Tuesday, April 23, 2013

5 Reasons You Should Have Cyber Liability Insurance.

Imagine for a moment that your company has come under attack by a skilled hacker. The hacker has accessed your customers' names and contact information--and worse--your employees' social security numbers. On top of that, your website is disabled so that you can't take orders or collect the payments you need to stay in business.

Wouldn't it be nice to have cyber liability insurance right about now?
Insurance that protects you in case of a cyber attack may seem like something only large corporations would ever need, or could ever afford. But believe it or not, cyber liability insurance makes lots of sense for small companies as well. Here's why:

1. It's more affordable than you think.
"I've seen policies with premiums as low as $2,000 a year, though it can go up from there," says Ethan Miller, partner at the San Francisco law firm Hogan Lovells. You can get coverage as high as $30 million and deductibles as low as $10,000, depending on your needs and what you're willing to pay. Cyber liability insurance is still a fairly new concept, so there's a lot of variation among policies, and a lot of room for negotiation.

2. It can cover more than you think.
Many policies offer "first party" coverage--that is, they will pay you for things like business interruption, the cost of notifying customers of a breach, and even the expense of hiring a public relations firm to repair any damage done to your image as a result of a cyber attack. Having this cash available in the event of a crippling hack can keep the lights on till you're able to resume your normal cash flow. A good policy can even cover any regulatory fines or penalties you might incur because of a data breach.
Business interruption coverage can be especially important for a small business, Miller says, which may not be as diversified as a larger one, or have the same financial resources. "If a larger company has one line of business shut down by a data breach, it may be able to depend on its other lines for revenue. A smaller company may only have one line of business."

3. You probably don't have a risk management team.
Big corporations have entire departments devoted to analyzing the risks the company could face and helping set policies and procedures to protect against them. You don't--but a good insurance carrier can perform a similar function.
"There are a couple of ways insurance can bridge that gap," Miller says. "An insurer might work with a small company to make sure a firewall is in place to protect your network, and make sure you have social media policies that reduce risk." Your insurer may well be willing to help with these areas because the better protected you are, the less likely you are to have a breach that could result in a claim.

4. Even if you don't host your data yourself, you're still responsible.
Is your website and any of your data hosted or stored in the cloud? Take a good look at your contracts: You're still legally responsible. "There's a significant risk," says Karen L. Stevenson, senior counsel at Buchalter Nemer, a law firm with offices in California and Arizona. You can't fully control how a cloud provider handles your data but an insurance policy can protect you if your cloud provider screws up.

5. Your general policy won't cover you.
Typically, a general liability policy specifically excludes losses incurred because of the Internet, Miller says. So a good cyber liability policy can pick up where your general policy leaves off.
Make sure your cyber policy covers laptops and mobile devices as well, to give yourself coverage in as many situations as you can. "Work with your broker to integrate cyber liability with your general policy and employment liability policy," Miller advises. "You want to give yourself the most seamless coverage possible."

Tuesday, April 16, 2013

Wrong estimate for health care subsidies may be costly!

Millions of people who take advantage of government subsisidies to help buy health insuranc could by next year get stung by surprise tax bills if they don't actually project their income.

The Affordable Health Care Act will offer subsidies to help people buy private health insurance on state based exchanges, if they don't already get coverage through their employers. The subsisidies are based on income. The lower your income, the bigger the subsidy.

BUT, the government doesnt know how much money you're going to make next year. And when you apply for the subsidy this fall, it won't even know how much you're making THIS year.

So unless you tell the government otherwise, it will rely on the best information it has, your 2012 tax return, files this spring.

What happens if you or your spouse gets a raise and your family income goes up in 2012? You could end up with a bigger subsidy then you are entitled to. If that happens, the law says you have to pay back at least part of the money when you file your tax return in the spring of 2015.

That could mean smaller tax refunds or surprise tax bills for millions of middle class families.

R & R

As many of you know, I suffered a surprise but massive heart attack back in late February.

Am recovering steadily and will be back stronger then ever.

Thanks for all the kind wishes.

Richard

Friday, February 22, 2013

Are ACOs fundamentally flawed?


Many of the hundreds of accountable care organizations being created around the country are doomed to fail, three healthcare experts argue in a commentary in The Wall Street Journal.
They maintain the ACO model is largely based on flawed assumptions about the personal and economic behavior of doctors and patients. The concept mistakenly assumes ACOs can be successful and save money even if doctors don't make major changes to how they provide care and patients don't change their behavior or assume accountability.
To achieve high-quality, low-cost care, the industry needs to embrace reform approaches that go beyond the ACO model, such as shifting more care to less-expensive walk-in clinics staffed by nurse practitioners, according to the WSJ commentary.

The healthcare experts also recommend revising protective licensing procedures to allow, for example, highly trained nurses to administer anesthesia for some types of procedures, rather than anesthesiologists, according to the WSJ commentary.

Meanwhile, just last week the National Committee for Quality Assurance announced its first six accredited accountable care organizations: HealthPartners in Minnesota, Billings (Mont.) Clinic, Children's Hospital of Philadelphia, Essentia Health in Minnesota, Kelsey-Seybold Clinic in Houston, and Crystal Run Healthcare in New York. The voluntary NCQA accreditation, based on an assessment of 14 standards and 65 elements, is valid for three years.


Wednesday, February 6, 2013

Mid-market firms charged higher premiums for health insurance!

Mid-market companies on average were charged substantially higher premiums for group health insurance coverage in 2012 than larger firms, according to a study released Monday by Automatic Data Processing Inc.

Companies with between 1,000 and 2,499 full- and part-time employees were charged an average $10,351 per employee in 2012, 16% more than employers with more than 5,000 or more workers and 8.3% more than employers with between 2,500 and 4,999 workers, according to ADP's study. The average annual per-employee premium cost across all employers surveyed was $9,562.

Chris Ryan, ADP's vice president of strategic advisory services and co-author of the study, said in an email that several factors are likely to blame for midsize employers' cost disadvantage.
Midmarket firms “lack the size and scale needed to negotiate more favorable agreements with health plans, networks and TPAs. They are also less likely to operate self-funded health plans with the potential to reduce premiums,” Mr. Ryan said, adding that recent ADP research also suggested that “larger employers are more likely to have the financial wherewithal to provide employees with a health and wellness program to help contain premium costs.”
“Larger employers may be more effective in communicating and implementing consumer-driven health plans, and may also have more effective practices for conducting audits to ensure member eligibility,” Mr. Ryan said.

ADP's “2012 Study of Large Employer Benefits,” the first of its kind for the Roseland, N.J.-based payroll processing firm, examined health care costs and participation rates among 300 employers with more than 1,000 employees. In total, the study encompassed more than 2 million covered lives, including employees and their dependents.
Beyond headcount, certain other demographic factors were found to be predictive of higher-than-average health benefit costs. Manufacturers, professional and scientific services firms, health care providers and information technology firms were charged between 3% and 13% per employee per month more for group health benefits than the average employer, according to ADP's study.

In part, those industries' higher health care costs were driven by the average age of their respective workforces. Manufacturing companies were charged $899 per employee per month in premiums, the highest of any industry surveyed, and had an average employee age of 45.5 years. Conversely, employers in the hospitality and food services industry incurred the lowest monthly per-employee premiums in 2012 ($596) and the lowest average employee age (36.9 years) of any industry group surveyed.

Other factors such as geographic location and the “richness” of the benefits provided contributed to the disparity in benefits costs among industries, the study noted.

Wednesday, January 23, 2013

Supply chain disasters and disruptions can cause lasting reputation damage!

Supply chain disruptions frequently result in a direct financial hit for businesses, but the damage a disruption can inflict on an organization's reputation can have much longer term consequences.

Global sourcing strategies such as just-in-time inventory, competitive wages and cheap raw materials also can pose hard-to-quantify risks from second- and third-tier suppliers that could subject businesses to Foreign Corrupt Practices Act penalties, environmental violations and regulatory actions as well as reputational damage, experts say.

A recent example is the November fire at a Bangladesh factory that killed more than 100 garment workers, many of whom reportedly were locked in the building. The factory was making clothing for Wal-Mart Stores Inc., Sears Holdings Corp. and The Walt Disney Co., among others.

In 2011, Wal-Mart audited more than 9,000 factories and the factory in Bangladesh was not authorized to produce merchandise for the Bentonville, Ark.-based retailer due to safety standards. However, a supplier reportedly continued to subcontract work with the Bangladesh factory.

Thursday, January 17, 2013

For companies, cyber threats get MORE costly!

Cyber security will become an increasingly complex and costly part of doing business, but caution and preparedness is a better alternative than getting hacked or duped by cyber thieves, security experts have stated.

IT managers are grappling with vulnerabilities and security risks as companies move more of their networking operations off-site and into the so-called data cloud, and as more personal computing is done on smart phones and mobile devices.

Companies are also facing increasingly high stakes for preventing security breaches, as both clients and the government demand that companies do more to protect themselves from security lapses.

Outbreaks of attacks in recent months and years show a growing push by organized crime, sovereign nations and internet activists to exploit weaknesses in the data security of US networks and their users.

The websites of large banks, for example, have been hit with what are called 'denial-of-service' attacks. While banks have not reported sensitive customer data being stolen during these attacks, their websites have repeatedly crahsed forcing customers to bank offline.

A big concern for IT managers is the growing demand that companies let their workers use their own personal devices - be it laptops, tablets or smart phones - to connect with a companies servers.

Known as BYOD (Bring you own device), the trend is proving to be a nightmare for IT managers. In essence thay now have to secure something they don't have control over.

Small businesses, which typically lack the IT expertise, are particularly vulnerable and appear to be more of the focus of hackers' attention.

A continued sign of the growing threat is the emergence of Cyber Liability insurance policies to help businesses deal with the costly aftermath of a cyber attack.

Becuase standard General Liability insurance policies will not protect from a cyber attack, insurers have introduced specialty coverage that can help defray costs of a breach. This can include the costs of notifying customers, conducting forensic investigations and even liability for class-action lawsuits.