Download

The California Homemade Food Act And Insuring Home-Based Businesses

While the new California Homemade Food Act creates new opportunities for home-based businesses, it also adds a responsibility to all of us in the insurance field to identify risk and suggest creative solutions.

When I think about businesses/people working out of their homes, the first picture that comes to mind are people working on their computers — in virtual offices, remote offices, and oftentimes offices outside of the United States.

That is why it came to me as a surprise when Yahoo recently proclaimed all their employees had to "come back to work." One news line read "work at home and you will be fired." Clearly this is a change, especially for a high tech company. Marissa Mayer, the president and CEO of Yahoo as of 2013, defends her stance and says it will "separate out the truly productive workers from stay at home slackers who abuse the system." Needless to say, the news is buzzing about this, so time will tell if she sticks to her guns.

While Yahoo is "going back to the workplace," more and more people are choosing to work from their home. The current economy has redefined how people cope with the unemployment dilemma, and many businesses encourage staff to work from home to better maximize their production and as a means to better deal with the demands of work and family.

Now home-based bakeries and cooks are getting a new incentive to work from home with the passage of a new law in California. Other states may have or may adopt similar laws. The California Homemade Food Act has created a new category of food producers called "cottage food producers" which will allow people to cook their food items in their kitchens at home. Up until this law was enacted, food producers had to use commercial kitchens. These food producers could include: caterers, suppliers to organic markets or farmers markets, and bakeries that supply local restaurants with breads or desserts.

Not all foods are approved to be cooked out of a home — only foods that are considered to be "safe" fall under this law. Approved items include: baked goods, cookies, coffee, nuts, vinegar, candy, and dried pasta.

"We talked with the different health departments and various scientists, and these products are 99.9% safe," accords to Mike Gatto, California Assemblyman. The state will require cottage food producers to take a food handling class and pass an exam that is created by the California Department of Public Health.

While the categories of the types of food that can be produced under this law are limited, at this time, it does open opportunities for some homeowners to work from their homes. From the broker/agent standpoint, we have to look more closely at the exposures and determine if the Homeowners Policy will pay for losses these home-based businesses might sustain. Here are some questions we need to ask our insured:

  1. Are they cooking in a kitchen in their dwelling?
  2. Are they cooking in a kitchen they have put in a detached structure?
  3. Have they installed commercial cooking equipment in either their home or other structure?
  4. Are they required and, if so, have they installed approved fire detection and suppression devices for their cooking equipment?
  5. Are they operating the business in their personal names (as they appear on the homeowners policy) or have they formed a business and filed for a business name?
  6. Do they have any employees?
  7. How do they deliver the goods that they cook? In their personal vehicle?
  8. Have they purchased a vehicle in the name of their business to deliver their goods?
  9. Do they have customers come to their home for any reason?
  10. How are they storing their food supplies and finished product?
  11. Do they have a website for their business?
  12. Do they sell product via the website?

These are just a couple of questions in a long list of considerations. The answer to these questions will direct the broker/agent as to how the Homeowners policy should be endorsed, not to mention the concerns relating to the personal auto used for delivery purposes or perhaps a truck purchased in the company name.

While the new law creates new opportunities for the home-based business, it also adds a responsibility to all of us in the insurance field to identify risk and suggest creative solutions. The insurance community center conducted a two hour class on insuring businesses operating out of a home in January of 2013. That archived webinar is available to all Insurance Community University members and the new Business in the Home audio presentation is now available in the Insurance Community University Library.

Sign up for classes today. Either join the University for one low price for the entire agency for all classes and products ... or enroll in individual classes. Click here and be ready to learn!

Thorny FMLA Eligibility Issue: Counting Hours Worked To Meet the 1250 Hour Threshold

If an employer does not have an accurate and reliable way of accounting for an employee's hours, the employer will bear the burden on summary judgment of proving that the employee did not meet the Family & Medical Leave Act eligibility requirement, which is a very difficult burden.

Donnelly v. Greenburgh Central School District, a recent federal court decision, addresses one of the core eligibility issues under the Federal Family & Medical Leave Act (FMLA).

The court focused on what hours must be counted toward the 1,250 hours of actual work when determining whether an employee is eligible for leave under the FMLA leave. In particular, the court focused on counting work from home or away from the workplace. The former high school teacher alleged that he was denied tenure in retaliation for taking FMLA leave. The district defended by arguing that Donnelly was not eligible for FMLA leave because he had not worked at least 1,250 hours during the previous 12 months.

The district relied on the certificated collective bargaining agreement to calculate the number of hours Donnelly actually worked. The collective bargaining agreement provided that the maximum work day for a teacher was 7.5 hours, which is one hour longer than the school day. The district multiplied this number by the number of days Donnelly worked during the previous year and found that he worked 1,247 hours (only three hours shy of qualifying for FMLA leave).

Donnelly argued that he typically worked 1.5 hours before and after class and that additional time should be included in calculating his FMLA eligibility. A judge disagreed and relied upon the maximum work day in the collective bargaining agreement in finding that Donnelly was not eligible for FMLA leave because he could not produce reliable evidence showing that he actually worked 1.5 hours each day before and after class performing work that was integral to his teaching job. Accordingly, the judge dismissed his FMLA retaliation claim.

The Federal Appeals Court reversed, finding that a jury should decide whether Donnelly worked enough hours to qualify for FMLA leave.

The Court first noted that under the FMLA regulations, because the school district did not maintain accurate records of the actual hours Donnelly worked, the district had the burden of proving that Donnelly did not work 1,250 hours and was, therefore, ineligible for FMLA leave. The Court further held that the collective bargaining agreement did not govern how many hours Donnelly worked for purposes of FMLA eligibility. The Court emphasized that all of the hours Donnelly worked performing activities that were an integral and indispensable part of his job as a teacher should be counted, regardless of the work day provision in the collective bargaining agreement.

The most important part of the Court's ruling deals with counting work performed from home. The Court held that, especially in the case of teachers who grade papers and plan lessons from home during "off duty" hours, there is no preclusion from counting that time when calculating FMLA eligibility, as long as the work is an integral and indispensable part of the job.

What This Means for Employers

  1. If an employer does not have an accurate and reliable way of accounting for an employee's hours, the employer will bear the burden on summary judgment of proving that the employee did not meet the eligibility requirement, which is a very difficult burden. This will be especially difficult when dealing with salaried employees and those exempt from overtime, because under separate wage and hour laws you cannot require them to record their hours or clock in and out.
  2. Work from home may be counted in determining FMLA eligibility. We live in an era when employers expect employees to be accessible at all times because of cell phones and smart phones. If you expect an employee to respond to email or calls after hours, you may be required to count those hours in determining FMLA eligibility. Furthermore, even if an employer has no way of accounting for work from home, that work may nonetheless be counted in determining FMLA eligibility.

Copper Theft Solution Reduces Claims For Construction Sites

Wireless video verified alarms for outdoor applications mean that loss control professionals have an effective tool to fight copper theft that is affordable enough for implementation by their policy holders.

Copper theft presents a significant challenge for loss control.

Unlike other property crimes where "recovery" goes a long way toward mitigating the loss, such as the recovery of a stolen car in an auto theft, the recovery of the stolen copper seldom impacts the size of the claim.

Copper theft is different because the damage done to a building stealing a few hundred dollars' worth of copper can cost insurers tens of thousands of dollars to repair. The typical copper theft claim involves the damage done ripping wires and plumbing out of walls or the coils from a rooftop HVAC system. In vacant buildings, thieves target water lines and sprinkler systems as well as the electrical wiring. Once a vacant property has been hit, thousands of dollars must be spent to bring it back up to code before it can be occupied. It is this "collateral damage" that makes copper theft claims so expensive to an insurance company.

The key to reducing copper theft claims is prompt police response. The faster law enforcement arrives, the less time thieves have to damage the property. Faster police response is what wireless video alarms deliver and why they are a valuable tool for loss control against copper theft.

Copper theft has impacted insurance companies across North America, becoming a mainstream problem covered by television news. The following reports from television news underscore much of what this article is attempting to communicate — a new paradigm to mitigate risk and reduce claims impacting the real world from Virginia to Arizona.

Construction crime is a close cousin to copper theft and has been a black hole for risk management with few affordable solutions. The nature of construction risk is temporary and this means that wired surveillance cameras and alarm systems are simply too expensive and cumbersome to install to make them cost-effective.

The technology challenges are significant: in addition to limited budgets there is often no power, no phone lines, and no easy access to internet. Policy holders do not want to spend large amounts of money for temporary infrastructure that has no value after the job is done. For construction, human guarding is the most obvious approach, but it is beyond the budgets of many job sites. With guarding cost prohibitive, from a loss control perspective there have been very few affordable options for mainstream policy holders to protect their projects. Construction remains a problem child for many insurers who are forced to raise deductibles and implement exclusions to make construction profitable.

The following newscast from Buffalo, New York describes the challenges of securing a construction site and successes found with wireless video alarm systems.

While human guards have become too expensive and unreliable for many sites, technology is improving and loss control has a new tool to secure construction sites. Portable wireless video alarms give loss control professionals an affordable tool to deliver police response to a job site before the damage occurs. These new wireless camera/detectors (called MotionViewers) sense an intruder and send a short video clip of the incident over the cell network to a central monitoring station for immediate review and police dispatch and priority police response.

The immediate review/response with a monitored video alarm has proven more effective than human guards as the sensor/cameras are installed in multiple points across the job site to detect and report any activity. The crucial factor in reducing claims for copper theft is immediate police response, and video verified alarms make all the difference — the monitoring central station operator is a virtual eyewitness to the crime.

Police treat a video verified alarm as a crime-in-progress — they respond faster and they make arrests. Case studies on video verified alarms have arrest rates of over 50%. One construction site in Arizona had 40 arrests over four months on a single site. Arrests make a difference because one arrest prevents an additional 30 crimes — copper theft is typically done by habitual thieves who target construction sites or vacant property.

To be affordable and effective, the camera/sensors must be easy to install, without the cost of trenching cables and running wires. Power is a challenge as many construction sites have only temporary power provided by generators during working hours. Many vacant building have no power at all.

The wireless Videofied alarm systems need no infrastructure to secure a site. They operate for months or even years on batteries, communicating over the cell network to the central station. These portable MotionViewers are more effective than fixed cameras because they can be moved to protect the assets on a job site as the project evolves. Portability is important because construction theft is often an inside job by a subcontractor familiar with the delivery and location of expensive materials or assets — and they know the locations of fixed cameras and how to avoid them. In contrast, magnetic mounts on the wireless MotionViewers enable the job supervisor to move the cameras, placing them on steel studs and tool cribs at the end of the day to protect what is most at risk.

Wireless video verified alarms for outdoor applications mean that loss control professionals have an effective tool to fight copper theft that is affordable enough for implementation by their policy holders. For more information visit www.videofied.com.

Business Income And Dependent Property From A Secondary Location

Additional coverage under the Dependent Property Endorsements is very important to consider, especially for manufacturing accounts.

There was a lot that changed with the Commercial Property Forms in the 2013 series. In fact, most forms underwent some sort of modification. One of the most interesting of the changes was the introduction of an optional coverage available on the Dependent Property Forms for Dependent Properties in the Supply Chain (Business Interruption).

By way of background, the Business Income and Extra Expense forms require that there is direct damage at the premises described by a covered cause of loss that gives rise to a loss of income or need to pay extra costs to operate during the period of restoration. In providing this form of coverage, we have been aware of the exposure to a loss of income due to a physical loss at a location that our insured depends on for various reasons. Recognizing that a loss to a dependent location could cause financial harm to our insured, ISO created Dependent Property Endorsements (CP 1508, CP 15 09, CP 1534) provided on a scheduled basis. What this means is that, for our insured, we identify what company(ies) they are dependent on and schedule those locations on the Dependent Property Form attached to their business income policy.

For example, we could be insuring a winery that is dependent on a single manufacturer to manufacture their distinct wine bottle and provide them with their customized cork. If that bottle manufacturer had a loss to their manufacturing facility by a peril insured against on the winery's policy and the winery now has no bottles and the winery can demonstrate they are losing money or incurring an Extra Expense by going to a more expensive alternate supplier then the Dependent Property Endorsement could respond.

What we learned, when losses such as this arise, is that oftentimes the physical loss did not occur at the dependent location we scheduled on the policy but rather to a "location" that the dependent property was dependent upon to supply them a product or service. So to expand on the winery example — the bottle manufacturer is dependent on a single cork manufacturer to supply them with the blank corks they customize and the cork manufacturer has a loss (covered peril) and cannot supply the wine bottle company with the product. We never identified the cork manufacturer on our insured's policy as there was no known or direct relationship.

The new language on the Dependent Property forms have an option for "secondary contributing locations" and "secondary recipient locations." Secondary locations are limited to direct suppliers and recipients of the dependent property's materials or supplies.

On the form, secondary contributing location and recipient location are now defined terms. There are some important clarifications of the coverage:

  1. The secondary location is not identified in the schedule. However, there is a box on the schedule that has to be marked identifying that a secondary location has been included.
  2. The secondary location cannot be owned or operated by the "contributing" or "recipient" location that is identified in the schedule.
  3. There is clarity that a secondary location is not a road, bridge, tunnel, waterway, airfield, pipeline or any other similar area or structure.
  4. There is clarity that any source of "services" in the area of water, power, wastewater removal or communication supply cannot be a secondary dependent property. These would be covered under Utility Interruption endorsements.
  5. Lastly, there is clarity that the secondary dependent property coverage is subject to the territory of the policy and is not worldwide.

This additional coverage under the Dependent Property Endorsements is very important to consider, especially for manufacturing accounts. This all gets back to our identifying exposure and providing solution.

Sign up for classes today. Either join the University for one low price for the entire agency for all classes and products ... or enroll in individual classes. Click here and be ready to learn!

Leap Year: Season 2, Episode 7 - A Moment of Weakness

A professional liability policy can cover a small business for past acts of their employees.|


Leap Year Season 2: Episode 7 by Mashable A scorned woman, a programmer with dual personalities, a rival executive literally in the closet and a double-crossing brother. That's a good foundation for a Greek tragedy or a modern-day telenovela, or the current season of Leap Year. In a near perfect storm of personal and professional challenges, the C3D team is on the verge of a complete breakdown, and nowhere closer to getting their product ready for the launch. The Kiss continues to reverberate back at the C3D offices and the late nights there are more about loneliness and soul-searching than the all night programming sessions people normally expect at a startup. Bryn's decision to take matters (and June Pepper) into her own hands will only up everyone's stress levels. It feels like the whole team is getting close to their breaking point, especially Aaron. Kicked out of his home and looking forward to sleepless nights at the office, he then finds out it was his brother Derek who's been spying on them and helping the enemy this whole time. Firing Derek couldn't have been much easier for Aaron than telling Lisa he hooked up with Bryn. And who knows what else Derek shared with their rivals? There's no insurance for a shattered relationship, but C3D could have protected themselves against future problems at the company caused by Derek's professional negligence, even now that he's gone. Their professional liability policy would cover them for past acts of their employees. This is important, because who knows exactly what Derek's been up to these past few weeks, or even what he did right after Aaron told him to pack up and leave. Besides, who wants to worry about employees continuing to hurt you even after they're gone? Now that C3D has added kidnapping to their list of regular business tactics, what's next? Jack challenging Sam the CEO of Livefye to an old fashioned duel? Things are starting to get really, really interesting, and dangerous. After the last couple weeks, do you think C3D is starting to lose their moral compass? Or are they just doing what's necessary to survive and beat the competition?

Hunter Hoffman

Profile picture for user HunterHoffmann

Hunter Hoffman

Hunter Hoffmann is head of U.S. communications at Hiscox and is responsible for media relations, social media, internal communications and executive messaging. He joined Hiscox in August 2010 and has a B.A. from Trinity College (CT) and an M.B.A. from Cornell University.

Baseline Testing: Book End Solution - Does It Qualify as Business Necessity?

Given all the legal mandates for the ADA and EEOC, coupled with state workers' compensation laws and Federal Mandatory reporting issues for work-related injuries, why do post-offer pre-placement tests? A better solution is baseline testing or a book end solution.

Congress enacted the Americans with Disabilities Act in 1990 which included the terms "job-related and consistent with business necessity" in Section 703(k) of Title VII as part of a Congressional compromise. The amendment to the act which went into effect in 2008 did not affect the business necessity provision.

Case law regarding business necessity is very limited; however, a recent case in point is Atkins v. Salazar, 2011 U.S. App. LEXIS 25238 (5th Cir., Dec. 12, 2011), in which the Fifth Circuit issued an instructive opinion analyzing the business necessity defense in the context of diabetes.

The Fifth Circuit described the business necessity standard as follows:

For a qualification to be "job-related," "the employer must demonstrate that the qualification standard is necessary and related to 'the specific skills and physical requirements of the sought-after position.'" Similarly, for a qualification standard to be "consistent with business necessity," the employer must show that it "substantially promote[s]" the business' needs.

The court further noted, based on an earlier ruling, that it must "take into account the magnitude of possible harm as well as the probability of occurrence ... the probability of the occurrence is discounted by the magnitude of its consequences."

Under the Americans with Disabilities Act, not only must a medical exam be job-related, it must also be consistent with business necessity. This means that the medical exam must relate to the essential functions of the job. The medical exam must test the ability to perform the primary functions of the job. For example, if you are a cashier at a grocery store, the essential functions of your job would be to ring people up and help them bag their items. Any medical exam your employer required would have to be related to how you perform those functions in order to be consistent with business necessity. It is important to note that as long as the medical exam evaluates some function of the job, it should satisfy the elements of business necessity.

Under the Americans with Disabilities Act, an employer may have the ability to make disability-related inquiries or require medical examination. After the applicant is given a conditional job offer, but before starting work, an employer may make disability-related inquiries and conduct medical examinations, regardless of whether they are related to the job, as long as it does so for all entering employees in the same job category (post-offer). After employment has commenced, an employer may make disability-related inquiries and require medical examinations only if they are job-related and consistent with business necessity.

The Americans with Disabilities Act requires that all medical information obtained during such inquiries or testing be treated as confidential medical information. While this provision covers all employees, only disability-related inquiries and medical examinations are subject to the Americans with Disabilities Act's restrictions. A disability-related inquiry is defined as asking questions or testing that is designed to elicit information about a person's disability. Therefore, questions or testing that is not designed to ask or evaluate information about an individual's disability are not prohibited under the ADA.

A medical test as defined under the Americans with Disabilities Act is a procedure or test that seeks information about an individual's physical or mental impairments or health. Factors that determine if it is a medical test include:

  • whether the test is administered by a health care professional;
  • whether the test is interpreted by a health care professional;
  • whether the test is designed to reveal an impairment or physical or mental health;
  • whether the test is invasive;
  • whether the test measures an employee's performance of a task or measures his/her physiological responses to performing the task;
  • whether the test normally is given in a medical setting; and,
  • whether medical equipment is used.

The topic of medical testing, especially functional testing, is a controversial subject. In the fall of 2009 two major case precedents brought to light these very issues — Indergard vs. Georgia Pacific and the class action lawsuit brought against Sears. On September 29, 2009, the U.S. Equal Employment Opportunity Commission (EEOC) announced a record-setting consent decree resolving a class lawsuit against Sears, Roebuck and Co. under the Americans with Disabilities Act for $6.2 million.

These recent rulings bear out that the Functional Capacity Evaluation (FCE) may be a medical exam. Even when classified as medical evaluations, Functional Capacity Evaluations don't physically correlate with true physiological function. The issue becomes whether or not these tests are able to accurately or objectively test for functionality. These rulings illustrate that Functional Capacity Evaluations that contain validity measurements that are subjective observations, do not correlate with effort and are not consistent with affected body parts are not legally defensible.

As we have seen with the Indergad and Sears cases, courts are examining these issues closely and unless there is an objective assessment, the employer or carrier is left virtually unprotected. For ADA compliance, the testing needs to be repeatable, objective, and address functionality.

Under the Americans with Disabilities Act, an employer may not require a current employee to undergo a medical examination unless the examination "is shown to be job-related and consistent with business necessity." 42 U.S.C. § 12112(d) (4) (A). This section applies to all employees, whether or not they are disabled under the Americans with Disabilities Act. The Indergard decision clearly demonstrates the need for an objective measure of performance that must conform with business necessity.

In addition, recent case law — EEOC vs. Celadon Trucking — illustrates that if an individual does not meet the essential functions of the job, an employer needs to enter into the interactive process for the position for which they were applying or for any other open position for which the candidate is qualified.

Given all the legal mandates for the ADA and EEOC, coupled with state workers' compensation laws and Federal Mandatory reporting issues for work-related injuries, why do post-offer pre-placement tests? A better solution is baseline testing or a book end solution.

The Americans with Disabilities Act regulates testing that has the potential to evaluate a disability. So if a baseline test is non-invasive, captures the essential functions of the job with not only a reliable validity measurement but with an objective assessment of the muskuloskeltal system and is not read at the time of testing, it is not only acceptable under ADA but technically outside the scope. Why? Data is not evaluated at the time of the baseline test so no disability is identified and no medical questions are asked. It can be done at post-offer or with existing employees.

The book end solution is completed when there is a work-related incident, another test is performed under the workers' compensation pending case, and the results are compared. In the work-related case, the medical evaluation post loss test is allowed and not a violation of the Americans with Disabilities Act. Appropriate releases are signed prior to conducting the baseline testing, and the data is kept confidential. If no work-related injury occurs, the baseline data is never interpreted.

In summary, according to the Fifth Circuit ruling in the Atkins case, for a qualification standard to be "consistent with business necessity," the employer must show that it "substantially promote[s]" the business' needs. The business needs in the case of baseline tests are to provide better and faster treatment for the injured worker and to accept claims that arise out of the course and scope of employment.

A Look At Cyber Risk Of Financial Institutions

You cannot be a financial institution operating in the 21st Century and not have a cyber risk management plan which includes the purchase of cyber insurance.

Overview Of The Risk
There were more than 26 million new strains of malware released into circulation in 2011. Such a rate would produce nearly 3,000 new strains of malware an hour! Almost two-thirds of U.S. firms report that they have been the victim of cyber-security incidents or information breaches. The Privacy Rights Clearinghouse reported that since 2005, more than 534 million personal records have been compromised. In 2011, 273 breaches were reported, involving 22 million sensitive personal records. The Ponemon Group, whose Cost of Data Breach Study is widely followed every year, indicated a total cost per record of $214 in 2011, an increase of over 55% ($138) compared to the cost in 2005 when the study began.

Other surveys are consistent. NetDiligence, a company that provides network security services on behalf of insurers, reported in their "2012 Cyber Risk and Privacy Liability Forum" the results of their analysis of 153 data or privacy breach claims paid by insurance companies between 2006 and 2011. On average, the study said, payouts on claims made in the first five years total $3.7 million per breach, compared with an average of $2.4 million for claims made from 2005 through 2010.

And attacks simply don't target large companies. According to Symantec's 2010 SMB Protection report, small busineses:

  • Sustained an average loss of $188,000 per breach
  • Comprised 73% of total cyber-crime targets/victims
  • Lost confidential data in 42% of all breaches
  • Suffered direct financial losses in 40% of all breaches

Indeed, according to the 2011 Verizon Data Breach Report, in 2010, 57% of all data breaches were at companies with 11 to 100 employees. Interestingly, it was the Report's opinion that 96% of such breaches could have been prevented with appropriate controls. Bottom line: cyber attacks are here to stay — and in many ways, they are getting worse.

A Look At The Financial Institution Sector
Willy Sutton once infamously remarked that he robs bank because "that's where the money is." According to Professor Udo Helmbrecht, the Executive Director of the European Networking and Information Security Agency, if Willy Sutton was alive today, he would rob banks online.

Criminals today can operate miles, or even oceans, away from the target. "The number and sophistication of malicious incidents have increased dramatically over the past five years and is expected to continue to grow," according to Gordon Snow, Assistant Director of the Cyber Division of the Federal Bureau of Investigation (testifying before the House Financial Services Committee, Subcommittee on Financials Institutions and Consumer Credit). "As businesses and financial institutions continue to adopt Internet-based commerce systems, the opportunity for cybercrime increases at the retail and consumer level." Indeed, according to Snow, the FBI is investigating 400 reported account takeover cases from bank accounts of US businesses. These cases total $255 million in fraudulent transfers and has resulted in $85 million in actual losses.

According to the FBI, there are eight cyber threats that expose both the finances and reputation of financial institutions: account takeovers, third-party payment process breaches, securities and market trading company breaches, ATM skimming breaches, mobile banking breaches, insider access, supply chain infiltration, and telecommunications network disruption.

It was telecommunications network disruption that dominated the news in 2012.

Otherwise known as a distributed denial of service attack, US banks were attacked repeatedly throughout the year by sophisticated cyber "criminals" whose attacks were eventually sourced to the nation of Iran in what would truly be considered a Cyber War attack against this country's infrastructure.

Among the institutions hit were PNC Bank, Wells Fargo, HSBC, and Citibank, among many others. Big or small, it made no difference. At the end of the day, as many as 30 US banking firms are expected to be targeted in this wave of cyber attacks, according to the security firm RSA. And it is likely that we are not at the end of the day. On January 9, 2013, the computer hacking group that has claimed responsibility for cyber attacks on PNC Bank vowed to continue trying to shut down American banking websites for at least the next six months.

That is not to say that financial situations only had to worry about distributed denial of service attacks launched by hostile nation states in 2012.

On December 13, 2012 the Financial Services Information Sharing and Analysis Center, which shares information throughout the financial sector about terrorist threats, warned the US financial services industry that a Russian cyber-gangster is preparing to rob American banks and their customers of millions of dollars. According to the computer security firm, McAfee, the cyber criminal, who calls himself the "Thief-in-Law," already has infected hundreds of computers of unwitting American customers in preparation to steal that bank account data.

Of course not all threats look like they come from the latest 007 flick. On October 12, 2012, the Associated Press reported TD Bank had begun notifying approximately 260,000 customers from Maine to Florida that the company may been affected by a data breach. Company spokeswoman Rebecca Acevedo confirmed to the Associated Press that unencrypted data backup tapes were "misplaced in transport" in March 2012. She said the tapes contained personal information, including account information and security numbers. It is unclear why the bank waited until October to notify customers. Over 46 states now have mandatory notification laws that dictate prompt notification to bank customers of missing or stolen "Personally Identifiable Information." Failure to make timely notification can, and often does, prompt customer lawsuits and regulatory investigations.

The bottom line: you cannot be a financial institution operating in the 21st Century and not have a cyber risk management plan which includes the purchase of cyber insurance.

The Cyber Insurance Market
With these facts, it is not surprising that the cyber insurance market has grown tremendously from its initial beginning in 2000. Starting with what was the brainchild of AIG and Lloyds of London, the market has grown to over 40 insurance providers. A widely accepted statistic is that the market now produces over $1 billion in premium to insurance carriers on a worldwide basis.

Despite the increasing claim activity, informal discussions with the market continue to indicate that cyber risk is a profitable business. Perhaps, it is for this reason, cyber premium rates are flat to down 5% according to industry reports in the market where rates in property-casualty are generally increasing.

Carriers also see this as an area where there are many non-buyers, and statistics seem to back them up. According to the "Chubb 2012 Public Company Risk Survey: Cyber," 65% of public companies surveyed do not purchase cyber insurance, yet 63% of decision-makers are concerned about this cyber risk. A risk area with a high level of concern but little purchase of insurance is an insurance broker's dream. In a recent Zurich survey of 152 organizations, only 19% of those surveyed have bought cyber insurance despite the fact that 76% of companies surveyed expressed concern about their information security and privacy.

It is unclear why there aren't more buyers but most of the industry believes it's a lack of education. For example, previous surveys indicated that over 33% of companies incorrectly believe that cyber risk is covered under their general corporate liability policy.

It is then perhaps not surprising that the Betterley 2012 market report stated "we think this market has nowhere to go but up" Although, they quickly qualified, "as long as carriers can still write at a profit."

Navigating School Board And Educators Legal Liability Policies

With many schools having renewals on or around July 1, now is the time to formulate your renewal strategy, communicate the conditions of the market to your insured, and begin discussions with your current and prospective insurers.

Brokers who place School Board and Educators Legal Liability insurance are beginning to notice that the marketplace has gotten more difficult. Layoffs from budget cuts have triggered an increase in Employment Practices Liability (EPL) claims, while the tough job market has led to an increased amount of "failure to educate" claims.

The very public proceedings involving Penn State University have recently reminded us that sexual abuse and molestation are critical claim issues for schools. Any article written about a class of business that touches Personally Identifiable Information (PII) and doesn't mention Cyberliability fails to address another major source of trouble.

Based on these and other factors, insurers are either non-renewing business or re-underwriting their book, which leads to a restriction in terms.

The typical School Board or Educators Legal Liability policy is designed to protect not only teachers, but also school board members, administrators, volunteers, student teachers and various other members of the educational staff. In a standard policy, the definition of "Wrongful Act" includes coverage for an actual or alleged breach of duty, neglect, misleading statement and other errors or omissions of an insured educator in their capacity or scope of employment on behalf of the educational institution. Most policies also include coverage for Employment Practices Liability (EPL) claims, which tend to be the most frequent cause of loss.

Typical allegations found in claims include:

  • Failure to educate
  • Failure to supervise a classroom
  • Loss of accreditation
  • Employment-related lawsuits claiming sexual harassment, wrongful termination or discrimination
  • Misstatements, misleading statements, breaches of duty, neglect, errors or omissions made by a paid or volunteer board member who assists the school in making critical decisions about operations and economic survival
  • Failure to respond to or prevent bullying activities of the students

Market Commentary
Below are examples of the additional claim scenarios that insurers are seeing in this class of business.

"We are seeing the severity of educators' claims increase dramatically." — Stephanie Gardner, RSUI

"The biggest issue that we have seen regarding Educators Legal Liability is on the EPL side. This has historically been a frequency-driven class and we have seen an even larger increase in frequency. We have also seen frequency develop into severity, which we had not seen to this extent before. There doesn't seem to be any new trend in the type of EPL claims, just more of them. I believe a lot of this is just a function of the economy and the pressure on school districts to reduce their budgets." — Matthew Cibulskas, Westchester Specialty

"Bullying claims are being litigated under a 'failure to supervise' accusation. The financial damages to the parents are that they had to pay private school tuition because they had to leave the public school system after nothing was done to stop the bullying. And redistricting claims — many institutions have budget issues and, as a result, are closing schools and consolidating. This has triggered a lot of claims against the school boards." — Steve Krusko, AIG

"I have seen issues with the for-profit educational segment regarding the federal tuition funding (loans/scholarships) as well as issues with dismal graduation rates and failure to educate allegations." — Roy Huelsebusch, Crum & Forster

"Unfair competition and misrepresentation during the admissions process, as well as admissions to programs that don't have full accreditation yet (nursing programs seem to be frequent offenders here). Regulatory interest — a high percentage of tuition comes from Pell Grants so state Attorneys General have been pursuing litigation for unfair/deceptive trade practices." — Rob Faber, AIG

If there was just one area of concern, underwriters could manage that risk with exclusions, sublimits, higher retentions or other means of mitigation. However, with severity increasing and claims coming from many directions, the marketplace has to respond. Underwriters can either withdraw from the marketplace or attempt to work around the hot spots. As mentioned earlier in this article, many insurers have moved away from this class while others are indeed revising their pricing, retentions and coverage terms.

With many schools having renewals on or around July 1, now is the time to formulate your renewal strategy, communicate the conditions of the market to your insured, and begin discussions with your current and prospective insurers.

The Changing Insurance Marketplace And How It Can Affect How Employers Manage Costs

Professional Employer Organizations have historically been an alternative to employers who have had a history of claims, because the Professional Employer Organization companies seem to offer lower costs. But does this appearance of lower cost represent real savings?

Workers' compensation insurance, like other employee benefits programs, continue to be a major expense to most employers. Decision makers are always looking for ways to better manage their cost, but sometimes the containment can be out of their influence.

For many years, employers enjoyed lower workers' comp rates as a result of reforms signed by our previous Governor and the competitive nature of the California insurance marketplace. Late last year, the workers' comp market began to change and insurance companies began to raise rates and become more selective about which employers they would keep or consider as new customers. Rising medical costs to treat injuries, increases in the insurance company costs of doing business, as well as lower returns of investment by insurance companies also led to this market shift.

Employers who had a series of injury claims, or even a large claim, also experienced greater increases in their workers' comp premium, because of the way their Workers' Comp Experience Modification Factor calculation was changed.

As a result of these premium increases, there has been a move by employers to seriously consider a Professional Employer Organization (PEO) to take the place of their workers' comp and employee benefits programs. A Professional Employer Organization is an arrangement where an employer essentially transfers their employees to another organization who then "leases" them back to their organization. This may relieve employers of direct involvement in the management of employees, but they still retain responsibilities as a "co-employer."

Professional Employer Organizations have historically been an alternative to employers who have had a history of claims, because the Professional Employer Organization companies seem to offer lower costs. In my experience, most Professional Employer Organizations organizations offered little or no reduction in the number and severity of work injuries and resulted in a continued increase in the employer's Experience Modification Factor.

To obtain up to date marketing information about how the major Professional Employer Organization organization view this changing insurance marketplace and how they are planning to respond to these changes, my firm's specialist contacted the seven Professional Employer Organization organizations that are utilized. The following information was obtained and it is being passed on to you, because this segment of employment and insurance providers is important for employers to know so they can make a more informed decision when considering the use of a Professional Employer Organization:

  • Those employers who are unprofitable to a Professional Employer Organization are receiving rate increases in their insurance premiums and/or administrative fees to make them profitable to the Professional Employer Organization
  • For those unprofitable employers who are not accepting the rate increases, they are being non-renewed. This action is very rare, but is a sign that the Professional Employer Organization marketplace, like the workers' comp insurance companies, are taking actions to become more profitable.
  • Professional Employer Organizations only seem to consider new employers that have at least 10 full time employees
  • The annual employees' compensation must average at least $30,000
  • Professional Employer Organizations are dropping certain industries where the PEOs have encountered consistent non profitability

This information update causes us to conclude that employers who are historically financial losers to the insurance industry are also losers to the Professional Employer Organization organizations.

It can no longer be assumed that a Professional Employer Organization is always a viable alternative to employers who are not controlling their cost of work injuries.

Claims-prone employers who feel they can just "shop" every year to get the lowest rate will probably have a rude awakening.

What are some of changes that employers need to make to avoid a history of frequent and costly work-related injuries to keep employees from becoming "patients" of the workers' comp medical system?

  • Accept that workers' comp is a way to finance claims
  • Understand that you, as the employer, are ultimately paying for each work injury — have a claim and you the employer pays it back plus more
  • Take the selection of employees and safety in the workplace more seriously — match the characteristics of the job with the characteristics of the candidate being considered
  • Take an active role in the claims process
  • Train employees in safe work practices and hold them and their supervisors accountable
  • Maintain a respectful and positive relationship with employees
  • Create an open working relationship with a medical clinic that practices "evidenced based medical treatment"
  • If you do not have the resources to make changes, hire the appropriate insurance advisor to help them

The decisions employers make will determine how profitable their enterprise will be and ultimately will influence the financial value of their business. This is one of those times where appropriate decisions need to be made. The organization's financial success and the welfare of those who are employed by the enterprise are in the "hands" of the company's leaders. Let's hope the best decisions are made.

Modern Burglar Alarms Remain One Of The Best Defenses Against Losses

There is no question today that alarm intrusion systems are often one of the first lines of defense against insured losses from crime.

In the past few weeks, we have published two articles by Keith Jentoft, the Partnership Liaison of the nonprofit Partnership for Priority Video Alarm Response, regarding the use of video verified alarms. Recently, David Margulies of the Margulies Communications Group approached us and asked if we would be willing to publish an article which provides a different perspective. David's article appears below.

There is no question today that alarm intrusion systems are often one of the first lines of defense against insured losses from crime. According to the Electronic Security Association, which represents the majority of companies in the alarm industry, the breakdown for intrusion alarms shows them protecting virtually every type of insured business enterprise:

  • residential: 40%
  • commercial (office buildings, retail, banks, etc.): 30%
  • institutional (schools, hospitals, churches, etc.): 11%
  • industrial (factories, warehouses, utilities, etc.): 12%
  • government (local, state, federal Facilities): 7%

In a national survey of police chiefs, 90 percent acknowledged that alarms both deter burglary attempts and increase the probability of a burglar being apprehended. Of the nation's approximately 18,000 public safety agencies, only a handful require confirmation from a business owner, witnesses or security guard before police are dispatched to an alarm site.

One of the most in-depth and comprehensive studies of the effectiveness of alarm systems in preventing losses was conducted by the Rutgers University School of Criminal Justice (SCJ). The study found that in Newark, New Jersey, residential burglar alarm systems decreased crime. While other studies have concluded that most burglars avoid alarm systems, this is the first study to focus on alarm systems while scientifically ruling out other factors that could have impacted the crime rate.

Researchers concentrated on analyzing crime data provided by the Newark Police Department. "Data showed that a steady decrease in burglaries in Newark between 2001 and 2005 coincided with an increase in the number of registered home burglar alarms," said study author Dr. Seungmug (a.k.a. Zech) Lee. "The study credits the alarms with the decrease in burglaries and the city's overall crime rate."

In short, the study found that an installed burglar alarm makes a dwelling less attractive to the would-be and active intruders, and protects the home without displacing burglaries to nearby homes.

The study also concluded that the deterrent effect of alarms is felt in the community at large. "Neighborhoods in which burglar alarms were densely installed have fewer incidents of residential burglaries than in neighborhoods with fewer burglar alarms," the study noted.

The alarm industry has aggressively addressed the issue of false alarms because of concerns that they were putting a strain on police resources. In 2003, industry leaders created the Security Industry Alarm Coalition (SIAC) which is comprised of four major North American security associations — Canadian Security Association (CANASA), Security Industry Association (SIA), Central Station Alarm Association (CSAA) and the Electronic Security Association (ESA) — representing one voice for the alarm industry on alarm management issues. The Security Industry Alarm Coalition's primary charter is to significantly reduce calls for service while strengthening the lines of communication with law enforcement professionals and end users.

"Eighty-five percent of the nation's alarm systems generate no calls to the police in any given year," said Stan Martin, Executive Director of the Security Industry Alarm Coalition. "People who say that 98 percent of reported burglar alarms are false are trying to justify ending police response to alarms without human verification of a crime (verified response). These people have failed to perform their due diligence on public safety and industry best practices."

Working in a partnership with law enforcement, the Security Industry Alarm Coalition has helped communities significantly reduce the number of alarm calls made to police by promoting industry and law enforcements best practices including:

  • The model ordinance requires registration of all alarm systems.
  • Two phone calls by alarm companies to alarm owners prior to calling police.
  • Technology designed into systems to avoid accidental triggering.
  • Fines for alarm owners who create unnecessary dispatches.
  • Suspending response to the chronic abusers.

According to a study just released by the Urban Institute, these steps allow communities to maintain police response while conserving law enforcement resources. The study notes that Montgomery County, Maryland was able to save $6 million in costs and reduce alarm calls by 60 percent. The reduction in alarm calls from 44,000 to 16,000 came despite a significant increase in the number of alarm systems.

According to Glen Mowrey, the National Enforcement Liaison of the Security Industry Alarm Coalition:

  • Marietta, Georgia reduced alarm calls 65 percent in two years with annual revenues of $223,050 in 2008 and $94,800 in 2009;
  • Johnson City, Tennessee reduced alarm calls 50.1 percent over a four-year period;
  • Union City, Tennessee showed a reduction of 55.4 percent over a four-year period; and,
  • during a 14-year period, the police department in Charlotte-Mecklenburg, North Carolina brought down its percentage of alarm calls, out of total calls for service, from 20.1 percent to 2.4 percent annually, netting 13.5 police officers and an annual revenue in 2009 of $334,470, which includes a reimbursement for 2.5 full-time employees from an outsource company contracted to administer the billing and tracking component.

As new technology emerges, the Security Industry Alarm Coalition is at the forefront of helping develop standards and policies with its partners in the law enforcement community. "Alarm systems and technology are constantly changing and improving," said Stan Martin, SIAC Executive Director. "Our major and long established trade and professional associations that support SIAC are constantly working to make sure there are standards in place to properly apply this technology."

"The working relationship between public safety agencies and the alarm industry has never been stronger," said Mowrey, not only the National Enforcement Liaison of SIAC, but also the former Deputy Chief of Police in Charlotte/Mecklenburg, North Carolina. "Eleven states have created state-wide committees to work with the industry on alarm issues and they all have adopted some form of SIAC's model alarm ordinance."

The Security Industry Alarm Coalition also serves as the industry's voice working with national law enforcement organizations such as the International Association of Chiefs of Police and the National Sheriffs Association.

Through the Security Industry Alarm Coalition, the alarm industry is always available as a resource to the insurance industry for questions, concerns, or more information on how the alarm industry can continue to protect the insured from unnecessary losses.