Download

Whistleblower Suits: Emerging Risk on MSP

There is an emerging risk on Medicare Secondary Payer (MSP) compliance because of private citizens filing lawsuits.|

sixthings
There is an emerging area of risk associated with Medicare Secondary Payer 1 (MSP) compliance. Workers’ compensation, liability, and no-fault insurance, including self-insurance plans, are exposed to penalties and conditional payments, and there may be violations of the False Claims Act (31 U.S.C. §§3729 – 3733) (FCA) that could lead to fines plus treble damages. The risk stems from lawsuits commonly known as qui tam actions that are being brought by private citizens known as relators, who are bringing these lawsuits. Relators could recover anywhere from 15% to 30% of the damages in the suits, plus attorney’s fees and costs. The success of such lawsuits largely depends on whether the U.S. intervenes as plaintiff. Companies and insurance carriers that are responsible reporting entities (RREs) must exercise caution on what data on settlements, judgments, awards and other payments is sent to the U.S. and ensure the data is consistent with the Centers for Medicare & Medicaid Services (CMS) guidelines, policies and regulations. A solid reporting solution is a critical step for protection, but must also integrate business intelligence to eliminate the submission of false claims and allow the appropriate reporting of claims. Background The FCA was enacted in 1863 by a Congress concerned over the quality of goods being supplied to the Union Army during the Civil War.  Commonly referred to as “Lincoln’s Law,” the rule depended on the private citizen to help the government identify fraud against it. This private citizen, or relator, was rewarded if the government won a judgment. During World War II, the law changed and made it harder for private citizens to assist. When their incentive disappeared, the government’s ability to identify fraud slowed to a trickle even as government contracts surged because of the war. After decades of defense contractor abuse, President Reagan, working with a bipartisan Congress, changed the law in 1986. Fines rose  from a minimum penalty of $2,000 to a range of $5,000 to $10,0002 per violation; recoverable damages went from double to treble; and, most importantly, private citizens again had incentives to coordinate with government to prosecute fraud. Today, more than 80% of FCA actions are qui tam driven, and recoveries exceeded $4.9 billion in the fiscal year that ended Sept. 30, 2012.  Such actions are predicted to increase into the foreseeable future. A qui tam, or whistleblower, claim starts with an individual being aware of a possible fraud being perpetuated against the U.S. Typically, a whistleblower works for the organization that is alleged to be perpetuating the fraud, raises a concern and then suffers an adverse employment action for doing so. The results can be costly to the organization. Consider a quality-control expert at Hunt Valve in Ohio3. Her company made valves for nuclear attack submarines and reactors. The valves were never inspected, and paperwork was fabricated. When she raised concerns, she was fired and forced to move out of town. The responsible parties, Northrup Grumman Newport News, General Dynamics Electric Boat and three other defendants, paid a $13.2 million settlement to the U.S. Also consider a pharmacist who was treated similarly by his new employer, Omnicare4. He had previously owned a “mom and pop” drugstore outside of Chicago and was a seasoned pharmacist. He discovered widespread drug switching for profit, and, when he notified his bosses, he was fired and forced to work as a temp at other pharmacies that engaged in the same bad practices. He then brought an action and secured a $120 million settlement. A third example is rare in that the relator was the CEO of a laboratory company5. He realized that a competitor was producing a particular testing product that was defective and caused dialysis patients to be overdosed with expensive and harmful drugs that Medicare paid for. He brought the test results to the competitor’s attention but was rebuffed. He filed under FCA and recovered $302 million for the government. Certain private citizens are barred from being a relator. If someone was convicted of criminal conduct arising from his or her role, the citizen is not allowed to sue6. If another qui tam concerning the same conduct has already been filed, known as the first bar rule, no suit is allowed7. Where the government is already a party to a civil or administrative money proceeding concerning the same conduct, the action is also barred8. Finally, if the information was already disclosed to the public (and the relator is not the source), the matter is barred under the “public disclosure” rule9. If allowed, a qui tam complaint is filed under seal for 60 days. During this period, the government is required to investigate the allegations to determine if it will intervene. The government can extend this period under seal if it needs further time to investigate, and typically does so. Sometimes, the government may take a year or more to decide. If the government does intervene, it has primary responsibility to prosecute and pay for it10. When the government declines to intervene, the relator can proceed on his or her own, paying the costs, and the seal is lifted. The cost to prosecute can be prohibitive, and many FCA actions fail if the government declines to intervene. However, the law does increase the relator’s share of the damages from a floor of 15% of the damages to a minimum of 25% as compensation for the additional risk. To win, the relator must prove that the defendant’s conduct, or lack of conduct, meets one of the statutory requirements under 31 U.S.C. §3729(a). The areas where most of the conduct or lack of conduct fall are: 1) knowingly submitting a false claim or record to the government for payment11; 2) knowingly avoiding the submission of a claim or record to the government to avoid the payment of money to the government12; and 3) liability for those who conspire to violate the FCA13. A prima facie case of prosecutable FCA conduct in any of the three areas would require the relator to establish: 1) the submission of a false claim/record, or avoiding the filing of a required claim/record to the government; and 2)  knowledge of the falsity itself.  31 U.S.C. §3729(b)(1) sets forth how knowledge of the false information for the claim or record can be defined. It can be (1) actual knowledge; (2) deliberate ignorance of the truth or falsity of the information; or (3) reckless disregard of the truth or falsity of the information. The fact finder will require concrete evidence to uphold the FCA violation. The relator will also be focused on the applicable regulations, rules and policy memoranda from the government. The Trends After 1986, contractors for the Department of Defense were the primary focus of the government concerning FCA because of unbridled fraud. When the law changed, both government and private citizens unleashed prosecutions against contractors such as United Technologies ($150 million), Boeing ($75 million), Teledyne ($85 million) and Litton ($82 million). As lawsuits were filed, and the substantial recoveries publicized, the industry responded with increased compliance and vigilance to the point that FCA actions are rare in this area today. Next FCA were lawsuits involving the big pharmaceutical companies. Glaxo Smith Kline paid $1.2 billion for the unlawful promotion of Paxill, Wellburtin, Advair, Lamictal and Zofran for uses not approved by the Food and Drug Administration. Johnson & Johnson paid $2.2 billion for similar off-label use promotion. These highly publicized settlements, and changes in how drug companies may interact with providers, has seen a tapering of such cases and left the FCA qui tam industry on the search for the next area of fraud, waste and abuse against the government. One method to determine the next industry trend for FCA actions is to follow the focus of certain government enforcement agencies.  The Office of Inspector General (OIG) is one such Agency to monitor enforcement actions.   The OIG has focused recovery efforts on big pharmaceutical companies, and recent focus has been on Providers for Medicare & Medicaid items and services.    FCAs have been equally as active against these Providers.  As a result, the OIG had a particularly effective year in recovering over $4.3 billion in 2013 against Providers, returning $8 for every $1 spent by the Agency. The OIG is also responsible for MSP compliance enforcement.  An example of OIG activity is the recent settlement late last year by a Texas health system for $3.67 million14.   In that situation, the Relator alleged that Baptist Health Care billed Medicare for items and services it provided to beneficiaries that were covered by other payers such as workers’ compensation, liability and no-fault insurance (Plans).  Under MSP law Medicare is allowed to pay for such items and services, when no payment has been made, or payment is not reasonably expected to be made.  If that is the situation then Medicare pays, but on the condition it be reimbursed for items and services if payment is ever made by the Plan.   That is what happened here.  The Plans made payment to the Provider, but no reimbursement occurred, and when the oversight was brought to the attention by the Relator, he was ignored.  Correction to the Program was made, but past errors were not corrected.  The Provider therefore recognized the falsity of its information, and easily satisfied the criteria for the Relator when it did not reimburse for historical errors after it was brought to their attention.  The FCA community is therefore aware of MSP violations and how it can implicate the FCA. An area that may be subject to FCA is the Medicare & Medicaid SCHIP Extension Act of 2007 (MMSEA).  This law modified the MSP to require data reporting by RREs.  To encourage participation, the government included a penalty provision for non-compliance of up to $1,000 per day, per claim for failure to report15.  The OIG has adjusted its work plan for 2013 and 2014 to look at the MMSEA and the associated penalties that arise from non-reporting of data.  OIG involvement typically precedes FCA qui tam actions.  It is this area where the greatest potential for FCA actions are likely to begin to take root. An example of a matter that nearly received government backing was the recent seal that was lifted on March 20, 2014 with respect to a U.S. District Court case filed in the Western District of New York.  The government did not choose to intervene, and the Relator is a personal injury attorney who has filed against well over 50 insurance carriers and a few trucking companies that self-insure.  The main cause of action alleged was that these companies shifted MSP risk to the United States government through the use of a general release16.  Whether there will be success under the FCA remains to be seen as the root cause appears to be brought under a FCA conspiracy theory.  The Relator will have to prove a false claim, or avoidance of filing a claim, knowledge thereof the falsity, and the impact to the government.  It is unclear, based on present allegations, if the lawsuit will pass the procedural stages, but it does demonstrate that the FCA qui tam industry is taking a serious look at the MSP area for recovery. Concerns for the RRE in this area are potentially significant.  Only recently has MMSEA data been accepted by CMS for reporting by the RRE.   As of 1/1/2010, CMS received quarterly downloads from RREs’ workers’ compensation and no-fault plans that involve cases where Ongoing Responsibility for Medical (ORM) was determined.  Pursuant to the CMS User Guides, Regulations, and Memoranda, these RREs must monitor all claims, no matter the case status that were open on 1/1/2010, re-opened or newly reported after that date.  Once identified, ORM status is to be reported, but it can be immediately terminated if certain established CMS criteria is met. On October 1, 2010, CMS started to accept the second MMSEA data element from RREs’ workers’ compensation and liability plans regarding the Total Payment Obligation to Claimant (TPOC) meeting certain value thresholds.  These TPOCS, or settlements with Medicare beneficiaries, were collected typically the quarter before reporting, and then submitted during an assigned window period set up by CMS for the RRE. The reporting requirement under the MMSEA provides a relatively straightforward way to establish a claim/record being submitted to the government under the FCA.   Whether or not it is false would depend on the Regulations, Rules, Policies (User Guides) and Memoranda from the government about what and when to report.    FCA criteria can be easily met, as it is simple to determine from the data when a claim/record was submitted or if it was missed.  Determining whether it is false would be harder, but how claim systems manage information based upon the regulations, rules, and policies could be probative on that point.  This exact issue came up in an older FCA case involving a Medicare fiscal intermediary, known as Highmark17.  This entity served two roles with Medicare, one as a Medicare contractor processing payment claims, and the other as a private provider of services.    An FCA action was brought against Highmark for inconsistent claim processes and the court found basis to sustain the FCA complaint based on the fact that the claims processing system did not properly line up with Medicare requirements.  Consistent with that ruling, the CMS User Guides and related policy memoranda would be similarly construed and therefore whether an RRE had a case to report as a TPOC or ORM would be based on how those rules would apply. An RRE’s exposure to an FCA action is mitigated if the RRE utilizes an MMSEA reporting system that is tested.  Most MMSEA reporting systems are compliant with the technical aspects of the CMS User Guides; however, they lack the processes that integrate the CMS regulations, policies and user guide rules to allow the end-user to enter the appropriate data.  Most reporting systems lack a MMSEA solution with built-in business intelligence to allow the right information to be entered at the right time.  The adjuster responsible to enter the data at the critical points needs to be guided to ensure correct submission of data to the government. Franco Signor LLC processes over 2M records each month to the government for RREs.  We have audited over 1,900 RREs and have drawn the conclusion that the MMSEA reporting systems are sound, but the data being populated by the front-lines is not consistent with known rules, regulations and policies of Medicare.  We have recommended business intelligence methodology to guide the adjuster to avoid the potential MSP exposure, as well as the emerging risk of associated FCA exposure.  The cost is minimal to secure a base line on MSP compliance performance.  Integration of business intelligence takes time, but must be accomplished before MSP penalties become fully enforceable.  Do not be the RRE whose MMSEA reporting system and methodology is tested by an FCA or qui tam action. [1] 42 U.S.C. §1395y(b) [2] Today the FCA penalty range is set at $5,500 to $11,000 based on auto triggers within the legislation [3] Gonter v. Hunt Valve Co. 510 F.3d 610 (2007) [4] http://www.quarles.com/omnicare-settles-more-allegations-2013 [5] http://www.phillipsandcohen.com/Success-for-Clients/P-C-s-Successful-Whistleblower-Cases.shtml[6] 31 U.S.C. §3730(d)(3) [7] 31 U.S.C. §3730(b)(5) [8] 31 U.S.C. §3730(e)(3) [9] 31 U.S.C. §3730(e)(4)(A) [10] 31 U.S.C. §3730(c)(1) [11] 31 U.S.C. §§3729(a)(1)(A) and (B) [12] 31 U.S.C. §3729(a)(1)(G) [13] 31 U.S.C. §3729(a)(1)(C) [14] http://www.francosignor.com/blog/medicare-jurisdiction/medicare-secondary-payer-act-implicated-in-false-act-claim-against-hospital [15] 42 U.S.C §1395y(b)(8) [16] U.S. v. Allstate Insurance Company, et al., Case #cv-01015-WMS, U.S. Dist. Court for the Western District of New York. [17] http://www.paed.uscourts.gov/documents/opinions/04D0039P.pdf

Roy Franco

Profile picture for user royfranco

Roy Franco

Over the past two decades, Roy A. Franco has emerged as one of the principal architects of policies and practices that define the world of Medicare Secondary Payer (MSP) compliance. From his experience as director of risk management for Safeway from 1993-2010, he realized the need for greater clarity and efficiency in matters related to Medicare compliance.

TRIA: A Real Need, and the Time Is Now!

Without an extension of the Terrorism Risk Insurance Act, many high-profile properties will be unable to secure coverage. 

The Terrorism Risk Insurance Act (TRIA) was initially passed in November 2002 as a response to the terrorist attacks of Sept. 11, 2001. Private insurance carriers had responded to the attacks by excluding acts of terrorism from coverage, and TRIA was needed to entice private carriers to once again cover this risk. By providing the necessary reinsurance so the insurance industry can properly define and limit the financial impact of another significant terrorist event, TRIA-backed terrorism coverage is widely available today at affordable costs.

Currently, TRIA is scheduled to expire at the end of 2014,and Congress is actively debating whether to extend or modify the current coverage. Many in Congress argue that TRIA is no longer necessary. They feel that the threat of terrorism has diminished and that the private insurance industry will continue to provide terrorism coverage without the federal government backstop. 

The bombings at last year's Boston Marathon highlight that, indeed, the U.S. still faces a very real threat of terrorist attacks. And the threat is far greater than many realize. A March 2014 report from the Insurance Information Institute highlighted the continued threat of terrorism in the U.S. by detailing 21 separate attempted terrorist acts that were thwarted by law enforcement between 2009 and 2013. Unquestionably, the threat of terrorist attacks against the U.S. remains high.

The pending expiration of TRIA is highlighting what the private carriers' response will be without this financial backstop. Property carriers are tying their terrorism coverage expiration dates to the expiration of TRIA. Without TRIA, many high-profile properties will be unable to secure coverage from the private marketplace. Workers’ compensation coverage is statutory and cannot exclude terrorism as a cause, so carriers in this market are responding to TRIA’s pending expiration by declining coverage to employers in certain geographic areas beyond the end of 2014. Regardless of location, industries with a high concentration of employees, such as healthcare, higher education, defense contractors, financial services and technology companies, are also finding limited markets beyond the end of 2014. This leaves employers with fewer options, which will ultimately result in increased pricing.  

But there is a solution. TRIA works. It provides the high-level backstop that the insurance industry needs to forecast potential exposure to a terrorist event and allow companies to underwrite the coverage. TRIA is designed to only be triggered by an extremely large event, even beyond the scope of the Sept. 11 attacks. There are also recoupment provisions built into the law that will repay the federal government if TRIA is triggered, so it is not simply a handout to the insurance industry. TRIA has truly been one of the most successful public/private partnerships in recent memory.  

The time to act is now. Congress is debating the issue. I encourage you to reach out to your members of Congress and let them know your thoughts on this important topic:

http://www.usa.gov/Contact/US-Congress.shtml#Contact_Your_Representative_in_the_U.S._Congress

Finally, Marsh recently released its 2104 Terrorism Risk Insurance Report. This report summarizes the current outlook regarding TRIA’s potential expiration, provides benchmarking related to terrorism insurance take-up rates and pricing and offers alternative insurance and risk management solutions for terrorism risks that will be useful for organizations even if TRIA is renewed or extended. I encourage you to read the full report here.

The Science (and Art) of Data, Part 2

There are not enough good data scientists to go around. So, should you "buy" them, "rent" them or "build" them. A hybrid may be the answer.

Given the high need and growing demand for data scientists, there are definitely not enough of them. Accordingly, it is important to consider how an insurer might develop a core talent pool of data scientists. As it is often the case when talent is in short supply, acquiring (i.e., buying) data scientist talent is an expensive but fairly quick option. It may make sense to consider hiring one or two key individuals who could provide the center of gravity for building out a data science group. A number of universities have started offering specialist undergraduate and graduate curricula that are focused on data science, which should help address growing demand in relatively soon. Another interim alternative is to “rent” data scientists through a variety of different means – crowdsourcing (e.g., Kaggle), hiring freelancers, using new technology vendors and their specialists or consulting groups to solve problems and engaging consulting firms that are creating these groups in-house.

The longer term and more enduring solution to the shortage of data scientists is to “build” them from within the organization, starting with individuals who possess at least some of the necessary competencies and who can be trained in the other areas. For example, a business architect who has a computational background and acts as a liaison between business and technology groups can learn at least some of the analytical and visualization techniques that typify data scientists. Similarly, a business intelligence specialist who has sufficient understanding of the company’s business and data environment can learn the analytical techniques that characterize data scientists. However, considering the extensive mathematical and computational skills necessary for analytics work, it arguably would be easier to train an analytics specialist in a particular business domain than to teach statistics and programming to someone who does not have the necessary foundation in these areas.

Another alternative for creating a data science office is to build a team of individuals who have complementary skills and collectively possess the core competencies. These “insight teams” would address high-value business issues within tight time schedules. They initially would form something like a skunk works and rapidly experiment with new techniques and new applications to create practical insights for the organization. Once the team is fully functional and proving its worth to the rest of the organization, then the organization can attempt to replicate it in different parts of the business.

However, the truth is there is no silver bullet to addressing the current shortage of data scientists. For most insurers, the most effective near-term solution realistically lies in optimizing skills and in team-based approaches to start tackling business challenges.  

Designing a data science operating model: Customizing the structure to the organization’s needs

To develop a data science function that operates in close tandem with the business, it is important that its purpose be to help the company achieve specific market goals and objectives. When designing the function, ask yourself these four key strategic questions:

  • Value proposition: How does the company define its competitive edge?  Local customer insight? Innovative product offerings? Distribution mastery? Speed?
  • Firm structure: How diverse are local country/divisional offerings and go-to-market structures, and what shared services are appropriate? Should they be provided centrally or regionally?
  • Capabilities, processes and skills: What capabilities, processes and skills do each region require? What are the company’s inherent strengths in these areas? Where does the company want to be best-in-class, and where does it want to be best-in-cost?
  • Technology platform: What are the company’s technology assets and constraints?

There are three key considerations when designing an enterprisewide data science structure: (a) degree of control necessary for effectively supporting business strategy; (b) prioritization of costs to align them with strategic imperatives; and (c) degree of information maturity of the various markets or divisions in scope.

Determining trade-offs: Cost, decision control and maturity

Every significant process and decision should be evaluated along four parameters: (a) need for central governance, (b) need for standardization, (c) need for creating a center of excellence and (d) need for adopting local practices. The figure below illustrates how to optimize these parameters in the context of cost management, decision control and information maturity.

This model will encourage the creation of a flexible and responsive hub-and-spoke model that centralizes in the hubs key decision science functions that need greater governance and control, and harnesses unique local market strengths in centers of excellence. The model localizes in regional or country-specific spokes functions or outputs that require local market data inputs, but adheres to central models and structures.

Designing a model in a systematic way that considers these enterprise-wide business goals has several tangible benefits. First, it will help to achieve an enterprisewide strategy in a cost-effective, timely and meaningful way. Second, it will maximize the impact of scarce resources and skill sets. Third, it will encourage a well-governed information environment that is consistent and responsive throughout the enterprise. Fourth, it will promote agile decision-making at the local market level, while providing the strength of heavy-duty analytics from the center. Lastly, it will mitigate the expensive risks of duplication and redundancy, inconsistency and inefficiency that can result from disaggregation, delayed decision making and lack of availability of appropriate skill sets and insights.


Anand Rao

Profile picture for user Anand_Rao

Anand Rao

Anand Rao is a principal in PwC’s advisory practice. He leads the insurance analytics practice, is the innovation lead for the U.S. firm’s analytics group and is the co-lead for the Global Project Blue, Future of Insurance research. Before joining PwC, Rao was with Mitchell Madison Group in London.

Many Agents Expose Themselves to Dangers

Some 90% of E&O suits against agencies could be prevented through careful attention to practices and procedures.

Many insurance agents are confused about their role, which brings about misplaced loyalties and greater E&O exposures.

Let’s start with a question: Does the agent owe the policyholder the common law duty of good faith and fair dealing? Most insurance agents would respond with a resounding “yes” – but they’re wrong.

The duty of good faith and fair dealing is a non-delegable duty that applies only between the parties to the contract, and the parties are the insurance company and the insured – not the agent. Put simply, the agent is not the agent of the policyholder. The duties of good faith and fair dealing belong to the insurance company, not the agent.

So what duties does an insurance agent owe to the policyholder/applicant? Under common law, there are really but two:

  • Use reasonable diligence in attempting to place the requested insurance.
  • Inform the client promptly if unable to do so.

That’s it!

Some states may provide for a “special relationship” to have been created, which may provide for some additional duties. However, such a relationship is state-specific, requires some acts of commission to create and is beyond the parameters of this article.

Under statutes, there is really only one duty: Refrain from deceptive trade practices.

Every agent knows that the insurance code has a lot of pages devoted to prohibited practices. However, a careful review of the NAIC model law (upon which all states base their deceptive trade practices code) finds that all deceptive trade practices applicable to an insurance agent involve commission of an act, not the omission of an act. Under the model law, doing something incorrect is worse than not doing anything. Insurance agents may assume some duties that are not imposed upon them by law, thinking that they have such duties. If duties are “assumed,” even through ignorance, the law will hold agents to a professional standard for those assumed duties. If you make yourself out to be a coverage expert, the law will hold you to that expert standard.

Some 90% of E&O suits against agencies could be prevented through careful attention to practices and procedures.

By contrast, the duties owed by the agent to the insurance company are many. As a fiduciary of the principal, the agent owes the company:

  • Loyalty
  • Utmost good faith
  • Candor/full disclosure
  • Refraining from self-dealing
  • Integrity, skill and care
  • Fair and honest dealing
  • Duty to follow instructions

Something many insurance agents may not have considered: Your responsibility to not breach your fiduciary duties to the insurance company are the largest part of your professional/ethical responsibilities as an agent.

(It is not a two-way street. The insurance company is NOT a fiduciary of the agent. In other words, an agent acts on behalf of the insurance company, but the insurance company does not act on behalf of the agent. Under common law, the insurance company only owes the agent: indemnification, payment of compensation and fair dealing.)

Some confusion may occur about agents’ responsibilities because of two issues: vicarious liability, which holds that a principal may be held liable for actions by its agent, and the legal maxim that a wrongdoer is ultimately responsible for his own wrongdoing. If an insurance company is held liable for the wrongdoing of its agent (vicarious liability), the insurance company can seek recovery from the agent, (holding the wrongdoer ultimately responsible).

If the insurance company is held vicariously liable for the agent’s wrongdoing, a decision to seek recovery from the agent may depend on:

  • What did the agent do wrong?
  • What recovery did the insured get?
  • What recovery is available to the principal (the insurance company)?
  • What was the agent’s thinking?

A common misconception is that all one has to do to avoid personal liability is to establish a corporation or limited liability entity. That is incorrect because:

  • Professional liability is personal liability.
  • Fiduciary liability is personal liability.

Summary

Insurance agents may assume many duties not imposed upon them by law. Assuming those duties holds the insurance agent to a professional standard not otherwise imposed.

The majority of an agent’s duties are owed to the insurance company, and it is the company’s vicarious liability for the actions of the agent that may ultimately get the agent sued. In other words, the biggest E&O exposure an agent may face is ultimately an action brought by the insurance company because of a wrong action or breach of fiduciary duties. Knowing this makes it all the more important that the agent fully understand and trust the insurance company before assuming the responsibilities and duties imposed upon agents.

What the Next-Gen Insurer Will Look Like

The journey to the Next-Gen Insurer has started, with or without you. The longer you wait to begin your journey, the more difficult it becomes.

Innovation is a crucial strategic mandate that is defining a new era of winners and losers. From retail to entertainment and everything in between, decades of business traditions and assumptions are toppling because of change – change that runs the gamut from customer behaviors and expectations to the use of new technologies. This level of change and disruption is unprecedented in the history of the insurance industry. And the pace just doesn't slow down: new technologies, the mash-up of technologies, new uses for these technologies, new competition, new customer behaviors, needs and expectations. These changes are demanding a new and responsive insurance industry.

At the same time, the impact of influencers is escalating -- from both inside and outside the industry -- and the explosion of data, the lifeblood of insurance, is creating new challenges as well as opportunities. This blitz is challenging and disrupting sacred business and operational models and assumptions, requiring new thinking, experimentation, the adoption of new technologies and yes … innovation. Many insurers, large and small, are grappling with getting their heads around how the business of insurance will change in the next three to five years.

While looking to the future has long been a part of our very culture, our ability to envision the future for insurance companies is often stymied by the priorities and challenges of today. However, if we want a future, we must rethink how we embrace innovation as the core of the Next-Gen Insurer.

A Next-Gen Insurer must reimagine the core components of insurance – the business models, products and services, infrastructures,and customers. All need to be underpinned by a culture that embraces collaboration, transformation and innovation. Forward-thinking insurers are defining what they will look like three, five and 10 years from now, planning how they will respond to influencers within and outside the industry, the path they will take to get there and the relationships that will fuel the journey.

Many insurers are on the journey, but they are going at different speeds and focusing on the different priorities that will uniquely differentiate and position them as market leaders. Some are reimagining the fundamentals of insurance, while others are retooling products, services, distribution and processes. Regardless of the approach, becoming a Next-Gen Insurer is a long-term, enterprisewide endeavor. It’s important to think big even though actions may start small.

So how to begin?

First, recognize that the innovation journey has started, with or without you. The longer you wait – the more difficult it becomes, and the more likely it is to be detrimental to your long-term business. Insurers must define their unique vision for how they will evolve into a Next-Gen Insurer by examining the fundamentals of the insurance business and determining how new levels of agility, flexibility, creativity and competitiveness can be created. There are four critical business components that insurers must reshape in their Next-Gen Insurer model: the customer, products and services, infrastructure and business model.

At the same time, companies must identify, track, assess and define how to respond to or leverage key influencers and trends. Prioritize them, developing scenarios and plans of action, experimenting and collaborating. This is paramount, not just for competitive advantage but for long-term survival. The coming years promise unparalleled opportunity for insurers to increase their value to their customers. Those that best capitalize on the key influencers will realize the most in rewards. In contrast, those that do not prepare for the future will find themselves falling behind, losing both competitive position and financial stability.

Equally critical is recognizing that no business, regardless of size, can go it alone and expect to lay hold of all the possibilities and reap all of the benefits. Most insurers lack the time, expertise and resources to track all of the influencers unless they engage outside industry resources. Insurers must identify partners who can mobilize an ecosystem of both internal and external relationships and resources to capture potential, change legacy cultures and enable the ideas and technologies that can be uniquely deployed within their companies to create their Next-Gen Insurer.

But most importantly, create and nurture a culture of innovation that starts at the top and is seen, heard and acted upon each and every day. Begin by identifying those within your organization who are the outside-the-box thinkers: those renegades and dreamers who can be advocates on the journey.

The innovation journey toward reinventing the business of insurance has started. Don’t delay, because what is innovative today will be expected tomorrow.

Begin your journey today -- to ensure that you have a tomorrow.

For information about a detailed report on the Next-Gen Insurer, click here. To learn more about where the leaders in the industry are in their innovation journey, consider attending the 2014 SMA Summit in Boston Sept. 15, 2014.

The 7 Keys to Strong Passwords

Twelve characters are the absolute minimum, but passwords can be both easy to remember and hard for an attacker to crack. 

Creating a strong password may seem like a chore, but sometimes it can literally be the only thing standing between a cybercriminal and your personal and financial information or access to your company’s network and intellectual property. Here are some tips for creating a strong password (that you can actually remember):

1) The most important factor in creating a secure password is length. A longer sequence of characters (letters, numbers and possibly punctuation marks) means more possible combinations to help thwart an attacker. The absolute minimum should be 12 characters. If a password has eight characters, for example, modern password cracking software will break it in a matter of hours. A difference of four characters in a password may not seem like much, but there is a huge increase in the number of possible combinations it will yield (and hence attempts that the cracking software will have to make before it can break the password in question). Even if only letters and numbers are allowed, there are 14 million times as many combinations with a 12-character password vs. an eight-character one. If punctuation marks are included, the 12-character password is 81 million times as hard to break. Simply put, longer passwords are always better.

2) Use a nonsensical (or completely personal) passphrase. You can pick a password that is both easy for you to remember and hard for an attacker to figure out. If you really want to, you can mix in random characters like $, @, etc., though hackers are well aware that people try this trick. Truth be told, it’s really the length that makes a passphrase difficult to crack, so the special characters will essentially make the password more difficult to remember while not making it any harder to break.

When creating your phrase, make sure it really is unique to you (or genuinely random). Avoid famous literary quotes and song lyrics – hackers can check for those. A good nonsensical passphrase might be something like: CyanStapleWashingtonBanana44 (don’t use this exact one – or any other suggestion you see online. Hackers can find those, too). A personal phrase can be effective because it relates to something that’s memorable to you. Just make sure it isn’t a widely known event. Perhaps you can use that time you were surprised at the aquarium: “BlueLobstersAreReal!” It’s long enough that a machine won’t break it anytime soon; no one is going to guess it; and you will remember it.

3) Don’t use the same password for multiple sites. Reusing passwords is known as "daisy-chaining." If one account gets compromised, it will instantly expose others with the same (or a similar) password to attacks.

4) Don’t have a file or email called "passwords" anywhere on your computer (or saved in an email). These are easy for a hacker to find.

5) Change passwords regularly – perhaps every few months. If a database storing a site’s passwords has been compromised (which is often not discovered right away), changing a given password makes it effectively useless to an attacker even if it’s stolen and eventually cracked.

6) Use “multi-factor authentication” whenever it’s available. Additional “authentication factors” are just ways to ensure you are who you say you are. This can mean something like a fingerprint scanner or a code sent to your phone via text message that is then entered in addition to your password. If an attacker only has your password, she still won’t be able to get access. If you’re curious to see what this looks like in practice, Google has a good explanatory video here.

7) Avoid using security questions, if you can. Frequently, these questions are used as a way around the dreaded “I forgot my password” problem. The questions may sound helpful, but they almost always focus on information that can be found elsewhere online (where you went to school, pet’s name, favorite color, etc.). Any hacker will know to look for this information and can use it to get into your account – and potentially lock you out. Unfortunately, some sites require you to use the questions. If possible, try to select questions that don’t have just a few or even a single answer that a hacker can find (your mother’s maiden name, for example).

Remember that there is no such thing as an impervious system, but that doesn’t mean you should make it easy for attackers. If you’re a difficult target, they may well move on to an easier one.

Navigating EEOC and Labor Department

The focus is likely to be on the Americans with Disabilities Act and the Genetic Information Nondiscrimination Act -- and litigation should increase.

Trends in 2013 suggest that the Equal Employment Opportunity Commission is stepping up litigation, potentially involving large dollars.

Recoveries by the EEOC were $39 million in 2013, slightly down from the $44 million recovered in 2012, but 2013 featured some high-profile cases. In 2014, the focus is likely to be on the Americans with Disabilities Act (ADA) and on the Genetic Information Nondiscrimination Act (GINA).

Even though GINA has been in effect since 2009, it wasn’t until 2013 that the EEOC filed its first lawsuit alleging genetic discrimination. The suit, against Tulsa-based Fabricut (Civil Case No: 13-CV-248-CVE-PJC), alleged the company violated the ADA by refusing to hire a woman because it regarded her as having carpal tunnel syndrome and violated GINA when it asked for her family medical history in a post-offer medical examination. Employers need to be very aware that GINA prohibits requesting family medical history, even with a contract medical provider during a post-offer examination. In May 2013, Fabricut agreed to settle the suit for $50,000 and to take specific actions to prevent future discrimination.

Just nine days into 2014, the EEOC settled its first systemic lawsuit alleging GINA violations, for $370,000. According to the complaint (EEOC v Founders Pavilion Inc. No 13- CV-06250), Founders Pavilion conducted post-offer, pre-employment medical exams and asked applicants to provide information about their family medical history. The suit also alleged that Founders Pavilion: fired an employee after refusing to provide her with an accommodation, a violation of the ADA; refused to hire two women because of a perceived disability; and either refused to hire or fired three women because they were pregnant.

It appears that there will be a major focus in 2014 on ADA and GINA violations –- which go hand in hand. Note that the trend in EEOC litigation regarding ADA claims has shifted from disability to a focus on an employer’s obligation to provide reasonable accommodations.

For federal contractors, the key question in 2014 is: “Are you disabled?” The Labor Department issued new rules that will require federal contractors with 50 or more employees or with more than $50,000 in government work to pose that question to workers, in an effort to reduce the ever-increasing jobless rate of people with disabilities. Employees aren’t required to answer the question, but federal contractors will have to show that at least 7% of their workforce has disabilities or will face fines and potential loss of contracts.

Although the ADA does not allow employers to inquire about disability, the EEOC has made an exception so employers can comply with the Labor mandate. But lots of issues will arise. Do employees want their bosses to perceive them as disabled? Will more employees qualify as disabled with the broader definition of disability enacted with the 2008 amendment to the ADA? What will happen to reasonable accommodations, given that the exception that allows employers to ask about disabilities doesn’t appear to then allow a disabled individual to ask for a reasonable accommodation? 2014 will certainly be interesting!

While we wait to see what shakes out, there are some practices and employer can follow.

Relative to GINA, it is important for employers to know that the new regulations provide a quasi-safe harbor to employers who have inadvertently received genetic information when that information was not sought. The EEOC suggests that the employer use the following language on any requests for medical information:

“The Genetic Information Nondiscrimination Act of 2008 (GINA) prohibits employers and other entities covered by GINA Title II from requesting or requiring genetic information of an individual or family member of the individual, except as specifically allowed by this law. To comply with this law, we are asking that you not provide any genetic information when responding to this request for medical information. ‘Genetic information’ as defined by GINA includes an individual’s family medical history, the results of an individual’s or family member’s genetic tests, the fact that an individual or an individual’s family member sought or received genetic services, and genetic information of a fetus carried by an individual or an individual’s family member or an embryo lawfully held by an individual or family member receiving assistive reproductive services."

Relative to reasonable accommodations, employers are being urged by the EEOC to accept a doctor’s work release even if it has restrictions. Employers are also being urged to document entering into the interactive process if the reasonable accommodation is not straightforward or if the employer cannot meet the physician’s restrictions.

Although an employer may not ask disability-related questions or conduct a medical exam of an applicant until after making a conditional offer of employment, an employer may condition employment on the results of a medical examination or inquiries so long as all employees in a classification are subject to the same testing and or inquires and so long as the testing does not infringe on GINA. In addition, post-offer examinations may not be used to discriminate against individuals with disabilities. The testing must also be job-related and consistent with business necessity and evaluate some of the essential functions of the job. Furthermore, these tests cannot discriminate against a certain class. For example, they cannot be unduly difficult for a woman.

According to the ADA, the term “discriminate” includes an employer’s failure to make reasonable accommodations. The applicant should be provided the criteria for passing the test, based on the job description. It is very important for the employer to enter into the interactive process if performance of the essential job functions cannot be met.

Baseline testing -- a tool that can assist employers in managing employees’ injuries by establishing if the injury arose out of the course and scope of employment -- must follow the same guidelines as a post-offer test. Baseline testing must be conducted for all individuals in a classification, must be consistent with business necessity, cannot discriminate against a certain class and must evaluate some of the essential functions of the job. Baseline testing differs from post-offer testing in that it is usually not read until a work-related incident occurs.

2014 might be a trying time for employers, but the best defense for an employer is to be prepared.

Cyber Challenges Under NIST's Framework

The cybersecurity framework is voluntary -- for now -- but attorneys and regulators may claim it is a de facto standard for all companies. 

On Feb. 12, the National Institute of Standards and Technology (NIST) released its long-anticipated Framework for Improving Critical Infrastructure Cybersecurity together with a companion Roadmap for Improving Critical Infrastructure Cybersecurity.The framework is issued in accordance with President Obama’s Executive Order 13636, Improving Critical Infrastructure Cybersecurity Version 1.0., which gave NIST the task of developing a cost-effective framework “to reduce cyber risks to critical infrastructure.” The companion roadmap discusses NIST’s next steps with the framework and identifies key areas of development, alignment of cybersecurity standards and practices within the U.S. and globally and collaboration with private and public sector organizations and standards-developing organizations.

 

The framework applies to organizations in critical infrastructure. But, given the pervasiveness of cybersecurity incidents, and the ever-present, increasing and evolving cyber risk threat, all organizations should consider whether their current cybersecurity risk management practices would pass muster under the framework. In addition, although the framework is “voluntary”—at least so far—organizations are advised to keep in mind that creative class action plaintiffs (and even some regulators) may nevertheless assert that the framework provides a de facto standard for cybersecurity and risk management even for noncritical infrastructure organizations. One thing that companies should consider as they review the framework is what “tier” of cybersecurity risk management they wish to achieve. The tiers—which range from “informal, reactive” responses to “agile and risk-informed” are addressed below, together with an overview of the framework and additional detail regarding certain of its key aspects.

 

Overview
 

 

At a high level, as its name indicates, the framework provides a structure for critical infrastructure organizations to achieve a grasp on their current cybersecurity risk profile and risk management practices, to identify gaps that should be addressed to progress toward a desired target state of cybersecurity risk management and to internally and externally communicate efficiently about cybersecurity and risk management.

 

 
 
 
Building from global standards, guidelines and practices, the framework provides a common taxonomy and mechanism for organizations to:

 

 
  1. Describe their current cybersecurity posture;
  2. Describe their target state for cybersecurity;
  3. Identify and prioritize opportunities for improvement within the context of a continuous and repeatable process;
  4. Assess progress toward the target state;
  5. Communicate among internal and external stakeholders about cybersecurity risk.
 
 
 
NIST has emphasized that the framework “complements, and does not replace, an organization’s risk management process and cybersecurity program.” In addition, NIST properly notes that the framework “is not a one-size-fits-all approach” to managing cybersecurity risk, given that organizations" have unique risks—different threats, different vulnerabilities, different risk tolerances.
 
 
 

 

In releasing the framework, NIST explained that it provides a structure that organizations, regulators and customers can use to create, guide, assess or improve comprehensive cybersecurity programs and “a common language to address and manage cyber risk in a cost-effective way” based on business needs, without placing additional regulatory requirements on businesses.” NIST also notes that organizations can use the framework “to determine their current level of cybersecurity, set goals for cybersecurity that are in sync with their business environment and establish a plan for improving or maintaining their cybersecurity.” Moreover, because it refers to globally recognized standards for cybersecurity, the framework can also be used by organizations located outside the U.S. and can serve as a model for international cooperation on strengthening critical infrastructure cybersecurity.
 
 
 

 

Although applying to organizations in critical infrastructure, the framework may be used by any organization as part of its effort to assess cybersecurity practices and manage cybersecurity risk.
 
 
 

 

Three-Part Approach

 

 
 
 
The framework adopts a risk-based approach composed of three parts: the core, the profile and implementation tiers.
 
 
 

 

Framework Core

 

 
 
 
The framework relies on existing global cybersecurity standards, guidelines and practices as a basis to build or enhance an organization’s cybersecurity risk management practices.
 

 

The framework core presents five high-level “functions,” which, as stated by NIST, “organize basic cybersecurity activities at their highest level.” The five functions are: (1) identify, (2) protect, (3) detect, (4) respond and (5) recover. NIST explains that these five high-level functions “provide a high-level, strategic view of the lifecycle of an organization’s management of cybersecurity risk” and will provide “a concise way for senior executives and others to distill the fundamental concepts of cybersecurity risk so that they can assess how identified risks are managed, and how their organization stacks up at a high level against existing cybersecurity standards, guidelines and practices.”
 
 

 

 
For each of the five functions, the framework core identifies underlying key categories and subcategories of cybersecurity outcomes, then matches those outcomes with “informative references” that will assist organizations in achieving the outcomes, such as existing cybersecurity standards, guidelines, and practices. By way of example, categories within the “protect” function include access control, awareness and training, data security, information protection processes and procedures and protective technology. Subcategories under the “access control” category within the protect function include "identities and credentials are managed for authorized devices and users” and “[n]etwork integrity is protected, incorporating network segregation where appropriate.” “Informative references” for "identities and credentials are managed for authorized devices and users” include:
 
 
 

 

  • CCS CSC 16
  • COBIT 5 DSS05.04, DSS06.03
  • ISA 62443-2-1:2009 4.3.3.5.1
  • ISA 62443-3-3:2013 SR 1.1, SR 1.2, SR 1.3, SR 1.4, SR 1.5, SR 1.7, SR 1.8, SR 1.9
  • ISO/IEC 27001:2013 A.9.2.1, A.9.2.2, A.9.2.4, A.9.3.1, A.9.4.2, A.9.4.3
  • NIST SP 800-53 Rev. 4 AC-2, IA Family20
 

 

 
Figure 1 from the framework depicts the core:

 

 
 
 
 
 

 

 
NIST explains that the core “presents industry standards, guidelines and practices in a manner that allows for communication of cybersecurity activities and outcomes across the organization from the executive level to the implementation/operations level.”
 
 
 

 

Implementation Tiers

 

 
 
 
The implementation tiers describe the degree to which an organization's cybersecurity risk management practices exhibit the characteristics defined in the framework. The tiers range from partial (tier 1) to adaptive (tier 4) and describe an increasing degree of rigor and sophistication in cybersecurity risk management practices and “the extent to which cybersecurity risk management is informed by business needs and is integrated into an organization’s overall risk management practices.” By way of example, considering the risk management aspect, at tier 1, “[o]rganizational cybersecurity risk management practices are not formalized, and risk is managed in an ad hoc and sometimes reactive manner.” At tier 2, “[r]isk management practices are approved by management but may not be established as organizational-wide policy.” At tier 3, “[t]he organization’s risk management practices are formally approved and expressed as policy" and “[o]rganizational cybersecurity practices are regularly updated based on the application of risk management processes to changes in business/mission requirements and a changing threat and technology landscape.” At tier 4, “[t]he organization adapts its cybersecurity practices based on lessons learned and predictive indicators derived from previous and current cybersecurity activities” and “[t]hrough a process of continuous improvement incorporating advanced cybersecurity technologies and practices, the organization actively adapts to a changing cybersecurity landscape and responds to evolving and sophisticated threats in a timely manner.”
 
 

 

Profile

 

 
 
In essence, the framework profile assists organizations to progress from a current level of cybersecurity sophistication to a target improved state that meets the organization’s business needs. As stated by NIST, a profile is used to “identify opportunities for improving cybersecurity posture by comparing a current profile (the “as is” state) with a target profile (the “to be” state).” Comparison of profiles may reveal gaps to be addressed to meet cybersecurity risk management objectives. NIST states that the framework profile “can be characterized as the alignment of standards, guidelines and practices to the framework core in a particular implementation scenario.”
 

 

 
Framework Implementation
 

 

 
The framework is voluntary—at least for now. NIST also has explained that the framework “complements, and does not replace, an organization’s risk management process and cybersecurity program.” Organizations can use the framework as a reference to establish a cybersecurity program, or leverage the framework to “identify opportunities to strengthen and communicate its management of cybersecurity risk while aligning with industry practices.” The framework recognizes that “[o]rganizations may choose to handle risk in different ways, including mitigating the risk, transferring the risk, avoiding the risk, or accepting the risk, depending on the potential impact to the delivery of critical services.”
 

 

 
Importantly, the framework can be used as a means to communicate an organization’s required cybersecurity standards to business partners. As stated by NIST, “[t]he framework provides a common language to communicate requirements among interdependent stakeholders responsible for the delivery of essential critical infrastructure services,” such as the use of a target profile to “express cybersecurity risk management requirements to an external service provider (e.g., a cloud provider to which it is exporting data).” This is significant, because the cybersecurity shortcomings of “cloud” and other providers can have a profound impact on supply chains. As noted by NIST in the roadmap:
 

 

 
All organizations are part of, and dependent upon, product and service supply chains. Supply chain risk is an essential part of the risk landscape that should be included in organizational risk management programs. Although many organizations have robust internal risk management processes, supply chain criticality and dependency analysis, collaboration, information sharing and trust mechanisms remain a challenge. Organizations can struggle to identify their risks and prioritize their actions—leaving the weakest links susceptible to penetration and disruption. Supply chain risk management, especially product and service integrity, is an emerging discipline characterized by diverse perspectives, disparate bodies of knowledge and fragmented standards and best practices.
 

 

 
Incentives—and Cybersecurity Insurance

 

 
 
As-of-yet-unspecified governmental incentives will be offered to organizations that adopt the framework. The executive order directs the secretary of Homeland Security, in coordination with sector-specific agencies, to “establish a voluntary program to support the adoption of the framework by owners and operators of critical infrastructure and any other interested entities,” and to “coordinate establishment of a set of incentives designed to promote participation in the program.”

 

 
 
On Aug. 6, 2013, the White House previewed a list of possible incentives, including cybersecurity insurance at the top of the list. If cybersecurity insurance is adopted as an incentive, organizations that participate in the program may, for example, enjoy more streamlined underwriting and reduced cyber insurance premiums. As stated by Michael Daniel, special assistant to the president and cybersecurity coordinator, agencies have “suggested that the insurance industry be engaged when developing the standards, procedures and other measures that [make up] the framework and the program” and that “[t]he goal of this collaboration would be to build underwriting practices that promote the adoption of cyber risk-reducing measures and risk-based pricing and foster a competitive cyber insurance market.” Mr. Daniel states that NIST “is taking steps to engage the insurance industry in further discussion on the framework.”
 

 

 
The placement of cybersecurity insurance at the top of a list of possible incentives underscores the important role that insurance can play in an organization’s overall strategy to manage and mitigate cybersecurity risk, including supply chain disruption. Adam Sedgewick, senior information technology policy advisor at NIST, stated that NIST views “the insurance industry as a major stakeholder [in] helping organizations manage their cyber risk.” All of this is consistent with the SEC’s guidance on cybersecurity disclosures under the federal securities laws, which advises that “appropriate disclosures may include” a “[d]escription of relevant insurance coverage” for cybersecurity risks.
 
 

 

Going Forward
 

 

 
The framework is a “living document,” which states that it “will continue to be updated and improved as industry provides feedback on implementation.” As the framework is put into practice, lessons learned will be integrated into future versions to ensure it is “meeting the needs of critical infrastructure owners and operators in a dynamic and challenging environment of new threats, risks and solutions.” NIST will receive and consider comments about the framework informally until it issues a formal notice of revision to version 1.0, at which point it will specify a focus for comments and specific deadlines that will allow it to develop and publish proposed revisions. In addition, NIST intends to hold at least one workshop to provide a forum for stakeholders to share experiences in using the framework, and will hold one or more workshops and focused meetings on specific areas for development, alignment and collaboration. Therefore, organizations will continue to have the opportunity to potentially shape the final framework.

 

 
 

Issue 'Tickets' for Safety Violations?

Alberta may be on to something by issuing fines -- putting the blame where it belongs, whether company or worker -- before someone gets hurt.

A recent article in CompNewsNetwork describes the training of Alberta’s first occupational health and safety peace officers.

Don't get too excited. "Peace officer" is the same politically correct mumbo jumbo term some jurisdictions use for their prison guards.

These peace officers will have the ability to write tickets to employers and workers who cut corners and put people at risk. Classes of officers will continue training until all 143 OHS officers are certified to write tickets. The fines will range from $100 to $500. While employers here in the States have become accustomed to potential fines and regulatory actions for workplace safety infractions, this is different. First, a ticketing action is onsite and immediate, similar to being pulled over for driving 98 mph in a school zone. Second, and most dramatically, the worker -- the employee previously known as the innocent victim of corporate greed and arrogance -- could be the one on the receiving end.

That is huge: personal accountability in a no-fault world. Who'd ever heard of such a thing? Frankly, I have my doubts, but it will be interesting to see if this type of approach has any impact on reductions in workplace accidents.

The ticketing of employees for safety violations will strike some as a breach of exclusive remedy; the no-fault doctrine that has guided our industry for more than 100 years. 

I think they may be wrong. The adherence of exclusive remedy is strictly post-accident -- once an injury has occurred. These citations on the other hand are clearly in the safety and prevention realm. Personal responsibility still applies in that world. As long as, that is, this method is used in a preventative manner and not a post-injury action.

What remains to be seen is what these peace officers are willing to do. There is always a tendency to go for the “deep pocket,” and writing a $500 citation for a faceless company may be much easier than issuing it to the forklift operator with a wife, three kids and a broken-down car. And what of the post-accident investigation? Will these officers cite an employee for causing an accident? If I am a worker injured by another’s action, an action for which he receives the equivalent of a traffic citation, does that cement potential third-party liability for him?

Under our workers’ comp system in the States, this policy of writing tickets would be much less likely to see the light of day. Still, it is a concept worth watching. It is possible that Alberta is on to something here that will help avoid accidents by putting the blame where it belongs, whether company or worker, before someone gets hurt.

Yeah, that’s the ticket.

Go on Offense Using Social Media

Most companies make a common mistake: They set up accounts on popular social media sites like Facebook and Twitter -- then stop.

The plane pushed back as I settled into the sports section of my local paper. Just as I was getting comfortable, the pilot made an announcement that our flight was going to be delayed for a short time. We ended up sitting on the tarmac for two hours.

I missed my connection, and, to make matters worse, the customer service personnel at the connecting hub airport were anything but service-oriented. Frustrated beyond belief, I posted a message on Twitter, my Facebook page and on several travel sites, “ABC Airlines SUCKS!"

Much to my surprise, less than an hour later I got a post to my rant signed by the airline's customer service department, with a link to their website. The link led me into a chat room where I described my experience. A service representative apologized and offered me an upgrade on my return flight home the next day. My frustration ebbed. I even posted another Tweet: "Thanks, ABC Airlines Customer Service!!"

The experience taught me two valuable lessons: (1) With the advent of social media, unhappy customers can do real damage to a company's reputation; and (2) companies can no longer wait for their customers to call and complain. They must engage their customers in real time.

Since that experience I've been focused on how our company can leverage social media to improve our customer service. The effort required me to better understand all that social media entails. Fortunately, we have a lot of experts - the young people who work for us. They use social media like a second language. It's incorporated into their lives.

The same approach applies to a successful social media strategy for a business. The organization must incorporate social media into its day-to-day operations. Most companies make a common mistake: They set up accounts on the popular social media tools like Facebook and Twitter but don't do much after that. In effect, social media gets treated as an outlier.

Opportunistic social media

Many people think of social media as Facebook and Twitter—but those are just tools. I view social media as the ability to engage in social interactions online with people you know and don't know. You engage with social media through a series of websites and applications. But it’s the collective power to communicate that makes it so powerful.

Imagine if you could "communicate" regularly with an existing policyholder. You wouldn't need to wait until some triggering event like a problem with a bill or frustration with a claim occurs. Research shows that such regular contact would increase an insurance company's retention rate.

Here's an example of opportunistic social media: When there’s a potential major weather event, use social media sites to offer tips on how to secure a home and inventory personal holdings. The information will come up on searches and drive traffic to both your social media sites and website. A company can even change its homepage temporarily and put up a splash page: If you’re in this area, click here; if not, click a different button for the homepage.

People don’t think about insurance often. That’s why opportunistic use of social media is effective. People will be more inclined to read something from an insurer when they’re concerned about their immediate safety and security.

Going on defense

Social media poses challenges and dangers for any company serving the public. Consumers now have power to wreak havoc. Anyone who feels, rightly or wrongly, abused by an insurer can use social media to post an angry screed: “ABC Insurance Co. stinks."

That can do real damage to your brand. Negative reviews get aggregated, and, if there are enough of them, they’ll show up at the top of an online search of your company.

Customers tend to post only when they’re angry with their insurer. Happy customers typically remain silent. How can you find out about problems customers are having before they are angry enough to call? Establish a team dedicated to scouring all social media for comments about your company.

If I had any doubts about the impact of social media, the view out my window provides ample evidence. Located in the middle of Silicon Valley and just a short walk to Facebook’s headquarters, I'm surrounded by start-up companies bringing new services and tools to the digital world. The social media revolution is here to stay.