through the air, sometimes as far as several hundred feet. Any computer within range can pull the signal from the air and access the internet. Unless precautions are taken, others can “piggyback” on the network or access information on the computer.

Use encryption. Encryption encodes the information so that it’s not accessible to others. It is the most effective way to secure a network. Two main types of encryption are available: Wi-Fi Protected Access (WPA) and Wired Equivalent Privacy (WEP). WPA2 is strongest so it should be used whenever possible. Since some older routers use the less secure WEP encryption, consider upgrading to a newer, more secure router. Note that wireless routers often come with the encryption feature turned off, so be sure to turn it on.

Use anti-virus and anti-spyware software. Since hackers are constantly developing new ways to attack computers and networks, security software is necessary. This software needs to be updated periodically so systems should be set to update automatically whenever possible.

Change the name of the router. The name of the router (often called the service set identifier or SSID) is likely to be a standard, default ID assigned by the manufacturer. Change the name to something private and unique.

Change the router’s pre-set password. Manufacturers typically assign a standard default password to a wireless router. Default passwords should be changed. Visit the manufacturer’s website to learn how to change the password.

Limit access to the wireless network. Every computer that is able to communicate with a network is assigned a unique Media Access Control (MAC) address. Wireless routers usually have a mechanism to allow only devices with particular MAC addresses to access the network. However, since MAC addresses can be mimicked, don’t rely on this step alone.

Turn off wireless network when it’s not being used. A wireless network cannot be accessed when it is turned off.

Be cautious when using a public wireless network. Many cafés, hotels, airports and other public places offer wireless networks for their customers to use. These “hot spots” are convenient, but they may not be secure.

Organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you’d like to subscribe to our weekly newsletters please click here.

New Deadline for Affordable Care Act’s Employer Notice Requirement

Under the Affordable Care Act (ACA), employers are required to give employees written notice about their options for purchasing health insurance through Affordable Insurance Exchanges (Health Insurance Marketplaces). Though the original March 1, 2013 deadline was delayed, the Department of Labor (DOL) recently announced the new deadline for employers to begin giving this notice.

Beginning October 1, 2013, employers must provide the required ACA notice to new employees at the time of hiring. In 2014, the DOL will allow employers to satisfy this requirement by providing the notice within 14 days of an employee’s start date. An employer’s current employees must receive their notice no later than October 1, 2013.

Notice must be given to each employee regardless of their plan enrollment status or their part-time or full-time status. Employers are not required to provide a separate notice to dependents or other individuals who are or may become eligible for coverage under the plan. The notice, which must be understood by the average employee, may be provided by first-class mail or, in some instances, electronically.

The ACA’s notice requirement applies to employers covered by the Fair Labor Standards Act (FLSA). The FLSA generally applies to employers with one or more employees who are engaged in, or produce goods for, interstate commerce. Also the FLSA typically does not cover enterprises with less than $500,000 in annual dollar volume of business. However, the FLSA does cover specific entities regardless of their dollar volume of business, including hospitals, preschools, elementary and secondary schools, institutions of higher education, and federal, state and local government agencies.

To help employers satisfy their notice requirement, the DOL has prepared two model notices. There is one model notice for employers who offer a health plan to some or all employees, and another model notice for employers who do not offer a health plan. Employers may also use modified versions of these model notices as long as the required information is present.

If you would like to learn more about your obligations under the Fair Labor Standards Act, click here. If you would like information about insuring against FLSA claims, click here.

If you would like to subscribe to our newsletters please click here.

Are You Ready for the 2013 Hurricane Season?

For those living or working in areas at risk of experiencing a tropical storm or hurricane, June 1st rarely passes unnoticed. At Setnor Byer Insurance & Risk, we understand that preparing for Hurricane Season is rarely easy and often stressful. We also understand that a lack of awareness and preparation can make a bad situation worse, and that the best way to limit the risk is to take preventative steps now.

The National Oceanic and Atmospheric Administration (NOAA) estimates a 70 percent probability that the 2013 Hurricane Season will bring:

  • 12 – 18 Named Storms (winds of 39 mph or higher)
  • 6 – 10 Hurricanes (winds of 74 mph or higher)
  • 3 – 6 Major Hurricanes (winds of 111 mph or higher)

These estimates indicate that activity will exceed the seasonal average of 11 named storms, six hurricanes and two major hurricanes.

According to NOAA administrator Jane Lubchenco, Ph.D., “the United States was fortunate last year. Winds steered most of the season’s tropical storms and all hurricanes away from our coastlines…However we can’t count on luck to get us through this season. We need to be prepared, especially with this above-normal outlook.”

Though different situations call for different measures, the following tips can assist you in developing your own plan for dealing with the 2013 Hurricane Season.

Before the Storm

  • Monitor the news to allow time to prepare.
  • Identify all tools and equipment that will be needed to secure property before a storm and limit the damage after the storm (flashlights, batteries, caulking, tarpaulins, sandbags, cutting and fastening equipment, etc.).
  • Clear drains and downspouts to minimize the risk of flooding.
  • Move items inside.
  • Unplug electrical equipment and move property away from windows.
  • Check and secure all documents and records.
  • Take or update photographs of real and personal property.
  • Gather insurance policies and agent/insurer contact information.

After the Storm

  • Only after it has been declared safe to do so, look for any property damage and take reasonably necessary steps to protect against any further damage.
  • Report fallen power lines to power company immediately–stay away from them!
  • Check exterior walls and roof for damage from wind, rain, flying objects and rising waters (flood insurance).
  • Check all interior perimeter walls, floors, and roof for leaks and water damage.
  • Document all damage with photographs and video.
  • Prepare detailed damage reports.
  • Call your insurer or agent as soon as possible to report damage.

While preparing for Hurricane Season is never easy, our team of experienced and responsive professionals can work with you to make sure that your home, cars and property are protected.

For over 30 years, Setnor Byer Insurance & Risk has been helping our clients prepare before the storm and rebuild after. Our clients benefit from a Hurricane Insurance Program that includes an emergency and after hours claims service hotline in addition to guidance for disaster planning.

If you would like more information about how Setnor Byer Insurance & Risk can help you prepare for the 2013 Hurricane Season, contact us.

If you would like to subscribe to our newsletters please click here.

Prevent Data Security Breaches by Protecting Laptop Computers

While laptop computers can increase workforce productivity, they also increase the risk of harmful and costly data security breaches. Since a lost or stolen laptop can jeopardize sensitive information, the Federal Trade Commission recommends the following preventative measures to protect laptop computers and the personally identifying information it contains.

Treat laptops like cash. People don’t leave their cash unattended, not even for a minute. When traveling, cash isn’t usually checked with luggage and it isn’t left in the backseat of the car. Keep the same watchful eye on the laptop as you would on cash.

Lock laptops with a security cable. Whether in the office, a hotel or some other public place, a laptop security cable should always be used. Attach it to something immovable or to a heavy piece of furniture, such as a table or a desk. Security cables work similarly to bike locks. You can purchase them at Office Depot, Amazon, Staples, etc.

Be on guard in airports and hotels. The confusion and shuffle of security checkpoints can be fertile ground for theft. Keep an eye on the laptop when going through airport security. Hold onto it until the person in front of you has gone through the metal detector, and wait for it to emerge on the other side. When staying in a hotel overnight, a security cable may not be enough. Store the laptop in the room safe. If leaving a laptop attached to a security cable in a hotel room, consider hanging the “do not disturb” sign on the door.

Consider an alarm. Depending on security needs, a laptop alarm can be an excellent security device. Some laptop alarms sound when there’s unexpected motion, or when the computer moves outside a specified range. A program that reports the location of stolen laptops upon being connected to the internet can also provide additional security.

Consider carrying laptops in something more discreet than a laptop case. When taking a laptop on the road, carrying it in a computer case may advertise what’s inside. Consider using a suitcase, a padded briefcase, or a backpack instead.

Don’t leave laptops unattended. Though colleagues may seem trustworthy, avoid the temptation to leave laptops unattended, even for a minute. Laptops should be taken whenever possible. If taking the laptop is not an option, use a cable to secure it to a table or desk.

Don’t leave a laptop in a car. Parked cars are a favorite target of laptop thieves. If leaving a laptop in a car is the only option, keep it locked up and out of sight.

Don’t put laptops on the floor. Whether at a conference, coffee shop, or registration desk, laptops should not be left on the floor. If it is necessary to put the laptop down, place it between your feet or up against your leg so you remember that it’s there.

Don’t keep passwords with the laptop or in its case. Remembering strong passwords or access numbers can be a challenge. However, leaving them in the laptop carrying case or on the laptop is like leaving keys in a car. In the event a laptop is lost or stolen, don’t make it easy for a thief to access sensitive information stored on the device.

Create ‘Uncrackable’ Passwords

The best passwords are over 6 characters, include upper and lowercase letters, and use numbers and symbols. Passcreator.com can generate a password that is nearly impossible to crack. However, this would mean you probably won’t remember it on your own. So, if you have to write any of your passwords down keep that document separate from your laptop. You can write them down on a piece of paper and keep them in your wallet. You can store them on Google Drive. Just be sure to password protect the doc! You can also store them on an Excel spreadsheet and protect the workbook to make it harder for a hacker to view its contents.

Encrypt sensitive data. The consequences of a lost or stolen laptop can be minimized by encrypting the data stored on the device so that it cannot be accessed by anyone without the proper authorization.

Organizations should also consider protecting against data security breaches with insurance. Various cyber liability products are available to protect against privacy injuries, such as identity theft, and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that adequate coverage is obtained. If you would like to learn more about insuring against data security breaches, contact us.

If you would like to subscribe to our newsletters please click here.

Pushing Back the Clock on the Affordable Care Act

On January 1, 2014, a number of the Affordable Care Act’s (ACA) more significant provisions will go into effect. This means that many employers renewing their health plans on or after January 1st can expect big changes to their plans and, most likely, their premiums. However, some small group employers (typically those with no more than 50 employees) may have the option of delaying these expected changes with off-cycle renewals.

Off-cycle renewals allow employers to change the renewal date of their health plans. Since some of the ACA’s 2014 changes do not apply until the renewal date, health plans renewing earlier in the year will experience premium increases sooner than those renewing later in the year. Regardless of a plan’s natural renewal date, an off-cycle renewal can change a plan’s renewal date to late 2013, thereby effectively delaying implementation of the changes, and the expected premium increase, until late 2014.

With off-cycle renewals, employers may be able to delay the impact of several ACA provisions that are expected to increase premiums, such as:

  • Premium Rating Restrictions (Community Rating). Restrictions on the ability of health insurance issuers to determine premium rates based on health status, gender or other factors. Only age, rating area, family coverage and tobacco use may be used to vary premiums.
  • Essential Health Benefits Requirement. Health plans offered in the small group markets must cover all of the Essential Health Benefit Categories.
  • Guaranteed Availability of Insurance. Requires guarantee issue and renewability of health insurance regardless of health status.
  • Pre-Existing Condition Exclusions. Insurers will not be able to exclude employees from coverage based on pre-existing conditions.
  • Cost-Sharing Restrictions. Limitation on annual deductibles and maximum out-of-pocket expenses.
  • Elimination of Annual Limits on Insurance Coverage. Though lifetime limits on most benefits have been prohibited since 2010, beginning January 1, 2014, annual dollar limits will also be prohibited.

Whether an off-cycle renewal is an option for a particular employer depends on several factors.

  • Size of Employer. Off-cycle renewals are currently being offered to small group employers, which are typically employers with no more than 50 employees, though some employers with up to 100 employees may also qualify.
  • Insurance Company. Insurers decide whether they want to offer off-cycle renewals and to whom. Some insurance companies have decided to not offer off-cycle renewals and other are only making them available to specific clients.
  • Natural Renewal Date. Plans that naturally renew late in the year may not experience sufficient benefits to justify an off-cycle renewal.

Since an off-cycle renewal essentially continues an employer’s current plan, various changes required by the ACA will not affect the premium. However, plans will still be subject to their insurer’s regular medical underwriting process, so employers may still experience a premium increase. Continuing under a current plan also means that employees will not have access to various coverage provisions required by the ACA.

Though there doesn’t seem to be anything in the ACA expressly prohibiting off-cycle renewals, federal regulatory agencies may decide to address and possibly prohibit the practice of manipulating renewal dates. Employers must also ensure compliance with various laws that may be implicated by changing a plan’s renewal date, such as the Internal Revenue Code and ERISA.

Those considering an off-cycle renewal must act soon. Many insurance companies are imposing strict deadlines by which employers must request an off-cycle renewal. Since this can be a lengthy and complicated process, now is the time to get started.

If you would like to see if your health plan would benefit from an off-cycle renewal, please contact us.

If you would like to subscribe to our newsletters please click here.

Calculating Workers Compensation Insurance Premiums

Workers’ Compensation (WC) provides medical, disability, rehabilitation or death benefits to employees who have suffered a job-related injury or illness. Employers are generally required by their state’s law to provide WC coverage to employees. Since most employers purchase insurance to satisfy this statutory obligation, it is important to understand how WC insurance premiums are calculated.

The formula for calculating the starting WC premium is (Payroll / 100) x (Premium Rate). To understand this formula we need to discuss three elements that play a big part in calculating the premium.

Payroll

The premium for WC insurance is based on an employer’s payroll, which is generally defined to include the total remuneration paid by an employer. Payroll typically includes wages, salaries, commissions, bonuses and paid time off, and typically excludes tips, severance, active military duty pay and employee discounts. Employers should check state-specific requirements, including the treatment of executive officers, when calculating payroll for WC insurance purposes.

Classification (Class) Code

Insurance companies use class codes to assign premium rates to specific workplaces based on the risks associated with a particular kind of work. Most states use the classification codes developed by the National Council on Compensation Insurance (NCCI). There are approximately 550 different class codes and they can be very specific. For example, the correct code for Janitorial Services by Contractors may depend on whether the services include window cleaning above ground level.

Though a single employer can be assigned more than one class code, it is important to note that classification codes are designed to categorize employers with common exposures rather than the specific occupations of each employee within an organization. Since class codes are specific and appear to be somewhat conflicting, choosing the appropriate class code is not always easy and mistakes are common.

Premium Rate

Each class code is assigned a premium rate that corresponds to the risks associated with that particular kind of work. These rates, which are evaluated regularly, are applied to every $100 of payroll. Higher risk jobs are given higher premium rates. NCCI provides premium rates for each of its class codes, and many states rely on them when setting their own rates.

Now, let’s assume an employer has a payroll of $187,500 and that the premium rate for its classification code is $1.07. Divide the payroll by 100 [187,500 / 100 = 1,875], and multiply the quotient by the premium rate [1,875 x 1.07] to get a premium of $2,006.25. Note that if the applicable premium rate is $6.05, then the premium would be $11,343.75.

Remember that this is only the starting premium. Additional pricing factors may be applied to the starting premium to arrive at the final premium, such as:

  • Minimum premium requirements
  • Experience modification based on prior loss history
  • Discounts based on the size of the premium
  • Credits for qualifying safety and drug-free programs
  • Dividend plans tied to loss experience
  • Audits adjusting premiums to reflect actual (rather than estimated) payroll

Since the starting premium can be significantly affected by these additional pricing factors, a reputable insurance agent with substantial experience in evaluating and placing WC insurance should be consulted. For those employers with a statutory obligation to provide WC coverage, mistakes can be very costly.

If you would like more information about obtaining workers’ compensation insurance for your organization, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Sensitive Data: Don’t Forget the Copy Machine

Collecting personally identifying information from clients, such as names, social security numbers and credit card numbers, is common practice. This means that protecting against a data security breach is (or should be) a priority for virtually every organization. Unfortunately, when it comes to implementing data security measures, many organizations overlook a significant and somewhat obvious threat: the copy machine.

Commercial copiers have come a long way, and though they may not look it, they are powerful computers. Today’s generation of networked multifunction copiers are “smart” machines capable of copying, printing, scanning, faxing and emailing documents. To manage incoming jobs and heavy workloads, these copiers require hard disk drives capable of storing a lot of information. And, since they are often leased, returned and then leased or sold again, the Federal Trade Commission (FTC) recommends including copy machines in an organization’s data security plans.

Understanding security options is the first step to controlling the risks posed by copy machines. Most manufacturers offer data security features with their copiers, either as standard equipment or as optional add-on kits. These features typically involve encryption and overwriting.

Encryption is the scrambling of data using a secret code that can be read only by particular software. Copiers offering encryption encode the data stored on the hard drive so that it cannot be retrieved even if the hard drive is removed from the machine. Since encryption is typically an automatic feature with many copiers, specific steps or processes are generally not necessary.

Overwriting changes the values of the bits on the hard drive that make up a file by replacing existing data with random characters. By overwriting the drive space occupied by a file, its traces are removed, and the file can’t be reconstructed as easily. This is different from deleting or reformatting, which doesn’t actually alter or remove the data.

Depending on the copier, the overwriting feature may allow a user to overwrite after every job, periodically or on a preset schedule. Users may also be able to set the number of times data is overwritten; generally, the more times data is overwritten, the safer it is from being retrieved. The FTC recommends overwriting the entire hard drive at least once a month.

Finally, security measures must be taken before returning, selling or discarding a copy machine. Check with the manufacturer, dealer, or servicing company for options on securing the hard drive. Some may offer to remove the hard drive so that it can be disposed of, stored or destroyed pursuant to an organization’s own security policies and procedures. Others may undertake the task of overwriting the hard drive. These services may involve an additional fee, so check the lease or purchase agreement before deciding how to proceed.

Copiers are often the center of an organization’s operations. They have “seen” and saved countless documents with sensitive, confidential or personally identifying information. This is why protecting the copy machine should be a part of every organization’s data security plans.

Organizations should also consider protecting against data security breaches with insurance. Various insurance products are available to protect against privacy injuries, such as identity theft, resulting from security breaches and to cover the cost of complying with various data breach notice laws. Given the complexity of the risk, an experienced insurance agent should be consulted to ensure that proper coverage is obtained and that no gaps remain.

If would like to learn more about preventing data security breaches, take our online course Information Risk Management: Strategies for Preventing and Mitigating Information Security Breaches.

If you would like to learn more about insuring against data security breaches, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Protecting Valuable Business Papers and Records

Businesses often prepare an inventory of valuable property to simplify the process of filing an insurance claim in the event of a loss. For some reason, papers and records rarely make the list, even though losing these documents could disrupt business operations. Fortunately, insurance is available to cover the unbudgeted and often significant costs of dealing with a loss of business papers and records.

Valuable Papers and Records (VPR) coverage is a type of property insurance that covers the cost to research, replace or restore information that is lost when papers and records are damaged or destroyed. This insurance generally covers papers and records owned by the insured or in the insured’s care, custody and control, and it is often found in property insurance and small business owners’ policies. Large or unique risks may require a separate, stand-alone policy.

Notably, since VPR covers the cost of reproduction, it is not intended to protect items that cannot be replaced or duplicated because they will only be valued at the cost of blank material of substantially identical type. So, if an original Declaration of Independence is lost, the insurer will cover the cost of a blank piece of paper. To ensure maximum protection, irreplaceable items must be listed separately under the policy and possibly appraised so their value can be determined. In some cases, a separate insurance policy may be necessary.

VPR coverage is ideal for most businesses, including:

  • accountants
  • law firms
  • architects and engineers
  • physicians and medical offices
  • businesses that regularly produce and rely on important documents, such as files, receipts, invoices, lists, contracts, etc.

When shopping for VPR coverage, it is important to know what the policy does and does not cover. Although definitions may vary, ‘Valuable Papers and Records’ are generally defined to include documents, manuscripts and records that are inscribed, printed or written, including abstracts, books, deeds, drawings, films, maps and mortgages.

VPR policies do not typically cover money or securities. Importantly, once papers and records are reduced to electronic format or saved on some form of electronic media (CDs, hard drives, tapes, disks, etc.), they are generally excluded from coverage under a VPR policy, and need to be insured under an Electronic Data Processing policy.

The cause of the direct physical loss or damage to the papers and records must be a covered loss under the policy. Losses caused by errors in processing or copying, earth movement, war, neglect, nuclear hazard and various events involving water are typically not covered. Since even the broadest policy forms have exclusions, it is important to review them carefully.

Coverage limits should be enough to cover the cost of replacing or reconstructing lost information through research or transcription from other sources. While VPR generally covers items kept at the premises listed on the policy’s declarations, papers and records kept at an unlisted location may be subject to a lower limit (sub-limit) or may be excluded from coverage altogether. Make sure the policy lists all locations where papers and records may be stored.

In addition to VPR insurance, businesses may consider storing papers and records in a facility with the reputation, amenities and expertise needed to offer maximum protection. According to Carlos Diaz of Value Store it, “Not all storage facilities offer a comprehensive approach to this risk. Not all solutions are the same.” Some additional services to look for in a storage facility include:

  • Professional and responsive staff
  • Physical features/amenities (fire and security system, climate control, etc.)
  • Experience in handling and storing similar papers and records
  • Comprehensive Solutions (digitizing, e-filing, bulk shredding, etc.)
  • Ability to comply with applicable laws (HIPAA, Gramm-Leach-Bliley, etc.)

Be sure to visit the storage facility and check references, and before moving in, confirm coverage by checking the VPR policy. If it has lower limits for papers and records stored off-premises or excludes coverage altogether, the storage facility may need to be added to the list of covered locations.

Though protecting against the loss of papers and records is rarely high on the list of priorities, it should be. Those who underestimate the importance of papers and records may one day recognize they are not just valuable, they are invaluable.

If you would like to learn more about protecting your valuable papers and records, please contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Will business owners buy insurance online?

Insurance companies such as Geico and Progressive started selling personal insurance online over a decade ago. So is it safe to assume that business insurance can also be sold online?

We decided to explore this endeavour and we’re not the only ones. Plenty of insurance agencies offer business insurance, but very few can offer clients an online quote.

Just because the tool is out there doesn’t mean business owners will use it. Getting a quote for business insurance is significantly more complicated than obtaining a personal quote. Some of the other agencies that are offering business quotes are approaching it quite differently than we did.

Hiscox is targeting small business with a page on their site dedicated to explaining the various types of insurance coverage small business owners need. Apogee lists the types of insurance they can quote instantly and features a video tutorial of how to use their quoting tool. Our tool lists all the instant quotes we offer including Property and Liability Quotes, Professional Liability Quotes, Business Auto Quotes, and many more.

The introduction of this tool to our website also created the need for a complete redesign. We call ourselves a full-service independent insurance agency and creating this tool made us realize the possibility for an online marketplace. If clients can get quotes online they should be able to service their policies online as well. That’s why we also created a service page which allows clients to manage their policies online

If successful, online quotes for business insurance could be a big game changer. It will be interesting to see how many more agencies begin offering business quotes online. Get a quote and let us know what you think.

At Setnor Byer Insurance & Risk, we are committed to offering you a seamless insurance experience. Check back with us periodically for informational updates about insurance news. If you have specific questions about our instant quoting tool or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.

Health Benefits and Value under the Affordable Care Act

The Department of Health and Human Services (HHS) released final rules pursuant to the Affordable Care Act (Act) that are designed to help consumers shop for and compare health insurance options in the individual and small group markets. According to the HHS, these final rules will promote consistency among health plans, protect consumers by ensuring that plans cover a core package of health benefits and limit out of pocket expenses.

To make it easier for consumers to make apples-to-apples comparisons among health insurance plans, the final rules create uniform standards of coverage and value.

Essential Health Benefits

The Act provides that health plans offered in the individual and small group markets, including those available through Health Insurance Marketplaces (Exchange), must offer a core package of items and services known as Essential Health Benefits or EHBs, which must be equal in scope to those benefits offered by a typical employer plan. Under the Act, EHBs must provide:

  • Ambulatory patient services
  • Emergency services
  • Hospitalization
  • Maternity and newborn care
  • Mental health and substance use services, including behavioral health treatment
  • Prescription drugs
  • Rehabilitative services and devices
  • Laboratory services
  • Preventive and wellness services and chronic disease management
  • Pediatric services, including oral and vision care

To protect consumers against discrimination the final rules also:

  • Prohibit discriminatory benefit designs
  • Include special standards and options for coverage not typically covered by individual and small group policies
  • Include standards for prescription drug coverage

Actuarial Value

The final rules outline actuarial values of individual and small group plans to help consumers distinguish and compare plans offering different levels of coverage. Actuarial Value, or AV, is calculated as the percentage of total average costs covered by a plan. For example, if a plan has an AV of 70%, a consumer could expect to pay an average of 30% of the costs.

Beginning in 2014, non-grandfathered health plans in the individual and small group markets must meet certain AVs, which have been assigned the following “metal levels”:

  • A platinum health plan has an AV of 90%.
  • A gold health plan has an AV of 8%.
  • A silver health plan has an AV of 70%.
  • A bronze health plan has an AV of 60%.

To give health plans some flexibility, a plan can meet a particular metal level if its AV is within 2% of the standard. For example, a silver plan may have an AV between 68% and 72%. The final rules also provide flexibility, if necessary, for issuers in the small group market regarding annual deductible limits to achieve a particular metal level.

To streamline and standardize the calculation of AV for health insurance issuers, HHS is providing a publicly available AV Calculator. In 2014, this calculator will use a national standard population, but in 2015, HHS will accept state-specific data sets for the standard population if states choose to submit alternate data for the calculator.

According to HHS, these final rules will give consumers a consistent way to compare and enroll in health coverage in the individual and small group markets, while giving states and insurers more flexibility and freedom to implement the Act. Time will tell if these final rules will achieve their desired purpose.

At Setnor Byer Insurance & Risk, we are committed to guiding you through Health Care Reform. Check back with us periodically for informational updates about the Affordable Care Act. If you have specific questions about the Act or if you are ready to take action and would like to see how Setnor Byer Insurance & Risk can help, contact us.

If you’d like to subscribe to our weekly newsletters please click here.