Category: HB Risk Notes

  • Maximizing Insurance as Climate Change Intensifies

    Maximizing Insurance as Climate Change Intensifies

    HB presents an Anderson Kill webinar on-demand

    MAXIMIZING INSURANCE RECOVERY AS

    CLIMATE CHANGE INTENSIFIES

    As weather-induced disasters continue to intensify, maximizing insurance coverage after major storms, floods, wildfires, and other natural cataclysms is an essential survival skill for any business.

    In this session, attorneys who have successfully litigated property, business interruption and contingent business interruption claims from Hurricanes Katrina through Ida, along with wildfire and other major disaster claims, walk participants through all phases of insurance recovery, from buying the right policies to pursuing claims with persistence and awareness of pitfalls, to litigating successfully when necessary. Specific lessons from Hurricanes Sandy (2012), Harvey (2017) and Maria and Irma (2020) will be addressed.

    Topics:

    • Developing a pre-storm preparedness plan, including mitigation efforts, assembly of a claims team, and insurance coverage review;
    • Moving quickly to protect property from further damage, performing all emergency repairs, and documenting all losses in detail;
    • Preparing and presenting well-supported property damage claims;
    • Recognizing and including business interruption losses and extra expense outlays;
    • Highlighting policy interpretation issues that affect the scope of available coverage;
    • Outlining strategies for pursuing claims and incentivizing the insurance company to resolve them with due speed.

    On-Demand Registration

    Includes

    • 1+ CLE credits (subject to bar rules). CLE codes are embedded in the video. CLE questions?
    • Insights from experienced professionals.
    • The complete PowerPoint presentation.
    • Continued access to the complete recording for later use.
    • Answers to your questions via email to the presenters, or write to HB.

    Meet the Panel

    Finley Harckham
    Anderson Kill

    Finley is a senior litigation shareholder in the New York office of Anderson Kill and serves on
    the firm’s Executive Committee. Finley regularly represents and advises corporate policyholders and
    other entities in insurance coverage matters. He has successfully litigated, arbitrated and settled
    hundreds of complex coverage claims. His areas of particular focus include property loss, environmental,
    business interruption, directors and officers liability, construction, professional liability, aviation liability,
    cyber and general liability claims.

    Finley also has extensive experience in the field of international arbitration. His arbitration clients
    include government contractors, consumer products companies and manufacturers which Anderson Kill
    has represented in a wide range of disputes involving, among other things, service contracts, the
    purchase and sale of components, raw materials and products, and licensing agreements. He has
    successfully prosecuted and defended arbitrations in European countries and the United States under
    the London Arbitration Act, and the AAA, ICC and UNCITRAL arbitration rules.

    More about Finley

    Rhonda D. Orin
    Anderson Kill

    Rhonda is the managing partner of the firm’s Washington, D.C. office. She is also co-chair of the COVID Task Group. Rhonda represents policyholders in coverage cases nationwide, including cyber liability, third-party tort and environmental liability claims, first-party property damage and business interruption claims, directors & officers liability, errors & omissions liability, fidelity bonds and alternative risk transfer arrangements, including for employee benefit plans.

    She has served as lead counsel in multiple jury and bench trials, argued before the highest courts of several states, and appeared in two cases before U.S. Supreme Court. Through jury verdicts, summary judgment decisions and confidential settlements before and during litigation, she has recovered hundreds of millions of dollars for policyholders, including nine-figure recoveries.

    More about Rhonda

    Dennis J. Artese
    Anderson Kill

    Dennis is a shareholder in the New York office of Anderson Kill. He is also co-chair of the firm’s Construction Industry practice group and a member of the COVID Task group. Dennis’ national practice concentrates on all types of insurance recovery litigation, with an emphasis on securing insurance coverage for construction-related first-party property losses and third-party liability claims as well as for property and business interruption losses stemming from natural disasters and other perils.

    Dennis has substantial experience in all phases of litigation, arbitration and property insurance appraisals, and has recovered hundreds of millions of dollars of insurance proceeds on behalf of policyholders in connection with a variety of property, builder’s risk, commercial general liability, umbrella and excess liability, D&O, E&O, crime, and political risk insurance claims. Dennis also has extensive experience in litigating insurance broker malpractice cases and other general commercial litigation disputes, including construction-related disputes. Dennis has been recognized by Super Lawyers for Insurance Coverage since 2012. He also has been recognized by Legal 500 for Insurance Advice to Policyholders and singled out as being a “superb lawyer and subject-matter expert.”

    More about Dennis

    Ronald Papa
    National Fire Adjustment Co.

    Ronald has been instrumental in NFA’s growth for more than 30 years. He has successfully adjusted more than 2,000 insurance losses working for a wide range of clients. Ron earned the prestigious designation of Senior Professional Public Adjuster and is accredited by the National Association of Public Insurance Adjusters (NAPIA), of which he is past president.

    He was named Person of the Year by NAPIA for “outstanding leadership” and recently addressed the National Symposium of Insurance Commissioners at their conference in Florida. Ron is approved as an instructor by numerous State Insurance Departments, the New York State Bar Association, and the Society of CPAs. He graduated from Niagara University.

    More about Ronald

    On Demand Registration

  • Analysis of Target Decision that Loss-of-Use Damages Included Card Replacement Costs Post-Data Breach | By Joshua Mooney, Judy Selby, and Tracey Kline | Kennedys Law

    Analysis of Target Decision that Loss-of-Use Damages Included Card Replacement Costs Post-Data Breach | By Joshua Mooney, Judy Selby, and Tracey Kline | Kennedys Law

    A Significant Deviation:
    Target v. Ace Finds Loss-of-Use Damages Included Post-Breach Card Replacement

    Analysis

    On March 22, 2022, the United States District Court for the District of Minnesota ruled that two ACE insurers were obligated to indemnify Target Corporation (“Target”) for the amounts it paid to settle claims related to replacement of payment cards impacted in a data breach, vacating an earlier decision in which the court found that Target was not entitled to coverage. Target Corp. v. ACE Am. Ins. Co., No. 19-CV-2916 (WMW/DTS), 2022 WL 848095 (D. Minn. Mar. 22, 2022), vacating 517 F. Supp. 3d 798 (D. Minn. 2021). The new decision deviates from how other courts have evaluated general liability coverage for damages because of “loss of use of tangible property that is not physically injured.” Insurers would do well to take notice.

    Background

    In 2013, Target was the victim of a massive data breach that occurred after hackers installed malicious software on its computer network, which enabled them to steal the payment card data and personal contact information of an estimated 110 million individuals with Target payment cards (the “Data Breach”). Multiple lawsuits were brought against Target, including suits by financial institutions (the “Issuing Banks”) that had issued debit and credit cards (the “Payment Cards”) affected by the Data Breach. The Issuing Banks filed class action lawsuits against Target, which were consolidated, along with various consumer suits, in the United States District Court for the District of Minnesota, in In re: Target Corporation Customer Data Security Breach Litigation, All Financial Institutions Cases, MDL No. 14-2522 (the “Issuing Banks Litigation”). In their Consolidated Class Action Complaint, the Issuing Banks asserted various causes of action against Target, including a claim for negligence by which they alleged that Target breached its duty to implement adequate technical systems or security practices that could have prevented the loss of customers’ sensitive personal and financial information. The Issuing Banks alleged that, because of Target’s failures, they incurred various losses, including costs associated with cancelling and reissuing Payment Cards that were compromised in the Data Breach. In May 2016, Target reached a settlement in the Issuing Banks Litigation for approximately $58 million, which the district court approved.

    In addition to settling the Issuing Bank Litigation, Target reached confidential settlements with the major card issuers, including Visa, MasterCard, American Express, and Discover, as well as numerous individual Issuing Banks. In total, Target settled all of the claims for approximately $138 million. Of that amount, according to Target, at least $74 million was paid to settle the Issuing Banks’ claims for the costs associated with replacing Payment Cards that they alleged had been compromised as a result of the Data Breach (the “Payment Card Claims”).

    Target gave notice of the Data Breach to its commercial general liability (“CGL”) insurers, including ACE American Insurance Company and ACE Property & Casualty Insurance Company (collectively, “ACE”), which had issued two CGL policies to Target that were in effect at the time of the Data Breach (the “ACE Policies”). In relevant part, the ACE Policies provided coverage for “‘ultimate net loss’ . . . because of ‘property damage’.” The policies defined “occurrence” as an “accident, including continuous or repeated exposure to substantially the same general harmful conditions.” They defined “property damage” to include “[l]oss of use of tangible property that is not physically injured,” and provided that “[a]ll such loss of use shall be deemed to occur at the time of the ‘occurrence’ that caused it.” The policies expressly stated that “electronic data” was “not tangible property.”

    ACE denied coverage. Subsequently, Target sued ACE, seeking indemnification exclusively for the payments Target made to settle the Payment Card Claims. Target and ACE agreed that the duty to defend was not at issue. At their Rule 26(f) conference, the parties agreed that they would file cross-motions for summary judgment on the sole issue of coverage and, if the court found coverage, the issue of the amount of damages would be resolved at trial.

    The Motions for Summary Judgment

    Target moved for partial summary judgment, seeking a declaration that the ACE Policies covered the costs Target incurred settling the Payment Card Claims. ACE cross-moved for summary judgment, arguing that Target had failed to satisfy its burden of establishing the elements required to trigger coverage under the ACE Policies—namely, that its settlement satisfied a legal obligation to pay “damages because of loss of use of tangible property” caused by an “occurrence.”

    In their motions, Target and ACE disputed a number of issues related to the question of whether the Issuing Banks claimed “damages because of loss of use of tangible property.” Among other things, the parties proffered contrasting explanations of what was compromised by the Data Breach. Target contended that the physical Payment Cards were compromised. By contrast, ACE argued that it was the intangible data embedded in the Payment Cards, not the Payment Cards themselves, that was compromised in the Data Breach.

    Relatedly, the parties disputed whether the Payment Cards lost their use as a result of the Data Breach. Relying heavily on the Eighth Circuit’s decision in Eyeblaster, Inc. v. Federal Insurance Co., 613 F.3d 797 (8th Cir. 2010),[1] Target argued that the Data Breach caused a loss of use of the Payment Cards because it resulted in the cards’ inability to function as intended. In particular, Target contended that an essential function of the Payment Cards was that each card applied exclusively to the cardholder’s own debts (i.e., the charges the cardholder made) and not to the fraudulent charges of some third person. When the data connected to accounts was compromised in the Data Breach, Target maintained, the physical Payment Cards associated with those compromised accounts could no longer be safely used without the risk of fraud. Accordingly, Target argued that the Payment Cards associated with the hacked accounts immediately lost their ability to function as intended—i.e., to provide secure access only to the cardholder.

    ACE disputed that the Data Breach resulted in loss of use of the Payment Cards. Among other things, ACE disagreed with Target’s contention that the function of the Payment Cards was to make payment transactions “safe and secure.” ACE argued that such a security function was the function not of the Payment Cards but, rather, of the merchant’s computer system. ACE maintained that the function of the Payment Cards was only to facilitate efficient point-of-sale purchases by carrying data and permitting that data to be transmitted to a merchant’s computer network via a “swipe” or “insert.” ACE then contended that the Payment Cards continued to have the ability to perform their function of carrying and transmitting data after the Data Breach. Because of this, and because the Data Breach did not result in the Payment Cards being physically removed from any cardholder’s possession, ACE argued that there was no loss of use of the cards.

    The parties also disputed whether there was a relevant distinction between “loss of use” and “loss of value.” ACE argued that the Supreme Court of Minnesota’s decision in Federated Mutual Insurance Co. v. Concrete Units, Inc., 363 N.W.2d 751 (Minn. 1985) created a distinction between “loss of use” and “loss of value,” holding that “diminution in value” was not “property damage” when the latter was defined as either “physical injury to . . . tangible property” or as “loss of use of tangible property.” Concrete Units, 363 N.W.2d at 756. Relying on Concrete Units, ACE contended that the Data Breach caused the Payment Cards to lose their value, not their use, and therefore Target’s settlement liability arising from the Issuing Banks’ replacement of the Payment Cards did not constitute loss-of-use damages.

    Target countered that Concrete Units did not draw the distinction between losses that ACE claimed it did. Target further asserted that the Issuing Banks did not allege that the Payment Cards merely became less valuable—and did not seek to recoup the economic loss they suffered because the cards’ market value decreased—as a result of the Data Breach. Instead, Target claimed, the Issuing Banks were forced to cancel and reissue the Payment Cards because the cards could no longer effectively or safely be used to perform their intended function.

    The parties further disputed whether the ACE Policies’ loss-of-use coverage applied only to time-based damages. ACE contended that was the case, and argued that loss-of-use damages under the policies should be measured by the losses a claimant incurred because of, and during, the tangible property’s temporary down time. Target countered that no such temporal limitation appeared in the policies or was recognized by, or consistent with, Minnesota case law.

    In addition, the parties disputed whether Target’s liability for the Payment Cards’ replacement costs was caused by a covered “occurrence” (which, as noted above, the ACE Policies defined, in part, as an “accident”). The parties’ dispute in this regard concerned, among other things, from whose perspective an “accident” was determined. Targeted maintained that an accident was determined from the perspective of the policyholder (i.e., Target). Target then argued that, because the Data Breach was an unexpected and unintended happening from its standpoint, its losses stemmed from an accidental “occurrence.”

    ACE counter-argued that an accident had to be determined from the standpoint of the actor who caused the “property damage.” ACE then contended that the relevant actors for purposes of the accident inquiry were the Issuing Banks that deactivated and replaced the Payment Cards. In addition, ACE maintained that the Issuing Banks knowingly, intentionally, and purposefully deactivated and replaced the Payment Cards so as to mitigate future economic losses incurred through fraudulent transactions. ACE argued that, as a result, Target’s liability did not arise out of an accidental “occurrence.”

    The February 8, 2021 Decision

    On February 8, 2021, the Minnesota federal district court, applying Minnesota law, denied Target’s motion for partial summary judgment and granted ACE’s motion for summary judgment, holding that Target had not met its burden of establishing that its settlement liability arising out of the Payment Card Claims was covered under the ACE Policies. Target, 517 F. Supp. 3d at 806 (the “2021 Decision”) Specifically, the court determined that there was an insufficient causal connection between Target’s claimed damages arising out of the Payment Card Claims and the alleged loss of use of the Payment Cards to trigger coverage. Id.

    In arriving at that conclusion, the court initially observed that Target’s theory appeared to be that, because the Payment Cards allegedly lost their use and Target resolved the Payment Card Claims by paying a settlement, the settlement of that liability necessarily constituted damages because of a loss of use. Id. at 804. The court stated that this was, “in essence, a but-for theory of loss-of-use damages.” Id. at 804-05. The court then cited—and seemingly agreed with—several decisions wherein courts rejected a “but-for” test for loss-of-use damages. Id. at 805 (citing Vicor Corp. v. Vigilant Ins. Co., 674 F.3d 1, 13 (1st Cir. 2012); Atmel Corp. v. St. Paul Fire & Marine Ins. Co., 430 F. Supp. 2d 989, 994 (N.D. Cal. 2006)). The court determined that, for loss-of-use damages to be “based on” alleged loss of use under Minnesota law, the damages had to “have some connection to the value of the use of the now-damaged property when it previously was unimpaired.” Id. The court explained that “[a] ‘commonly used measure of loss-of-use’ damages—reasonable rental value—illustrates this point.” Id. (quoting Jacobs v. Rosemount Dodge-Winnebago South, 310 N.W.2d 71, 78 (Minn. 1981)). “Renting a vehicle,” the court added, “allows for use of a vehicle when another vehicle has been rendered unusable and, as such, vehicle-rental costs typically are recognized as loss-of-use damages.” Id. (italics in original, underline added) (citing Barbarossa & Sons, Inc. v. Iten Chevrolet, Inc., 265 N.W.2d 655, 662-63 (Minn. 1978)).

    The court then observed that “the record [was] devoid of any allegation or evidence as to what the value of the use of the payment cards [was], either to Target’s customers or to the payment card companies.” Id. (emphasis in original). Because “the value of the use [was] not established or even approximated,” the court determined that “damages [could not] . . . be ‘based on’ the loss of use because there [was] no nexus between the damages and the loss of use.” Id. (emphasis in original) (citations omitted). The court concluded that Target had “not established a connection between the damages incurred for settling claims related to replacing the payment cards and the value of the use of those cards, either to the payment-card holders or issuers.” Id. For that reason, the court found that “the connection between the damages claimed and the loss of use of the payment cards [was] insufficiently direct and, therefore, the damages claimed [were] not loss-of-use damages covered under the [ACE] Policies.” Id. at 806.

    Before arriving at this conclusion, the court stated that Target’s reliance on the Eighth Circuit’s decision in Eyeblaster was “misplaced” because Eyeblaster involved the duty to defend, which was “distinct” from and “broader” than the duty to indemnify that was at issue. Id. at 803. The court explained:

    “Because the duty to defend is broader in scope than the duty to indemnify, some losses covered under a duty to defend fall outside of the narrower duty to indemnify. As such, it is not necessarily so that the loss covered under the insurer’s duty to defend in Eyeblaster is covered under ACE’s duty to indemnify in this case. For this reason, Eyeblaster does not confirm that coverage is available for Target’s loss.”

    Target filed a motion to alter or amend the court’s 2021 Decision pursuant to Federal Rule of Civil Procedure 59(e). In its motion, Target argued that the court’s decision was in error for two reasons.

    First, Target argued that ACE never raised the legal theory on which the court resolved the summary judgment motions—i.e., that Target had not established “a connection between the damages incurred for settling [the Payment Card Claims] . . . and the value of the use of those cards.” Target contended that the court likewise did not raise that argument at the hearing on the motions. Target claimed that, as a result, it did not have notice of and a reasonable time to respond to the argument, which constituted a violation of Federal Rule of Civil Procedure 56(f)(2).

    Second, Target argued that the 2021 Decision represented a “manifest error of the law” justifying alteration or amendment under Rule 59(e). Target contended that, to obtain coverage under a CGL policy for damages because of “loss of use,” Minnesota law requires the policyholder to demonstrate only that the damages be “causally related” to the loss of use. Target argued that the court “went further and imposed an additional requirement on Target to establish a connection between such damages and the value of the use of the property when it was unimpaired.” Target argued that this additional requirement had never been imposed by a Minnesota court and, furthermore, was incompatible with the Eighth Circuit’s decision in Eyeblaster.

    Target asked the court to (1) vacate its 2021 Decision and entry of judgment to permit additional briefing, evidentiary submissions, and (potentially) discovery; or, in the alternative, (2) alter or amend the judgment to grant summary judgment for Target; or, in the alternative, (3) alter or amend the judgment to deny both Target’s and ACE’s motions for summary judgment, which would permit the case to move forward into discovery and, ultimately, to trial.

    The March 22, 2022 Decision

    On March 22, 2022, the district court granted Target’s motion to alter or amend the 2021 Decision, vacated the court’s 2021 Decision, denied ACE’s motion for summary judgment, and granted Target’s motion for partial summary judgment. Target, 2022 WL 848095, at *4-5 (the “2022 Decision”). The court determined that the expenses Target incurred in settling the Issuing Banks’ Payment Card Claims were covered under the terms of the ACE Policies and that ACE was obligated to indemnify. Id. at *4. The court stated that it had “erred in its prior judgment” when it found that Target’s claim was not covered. Id.

    The court began by explaining that, to establish coverage under the ACE Policies for the costs it incurred settling the Payment Card Claims, Target needed to establish: (1) that its losses were the result of an “occurrence”; (2) that the “occurrence” resulted in the “loss of use” of property; and (3) that the property lacking use was “tangible property that [was] not physically injured.” Id. at *2. The court addressed each requirement and concluded that each was satisfied. Id. at *2-4.

    The court first found that Target satisfied its burden of demonstrating that its losses resulted from an “occurrence.” Id. at *2-3. The court reasoned:

    “The parties do not dispute that Target neither expected nor intended the Data Breach. The Data Breach was an accident, which is an “occurrence” within the terms of the Policies. Under Minnesota law, an accident includes the acts of the insured and “the consequences of the insured’s acts.” [Am. Fam. Ins. Co. v. Walser, 628 N.W.2d 605, 609 (Minn. 2001).] . . . The cancellation and resulting inoperability of the payment cards were the consequences of Target’s discovery of the accident, the Data Breach. For this reason, the Court concludes that the inoperability of the payment cards—necessitated by the Data Breach—is an “occurrence” within the terms of the Policies.”

    Id. at *3.

    Next, the court determined that Target met its burden of establishing that the Data Breach resulted in “loss of use” of the Payment Cards. Id. In doing so, the court favorably cited the Eight Circuit’s decision in Eyeblaster, which the court described as presenting a “factually analogous loss of use” issue—without discussing its previous determination that Target’s reliance on Eyeblaster was “misplaced” or explaining why the court no longer found that to be the case. See id. The court reasoned:

    “Here, the Data Breach compromised Target’s payment cards. By compromising the payment information listed on and associated with the payment cards, the Data Breach caused the Issuing Banks to cancel the compromised payment cards and issue replacement payment cards. Cancellation of the compromised payment cards rendered the payment cards inoperable. The payment cards lost their use. Although the compromised payment cards still existed, like the consumer’s computer in Eyeblaster, they could no longer serve their function. . . . The expense that Target incurred to settle claims brought by the Issuing Banks for the costs of replacing the compromised payment cards was a cost incurred due to the loss of use of the payment cards. As such, Target meets the second requirement for establishing coverage pursuant to the Policies.”

    Id. (citation and footnote omitted).

    The court briefly discussed, in a footnote, the causation issue that formed the basis for the 2021 Decision, stating:

    The parties and this Court’s prior order discuss the connection that must exist between the loss of use of the payment cards and the settlement of the Issuing Banks’ claims against Target. The Court need not repeat that analysis here as Minnesota case law clearly states that the insured’s claims “must be causally related to . . . the lost use.” Federated Mut. Ins. Co. v. Concrete Units, Inc., 363 N.W.2d 751, 757 (Minn. 1985). Target’s insurance claim is for the expense Target incurred settling the Issuing Banks’ legal claims demanding compensation for the cost of replacing the payment cards that lost their use following the Data Breach. There is a sufficient causal connection between Target’s claim for coverage and the payment cards’ loss of use so as to satisfy the causation requirement of Minnesota law.

    Id. at *3 n.3.

    Finally, the court concluded that Target satisfied its burden of showing that its claim was for property damage to “tangible property that [was] not physically injured.” Id. at *4. The court reasoned:

    ACE contends that Target is actually seeking compensation for the missing data, not the payment cards. But the parties do not dispute that the payment cards, the damaged property for which Target seeks coverage, are “tangible property that is not physically injured.” And it is the use of the payment cards, not the use of electronic data, that was lost. Because the payment cards are tangible property and the payment cards are not physically injured, Target has met the third requirement to establish a basis for its claim for coverage.

    Id. (emphasis in original).

    For those reasons, the court concluded that the costs of replacing the Payment Cards affected by the Data Breach were covered under the ACE Policies. Id. Subsequently, the court held that ACE was obligated to indemnify Target for Target’s settlement with the Issuing Banks for those costs. Id.

    The 2022 Decision represents a significant deviation from how other courts have viewed CGL coverage for damages because of “loss of use of tangible property that is not physically injured.” Of particular note is the court’s unexplained change in opinion with respect to whether Target’s claimed damages were sufficiently tied to the alleged loss of use of the Target Payment Cards.

    Courts have often couched loss-of-use damages in terms of consequential damages. See, e.g., J & D Towing, LLC v. Am. Alternative Ins. Corp., 478 S.W.3d 649, 655 (Tex. 2016); see also generally IRMI, Loss of Use as Property Damage, https://www.irmi.com/articles/expert-commentary/loss-of-use-as-property-damage (last visited Apr. 20, 2022). In doing so, courts have determined that, to constitute damages because of “loss of use of tangible property,” the claimed loss-of-use damages must be directly traceable to the loss of use of the tangible property. See, e.g., J & D Towing, 478 S.W.3d at 677.

    Consistent with the foregoing, many courts have determined that loss-of-use damages are not replacement costs. See, e.g., Advanced Network, Inc. v. Peerless Ins. Co., 119 Cal. Rptr. 3d 17, 25 (Cal. Ct. App. 2010) (“Coverage for ‘loss of use’ does not apply to an underlying action in which the claimant seeks only the replacement value of converted property.”). Atmel Corp. v. St. Paul Fire & Marine Insurance Co., 430 F. Supp. 2d 989, supra is illustrative. There, the insured, Atmel, manufactured and sold to Seagate electronic chips, which Seagate incorporated into disk drives that it later sold to its customers. Atmel, 430 F. Supp. 2d at 991. The Atmel chips were allegedly defective and caused Seagate’s disk drives to fail. Id. As a result, Seagate had to repair or replace the defective disk drives. Id. Seagate subsequently sued Atmel, and Atmel ultimately settled the lawsuit by agreeing to pay Seagate millions of dollars. Id. at 991-92.

    In ensuing coverage litigation between Atmel and its CGL insurers, the United States District Court for the Northern District of California held that Atmel’s settlement liability in the Seagate action did not trigger the at-issue CGL policies’ coverage for “loss of use of tangible property of others that isn’t physically damaged.” Id. at 994. The court reasoned:

    Seagate’s damages primarily consisted of costs associated with repairing and replacing the Atmel chips. Although Atmel is correct that these damages would not have been incurred but for the failure of the Atmel chips, that does not compel a finding that these damages are “loss of use” damages. Atmel’s expansive definition of “loss of use” damages includes any and all damages related to the failure of the Atmel chips in the Seagate drives, and does not require a nexus with Seagate’s (or its customers’) inability to use the drives. The Court does not hold . . . that loss of use damages can only consist of rental value or its equivalent. However, the Court holds that the damages alleged by Seagate at the time of the settlement were too attenuated from a “loss of use,” and there must be a more direct connection between the damages claimed and the loss of use of the property in order to establish coverage under the CGL policies.

    The 2021 Decision was largely in accord with Atmel and other decisions finding that costs to repair or replace property are too remote from a loss of use of the property to constitute loss-of-use damages. See Target, 517 F. Supp. 3d at 805. But in its 2022 Decision, the court reversed course, concluding that there was “a sufficient causal connection between Target’s claim for coverage and the payment cards’ loss of use so as to satisfy the causation requirement of Minnesota law.” Target, 2022 WL 848095, at *3 n.2. It is unclear what led to this change in heart by the court. In particular, it is unclear if the court was accepting the but-for theory of loss-of-use damages the court had seemingly rejected in its 2021 Decision.

    The 2022 Decision also raises questions concerning the court’s change of position as to the import of the Eight Circuit’s Eyeblaster decision. It is also unclear to what extent, if at all, the court’s decision was informed by the “loss of use” versus “loss of value” distinction urged by ACE.

    In light of the issues left unresolved by the 2022 Decision, it remains to be seen how the decision will impact courts’ evaluation of similar claims going forward. It will be particularly interesting to see how Target factors into the Home Depot, Inc. v. Steadfast Insurance Co. case, which is currently pending in the United States District Court for the Southern District of Ohio, under docket number 1:21-cv-00242.

    Home Depot involves facts that, at least as alleged by Home Depot, appear to be materially identical to those in Target—with the exception that Home Depot involves alleged breaches of both the duty to indemnify and the duty to defend (whereas Target involved just the former). Specifically, Home Depot was the victim of a data breach that allegedly compromised the payment cards of millions of Home Depot customers. Subsequent to the data breach, credit card issuers that were allegedly forced to cancel the compromised cards and issue replacement cards to customers sued Home Depot, seeking to recover, among other things, the costs they incurred in replacing the cards. Home Depot ultimately reached a settlement with the card issuers. It then sued its CGL insurers, alleging that they wrongfully denied coverage under policies that provided coverage for, in relevant part, “property damage” caused by an “occurrence.”

    Like the policies at issue in Target, the policies at issue in Home Depot define “property damage” to include “[l]oss of use of tangible property that is not physically injured,” and define “occurrence” to mean “an accident, including continuous or repeated exposure to substantially the same general harmful conditions.” Unlike the policies at issue in Target, however, the policies at issue in Home Depot—according to Home Depot, at least—are governed by Georgia law.

    We expect that Home Depot will point to the Target court’s 2022 Decision in an attempt to support an argument that it is entitled to coverage.[2] It is uncertain how the Home Depot court would in that instance evaluate the merits or persuasiveness of the Target decision, which we would expect to be appealed at the appropriate time. We are actively monitoring both the Target and Home Depot cases and will report on any developments.

    [1] In Eyeblaster, the insured, Eyeblaster, was an online marketing campaign management company. Eyeblaster, 613 F.3d at 799. A computer user sued Eyeblaster, alleging that Eyeblaster injured his computer, software, and data after he visited an Eyeblaster website. Id. Specifically, the plaintiff alleged, in pertinent part, that his computer was infected with a spyware program from Eyeblaster, which caused his computer to immediately freeze up and to operate so slowly that it essentially became inoperable. Id. at 799, 802. The plaintiff also alleged that he experienced “a hijacked browser” and “slowed computer performance, sometimes resulting in crashes.” Id. at 802. Additionally, he asserted that his computer had three years of client tax returns that he could not transfer because he believed the spyware files would also be transferred, and he therefore had to reconstruct those records on a new computer. Id. The plaintiff argued that his computer was no longer usable, and claimed among his losses “the cost of his existing computer.” Id.

    In coverage litigation between Eyeblaster and its insurers concerning whether the insurers breached their duties to defend and indemnify Eyeblaster in the underlying action, one of the issues was whether the allegations in the underlying action triggered coverage under a general liability policy that defined “property damage” to include “loss of use of tangible property that is not physically injured.” See id. at 802-03. The Eighth Circuit, applying Minnesota law, held that the allegations triggered coverage, reasoning that “[t]he plain meaning of tangible property include[d] computers, and the [underlying] complaint allege[d] repeatedly the ‘loss of use’ of [the plaintiff’s] computer.” Id. at 802.

    [2] No doubt cognizant of the Target court’s 2021 Decision, Home Depot appeared to craft the allegations in its complaint (which it filed two months after that decision was rendered) to address the standards articulated in the 2021 Decision. For instance, Home Depot alleged in its complaint that the ability to use the payment cards “had significant value” to the card issuers. Complaint ¶ 39, Home Depot, Inc. v. Steadfast Ins. Co., No. 1:21-cv-00242 (S.D. Ohio filed April 8, 2021). Home Depot further alleged that, as a result of the data breach, the card issuers “incurred costs including the cost to replace the compromised plastic payment cards as well as lost interest and transaction fees due to reduced card usage.” Id. ¶ 46. “Alternatively,” Home Depot asserted, “the cost to replace the compromised plastic payment cards approximates the value to the Issuing Banks of the loss of use of these cards.” Id.

    Id. at 994-95 (emphasis in original) (footnote omitted).

    The Authors

    Joshua Mooney

    Joshua MooneyKennedys

    Josh is a partner and head of the firm’s U.S. Cyber and Data Privacy practice. Based in Philadelphia, he advises clients on a wide array of data privacy and security issues, including breach response, compliance under such laws as CCPA, HIPAA, New York’s DFS Cyber Regulation and the SHIELD Act, and BIPA, and big data usage and licensing. Josh also advises on cross-border data transfers and implementation of privacy and security protocols. In addition, Josh represents insurers in media and cyber liability coverage matters.

    Judy Selby

    Judy SelbyKennedys

    Judith Selby is a partner in the firm’s New York office where she focuses on insurance coverage matters. Judy represents clients in all phases of large scale, complex first- and third-party insurance issues. She has extensive experience handling insurance coverage trials in the U.S. and international arbitrations in London. In addition to cyber security and privacy coverage, her experience includes matters involving underlying claims relating to environmental damage, toxic torts, TCPA, business interruption, bad faith, pharmaceutical products, and COVID-19 exposures. She also provides insurance due diligence advice in connection with mergers and acquisitions, run offs, and adverse development cover transactions.

    Judy is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    Tracey Kline

    Tracey KlineKennedys

    Tracey is an associate in the firm’s Philadelphia office. Her practice focuses primarily on insurance coverage litigation and cyber matters. Tracey represents and advises clients with respect to a variety of complex insurance coverage matters involving a variety of insurance policies, including general liability, directors and officers liability, cyber, and first-party property policies, among others. She has experience conducting depositions, leading arbitrations, and drafting pleadings and motions at all stages of litigation, and has worked on cases in courts throughout the United States.

    More about the firm.

  • Can we rely on shareholders to compel corporations to meaningfully act on ESG issues? | By Rebecca Boon and John Rizio-Hamilton | Bernstein Litowitz Berger & Grossmann

    Can we rely on shareholders to compel corporations to meaningfully act on ESG issues? | By Rebecca Boon and John Rizio-Hamilton | Bernstein Litowitz Berger & Grossmann

    The Authors

    Rebecca Boon

    Rebecca BoonPartner | Bernstein Litowitz Berger & Grossmann

    Rebecca Boon has been litigating securities fraud and shareholder rights actions for over a decade, recovering more than $1.5 billion for the firm’s institutional investor clients. Her work at the firm expands beyond litigation. Rebecca has advanced equality in the workplace by co-founding the Beyond #MeToo working group and leading landmark recoveries that have resulted in hundreds of millions of dollars back to investors and important social change among industries.

    Contact: rebecca.Boon@blbglaw.com

    John Rizio-Hamilton

    John Rizio-HamiltonPartner | Bernstein Litowitz Berger & Grossmann

    John Rizio-Hamilton is one of America’s top shareholder litigators. He works on the most complex and high-stakes securities class action cases, and has recovered billions of dollars on behalf of institutional investor clients.

    John led the trial team that recovered $240 million for investors in In re Signet Jewelers Limited Securities Litigation, a precedent-setting case that marks the first successful resolution of a securities fraud class action based on allegations of sexual harassment.

    Contact: johnr@blbglaw.com

    Can we rely on shareholders to compel corporations to meaningfully act on ESG issues?

    By Rebecca Boon and John Rizio-Hamilton

    This article was first published in the Responsible Investor, Aug., 10th, 2021. Posted with permission of the authors. Copyright 2021 by Rebecca Boon & John Rizio-Hamilton.  All rights reserved.

    There is an ongoing debate about the role that regulators should take regarding corporate obligations and accountability for ESG issues. Earlier this year, the Ontario Capital Markets Modernization Taskforce weighed in with its long-anticipated recommendation on diversity quotas for corporate boards. After receiving significant industry feedback, the Ontario Taskforce changed its initial recommendation from a requirement that public companies meet specific diversity targets, to allowing companies to set their own targets, report them, and develop a timeline for implementation. This ‘market-based’ framework for diversity would rely on investors to push corporations and hold them accountable.

    There was significant backlash when the Ontario Taskforce changed its initial recommendation. It was accused of not going far enough and caving to corporate pressure. However, it decided that allowing corporations to set their own quotas would avoid a ‘one size fits all’ approach, prevent corporations from simply complying with a minimum target, and limit instances of tokenism. The reporting requirement would force companies to implement material quotas and stand by them because they would be too afraid of investor reactions to do anything less than meaningful.

    In crafting governance reforms in some of the most significant derivative litigation in history, we spend considerable time thinking about how to enact meaningful and lasting social change at corporations. One key component is to get insider buy-in – because if the change is simply imposed from above, there could be internal resistance, a lack of commitment and a tendency to make only superficial progress. But the question is: can we rely on shareholders to compel corporations to meaningfully act on ESG issues? Recent history says yes. A market-based approach that incentivises good ESG practices could make a significant difference, when coupled with smart regulation.

    A recent study found that for every additional 8% of a company’s stock owned by the Big Three, the number of new women board members increased by 76%.

    For example, UK regulators just announced that London-listed companies should have at least 40% women and one non-white director on their boards. Similar to the Ontario Taskforce, the goals are not binding but if companies do not meet them, they must explain why. In the US, the Securities and Exchange Commission’s Advisory Panel also recently offered ESG and Diversity & Inclusion disclosure recommendations, designed to allow investors to understand what terms like ‘sustainable’ or ‘green’ actually mean.

    According to Chairman Gary Gensler, “investors should be able to drill down to see what’s under the hoods” at the companies and investment funds making these claims.

    The ‘Big Three’ asset management firms – BlackRock, Vanguard and State Street Global Advisors – recently made headlines when they supported Engine No.1, the Exxon activist investor that led a successful campaign to secure three board seats for its chosen candidates, in a bid to push Exxon to address long-term climate risk and move to clean energy, among other things. Exxon Director Ursula Burns acknowledged that the campaign’s success is part of a “tidal wave” of investor concerns on ESG issues. This victory would not have been possible without the support of three of the biggest investors in the US.

    In addition, big investors have committed to vote against firms that do not appoint more women directors to their boards. In January, State Street announced that it will now vote against the Chair of the Nominating & Governance Committee at companies in the S&P 500 and FTSE 100 that do not disclose the racial and ethnic composition of their boards; and in 2022, it will vote against them if they do not have at least one director from an underrepresented community.

    Similarly, Goldman Sachs will no longer take a company public without two diverse board members, one of whom must be a woman.

    The SEC has just approved a proposal by US marketplace Nasdaq for all its listed companies to disclose board-level diversity statistics and either meet the objective of 1 or 2 ‘diverse’ directors (depending on size) or explain why they have not. Some criticised the Ontario Taskforce – and others heralded it – for not taking Nasdaq’s “extreme position”.

    Are any of these initiatives enough? No. But investor pressure works. A recent study from the Kellogg School of Management at Northwestern University found that for every additional 8% of a company’s stock owned by the Big Three, the number of new women board members increased by 76%. Critically, the same study found that in response to investor pressure, women on boards get “power positions” on audit and nominating committees at even higher numbers than companies complying with mandatory quotas.

    Investors have also taken direct action by filing lawsuits alleging toxic workplace cultures of discrimination and retaliation against female executives, and racial and gender bias. And investors are no less active on environmental issues. For example, investors are currently prosecuting a securities fraud class action in Ohio against Energy Transfer, arising from the explosion of a natural gas pipeline that wreaked environmental havoc in Pennsylvania. These lawsuits are in early stages, but the pressure is on. Corporations have to address social issues because investors are demanding it.

    We have already seen what investor demands for accountability can do in US securities cases involving #MeToo issues and sexual harassment allegations. As the #MeToo movement went mainstream, we saw the first successful securities case addressing sexual harassment allegations – in a shareholder derivative lawsuit involving Fox News parent Twenty-First Century Fox. Investors were listening.

    Following a year of litigation, the lawsuit uncovered allegedly systemic problems at the network involving multiple senior executives, multiple types of discrimination and harassment, and a toxic workplace characterised by surveillance, retaliation and fear.

    Ultimately, as part of a $90m settlement, the plaintiff and the company unveiled a series of governance reforms designed to fix the broken sexual harassment culture at Fox News. The resulting Fox News Workplace Professionalism and Inclusion Council is majority-independent, but also has company participation, along with broad powers and a mandate to identify and solve the problems at the company. A critical component is investor accountability – the Council has the power to issue minority reports that Fox is mandated to post publicly for investors and the world to see. It also has a mandatory five-year term and if Fox determines to dissolve the Council, it must publicly state the reasons why. This approach set the stage for the recent high-profile settlement of a securities case against L Brands, which also settled for $90m. The firm committed to invest a further $45m over at least five years in a Diversity, Equity & Inclusion Council, and take other measures to protect employees from harassment and discrimination, requiring accountability when misconduct occurs.

    We also recently saw the first successful direct securities action certified as a class action involving allegations of sexual harassment against Signet Jewelers. When the market learned that hundreds of women had submitted declarations describing alleged sexual harassment reaching to the company’s highest levels, Signet was forced to halt trading to address them; and when trading resumed, the company’s stock price declined 13%. Again, investors were listening.  The Signet case settled for $240m in late 2020.

    It is too soon to know whether the newer cases will be successful, or whether the new regulations will have any teeth. But pressure from the Big Three and the corresponding dramatic increase in the number of women on corporate boards confirms that when investors demand diversity, companies respond. Investors have shown that they are willing and ready to compel corporations to act on important social issues. And recent securities cases involving #MeToo issues have demonstrated to the corporate world that investors can use their significant power to demand change and hold corporations accountable when they fail to act.

  • 7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation?

    By Jennifer M. Oliver

    The outcome of this case will have a dramatic impact on statutory damages.

    The Seventh Circuit U.S. Court of Appeals has certified a question to the Illinois Supreme Court over the accrual of claims under the Illinois Biometric Information Privacy Act (BIPA). The question, posed by the court in Cothron v. White Castle Systems, Inc., reads:

    “Do section 15(b) and 15(d) claims accrue each time a private entity scans a person’s biometric identifier and each time a private entity transmits such a scan to a third party, respectively, or only upon the first scan and first transmission?”

    The case was brought by an employee of the White Castle hamburger chain, which requires fingerprint scans for employees to access computer systems. The plaintiff charged that sharing her fingerprints with a third party vendor violated the law. Cothron v. White Castle Sys., No. 20-3202, 2021 U.S. App. LEXIS 37593 (7th Cir. Dec. 20, 2021).

    An accrual rule based on each collection, opponents to such a finding argue, would pose potentially existential damages — especially in the class action context — since BIPA provides for statutory damages of $1,000 or $5,000 per violation. Parties disagree on whether BIPA damages are mandatory or discretionary, however. Should the court determine that the first scan is the only scan that starts the statute of limitations clock ticking, opponents to that interpretation say,  anyone bringing a claim after five years would be out of luck, even if their private biometric data continued to be transmitted more than five years after the first occurrence.

    Preceding the federal court’s certification of this question by just five days, an Illinois appellate court ruled that, yes, claims under sections 15(a) and (b) accrue with each capture and use of a plaintiff’s biometric  information. Watson v. Legacy Healthcare Financial Services, LLC, et al., 2021 IL App (1st) 210279 No. 1-21-0279, Opinion filed Dec. 15, 2021.

    This is an important case to watch. Illinois was the first to implement such legislation, something several states have since emulated.

    Should the state Supreme Court come down in favor of an “all scans” interpretation, defendants may find themselves on the receiving end of devastating damages multipliers. Of course, the Illinois Supreme Court could determine that damage awards are at the discretion of a court, and are not mandatory under the law. Or it could rule that every scan or transmission restarts the statute of limitations clock, but that a claimant may only collect damages once for a series of transmissions of the same data, similar to how damages for defamation are not based on each publication of the same defaming remarks. Yet another possibility is that the court could determine that the clock starts to run when a claimant first learns of an alleged violation, which has precedent in litigation involving latent diseases caused by products, where individuals cannot know they were harmed until they developed a signature disease, i.e., one connected to a specific product.

    The ruling in this case is especially interesting as the COVID-19 pandemic has led to skyrocketing adoption of remote access tools that can collect biometric data for learning, court appearances, and work-from-home arrangements, and a corresponding uptick in BIPA lawsuits.

    Edited by Tom Hagy for MoginRubin LLP. Reposted with permission from the MoginRubin Blog. © 2022 MoginRubin LLP. 

    The Author

    Jennifer M. Oliver

    Jennifer M. OliverMoginRubin LLP

    Jennifer is a partner in the San Diego offices of MoginRubin LLP, where she focuses on antitrust, complex business, and investment litigation. Her experience includes active roles in several high-profile jury trials, serving as lead counsel in complex mediations, and arguing before courts at both the trial and appellate levels. Jennifer earned her B.S. (Business Administration), M.B.A., and J.D. degrees from the University at Buffalo, each with honors, where she also served as the Vice President of the undergraduate student body and was an editor of the Buffalo Law Review and Buffalo Intellectual Property Law Journal. Jennifer is also a certified information privacy professional.

    We are pleased to add that Jennifer is a member of the Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    More from Jennifer and her colleagues.

  • The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The Author

    Vincent J. Vitkowsky

    Vincent J. VitkowskyPartner | Gfeller Laurie LLP

    Vince Vitkowsky is a partner in Gfeller Laurie LLP, resident in New York. He focuses on cyber risks, liabilities, insurance, and litigation. Vince assists insurers and reinsurers in product development, and in all aspects of coverage evaluation and dispute resolution in many lines of business, including cyber, CGL, property, and professional liability. He also assists in complex claim evaluations, and if necessary, the defense of insureds in complex matters.

    Vince is also a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

    Contact: vvitkowsky@gllawgroup.com

    More from Vince and his colleagues.

    Melicent Thompson

    The New LMA War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies

    By Vincent J. Vitkowsky

    On November 25, 2021, the Lloyd’s Market Association released four War, Cyber War and Cyber Operation Exclusions (“Exclusions”). The LMA Cyber Business Panel spent well over two years drafting the Exclusions, which are models for use in standalone cyber insurance policies.  Lloyd’s has agreed that they meet the requirement that all insurance and reinsurance policies written at Lloyd’s must, except in very limited circumstances, contain a clause which excludes all losses caused by war.  The Exclusions address some difficult issues troubling the cyber insurance market for several years, following cyberattacks by nation-states (“states”) and threat actors associated with them.  They attempt to reduce uncertainty for both insurers and policyholders.

    Five interrelated issues.

    • The treatment of collateral damage (borrowing a concept from the traditional Law of Armed Conflict). Some state-sponsored attacks had significant effects on many entities that were not the intended targets.
    • How attribution is to be determined, and whether the insurers have an obligation to make payments while attribution is being determined.
    • The extent to which attacks by non-state actors associated with a state are excluded.
    • The treatment of state and state-sponsored cyberattacks directed at essential services, most notably those disrupting financial institutions and the financial markets infrastructure.
    • As in war exclusions in all lines of business, attempting to limit the aggregation risk.

    The Exclusions.

    The principal innovations in the Exclusions are to introduce the concept of “cyber operation” to insurance, to set processes for determining attribution, to partially clarify the scope of essential service, and to set a structure that de facto mitigates the aggregation risk.

    The key concepts and terms are as follows.

    War.  All four Exclusions contain an identical definition of War, largely based on traditional insurance policy language dating back to the Spanish Civil War.  It is “the use of physical force by a state against another state, or as part of a civil war, rebellion, revolution, insurrection, and/or military or usurped power or confiscation or nationalisation or requisition or destruction or damage to property by or under the order of any government or public or local authority, whether war be declared or not.”  (Emphasis is added, throughout this note.)  In the context of cyber war, this would include a cyberattack with kinetic effects.

    Cyber operation.  All four Exclusions also have an identical and innovative definition of cyber operation.  It is “the use of a computer system by or on behalf of a state to disrupt, deny, degrade, manipulate or destroy information in a computer system of or in another state.”

    Attribution.  All four Exclusions also contain an identical and innovative provision on “Attribution of a cyber operation to a state.”  It provides that the “primary but not exclusive factor” in attribution “shall be whether the government of the state (including its intelligence and security services) in which the computer system affected by the cyber operation is physically located attributes the cyber operation to another state or those acting on its behalf.”  Pending attribution by a state, “the insurer may rely upon an inference which is objectively reasonable as to attribution,” and no loss shall be paid.  If the affected state “takes an unreasonable length of time to, or does not, or declares it is unable to attribute the cyber operation to another state or those acting on its behalf,” the insurer, bearing the burden of proof, must “prove attribution by reference to such other evidence as is available.”

    Specified States.  This term appears in some of the Exclusions.  The specified states are China, France, Germany, Japan, Russia, UK or USA.

    The four exclusions treat cyber operations differently.

    The first Exclusion simply provides a blanket denial of coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation.”

    The other three Exclusions deny coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation that is carried out in the course of war.”

    The second Exclusion has additional provisions denying coverage for “retaliatory cyber operations between any specified states; and/or a cyber operation that has a major detrimental impact on the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity, or delivery of an essential service in that state; and/or the security or defense of a state.”  Although these are excluded, the policy may grant coverage for “any other cyber operations,” with a separately negotiated limit and aggregate.

    Significantly, essential service is defined as “a service that is essential for the maintenance or vital functions of a state including without limitation: financial institutions and associated financial market infrastructure, health services or utility services.”

    The third Exclusion is identical to the second, except it does not grant coverage for “any other cyber operations,” i.e., those not carried out in the course of war, retaliatory cyber operations between specified states, or those having a major detrimental impact.

    The fourth Exclusion is identical to the third, except it introduces the concept of “impacted state,” defined as “any state where a cyber operation has had a major detrimental impact on the functioning of that state [as defined in the third Exclusion], and/or security or defense of that state.”  Moreover, it limits the Exclusion for retaliatory cyber operations to those “leading to two or more specified states becoming impacted states.”  It also provides an exception to the Exclusion for loss from a cyber operation that has a major detrimental impact, so the Exclusion “shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”  That term is defined as “a computer system used by an insured or its third party service providers that is not physically located in an impacted state but is affected by a cyber operation.”

    The complete Exclusions can be found here.

    A serious attempt to reduce uncertainty.

    These Exclusions are not perfect.  Nothing is.  There is scope for dispute about the terms “an inference which is objectively reasonable,” “reference to such other evidence as is available,” “major detrimental impact,” and “essential service,” among others, as applied to specific facts.  But the Exclusions reflect a well-reasoned, serious attempt to reduce some of the uncertainties over the scope of coverage for state and state-sponsored attacks.

    Written Dec. 9, 2021 and posted with permission with minor formatting changes. Copyright 2021 by Vincent J. Vitkowsky.  All rights reserved.

  • IP Check-Up

  • Biotech Patent Wars: If at First You Don’t Succeed . . . University of California v. The Broad Institute

    Biotech Patent Wars: If at First You Don’t Succeed . . . University of California v. The Broad Institute

    Biotech Patent Wars: If at First You Don’t Succeed . . . University of California v. The Broad Institute

    Abstract

    This case discussed in this article is about two methods of editing DNA: one that has infinitely more lucrative applications because it can edit human DNA (plus all animals and plants), another that works in cell-free environments. Whether inventions are separate or part of the same innovation is an important factor in patent interference disputes; if there are two patentably distinct inventions there cannot be interference. One party in this case lost its argument that there was only one invention at issue, but returned with a second interference claim, arguing that it was the first inventor to constructively reduce to practice the animal and plant DNA editor. In this article, the author examines the nuances and intricacies of the patent process in the world of biology, and how patent lawyers must possess a level of knowledge in disciplines related to the inventions they seek to protect. This is necessary, for example, in understanding whether an invention is a significant improvement over prior innovations. The author also shares the importance of confidentiality especially when potentially groundbreaking (and lucrative) inventions are in development.

    Author

    Adrienne B. Naumann (adriennebnaumann@uchicago.edu) practices intellectual property law at the Law Office of Adrienne B. Naumann in Skokie, Illinois. She has held leadership positions relating to patents, science, and technology law with the Chicago Bar Association and the Converging Technologies Association. She currently serves as Secretary on the Board of the University of Chicago Women’s Alliance. Ms. Naumann has also written numerous articles on intellectual 56 Journal of Emerging Issues in Litigation property law and her book United States Federal Intellectual Property Developments includes discussion of decisions under the Defend Trade Secrets Act as well as those by the Supreme Court and was published by Pincus Professional Education.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…

  • To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses? | By Pamela Hans | Anderson Kill

    To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses? | By Pamela Hans | Anderson Kill

    To Pay or Not to Pay: Does Your Insurance Policy Cover Ransomware Losses?

    Abstract

    Ransomware attacks are a rapidly growing threat against organizations. Paying ransom demands is a risky proposition and may even lead to sanctions against the targeted company. Either way, the damage to a company’s operation and integrity can be cripplingly severe. Should a company suffer losses from cyber extortion, its insurance company will be one of the resources it turns to for relief. But with cyber
    coverage increasingly out of reach for some, policyholders may find coverage in more traditional coverages. In this article, the author evaluates the potential for coverage under several policy types, and underscores the importance of understanding policy language, the relevant law, and the potential regulatory ramifications of meeting ransom demands.

    Author

    Pamela D. Hans (phans@andersonkill.com) is the managing shareholder of Anderson Kill’s Philadelphia office. Her practice concentrates on insurance coverage exclusively on behalf of policyholders. Pam is also a member of the firm’s COVID Task Group and Cyber Recovery Group.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…

  • Digital Payments in Class Administration

    Digital Payments in Class Administration

    Now On Demand

    Epiq presents
    DIGITAL PAYMENTS
    Best Practices for Efficiency in Class Actions

    Recorded: Sept. 23, 2020
    75 minutes

    CLE credit: 1+
    Registration includes recording, materials, and answers to your questions.

    TAKE IT NOW!

    Epiq presents a CLE-eligible webinar
    Digital Payments
    Best Practices for Efficiency in Class Actions

    Recorded Live | Sept. 23, 2020

    produced by HB Litigation Conferences

    Modern life increasingly relies on digital solutions. Nothing has made that more apparent than the novel coronavirus pandemic. In terms of class action settlement payments, the impetus has never been greater to transition to the e-payment realm for security, convenience, cost-reduction, and improved fund disbursement.

    Class counsel and claims administrators have experimented for years with pre-paid debit cards, automated clearing house (ACH) deposits, and wire transfers, while others have tested judicial appetites for registered-user payment systems like PayPal and Venmo. However, digital payment schemes with multiple options — the primary of which is direct deposit — seem to be emerging as the favored solution.

    Though class action notice is increasingly being digitized, aided by the 2018 amendments to Federal Rule of Civil Procedure, particularly Rule 23(c)(2)(B), which permits notice by electronic means like emails and digital and social media, payment itself has lagged behind. Even with these challenges, electronic payment distribution is now a viable option. Courts are encouraging the shift to electronic payments, too. As the U.S. District Court for the Northern District of California specified in its November 2018 Procedural Guidance for Class Action Settlements, “[c]lass counsel should consider… distributions to class members via direct deposit.”

    As class actions lawyers and claims administrators consider digital payments, they must propose workable and achievable solutions, adhere to Rule 23, and minimize cy pres. Though widespread acceptance of this technology is still evolving, understanding the concept and embracing its benefits may lead to quicker adoption.

    Take our webinar as our panelists will address: 

    • Statistical trends in digital payment.
    • How to choose the right plan for your settlement structure.
    • How to choose the right plan for your class size & payment amounts.
    • Cost variables associated with different methods.
    • Vendor and program characteristics.
    • How to implement an effective program.
    • Avoiding excessive unclaimed funds.
    • Data security and privacy concerns.
    • Questions your judge will ask.

    Meet the Speakers

    Adam Zapala
    Partner
    Cotchett Pitre

    Adam Zapala is a partner in the San Francisco office of Cotchett Pitre, where he focuses on complex litigation, including antitrust, employment and civil rights, privacy and cybersecurity, qui tam/false claims, consumer protection, and class actions generally. He has served as lead counsel in some of the largest and most complex litigation matters in the country. He received his B.A. from Stanford University and his J.D. from the University of California Hastings College of Law. Read more about Adam and Cotchett Pitre.

    Paul G. Karlsgodt
    Partner
    BakerHostetler

    Paul is a partner in the Denver office of BakerHostetler, and serves as leader of the firm’s Privacy and Digital Risk Class Action and Litigation Team. He has significant experience representing companies in the insurance, healthcare, consumer, and education sectors, and is routinely named among the best lawyers in his field. Paul earned his J.D. from the University of Denver Sturm College of law and his B.S. from Purdue University. Read more about Paul and BakerHostetler. 

    Chris Ljungkull
    Director of Sales
    Digital Pay

    Chris brings Ljungkull 10+ years of experience building strategic partnerships across Financial Services, Enterprise SaaS, CPG, eCommerce, and Logistics. He draws heavily on his experience in fulfillment, print, and mail industries to help Legal Service customers develop solutions that do more with less. Read more about Chris and Digital Pay.

    Kim Stephens
    Member Partner
    Tousley Brain Stephens

    Kim Stephens is a Member Partner at Tousley Brain Stephens PLLC, where he focuses on commercial and class action litigation.  Prior to joining the firm he was a judicial extern clerk to Hon. Eugene A. Wright of the Ninth Circuit, and worked for the Seattle criminal defense firm of Allen &Hansen.  He has been appointed special attorney general for Washington State, as well as lead and co-lead counsel to manage numerous state, federal and multi-district class action matters. He received his B.A. from the University of Washington and his J.D. from the University of Washington School of Law. Read more about Kim and Tousley Brain Stephens.

    Judge Suzanne H. Segal (Ret.)
    Mediator
    Signature Resolution

    After 18 years as a U.S. Magistrate Judge with the Central District of California, including four years as the Chief Magistrate Judge, Hon. Suzanne H. Segal (Ret.) joined Signature Resolution as a mediator and arbitrator. During her tenure on the federal bench, Judge Segal presided over numerous trials, evidentiary hearings, motions and discovery conferences involving a variety of cases. Before that she served for 12 years as Assistant U.S. Attorney in the Civil Division of the Los Angeles U.S. Attorney’s Office. She received her J.D. from Claremont McKenna College and her J.D. from Cornell Law School. Read more about Judge Suzanne H. Legal.

    Moderator: Aideen Gaffney
    Vice President
    Epiq

    Aideen Gaffney draws upon over two decades of experience as an attorney and a skilled business development strategist to expand the scope and impact of our service offerings while providing effective solutions to our clients’ project needs.  Based on the West Coast, her particular experience centers upon class action administration, mass tort global litigation programs, and data breach response programs. Earlier in her career, Gaffney practiced law in San Francisco at Gordon & Rees LLP, and in Portland at Bullivant Houser Bailey PC,  handling complex insurance litigation and participating in two jury trials and two bench trials involving ‘bad faith’ litigation. She is a frequent speaker and writer on current topics affecting the legal administration industry, and has presented numerous CLE programs to clients. Aideen received her B.S. from Santa Clara University and her J.D. from Santa Clara University School of Law. Read more about Aideen and Epiq here.

  • Virtual Hearings: Changing Perceptions of Executive Testimony?

    Virtual Hearings: Changing Perceptions of Executive Testimony?

    Virtual Hearings: Changing Perceptions of Executive Testimony?

    Abstract
    Given the newly acceptable ease of securing testimony via webcam—necessitated by the pandemic—this article focuses on efforts to compel the appearance of corporate executives to testify in litigation. While there are many practical advantages to virtual testimony, the authors maintain that mere convenience cannot replace legal standards of relevance and undue burden when pursing the testimony of executives.

    Authors

    Sean J. Coughlin (scoughlin@bressler.com) is a Principal in the Financial Institutions group at Bressler, Amery & Ross, P.C., where he represents institutions and individuals in regulatory investigations and defense litigation. Before joining the firm, he was an Executive Director in the legal department at Morgan Stanley, a Managing Director at Citigroup/Smith Barney, and a Senior Assistant District Attorney in the Kings County District Attorney’s office.

    Jacqueline R. Meyers (jmeyers@bressler.com) is an associate at Bressler, Amery & Ross, P.C., whose practice focuses on securities defense litigation, arbitration, and regulatory investigations. She has specialized experience in litigation concerning arbitrability and enforcement of arbitration awards.

    About
    The Journal on Emerging Issues in Litigation is a co-production of HB, Fastcase, and Law Street Media. You can also hear the complementary (and complimentary) Emerging Litigation Podcast wherever podcasts appear. For questions, contact Tom Hagy, Editor in Chief, at Editor@LitigationConferences.com.

    Loading Viewer…