Download

The Two Must-Haves for Employment Practices Liability Insurance

The great majority of employers in California should at least seriously consider the addition of an EPLI policy, but not just any policy will do.

If you own or manage an organization and have not experienced an employee claim, count yourself lucky—and know that the chances are very good that your luck will change.

Many employers purchase Employment Practices Liability Insurance (EPLI) because general business insurance policies exclude employment-related claims for issues such as discrimination, harassment and wrongful termination.  Many EPLI policies do not, however, cover commonly asserted claims such as wage and hour violations or statutory penalties. The issues are complicated enough that decisions on EPLI require the assistance of two experts: a knowledgeable and trusted insurance broker and an experienced employment defense attorney. The insurance broker will guide you through the various policy options available and provide a wealth of risk-management information.  The defense attorney will advise on the real-world impact a particular policy will have when an employment claim arises.

If you purchase EPLI, you should prepare for employment claims before they are even asserted, by following these steps:

  • Select Defense Counsel in Advance. If you already use trusted employment law counsel, your carrier may allow you to designate your chosen law firm at the time the policy is purchased or renewed.  Some policies allow the insured to select its own counsel without such pre-designation.  Asking the right questions of your broker and specifying at the outset the employment lawyer you want is the best way to ensure that you get the defense counsel of your choice.  
  • Train Staff on Claims Recognition. Train key personnel to recognize a "claim" as it is defined under the EPLI policy.  What constitutes a "claim" is generally defined broadly.  A “claim” may even include pre-lawsuit claims, such as a discrimination complaint filed at a governmental agency like the California Department of Fair Employment and Housing.  Even a "demand" letter from a threatening employee or lawyer may constitute a claim.  As policies change from year to year, the definition of a claim may also change.  Key personnel should know what to do when a potential claim is spotted, including the who, what and when of communicating with the insurance broker or carrier.
  • Develop Protocol for Receipt and Processing of Claims. It is a good idea to have a specific person designated to whom all "claims" are promptly forwarded. The protocol should also include things such as identifying the name of the employee who received the claim and the date, time and how the claim was received.  It is critical to ensure that a potentially covered claim is properly and quickly processed. Communication problems can arise inside organizations because finance and operations executives, who were involved in buying the EPLI policy, tend to be knowledgeable about the terms of the EPLI policy, while human resources personnel tend to be the first to know that a claim has been filed.
  • Be Thoughtful and Precise in "Tendering" Claims to the Carrier. Once a claim arises, carefully consider the requirements in the policy for tendering the claim.  This may involve discussions with legal counsel regarding the pros and cons of tendering a particular claim at all and will definitely include advice on how and what to communicate with the carrier. Careful consideration cannot result in much delay.  EPLI policies typically require very prompt communication of claims and potential claims.  Follow carefully the means and timing of "tendering," i.e., providing written notice to the carrier, as stated in the policy.   A copy of the lawsuit, administrative charge or “demand” letter should accompany the tender.  Follow up to ensure that the carrier has received the claim and accepted it.

    As a general rule, attorneys' fees and costs incurred to defend a tendered claim may not "count" against the insured's retention (deductible) until the date of tender.   If you incur attorneys’ fees and costs before the claim is tendered to the carrier, your company will likely have to pay those fees plus the full amount of the retention.  Worse yet, if a claim is not tendered in the manner and time frame required by the policy, the claim may be denied.  

The great majority of employers in California should at least seriously consider the addition of an EPLI policy, but not just any policy will do.  Without the expert guidance of a knowledgeable broker and employment counsel, you might be shelling out premium dollars that do not effectively achieve your risk-management objectives.  Once you have a policy, the development of effective protocols for handling claims is essential.  Those protocols will ensure that claims are not denied and that they are positioned to be effectively defended.

As Obamacare's 'Compassionate' Reality Sets In, Companies 'Cruelly' Cut Health Benefits

Employers are doing just enough to avoid Obamacare's dictates.

Employees of shipping giant United Parcel Service recently got an unexpected delivery. The company announced that it would stop offering health coverage to the spouses of 15,000 workers.

UPS’s workers and their families can thank Obamacare for this special delivery. And UPS isn’t alone. American businesses are discovering each and every day that the president’s signature law will raise health costs for them and their employees in short order.

In a memo explaining the decision to employees, UPS stated that increasing medical costs “combined with the costs associated with the Affordable Care Act, have made it increasingly difficult to continue providing the same level of health care benefits to our employees at an affordable cost.”

One day before UPS’s big announcement, the University of Virginia announced that it would cut benefits for spouses who have access to health care through jobs of their own. The rationale was similar.

Delta Airlines recently revealed that Obamacare will directly increase its direct health costs by $38 million next year. After taking into account the indirect costs of the law, the company is looking at a 2014 health bill that’s $100 million higher.

Increasingly, large employers who aren’t dropping spousal health benefits are requiring their employees to pay monthly surcharges in the neighborhood of $100 per spouse.

Many small businesses are dropping family coverage altogether because they expect that Obamacare’s new tax on insurers will be passed on to them in the form of higher premiums. One Colorado-based business received notice from its insurer that the tax would increase premiums more than 20 percent.

The story is similar in Massachusetts. One new report concludes that over 45,000 small businesses in the Bay State will see premium increases in excess of 30 percent. In all, more than 60 percent of firms in the state will see their premiums go up.

Last month in California, the largest insurer for small businesses — Anthem — declared that it would not participate in the state’s small-business health insurance “marketplace,” Covered California. Only two years ago, Anthem covered one-third of small businesses in California.

Anthem’s exit represents one less choice for consumers — and a sign that competition may not be as robust in the exchanges as the Obama Administration promised.

Small businesses are responding to these higher premiums by trimming their labor costs in other ways. That’s not good news for workers.

Seventy-four percent of small employers plan to have fewer staff because of Obamacare, according to a recent U.S. Chamber of Commerce survey. Twenty-seven percent are looking to cut full-time employees’ hours, 24 percent to reduce hiring, and 23 percent to replace full time with part-time employees.

One in four small companies say that Obamacare was the single biggest reason not to hire new workers. For almost half, it’s the biggest business challenge they face.

These findings are consistent with a recent Gallup Poll showing that 41 percent of small businesses have already stopped hiring because of Obamacare. Another 19 percent intend to make job cuts because of the law.

All this tumult in the labor market is fueled by more than the increase in premiums engendered by Obamacare. The law effectively encourages companies to cut full-time jobs.

Obamacare requires employers with 50 or more workers to provide health insurance to all who are on the job for 30 or more hours per week. The law originally called for this “employer mandate” to take effect in 2014, but the Administration decided in July to delay enforcement of the mandate until 2015.

Employers are responding by doing just enough to avoid Obamacare’s dictates.

Administrators at Youngstown State University in Ohio recently told adjunct instructors, “[Y]ou cannot go beyond twenty-nine work hours a week. . . . If you exceed the maximum hours, YSU will not employ you the following year.” A week prior the Community College of Allegheny County in Pittsburgh made a similar announcement.

Hundreds of employees at Wendy’s franchises have seen their hours reduced for the same reason.

Meanwhile, companies with fewer than 50 employees are thinking twice about expanding — and thus being ensnared by Obamacare’s requirement that they provide health insurance.

The cost of each additional employee could be staggering. A firm with 51 employees that declined to provide health coverage would face $42,000 in new taxes every year — and an additional $2,000 tax for each new hire. Providing coverage, of course, would be even more expensive.

Meanwhile, as private firms large and small grapple with Obamacare-fueled cost increases, one large employer — the federal government — has been quietly exempting itself from portions of the law.

Top congressional staffers like their current benefits under the Federal Employee Health Benefits Plan (FEHBP), wherein the government pays up to 75 percent of the premiums.

But the law requires those who work in lawmakers’ personal offices to enter the exchanges. And in many cases, staffers  make too much to qualify for health insurance subsidies through the exchanges. So they’d be facing a hefty cut in their compensation.

Fearing a mass exodus of congressional staffers from Capitol Hill, the Obama Administration fudged the law to permit lawmakers’ employees to receive special taxpayer-funded subsidies of $4,900 per person and $10,000 per family.

Yet only three months ago, Senate Majority Leader Harry Reid (D-Nev.) claimed that Congress wouldn’t make exceptions for itself.

President Obama no doubt knows that these congressional favors won’t go over well with ordinary Americans. So he’s called on his most popular deputy — former President Bill Clinton — to try to sell the law to the public once again.

But unless the former president can lower employer health costs with little more than the power of his words, his sales pitch will likely fall flat.

This article was first published at Forbes.com.

Resolving the Confusion About ‘Admitted’ and ‘Non-Admitted’ Carriers

While your ultimate choice of an insurance company may be restricted based on the type of insurance you need, the priority should always be to seek a high-quality provider, regardless of whether the company is admitted or non-admitted.

Confusion sometimes arises about the difference between "admitted" and "non-admitted" insurance carriers and about the consequences of the difference. The designation of an insurance company by a state’s Insurance Commissioner as “admit­ted” may seem to give the company a stamp of authority, but this designation is primarily an administrative one rather than a mark of quality or stability. Other factors should be more important in the choice of a carrier.

Let’s take a close look at what admitted v. non-admitted really means.

What is an “Admitted” Insurance Company? - An admitted carrier is often referred to as a “standard market carri­er.” To qualify as an admitted carrier, an insurance company must file an application with each state’s insur­ance commissioner and be approved. Approval requires compliance with a state’s insurance requirements, including the filing and approval of that company’s forms and rates. This process often takes a long time.

Once a carrier is licensed to transact insurance business in a certain state, the carrier is required to pay a portion of its income into the state's insurance guaranty association. One of the main selling points of being an admitted is that the carrier’s liabilities are backed by that state’s “guaranty fund.” If an admitted company becomes insolvent, the state will help pay off policyholders’ claims. 

What is a “Non-Admitted “Insurance Company?  - A non-admitted carrier is often referred to as an “excess and surplus line carrier” and operates in a state without going through the approval process required for admitted companies. Non-admitted carriers are not bound by filed forms or rates and therefore have much greater flexibility to write and design policies to cover unique and specific risks, and to adjust premiums accordingly. When standard markets can’t or won’t write a risk, or when an admitted carrier cannot offer the appropriate terms, the non-admitted market is available to fill this gap.

Non-admitted insurance carriers are regulated by the state Surplus Lines offices, but regulation is far less invasive than for the admitted markets. The most obvious difference between admitted and non-admitted is that purchasers of non-admitted policies do NOT have the protection af­forded by the state’s guaranty fund. Each state does charge taxes for non-admitted insurance, and agents must be licensed in surplus lines to sell non-admitted insurance.

The designation as “non-admitted” should not be taken as an indication that these insurance carriers aren’t legitimate or financially stable. In fact, to sell surplus lines insurance, non-admitted insurance companies have to set aside a large monetary reserve or secure adequate re-insurance.

Insolvency - When an insurance commissioner determines that an insurance company is having significant financial difficulties, the insurance company will go through a process called “rehabilitation.” The state’s insurance commissioner will make every attempt to help the struggling company regain its financial footing. If the company cannot be rehabilitated, the company is declared insolvent, and the court will order liquidation.

Liquidation of an Admitted Carrier - If the carrier to be liquidated is an admitted company, the processing/pay­ment of existing and future claims is taken over by that state’s guaranty fund. However, the guaranty fund’s obliga­tions are limited by regulations and will only pay claims up to that state’s cap.  In some cases, if insureds exceed a certain revenue threshold they may not quality for any guaranty fund coverage. 

Depending on the state, guaranty funds usually provide only $100,000 to $500,000 of protection per policy even if the policy had a much higher limit. Most states are at $300,000. In addition, if several liquidations take place in one state, the state’s guaranty fund may be depleted. Policyholders often only receive pennies on the dollar of their true loss amount from a guaranty fund.

While state guaranty funds try to pay claims as quickly and efficiently as possible, payments are often slow.

In sum, although the guaranty funds provide some level of comfort if a carrier becomes insolvent, in reality, policyholders can be left with little or no assistance.

Liquidation of a Non-admitted Carrier - If a non-admitted insurance company goes “belly up,” the liquidator/receiver collects the assets of the company, determines all the liabilities/creditors outstanding, develops a plan to distribute the company’s assets and submits the plan to the court for approval (much like a typical bankruptcy pro­ceeding). In most cases, the insurance company’s estate will not yield sufficient money to pay the company’s cred­itors (including their policyholders' claims) in full. Policyholders often have to fund defense and settlement payments themselves before they can request reimbursement from the estate. Usually, the policyholder will have to wait patiently and will,  again, only get pennies on the dollar.

The largest surplus lines writer in the U.S. is Underwriters at Lloyd’s, London. In 1925, Lloyd’s created the Lloyd’s Central Fund, which pays claims in case any underwriting member should be unable to meet his or her liabilities. Unlike the guaranty funds, the Central Fund does not have a cap. The only cap for the Central Fund is the policy limit. (Illinois, Kentucky and the Virgin Islands are exceptions because Lloyd’s is admitted there and is subject to the state guaranty funds.)

Bottom Line - The choice between admitted and non-admitted insurance companies is something that needs to be considered, but examining the financial strength of the individual providers, the breadth of coverage and competitiveness of terms is more important. The priority should always be to seek a high-quality provider, regardless of whether the company is admitted or non-admitted.

When Terrorism Insurance Doesn’t, in Fact, Cover Terrorist Acts

The issues involved in insurance coverage for terrorism are complicated and need to be considered carefully by the insurance agent or broker.

Having marked another grim anniversary of 9/11, many companies have either bought insurance against terrorist acts or are considering doing so. But the issues related to coverage are more complicated than people realize.

Just because acts meet the common-sense definition of terrorism and are generally referred to as terrorist acts doesn’t mean they’ll be treated that way under a federal program known as TRIPRA, which is generally seen as terrorism insurance. To meet the standards under TRIPRA, the acts have to be officially certified as terrorist acts by the Secretary of the Treasury, in conjunction with the Secretary of State and the Attorney General. (TRIPRA stands for Terrorism Risk Insurance Program Reauthorization Act; it is the 2007 continuance of a program initially instituted in 2002 and known then as TRIA, for Terrorism Risk Insurance Act.)

The designation is important because a business damaged in what is officially certified as an act of terrorism can only collect on a claim if it has purchased terrorism insurance under TRIPRA, which is a reinsurance program designed to pool the risks from terrorism.

Reports following the bombings at the finish of the Boston Marathon in April say that few of the stores that were damaged carried terrorism insurance. Many of these claims are now in limbo because the bombings have not been certified as terrorist acts, but President Obama did use that term in a speech. His pronouncement will be part of the process that insurance adjusters will use to accept or deny coverage requests by the injured parties under various parties’ liability insurance as well as the physical damage and business interruption claims filed by the businesses that were affected by the bombing but that didn’t carry terrorism insurance. (According to an article in Insurance Journal, 207 property/casualty claims were filed related to the Boston bombings; 84 have been settled for a total of $1.2 million, and 76 have been closed without a payment.)

Where does this leave the agent and broker trying to take care of a client?  As is human nature, all of us in the US have become rather complacent about the prospects for acts of terrorism, and many clients may discount their exposure to this type of event.  Well, as a producer, your job is to identify risk and offer solutions.

Offering TRIA/TRIPRA coverage on a “sign here” basis is not good enough.  You should also investigate stand-alone terrorism coverage.  There are a number of markets that offer this coverage.  You need to offer both types of risk transfer in writing – get a quotation for the stand-alone coverage for property and casualty losses.  The marketplace provides more options for property risk than the casualty risk in stand-alone terrorism coverage, but it is still available for both areas.

Quite recently, several respected organizations and publishers within the insurance industry have put out very well-written articles providing information regarding TRIPRA and the terrorism marketplace, in general.

The first is an Insurance Journal article that outlines the issues and concerns surrounding the congressional debate that will need to take place within the next year, as the TRIPRA legislation expires at the end of 2014: Demand, Rates for Terrorism Insurance Coverage Remain Steady: Marsh.

Next is an article written by the Insurance Information Institute that provides an overview of terrorism issues and concerns and also speaks to the current legislation and reauthorization efforts: Terrorism Risk and Insurance.

Last is the 2013 Terrorism Risk Insurance Report researched and written by Marsh USA: 2013 Terrorism Risk Insurance Report (registration required).

To help you navigate the issues (and to demonstrate their complexity), here is a summary of how insurance for terrorist acts is handled:

  • If the insured purchased Commercial Property Coverage on a Special Form basis and Commercial General Liability Coverage, and the act is deemed a terrorist act, then:
    • If the loss is not “Certified,” there will be no coverage response even if the insured accepted the “TRIA” offer.
    • If the loss IS “Certified,” there will be no coverage response if the insured did not accept the “TRIA” offer.
    • If the loss is “Certified,” and the insured accepted and paid for the “TRIA” offer, coverage should respond.
    • Stand-alone terrorism coverage would respond, whether “Certified” or not.
  • If the loss is not deemed to be a terrorist act, then:
    • Coverage should apply under the Property Coverage form as an act of vandalism, fire, explosion, etc.
    • Coverage should apply under the Business Income and Extra Expense Coverage form for those that experience a covered direct physical loss.
    • Coverage should apply under the Business Income and Extra Expense Coverage form under Civil Authority for the period that the City of Boston shut down access to the immediately surrounding area.
    • If the Commercial Property / Business Income policy includes a manuscript endorsement, Ingress / Egress, then coverage should apply if there is a lack of access to or from the business.
    • Coverage will not apply to the general economic downturn experienced by businesses in geographic proximity during the aftermath of this event.
    • Coverage should apply under the General Liability policies for those entities that are sued as a result of the wrongful deaths and injuries that were sustained.

There are separate exclusions that apply to nuclear, biological, chemical and pollution-related events that could also remove coverage.

As you see, the issues are complicated and need to be considered carefully. Send me an email if you need more information.

You May Not Have All the Coverage You Think You Have

Arming yourself with knowledge ahead of time can help you to develop strategies and create records that maximize coverage, facilitate resolution of current disputes, and eliminate potential future disputes.

Misunderstanding the language contained in the self-insured retention ("SIR") in an insurance policy can cost policyholders millions of dollars.

SIRs, which appear in many liability policies, are similar to deductibles but require the insured to bear responsibility for a certain amount of the loss (including damages and defense costs) "before there is any coverage under the policy."1  (A deductible is generally a sum the insured "'must pay before the insurer owes its duty to indemnify the insured for a covered loss'" and generally refers "only to the 'damage for which the insured is indemnified, not to defense costs'").2   The language of the SIR, which varies from policy to policy, ultimately controls when and how an insured's coverage is triggered.

Some policies contain language that preclude anyone other than the named insured from satisfying the SIR—which can catch companies by surprise.

In a 2010 case, Forecast Homes, Inc. v. Steadfast Insurance Company3  ("Forecast"), a housing developer faced a construction defect lawsuit filed by several homeowners.4   The developer argued that its subcontractors' insurer, Steadfast, should provide coverage for the lawsuits, pursuant to contracts that required the subcontractors to provide additional insured coverage for the developer.5   But the courts disagreed because the named insured subcontractors, who were not parties to the construction defect lawsuits, did not satisfy the SIR in the Steadfast policies, a prerequisite for coverage.6   And, the developer could not satisfy the SIR itself as an additional insured.7

There were several Steadfast policies invoked in this lawsuit, but these policies contained essentially two versions of the SIR.8   Version one provided that "you [the named insured] shall be responsible for payment of all damages and defense costs for each occurrence or defense, until you have paid [SIR] amounts and defense costs equal to the [p]er [o]ccurrence amount shown in the Schedule[.]"9   Version two contained this same language but added explicit language precluding anyone other than the named insured from satisfying the SIR.10   The court held the plain language of version two clearly barred the additional insured developer from satisfying the SIR.11   But the court also found that the less explicit version one precluded anyone other than the named insured from satisfying the SIR, relying on the section providing that "you"—defined as the named insured—are responsible for payment of defense and damages until the SIR is satisfied.12   Developer Forecast Homes, to its surprise, could not satisfy the SIR to trigger coverage as an additional insured.

Under different language, though, courts have allowed insurers, additional insureds, or others to satisfy the SIR.  For example, in National Fire Insurance Company of Hartford v. Federal Insurance Company ("National"),13  National Fire Insurance Company of Hartford ("NFIC") paid its policy limits to settle a suit on behalf of its named insured (a restaurant) and its additional insured (a hotel).14   NFIC then sought reimbursement from the hotel's insurer, Federal Insurance Company ("Federal").15   Federal argued that it was not obligated to pay a portion of the hotel's defense or indemnity because the hotel had not satisfied the $250,000 SIR, and the SIR could not be satisfied through NFIC.16   The court disagreed.17

Similar to version one of the policy at issue in Forecast, the Federal policy provided "[w]e have no obligation or liability under such Coverages unless and until the applicable [SIRs] . . . . are exhausted by payments you make . . . .  You must pay all [SIR] expenses."18   But the Federal policy at issue in National contained language that "'bankruptcy, insolvency or the financial impairment of any insurer or any other person or organization does not relieve the hotel of its obligation to satisfy the SIR," unlike the language in Forecast that referred "only to the insured's own bankruptcy or solvency."19   The language in National, combined with the absence of explicit policy language prohibiting another insurer from satisfying the SIR, compelled National to find that there was no bar to NFIC satisfying the SIR in the Federal policy on behalf of the hotel, the named insured.20

What does this mean if you are an insurer considering settlement?  And how can insureds use this information to facilitate settlement or avoid future disputes?

  • Know your policy language ahead of time.  Make sure you look at your policy and other potentially relevant policies before entering settlement negotiations and understand exactly who can satisfy the SIR.  If the SIR must be satisfied by the named insured and you are an additional insured, make sure that topic is part of the negotiations.  If the named insured is not a party to the action, consider whether you have grounds to bring the named insured into the action.  If the SIR can be satisfied by other insurers or co-defendants, then you have more flexibility in negotiating.
  • Consider sharing your knowledge.  Knowing how to satisfy the SIR not only protects you in settlements but may help facilitate settlements.  For example, if your insurer is reluctant to contribute because it is taking the position that other insurers should be at the settlement table, look at the relevant policies and determine whether the other parties can satisfy the SIR in these other policies.  If so, pointing this out to the insurers and increasing their comfort level with their chances for contribution may compel the insurers to tender additional policy funds that allow for settlement. 
  • Spell it out.  Think about potential coverage disputes and explicitly state relevant terms that could help resolve any disputes that have arisen or may arise.  For example, if the named insured is required to satisfy the SIR and, in fact, does so, state that in the mediation or settlement briefs, or otherwise memorialize it, so that the issue is clear and does not lead to disputes.  Understanding the disputes that may arise can help insureds create records that will allow for quick resolution or avoid the disputes altogether.

These recommendations are particularly important to insureds in the construction industry, where contractors frequently require subcontractors to name them on their insurance policies as additional insureds and are frequently contractually required to name others on their own policies as additional insureds.  Similarly, these recommendations are also important to corporations that face large-exposure lawsuits that exceed the limits of their primary coverage and need to trigger coverage under their excess policies to resolve matters.  In these circumstances, knowing who can exhaust an SIR can be critical to securing potentially millions in coverage. 

For all insureds, arming yourself with knowledge ahead of time can help you to develop strategies and create records that maximize coverage, facilitate resolution of current disputes, and eliminate potential future disputes.

1 Hon. H. Walter Croskey, Hon. Rex Heeseman and Christina J. Imre, California Practice Guide: Insurance Litigation (The Rutter Group 2013) ¶7:384.

2 Id.; see also Forecast Homes v. Steadfast Insurance Co. (2010) 181 Cal.App.4th 1466, 1474 (internal citations omitted, original italics).

3 (2010)181 Cal.App.4th 1466.

4 Id. at 1470.

5 Id. at 1469-1470.

6 Id. at 1470.

7 Id.

8 Id. at 1470.

9 Id. at 1471.

10 Id. at p. 1472.

11 Id. at 1476-1478.

12 Id. at 1480-1481.

13 (2012) 843 F.Supp.23 1011.

14 Id. at 1012.

15 Id. at 1012-1013.

16 Id. at 1016.

17 Id. at 1017.

18 Id.

19 Id. at 1017, italics added; Forecast, supra, 181 Cal.App.4th at 1472.

20 National, supra, 843 F.Supp.23 at 1017.

Zero Injury: A Cultural Imperative for the Construction Industry

The shift to a zero injury culture instills a true belief that injuries and fatalities are not acceptable, should not be condoned, and cannot only be reduced, but actually prevented.

If there is a silver lining in the protracted downturn and delayed recovery in the construction economy, it is that “fatal construction injuries are down nearly 42% since 2006,” according to the BLS National Census of Fatal Occupational Injuries in 2011.

That same report observed that “fatal work injuries in the private construction sector declined to 721 in 2011 from 774 in 2010, a decline of 7% and the fifth consecutive year of lower fatality counts.”

However, as the general economy stabilizes and construction spending and project volumes increase, it will not be long before hiring pressures mount throughout the industry.

With an increase in hiring comes an opportunity to institute increased emphasis on safety through employee selection standards, substance abuse testing, new employee orientation and training processes, as well as job safety analyses and daily “huddles” to address project safety requirements.

There is no better time than now for construction company owners and construction financial managers to focus on systematic injury prevention by adopting a zero injury vision and strategy and begin a transformation into a zero injury culture.

Reality Check: Stop Rationalizing Construction Injuries & Fatalities As A Cost Of Doing Business

Stop for a moment and reflect on the hard fact that many construction workers are injured, disabled, and killed at work each year. It is widely recognized (or rationalized) that construction is a hazardous industry, accidents happen, and jobsite conditions are constantly changing and difficult to control.

The reality is that the overwhelming majority of injuries and fatalities are preventable. A common trait we’ve observed among companies that have adopted a zero injury culture is an underlying philosophy and belief that all injuries and fatalities can be eliminated.

What is required to make this philosophy a reality? Leadership resolve to change the prevailing attitude that rationalizes fatalities and injuries as an unfortunate aspect of the construction industry and a cost of doing business and a culture shift that changes the attitudes, beliefs, and behaviors of all industry stakeholders.

This shift to a zero injury culture instills a true belief that injuries and fatalities are not acceptable, should not be condoned, and cannot only be reduced, but actually prevented. This culture shift is necessary at the project, company, and industry levels, as well as in the thoughts and actions of each construction employee.

Zero Injury Culture Is For All Companies

Culture shapes the performance expectations of such key workplace attitudes as the importance of punctuality, wearing proper attire, and how hard to work (or not to work). It directly influences safety attitudes and behaviors, including whether employees wear protective equipment, ignore training instructions, and/or take safety shortcuts to finish work faster.

Therefore, culture determines if a company or work crew will act with a safety-conscious and risk-averse set of values or accept “at-risk” attitudes and behaviors as the prevailing norm.

With the emphasis on zero injury or zero incident culture by large contractors, many small- and medium-sized contractors are wondering if this is a suitable strategy for them as well. We believe all companies can benefit from adopting a zero injury vision and strategy.

The success of a company’s drive to attain a zero injury culture hinges on a company’s owners and senior leaders who must instill, reinforce, and sustain the core building blocks of a zero injury safety culture shown in Exhibit 1 below.

Exhibit 1: Zero Injury Safety Culture Building Blocks
Representative Examples
Attitudes

Zero Injury is attainable on every shift and every project.

Zero injury culture needs to permeate all company activities and not be viewed as a separate process.

Beliefs

All levels of the organization believe that zero injury is achievable — from company executives to all craft/trade employees.

 

All employees accept personal responsibility and accountability for zero injury.

 

Values

The company values the health and safety of all employees.

The company is committed to employees going home safe at the end of every work day.

Assumptions

Employees are not taking unnecessary risk.

New employees accept safe work practices as the expectation.

Norms

Employee behavior on projects rejects shortcuts and recognizes that unnecessary risk-taking is not acceptable.

Zero injury is ingrained in the way the company builds every construction project — regardless of size, location, company division, manager/supervisor, and/or schedule.

How To Institute A Zero Injury Culture

Companies that have adopted a zero injury culture generally have instituted the measurement of leading indicators in addition to traditional lagging indicators (which are discussed in Risk Performance Metrics). Leading indicators focus on the prevention-based activities that drive improved safety expectations and performance outcomes.

Exhibit 2 outlines a life cycle process for the development of a zero injury safety culture. We have high-lighted five distinct phases and delineated key steps and milestones for each phase. The five-phase model is presented to provide a useful framework for monitoring the progress of the evolving process.

For simplicity, Exhibit 2 summarizes key challenges, major milestones, and process outcomes in each of the five phases of the zero injury culture development life cycle. Similar to safety culture development, rarely is a one-size-fits-all approach appropriate for any organizational process or practice. Company culture is unique and will grow and change in its own way.

Building an organizational safety culture can be a slow and messy process, and it does not necessarily follow a linear progression. Sometimes the adage of “one step backward to go two steps forward” is necessary advice.

A model of organizational transformation that we found relevant and realistic to instituting zero injury culture is “Journey of Transformation: The CFO’s Perspective” (by Renee Beaulieu, Skip Perley, Dr. Perry Daneshgari, and Heather Moore in the May/June 2012 issue of CFMA Building Profits), which describes the Strategic Breakthrough Process Improvement.

Many of the companies adopting a zero incident or zero injury culture often describe their process of doing so as a journey.

Safety Culture Development Challenges

The 10-question Safety Culture Health Check in Exhibit 3 can provide your company’s leadership with an assessment of their personal and organizational readiness for instituting a zero injury culture.

Exhibit 3: Safety Culture Health Check

The following 10 questions are designed to provide a quick assessment of your company’s current safety culture. Even though this health check cannot provide insight as deep as a comprehensive, systematic safety perception survey, it is a useful tool for gauging the need to expand safety awareness and accountability.

  1. Does your company’s senior management team operationalize safety commitment and show demonstrable involvement in managing the process by addressing safety as a core strategic discipline that positively impacts the execution of company and project performance?
  2. Do your company’s supervisors and employees fundamentally believe that all accidents and injuries are preventable, or do they believe that accidents and injuries are part of working in the hazardous construction industry?
  3. Is your company known for having a robust safety program with rigorous attention to safety, or is safety known to take a backseat to production pressures?
  4. Does your company’s prevailing attitude toward safety regard it as a necessary evil that decreases productivity or as a vital process that positively impacts productivity and profitability by maintaining a healthy workforce?
  5. Is safety performance viewed as the responsibility of a corporate safety officer, or is adhering to safe work practices the responsibility of every employee?
  6. Does your company have a culture that condones or eliminates safety shortcuts?
  7. Does your company engage all employees in safety processes, including conducting safety observations to identify and correct unsafe conditions and “at-risk” behaviors?
  8. What is your company’s reputation for safety among peer group companies and among the recognized industry leaders?
  9. Is safety an important aspect of your company’s brand image and reputation?
  10. Is your senior management team willing to go “all-in” for the safety and welfare of its employees by making it a core value of the company?

It is crucial that the zero injury culture process be well conceived with thoughtful consideration of how to communicate the company’s commitment, secure employee engagement, and implement functional support structures to reinforce and sustain the process.

It is important to recognize that employees will intuitively know if the company leadership sincerely wants to adopt a zero injury culture. Employee skepticism will run high if the company has a history of initiating and quickly abandoning “fad of the month” safety programs.

A final “gut-check” question is necessary to determine your company’s readiness and resolve for adopting a zero injury culture: Is your company ready and willing to commit to adopting, instituting, and sustaining a zero injury culture? In honestly evaluating this question and its implications, it is natural to consider the challenges in doing so and identify the obstacles to overcome for your company to be successful.

Benefits & Outcomes

Once implemented, the benefits of a zero injury safety culture will be realized through reduced claim severity and frequency, increased productivity, and improved profitability. Once a zero injury safety culture is achieved, your company will:

  • Become an employer of choice, reduce voluntary attrition, and improve morale among existing employees
  • Increase productivity by decreasing time spent investigating employee injuries and reducing idle equipment, thereby increasing potential for improved margins
  • Decrease direct and indirect costs associated with employee injuries, thereby reducing your company’s total cost of risk
  • Demonstrate improvement in project owners’ prequalification metrics (e.g., total recordable cases (TRC); days away from work, job restriction, or transfer (DART); Workers’ Compensation Experience Modification Rate (EMR), etc.), thereby remaining on eligible bidder lists and increasing opportunities to bid desirable projects
  • Align zero injury culture with other strategic zerobased risk management objectives: zero defects, zero crashes, zero equipment breakdowns, zero defaults, zero IT downtime, and zero disruptions (For more information, read “Zero Disruptions: Preparing for Unexpected Business Interruptions & Protecting Your Assets” by Calvin E. Beyer and Brian J. Cooney in the May/June 2011 issue.)
  • Attain respect among peer competitors and establish a positive reputation in the industry

Management Safety Culture Assessment

Various survey instruments have been developed to measure perceptions of safety management culture. The Management of Safety Culture Assessment is based on the Determinants of Safety Culture Model, which assesses the measurable capacity and performance ability of companies to minimize accidents, injuries, and related costs.

According to Dr. Christopher Garrabrant, the Management Safety Culture Assessment and Determinants of Safety Culture model are founded on Charles Perrow’s 1994 discussion of Normal Accident Theory and High Reliability Theory, both of which correlate to reducing losses.

Garrabrant asserts this Management Safety Culture Assessment identifies and measures 15 factors within five broad categories that contribute to the success of a company’s safety culture, as shown in Exhibit 4.

Exhibit 4: Management Safety Culture Assessment
  Assessment Category Assessment Factors
1. Organizational Leaders Operationalize Commitment

Demonstrable senior leadership participation and involvement

Resource allocation

Core processes and results measured

Accountability system for safety at all levels of the organization

2. Identify Safety and Reliability as Goals

Safety as a goal is consistently and clearly articulated

Multiple and independent channels of communication

Decentralized decision-making authority

3. High Levels of Redundancy in Personnel and Technical Safety Measures

Continuous operations and training

Job hazard analyses are owned, continuously reviewed, and updated

4. Organization Strives for a “High Reliability Culture”

Presents optimism toward a desired future state

Consistent communications

Adaptability to change

5. Sophisticated Forms of Trial and Error Organizational Learning

Capacity to learn and act

Accident investigations are blame-free and pursue systemic improvements

Hazard analysis occurs before accidents

A company demonstrates the necessary values within its culture to promote the health and well-being of its employees. The culture demonstrates behaviors that can be expected to result in fewer workplace accidents and achieve a more rapid return to work should an accident occur. The assessment is intended to validate a company’s ability to exceed industry expectations of safety performance.

Importance Of A Zero Injury Mind Shift In The Construction Industry

We recognize that for a true zero injury culture to occur, the mindset of zero injury needs to reach beyond the individual company culture and become the norm for the construction industry as a whole, since many contractors use the same subcontractors, vendors, and workforce. Therefore, until the industry – including all owners, contractors, and employees – takes a unified stance against unsafe behaviors and acts, each individual company will obtain limited success as a zero injury culture.

We envision a construction industry with the shared culture where workers have the same positive experience at every project where they are asked to put in an honest day’s work without taking any unnecessary risk and where they safely complete their work each day.

In order to do that, we are encouraged to see general contractors and subcontractors band together with insurers to start working as an industry to change the norm for all workers to complete each work day safely.

Please take a moment to think about whether you are willing to do what is necessary to help make zero incidents, injuries, and fatalities a reality in your company and the construction industry.

Challenge the conventional thinking about the construction industry being hazardous and help make the vision of a zero injury culture within this industry a reality.

We appeal to every stakeholder of the construction industry to join the cause of making zero injuries a reality. There really is no higher calling for the construction industry – the time is now for zero injuries to be the expectation, the norm, and reality.

Web Resources

1. BLS Economic News Release: Census of Fatal Occupational Injuries Summary, 2011.

2. Zero Injury Techniques, University of Texas at Austin, Construction Industry Institute.

3. Safety Plus: Making Zero Accidents a Reality. University of Texas at Austin, Construction Industry Institute.

A Brief History of Zero Injury Culture in Construction

The concept of zero injury in construction has existed at least since 1993 with the publication of the Construction Industry Institute’s (CII) Zero Injury Techniques. The 1993 study highlighted 170 techniques that construction companies used for injury prevention. The CII’s follow-up study in 2003, Safety Plus: Making Zero Accidents a Reality, further popularized the term and increased awareness of the benefits of a zero injury culture.

The 2003 study quantified a significant demonstrable improvement in safety performance of companies adopting nine high-impact, zero injury techniques:

  1. Demonstrated management commitment
  2. Staffing for safety
  3. Planning (pre-project and pre-task)
  4. Safety education: orientation and specialized training
  5. Worker involvement
  6. Evaluation and recognition/reward
  7. Subcontractor management
  8. Accident/incident investigations
  9. Drug and alcohol testing

Since the two CII studies, a growing number of construction companies, many of which have more than $250 million in annual revenues, have adopted the vision of creating a zero injury culture. In the past couple of years, a cadre of such companies (known as The Incident & Injury Free CEO Forum) emerged to provide leadership by example on the benefits of zero injury culture.

Members of this group include American Infrastructure; Baker Concrete Construction; BMW Constructors, Inc.; Cal Dive International; Gilbane Company; Great Lakes Dredge & Dock; Hunter Roberts Construction Group; Jacobs; JMJ Associates; Lend Lease; Limbach Facility Services, LLC; Manson Construction Co.; Nicholson Construction Company; Skanska; Terracon; and Weeks Marine.

These companies are collaborating to expand awareness of zero injury techniques and have been engaging with representatives from major construction insurance carriers and brokers to foster greater adoption of zero injury culture throughout the construction industry.

Zero Incident
Many large companies have adopted programs with a more stringent focus of attaining zero incidents instead of merely zero accidents. The rationale is that incidents are “near hits” that could have resulted in injuries or fatalities and near hits are early warning signals of an underlying hazard that warrants attention and correction.

One of these companies distributed Safety 24/7: Building an Incident Free Culture to all its subcontractors. This book is recommended for any owner or strategic leader seriously interested in instituting a safety cultural change.

Authors
Cal Beyer collaborated with Eric Lambert in the writing of this article. Eric Lambert, CRIS, ARM, CHST, is National Director of Construction Quality and Safety for Zurich North America Commercial in its Boston, MA office. Eric has worked in the construction industry for the past 20 years to save lives, reduce loss, and make companies better. For the past 11 years, Eric has worked to make a zero injury culture a reality. Eric has participated in many construction industry roundtables and committees to learn from and provide input to improve the industry’s safety culture and practices.

© 2013 by the Construction Financial Management Association. All right reserved. This article first appeared in CFMA Building Profits. Used with permission.

Three Lessons on How to Chase Away Clients

Here are three lessons for brokers and consultants learned from Penn State’s implementation of perhaps the most unpopular wellness program in history.

If you don’t have time to read this now, remember one thing:  do NOT fine women $1200 for refusing to disclose on an HRA whether they intend to become pregnant.   Perhaps you think that is obvious but it isn’t to Penn State, which is doing exactly that

Until recently, human resources (HR) departments couldn’t get enough wellness programs.  They have been a gold mine for brokers, too, because high volumes of business have driven commissions that are not even subject to disclosure requirements. Vendors of wellness programs competed with each other to see who could offer the highest payouts to brokers and were not shy about admitting how aggressively they were trying to find new customers, even though every metric shows that wellness programs don’t work. 

All that changed when Penn State got into the wellness business.  Advised by Highmark and Truven Health Analytics’ Ron Goetzel, who oversees the now-discredited C. Everett Koop  award, Penn State implemented perhaps the most unpopular wellness program in history. The program triggered a change.org  petition and coverage in the Wall Street Journal , every HR department’s worst nightmare-- except perhaps for unionization, which is now also on the table, partly because faculty were so upset about the onerous requirements imposed on them in the name of their health.

The program is laid out in Harvard Business Review, along with some sample reaction in the way of comments, so we won’t repeat that posting here.   Instead, the goal of this posting is the next step:  provide some lessons from Penn State for brokers and consultants, so that the problems at Penn State don’t happen to you.

Lesson One:   Employees matter in wellness.

Don’t assume that the HR department speaks for the employees.  In this case, the anti-HR outrage was overwhelming and could easily have been anticipated. Think twice before recommending a program that punishes employees if they don’t follow rules for improving their health—and that employees will hate. If your client is considering this type of program, ask which the company would rather have:   employees with high morale or employees with low cholesterol?

Lesson Two:   Forcing employees to “do wellness” will backfire.

Never recommend a program where completing forms avoids a forfeiture of a large sum of money.   People will just lie.  At Penn State, a memo went around encouraging people to lie.  So, instead of creating a culture of wellness, you’d be creating a culture of deceit.

In particular, as mentioned in the summary, Penn State decided it would be a good idea to fine women $1200 for declining to disclose to Highmark whether they intend to become pregnant.  This is the ultimate in “forced wellness.”  Indeed it is probably the worst idea in the history of wellness, and we mention it here only because if a large employer, well-known health plan, and prominent consultant can come up with this scheme, it ’s not beyond the realm of possibility that others might too.

Lesson Three:   Wellness numbers don’t add up.  Don’t pretend they do.

Wellness should be undertaken on its own merits.  If you, like Penn State and its advisors, cite the discredited bromide that 75% of cost is caused by chronic disease, you’re setting your client up to fail, as it is easy enough to find proofs that such a statement is meaningless.  Wellness actually increases costs, because biometric screens  and “preventive” physicals have very negative ROIs.

So what should you do instead?   Cracking Health Costs offers many solutions.  Chief among them would be narrow networks focused on a few safe, ethical national centers of excellence such as Mercy in Springfield (MO), where 80% of patients referred for back surgery are prescribed conservative treatment instead.  Also, coordinate care to manage employees who really do get sick, the so-called ”Quantum Health Model.”  Specifically, in lieu of conventional and ineffective wellness programs, pursue a well-being program of the type pioneered by Healthways.  

A combination of those initiatives should reduce your client’s spending while also keeping them out of the newspaper.

Are You Really An At-Will Employer?

It is likely at least one half of the employers in California who think they are at-will employers are not.

The vast majority of private employers in California desire an at-will employment relationship with employees.  The vast majority also believe they are at-will employers.  They may be, but for a great many, it will take three years of litigation and several hundred thousand dollars to prove it.

It is often said that there are two types of employment: at-will employment and employment by contract.  This is actually a misnomer.  All employment is by contract.  It is either a contract for at-will employment or a contract for something else.  The most common alternatives to at-will employment are collective bargaining agreements in the union environment and individual employment agreements that provide for “good cause” termination.  In the at-will employment relationship, the employer is not required to provide advance notice of a termination decision and is not required to justify the decision with “good cause.”

It is also often said that in the absence of a written employment contract, all employment in California is at-will.  This is also a misnomer.  It is true that the Labor Code specifies at-will employment as the default employment relationship, but a written agreement is not necessary to overcome the default.  Oral agreements and implied-in-fact agreements can be entered which limit the employer’s rights to end the employment relationship.  Implied-in-fact agreements are the most problematic because the employer will not even know that it has entered into the agreement until the question is litigated and the court renders a decision.  A properly structured at-will employment relationship permits the employer to avoid this litigation.  It also provides the employer with flexibility in making decisions for operational reasons, and ensures that no judge or jury will later be called upon to second-guess the wisdom or fairness of the employer’s business decisions.

It is likely at least one half of the employers in California who think they are at-will employers are not.  Or, at least they are not in the sense that they can avoid extensive litigation by using the legal process of summary judgment to have wrongful termination lawsuits dismissed.  The problem arises because many employers, even the big ones, use borrowed or template documents.  Unfortunately, many of the attorneys and human resource professionals who write the documents lack a complete understanding of the law on at-will employment and they utilize documents which fail to properly establish the at-will relationship.  Employers who create documents on their own are at even greater risk for errors.  This is an area where the words and their precise placement really matters.

The most common errors made that interfere with the proper establishment of an at-will employment relationship are summarized below.

  • Relying exclusively upon at-will policy statements and agreements in employment application forms.  Courts have ruled that statements in employment applications are insufficient to prove at-will employment.
  • Relying upon at-will policy statements.  Courts have ruled that because policy statements are generally non-binding they cannot conclusively prove an at-will relationship.
  • Utilizing employee handbook language stating that the handbook is not intended to create a contract or contractual rights.  While that may be appropriate for most of the policies in the handbook, it can effectively wipe out any attempt in the handbook to create or confirm an at-will relationship.
  • Failing to utilize documents which create an at-will employment agreement. A key court decision that can be used to obtain summary judgment requires that the at-will nature of the employment relationship be set forth in an “employment agreement.”
  • Failing to control modification to the at-will employment agreement.  If a properly written at-will agreement can be modified without specific controls, the employer may be put to the burden and cost of litigation to prove that it was not modified.
  • Failing to integrate the at-will agreement.  Agreements that are integrated are much less likely to be subject to lawyers’ arguments and extensive litigation.
  • Failing to coordinate the numerous documents that may impact the at-will analysis. When the documents are not properly structured to work together in establishing the at-will relationship, there is an opportunity for lawyers’ arguments and litigation.
  • Failing to get good documents signed and failing to securely maintain them once signed.  Even the best designed documents are of limited value if they cannot be produced when needed.

Avoiding these errors can literally save years of litigation and hundreds of thousands of dollars in a typical wrongful termination case.  Even where an at-will employment relationship is not desired, these same types of errors can result in unnecessary litigation. 

Fortunately, the errors and litigation can be avoided.  Employers should start by taking the time to really understand the various forms of employment.  This includes the pros and cons of each form, and the elements necessary to properly establish each.  Regardless of the form desired, employers should take a comprehensive approach.  All of the documents which refer to or which may relate to the employment relationship should be audited. 

Once the audit is complete and the documents have been revised properly, attention should be turned to employee training.  Employees involved in the on-boarding process should understand the type of employment relationship being created and should be trained to avoid communications in interviews and communications in initial emails that may conflict with the desired relationship.  By following these steps employers will have surety in the type of relationship created and will avoid unnecessary litigation.

A Case For Cyber Insurance

The insurance industry can and should play a vital role in providing private sector incentives to foster increased network security in the critical infrastructure.  However, the insurance industry cannot do this alone.  The answer lies in a private-public partnership between the insurance industry and the federal government.

The Need Is There

There were more than 26 million new strains of malware released into circulation in 2011, the last year with solid data on malware. Such a rate would produce nearly 3,000 new strains of malware an hour! Almost two-thirds of U.S. firms report that they have been the victim of cyber-security incidents or information breaches. The Privacy Rights Clearinghouse reported that since 2005, more than 534 million personal records have been compromised. In 2011, 273 breaches were reported, involving 22 million sensitive personal records.  The Ponemon Group whose Cost of Data Breach Study is widely followed every year indicated a total cost per record of $194 in 2011, an increase of over 40% ($138) compared to the cost in 2005 when the study began.

Other surveys are consistent.  NetDiligence, a company that provides network security services on behalf of insurers, reported in their “2012 Cyber Risk and Privacy Liability” forum the results of their analysis of 153 data or privacy breach claims paid by insurance between 2006 and 2011.  On average, the study said, payouts on claims made in the first five years total $3.7 million per breach.

And, attacks simply don’t target large companies. According to Symantec’s 2010  SMB Protection report (again the last report with good data on SME), small busineses:

  • Sustained an average loss of $188,000 per breach
  • Comprised 73% of total cyber-crime targets/victims
  • Lost confidential data in 42% of all breaches
  • Suffered direct financial losses in 40% of all breaches

Indeed, according to the 2011 Verizon Data Breach Report, in 2010, 57% of all data breaches were at companies with 11 to 100 employees. Interestingly, it was the Report’s opinion that 96% of such breaches could have been prevented with appropriate controls.

Seemingly, not a week goes by without a reference to cyber risk hitting the mainstream press. Recently, a cyber attack was successfully launched against ATMs in 27 countries withdrawing over $40 million in over 30,000 transactions in less than 10 hours.  The New York Times recently reported that universities are facing a rising barrage of cyberattacks, mostly from China.1   And last year saw a number of denial of service attacks against financial institutions brought by sophisticated cyber “criminals” whose attacks were eventually sourced to the nation of Iran in what would truly be considered a Cyber War attack against the U.S. infrastructure.

All This Has Prompted Insurers To Enter The Market (And Make A Nice Profit To Boot)

Cyber-insurance began in earnest in 2000 when American International Group’s AIG eBusiness Risk Solutions unit launched AIG netAdvantage. Starting from scratch, premium jumped to over $100 million by the time the unit was merged into larger subsidiaries of AIG, just four years after its creation. AIG eBusiness was extremely profitable with estimates of loss ratio in the extremely low double digits.

Fast forwarding to today, the cyber-insurance market, according to the 2012 Betterley Report is “in the $1 billion range” in terms of premium (up from $800 million in the 2011 report) with close to 40 insurance carriers providing a standalone insurance policy.  Premium continues to increase with most carriers, accordingly to Betterley, reporting increases from 25% to 100% year over year.  Hard profit figures are difficult to come by; however, strong anecdotal evidence suggests that this line of insurance continues to be highly profitable.  Third party litigation continues to be slow to develop outside the privacy arena and first party claim losses, outside of breach funds, is non-existent.

From an underwriting point of view, some attention should be paid to theft of personal identifiable information (PII), especially with respect to first party costs associated with forensics and customer notification costs.  However, there are established methods to manage this risk successfully for the underwriter.  Indeed, in a widely followed report, Verizon reports that 90% of all breaches can be prevented with proper risk management guidelines.   Of course, like any other portfolio of business, care must be taken with respect to avoidance of catastrophic exposure, adverse selection and moral hazard.  There are underwriting guidelines and processes that can be developed to manage these exposures.

Yet The Market Still Has Plenty Of Room To Grow

Despite the increased attention to cyber incidents, most reports indicate only a minority of companies currently purchase cyber-insurance.  According to the “Chubb 2012 Public Company Risk Survey: Cyber,” 65% of public companies surveyed do not purchase cyber insurance, yet 63% of decision-makers are concerned about cyber risk. In a recent Zurich survey of 152 organizations, only 19% of those surveyed have bought cyber insurance despite the fact that 76% of companies surveyed expressed concern about their information security and privacy. A risk area with a high level of concern but little purchase of insurance? That’s an insurance carrier’s dream

It is unclear why there aren’t more buyers, but most of the industry believes it’s a lack of education. For example, previous surveys indicated that over 33% of companies incorrectly believe that cyber is covered under their general corporate liability.

Regardless of the reason, with respect to foreign corporations whose securities are traded on U.S. exchanges, a recent “Guidance” report2 published by the U.S. Securities and Exchange Commission on October 13, 2011 is likely to increase sales.  The report begins simply enough:

For a number of years, registrants (companies who register their securities with the SEC) have migrated toward increasing dependence on digital technologies to conduct their operations. As this dependence has increased, the risks to registrants associated with cybersecurity has also increased ... As a result, we determined that it would be beneficial to provide guidance that assists registrants in assessing what, if any, disclosures should be provided about cybersecurity matters in light of each registrant’s specific facts and circumstances.

The “guidance” report goes on to specify five “suggested” disclosures that may be “appropriate” to companies trading with securities registered with the SEC.  The fifth suggestion is the one that caught the eye of the insurance industry.  It reads simply:

Description of relevant insurance coverage.

This is the first time that I am aware that the SEC included insurance in one of their guidance reports.  The SEC tends to start investigations 18-24 months after issuing a guidance report. It is difficult to imagine how a general counsel would be able to meet this disclosure without an investigation, at least, of specific cyber insurance.  This is especially true given that over the course of the last few years, general liability underwriters have continued to tighten up any language in a general liability policy to a point where an insured would be foolish to even think the policy applies to cyber risks.3

Thus, it is then perhaps not surprising that the Betterley 2012 market report stated “we think this (cyber) market has nowhere to go but up.”  Although, they quickly qualified,  “as long as carriers can still write at a profit.”

And With A Private-Public Partnership There Is Even More Potential

Unlike many other countries, 80% or more of the critical infrastructure of the United States is in private hands.  As we have seen in the last year, cyber attacks are increasingly being brought by companies associated with hostile nation states.  Cyber-terrorism - even cyber-war - is close at hand and, in some minds, is already here.  The insurance industry can and should play a vital role in providing private sector incentives to foster increased network security in the critical infrastructure.  However, the insurance industry cannot do this alone.  The answer lies in a private-public partnership between the insurance industry and the federal government.  Productive discussions are already underway between the Department of Homeland Security and the insurance industry with specific proposals to safeguard and enhance our country’s security being reviewed.

For more details on the need for this public-private partnerships, and what is going on to bring it about, stayed turned for our next article.

1 Universities Face a Rising Barrage of Cyberattacks

2 Cybersecurity

3 While from time to time, this is tested by insureds (see Sony vs. Zurich), almost all commentators have admitted that the “die is cast.”

Cyberliability Update For The Healthcare Industry

There are very few businesses that don’t have some sort of cyberliability exposure.  Businesses providing healthcare services, or services that support the healthcare industry, also have to worry about HIPAA and the newly updated HITECH Act.