The Brave New World of Cybercrime Insurance Coverage Disputes

Computer crime and data breaches have become a reality for most businesses.  Words like spearphshing or ransomware that were obscure five years ago are now in the headlines on a regular basis.  The FBI calculated over $1.4 billion in reported losses from hacking and similar computer crime in 2017.  A data breach can cause serious monetary consequences for businesses, besides the goodwill hit of having to notify customers and colleagues of the intrusion.

Accordingly, business have tried to mitigate the risks of a data breach or hack through insurance coverage.  Since cybercrime coverage is in its infancy, it’s unsurprising disputes have arisen between businesses and insurers regarding the extent of coverage under these policies.

Emerging caselaw shows that cybercrime coverage is not immune from the traditional conflict between the insured’s interest in being made whole after a loss and the insurer’s interest in paying as little as possible on claims.  A good example is the recent decision by the U.S. Court of Appeals for the Sixth Circuit in American Tooling Center, Inc. v. Travelers Casualty and Surety Company of America.  American Tooling Center (“ATC”), lost over $800,000.00 in a phishing scam.  Hackers first infiltrated ATC’s email servers and obtained the names of ATC’s contacts with ATC’s Chinese subcontractor.  After ATC wired certain payments to its subcontractor, the hackers posed as the subcontractor’s agents and claimed to have never received the payments.  ATC canceled its initial wire transfer and re-sent the funds to the hackers.  ATC realized what had happened when the genuine subcontractor called to demand payment.

ATC tendered the claim to its insurance carrier, Travelers, under ATC’s coverage for “computer crime.”  ATC’s policy provided Travelers “will pay the Insured for the Insured’s direct loss of, or direct loss from damage to, Money, Securities and Other Property directly caused by Computer Fraud.”  ATC requested Travelers cover the over $800,000.00 it lost in the phishing scheme.

Travelers refused to pay.  Relying on the words “direct loss,” Travelers claimed ATC hadn’t actually lost the over $800,000.00 it wired to the hackers.  Instead, Travelers argued ATC only had a “direct loss” in the amounts it had to pay to its subcontractor over and above those amounts it paid to the hackers.  Since the subcontractor (presumably sympathetic to ATC) had settled for a reduced payment, Travelers claimed it need only pay ATC the amount its subcontractor agreed to accept.

The court had little trouble rejecting Travelers’ argument, stating:

A simplified analogy demonstrates the weakness of Travelers’ logic. Imagine Alex owes Blair five dollars. Alex reaches into her purse and pulls out a five-dollar bill. As she is about to hand Blair the money, Casey runs by and snatches the bill from Alex’s fingers. Travelers’ theory would have us say that Casey caused no direct loss to Alex because Alex owed that money to Blair and was preparing to hand him the five-dollar bill. This interpretation defies common sense.

Separately, Travelers also argued the phishing attack was not covered under ATC’s computer fraud coverage.  Travelers claimed coverage only existed where the perpetrator actually caused the transfer, not where the hackers deceived employees into transferring money unwittingly.  The court observed that if Travelers wanted to restrict coverage thusly, it could easily have made that explicit in the policy – indeed, the court pointed out many policies do restrict coverage in this way using language absent from Travelers’ policy.

The ATC decision underscores the emerging issues in cybercrime coverage disputes and the bases insurers will use to deny coverage for phishing, hacking and other computer crime causing losses to businesses.

Out of Network Billing for Emergency Room Visit: New Legislation Aims To Fix Loophole In Existing Law

In a medical emergency, patients are typically concerned with getting to the emergency room as fast as possible.  They often don’t stop to check whether the closest emergency room is at a hospital that is “in-network” with their health insurance plan; or, even if they do, the nearest in-network emergency room may be too far away.

Most health insurance plans exclude coverage for treatment with out-of-network hospitals, so this can cause insureds who seek treatment in an emergency without carefully checking whether their hospital is in-network with their insurer to pay astronomical out of pocket costs for treatment.

The federal Affordable Care Act (a/k/a “Obamacare”) imposed new rules on insurers that partially fix the problem of coverage for out-of-network emergency healthcare.  The ACA requires covering emergency care without limiting coverage on the basis care was rendered by an out-of-network provider.  The statute provides:

If a group health plan, or a health insurance issuer offering group or individual health insurance issuer [sic], provides or covers any benefits with respect to services in an emergency department of a hospital, the plan or issuer shall cover emergency services … in a manner so that, if such services are provided to a participant, beneficiary or enrollee … such services will be provided without imposing any requirement under the plan for prior authorization of services or any limitation on coverage where the provider of services does not have a contractual relationship with the plan for the providing of services that is more restrictive than the requirements or limitations that apply to emergency department services received from providers who do have such a contractual relationship with the plan….

42 U.S.C. § 300gg-19a(b)(1) (emphasis added).

Courts have summarized this rule as requiring insurers “to cover out-of-network emergency services in a way ‘that is [no] more restrictive than the requirements or limitations’ applicable to emergency department services received from in-network providers.”  Northside Hosp., Inc. v. Ambetter of Peach State, Inc., 2017 WL 8948348, at *1 (N.D. Ga. Dec. 1, 2017) (quoting 42 U.S.C. § 300gg-19a(b)(1)(ii)).

Washington State’s Patient Bill of Rights similarly precludes insurers from limiting coverage for emergency care on the basis the provider was out-of-network.  Washington law provides:

A health carrier shall cover emergency services necessary to screen and stabilize a covered person if a prudent layperson acting reasonably would have believed that an emergency medical condition existed…With respect to care obtained from a nonparticipating hospital emergency department, a health carrier shall cover emergency services necessary to screen and stabilize a covered person if a prudent layperson would have reasonably believed that use of a participating hospital emergency department would result in a delay that would worsen the emergency.

RCW 48.43.093 (emphasis added).

But there’s an important loophole in this rule.  Health insurers have to cover out-of-network emergency care under the rule, but the rule never states how much of the bill an insurer must pay.  This is a critical omission.  Most health plans limit the amount the insurer pays to special discount rates the insurer negotiated with its in-network providers.  But out-of-network providers haven’t agreed to accept this rate, which is often a tiny fraction of the out-of-network provider’s charge for an emergency room visit.

Thus, even where the insurer nominally covers emergency treatment at an out-of-network hospital, the insurer is only required to pay the amount it negotiated with its in-network providers.  Since the out-of-network emergency room hasn’t agreed to accept those rates, the insurer’s coverage will be inadequate – often by hundreds of thousands of dollars.  The patient then receives a bill for the difference despite having “coverage” for the emergency room visit.

This leads to the unfair situation where a person goes to an out-of-network emergency room and supposedly has coverage under the ACA and Washington Patient Bill of Rights, yet still winds up on the hook for medical bills that would have been paid had the provider been in-network.  As a practical matter, this renders the intent of the ACA and Washington Patient Bill of Rights – protecting insureds from crippling medical bills for visiting an out-of-network emergency room – completely ineffective.

Unfortunately, until a legislative solution emerges, insureds must still check the in-network status of their providers with agonizing precision – even in the event of a life-threatening medical emergency – despite the ACA and Washington Patient Bill of Rights.  Washington State’s legislature has proposed such a solution: HB 2114 – 2017-18 (“Protecting consumers from charges for out-of-network health services”).  That bill remains in legislative committee and faces harsh opposition from industry groups.

Court of Appeals Reiterates Insurer’s Obligation to Protect Policyholder From Lawsuit

When a driver crashes into another vehicle and is sued for damages, the driver’s insurer typically has an obligation to  defend the lawsuit and act in good faith to protect its insured’s interests.  When the insurer fails to do so, the driver likely has legal recourse under Washington law.

Washington’s Court of Appeals recently reiterated this principle in Singh v. Zurich American Insurance Company.  In Singh, the Court of Appeals ruled Singh’s insurer, Zurich American, was liable for failing to settle and defend claims against Singh in good faith.

On July 20, 2011, one of Singh’s employees, driving Singh’s semitruck, allegedly caused a 16-vehicle crash by failing to slow down for congested traffic.  Persons injured in the crash, and the families of those killed in the crash, sued Sing for damages.  Because of the dramatic injuries and deaths allegedly caused by Sing’s employee, the plaintiffs quickly advised Singh that they saw their damages recoverable from Singh as exceeding the limits of Sing’s insurance policy.  In other words, Singh knew that, if he lost the court case, he would have to pay significantly more money than his Zurich American insurance policy would cover.

Singh’s insurance policy with Zurich American obligated Zurich American to defend Singh in the lawsuit.  Zurich hired a lawyer to defend Singh.  Zurich’s lawyer recognized it was in Singh’s best interests to pay the entire insurance policy limit to settle the large monetary demands of the persons injured and killed in the crash.  But the attorney also recognized that disbursing the entire policy limit to the first plaintiffs to sue Singh would leave Singh without insurance coverage should later claimants seek damages from Singh.

Accordingly, Zurich’s lawyer proposed to reserve some of Singh’s policy limits to protect Singh from future claims arising from the crash.  However, Zurich ignored its lawyer’s advice and ordered the lawyer to settle the existing claims with the full policy limits.  Zurich’s lawyer did so.

Later, another person sued Sing claiming injuries in the crash.  Zurich refused to defend the lawsuit because Singh’s policy limits were exhausted from the prior settlement. Singh paid for his own counsel and ultimately paid $250,000.00 to settle the new claims.

Singh then filed suit against Zurich alleging Zurich acted in bad faith and violated Washington’s Insurance Fair Conduct Act (“IFCA”) and Consumer Protection Act (“CPA”).  The jury found in Singh’s favor, agreeing Zurich breached Singh’s insurance policy and acted in bad faith.

The Court of Appeals upheld the jury’s verdict.  The court observed the insurer’s duty to defend the insured “is one of the main benefits of the insurance contract.”  Thus, the court determined Zurich could not permissibly exhaust the policy limits then use its exhaustion of the policy limits as an excuse to continue defending Singh.  Doing so put Zurich’s interests over Singh’s in violation of the insurance policy and Washington law.  Notably, Zurich ignored its own lawyer’s suggestion it keep some policy limits in reserve to protect Singh from future claims.

Think Twice About Your Health Plan’s “Wellness” Review

It’s currently trendy for health plans to try to get their insureds to undergo a “wellness” screening in which the insurer collects personal health and lifestyle data from the insured.  These are often pitched as a benefit to the insured with the health plan saying, basically, “let us give you this great free screening!”   Sometimes the insurer even offers gift cards or other goodies to insureds who participate.

But as is typical for anything the company is incentivizing insureds to do, “wellness” screenings are often in the insurer’s interest – not the individual’s.

Health insurers have begun routinely collecting insured’s personal health and lifestyle data to justify premium increases based on the minutia of an individual’s daily life.   Just like tech companies can use the minutia of your personal data for marketing purposes, health insurers can use insured’s lifestyle and biometric data to raise premiums.

A recent NPR report details how “the health insurance industry has joined forces with data brokers to vacuum up personal details.”  Besides mundane details like race or education, insurers also reportedly track what TV you watch, your social media habits, and your online shopping, among other things.   One company boasts it collected health data on 150 million Americans going back to 1993.  Another filed a patent application to gather health-related information from social media.

Insurers use this data to price health care plans.  For instance, insurers reportedly consider women purchasing plus-size clothing to be at risk of depression; minority insureds to be more likely to live in dangerous neighborhoods; and recently-married insureds to be more likely to need childbirth care.

Insurers’ use of this data raises broader questions about the use of the data we readily share in the digital age, but it also emphasizes that the health insurer’s “wellness” exam might not be the altruistic offer it’s pitched as.

Medical Proof Required to Deny ERISA Claims Based on Intoxication Exclusion Says Fifth Circuit

Many ERISA plans and insurance policies contain provisions excluding coverage for losses caused by the insured’s intoxication.  In cases where the plan or insurer asserts such an exclusion, the question becomes what evidence must the insurer put forward in order to prove the insured was intoxicated and the exclusion applies?

The U.S. Court of Appeals for the Fifth Circuit recently answered that question in White v. Life Insurance Company of North America.  Life Insurance Company of North America (“LINA”) issued an ERISA-governed life insurance policy insuring Mr. White with Mrs. White as the beneficiary.  Mr. White was killed in a horrible car crash in which his vehicle crossed the center line and struck an oncoming 18-wheeler head-on.

LINA denied coverage asserting the policy’s intoxication exclusion precluded coverage because Mr. White was drunk at the time of the crash.  Weather and road conditions were clear at the time of the crash, Mr. White’s vehicle appeared to function properly, and paramedics reported smelling alcohol on Mr. White’s breath.  Hospital staff took blood and  urine samples from Mr. White that tested negative for alcohol but contained undefined amounts of amphetamines, cocaine, opiates, benzodiazepine, and cannabinoids.  The tests were preliminary and only indicated the presence, not the amount, of controlled substances.

The Court agreed with Mrs. White.  The LINA life insurance policies excluded coverage for death “caused” by Mr. White’s intoxication.  The policy (borrowing from Arkansas law) defined intoxication to mean “influenced or affected by the ingestion of alcohol [or] a controlled substance…to such a degree that the driver’s reactions, motor skills, and judgment are substantially altered and the driver, therefore, constitutes a clear and substantial danger or physical injury to himself or herself or another person.”

The Court found LINA’s evidence failed to meet the policy definition of intoxication.  LINA relied on the opinion of a toxicologist who opined it was impossible to estimate the level of Mr. White’s impairment at the time of the crash based on the preliminary test results.  The toxicologist opined only that “in the absence of any other cause of the collision, the drugs in [Mr. White’s] system could explain his level of impairment that resulted in his crash.”

Accordingly, the Court entered judgment in favor of Mrs. White.  The White case is an important reminder that ERISA plans and insurers cannot deny claims by asserting exclusions that lack tangible factual support.