Tag: Compliance

  • Two Judges Find Florida Medical Marijuana Law Unconstitutional

    The Program is ‘Absolutely Broken’ — Now What?

    Edited by Tom Hagy

    Florida Circuit Judge Karen Gievers just held that the Florida medical marijuana law is unconstitutional. Reporting on the judge’s Trulieve decision for the Florida Politics news service, journalist Jim Rosica called it “a rebuke to lawmakers and the Rick Scott Administration” that was “stunning even for” Judge Gievers. “In the spirit of boxing legend Muhammad Ali, known for his pre-fight rhymes, Gievers opined that in Florida ‘the medical marijuana system was broken. Now, in the Constitution, the people have spoken.’”

    Rosica reported that while Gov. Scott is appealing the major marijuana decisions against the state Department of Health, the transition team of Republican Governor-elect Ron DeSantis, including Lt. Gov.-elect  Jeanette Nuñez, has suggested that he will not continue to defend the law in court.

    Rosica continued: “Gievers, who retires in April, said her decision striking down the law ‘includ(ed), but (is) not limited to, replacement of the voter-selected registry plan with an arbitrary, inconsistent licensing scheme … throttling access of qualifying patients to … safe use of medical marijuana from (providers that) the Department has a clear, undisputed duty to register.’ In fact, just passing the law was itself unconstitutional, Gievers suggested: ‘Voters made clear in 2016 that the Legislature was to have no role in implementing access to and availability of medical marijuana.’” Read Rosica’s full article.

    ‘It is incumbent on the Legislature to fix this’

    Today I spoke with attorney Jonathan Robbins, who is actively litigating the matter on behalf of Tampa-based Florigrown. Robbins, chair of the cannabis practice at Akerman LLP , pointed to a similar holding in the Florigrown case, commenting that, yes, “yet another judge has found that the statute implementing the amendment is unconstitutional because of the arbitrary cap on the number of dispensaries that would qualify for licensing.”

    “This further illustrates,” Robbins told me, “that the Florida medical marijuana program is absolutely broken and needs to be fixed. But rather than the courts repairing it piecemeal, the Legislature needs to get something done. It is incumbent on the Legislature to fix this.”

    In the Florigrown case, Leon County Circuit Judge Charles Dodson granted an injunction and ordered DOH to issue licenses. Once DOH appealed that triggered an automatic stay. “We went back to Judge Dodson to lift the stay because people need their meds,” Robbins said. “The judge lifted the stay, but the DOH appealed to the 1st District to reimpose the stay, which the court did.” Briefing is under way.

    “Our client wants to operate but is restricted because the statute unconstitutionally creates special classes of companies entitled to licensing. Not only does it arbitrarily cap the number of licenses, it requires that licensees must be fully vertically integrated, meaning companies must cultivate, process and sell medical marijuana. This is inconsistent with what the citizens voted for,” Robbins said. He said this prohibits a company from merely dispensing the product, for example, effectively and unfairly shutting out many businesses.

    “The Legislature was charged with providing safe and affordable medical marijuana to patients who need it. All of this was to be in place in 2017. Here we are in 2019 and we still don’t have it,” Robbins said.

    While there are 14 companies operating and people can get marijuana, many more potential competitors are blocked from operating.

    Clearly, implementation of the law, overwhelmingly approved by Florida voters, has been less than smooth and requires quite a bit more ironing out. The lack of competition hurts businesses and patients alike, critics say. In the meantime there is plenty of confusion for companies ready to provide medical marijuana services in Florida.


    Join our webinar on Jan. 25,  when attorneys in the thick of the issue –  Akerman LLP  partners Jonathan S. Robbins  and  Ari H. Gerstin  — will share background, insights and practical guidance.

    What we will cover:

    • Background: Federal vs. State Law Conflict
    • History of Medical Marijuana in Florida
    • The 2016 Amendment to the Florida Constitution
    • Implementation of the State Medical Marijuana Program
    • Litigation Over the Constitutionality of the Implementation
    • Practical Considerations When Operating in This Industry
    • Banking and Insurance Issues
    • Ethical Considerations for Attorneys

    What you will get:

    • Up-to-the-minute insights from attorneys active in the litigation.
    • Thorough course materials for later reference.
    • Real-time answers to your questions via our moderated chat.
    • The ability to send questions in advance.
    • Continuing legal education credit (CLE)
    • Access for your entire team with a feed into your conference room.
    • No scheduling risk: Suddenly can’t make it? We will send you the recording.

    Register by Jan. 18 and save $50. 

  • Kenneth Jones of Tanenbaum Keale on Law Firm Tech Development Capabilities

    Should Law Firms Should be Able to Develop Custom Technologies?

    Here is #10 of Jones’ Top-10 List.

    #10. Security. The cloud is great, and generally speaking, companies in this space operate systems in a highly professional manner. However, occasionally one encounters special business needs which call for extensive “above and beyond” levels of security. This could be times a firm is storing financial information, medical records, or other data they wish to absolutely, positively protect. In these situations — under the theory that “no one does things better than I do” —it’s nice to have the option to build super-secure systems with features such as encrypted data within database tables, and to manage the systems with a very small number of highly trusted professionals specifically known by the law firm. Read more of the article posted by Thomson Reuters.


    Kenneth Jones oversees various aspects of technology at Tanenbaum Keale LLP in the role of Chief Technologist. He leads efforts to support TK’s computing environment and infrastructure, one that features a strategy of professionally protecting and processing client data in the cloud with highly skilled and respected leading-edge business partners in the technology space. Ken also helps lead and support various TK programs in the areas of security, compliance, business continuity and firm administration. Learn more. 

  • Courtney Klein on Social Media & Security

    A Restructured Paradigm for Corporate Teamwork

    By Courtney Klein of Soteria Risk Consultants

    Social media has become an integral part of everyday life. It’s how some of us get our news, research our opinions, learn about local events, and connect with friends. For the modern western business, it is also immensely important for staying in touch with customers, advertising, and overall visibility. For this reason, many companies employ veritable armies of “Social Media Specialists” that do everything from designing graphics to writing tweets to replying to customer questions and complaints. Some companies interact with each other (such as the hilarious and long-standing Twitter Battle between Wendy’s and McDonald’s), and some use it as their primary form of communication.

    Customers, too, know that social media is a way to get in touch with a company – for good reasons and for bad – and while many companies are aware that they will and do receive threats on social media, very few of them have any kind of protocol in place for how to deal with them – and even fewer still encourage their social media teams to pass this information on to or (better yet) work together with their security team. This sort of blasé attitude to threats – either because “it’s not my job” or “they can’t be serious” – leads to real-world ramifications. Incidents such as the April 4th Youtube Shootings (which, we acknowledge, was a failure of many different departments, companies, and law enforcement operations) are a reminder of just how social media “banter” can turn into a real-world nightmare.

    Now, in defense of essentially any company guilty of this, Social Media is a new beast that even the best are still trying to get their arms wrapped around. Not only is social media relatively new to the game, but it’s dynamic and ever-changing. What was relevant yesterday no longer will be tomorrow. Updates add new features and kill our favorites, terms of service changes impact business, trends are fleeting but ever so important for a business to understand, customer service issues must be dealt with in a timely fashion. Take all of this and add security concerns on top of the social media specialist’s plate and you’re only going to run into failure. That’s why we at Soteria are such strong believers in having social media and security teams work together every step of the way.

    Folding security into the fray … will make a world of difference

    With few exceptions, social media teams plan their calendar very carefully. Words must be scripted, graphics must be designed, legal must be consulted; it’s not often that there’s a “last minute tweet that just has to go out right here right now.” With everything else that goes into these seemingly benign releases, folding security into the fray is, ultimately, a minor change, but one that will make a world of difference. Giving the security team insight into what will be posted provides a number of benefits.

    The security team will be able to assess what posts may aggravate any known or active threats. In general, security teams like to keep information about who wants to do harm to a company under relative secrecy so as to not unnecessarily alarm staff. As a dedicated intelligence analyst (working for a company with an incredible need to integrate a security function into social media) I personally witnessed a number of occasions where I’d read a post – a perfectly fine, professional post that a normal person wouldn’t bat an eye at – and thought “Oh heck, John Doe isn’t going to be happy about this one,” and upon further investigation discovered that, as suspected, Doe was all sorts of worked up over 260 characters and was heading down to the local office to cause a ruckus. With a little bit of notice, my team could have prepared our local staff for the event and given them adequate time to get ready rather than going into overdrive mode.

    It can help reduce the stress that the social media team feels during the normal course of their duties. Most people know that it’s possible to directly message a company’s customer service group via social media, but often times it’s actually the social media team that is in charge of screening and fielding these messages. On the occasion when a hateful comment or threat comes through, the social media specialist on the receiving end – who likely and rightly doesn’t have a lot of experience with such things – may react in any number of ways, from panic to disbelief. Whatever the response is, the likelihood that they’ll consider sending it to security for analysis without some previous instruction to do so is slim to none. At the very least, giving these staff this simple instruction can mitigate some of the basic issues. At best, it can begin to smooth the path for future growth into a more robust Social Media-Security partnership.

    Even security teams with dedicated social media analysts are still constrained by the limits of being human. While your company may have a well staffed social media threat team there is only so much a person can handle at any given time. In reality, though, it’s more likely that whoever is watching social media for threats is also juggling a multitude of different security tasks as well. By working or liaising with your organization’s social media team, you’ll have extra eyes on all the time. Many times, when a person is threatening an organization online they are not directing this information to the company’s inbox or direct messaging their team. Sometimes it’s as simple (and clear) as someone saying “I’m going to go shoot up XYZ Company tomorrow” without any connection to official accounts. Most social media groups monitor for any mention of their company’s name as part of a marketing strategy and to ensure only legitimate accounts are using the company branding. Clearly, this threat is not something that they should be dealing with – but it is certainly the job of corporate security. Even a tenuous partnership between the teams could result in threats like this being effectively handled.

    Just as your average security specialist wouldn’t know how to effectively announce a major company event on Twitter, neither will your typical social media analyst have the tools and skills necessary to investigate threats and persons.

    Security teams, by the nature of our work, are often able to access information that is not available to social media teams. Tools like Nexis and TLO aren’t given to groups without a legitimate use case, but these tools are often necessary in order to identify a threat actor. Depending on the severity of a threat, this information is often incredibly useful when providing information to the police. They are generally so overworked, underfunded, and understaffed, that having so much information handed to them, especially with an honest, well-documented case file that explains the methodology of your investigation, is a relief, and will help jumpstart an investigation.

    Social media teams know who is a regular issue. They know that John Doe sends rude comments to the Instagram inbox every time something is posted. They also know that they have a lot more to their job description than just reading mean comments. The regulars are remembered because of their consistency, but there are other threats who may not come up often enough to remember, and these may be the most dangerous. Likewise, if John Doe suddenly stops sending his vitriol, a social media specialist is likely to feel relief, whereas an intelligence analyst or other security professional might feel apprehension. What’s changed? Where did he go? Was he arrested? Did he find a new target? Or is he planning something that’s taking all of his time? For five years Jarrod Ramos threatened the staff at the Capital Gazette through social media, phone calls, emails, and any means he could find. It was normal for them, though the staff never ignored his threats. But in 2016 he went quiet. The small newspaper had neither the staff nor the resources to figure out why, and it would have been impossible for them to guess that in June of 2018 Ramos would be responsible for the vicious murder of five of their colleagues, but that’s exactly what happened. Likewise, in the reverse, should a case of minor, random harassment become more regular it’s possible an overworked social media specialist might be so harried they just wouldn’t notice. Paying attention to and noticing such trends is well within the wheelhouse of Corporate Security, but our ability to do this work is dependent on good, effective, two-way communication with the people on the receiving end (including and beyond social media).

    Finally, and very importantly, it is imperative for any security team to work with the people in their organization if for no other reason than to build relationships. Security is, if we’re being frank, a pain for everyone. While, yes, our goal is to keep people alive and well, completing this task also means we have to be an impediment. The same perimeter security measures that keep out a bad actor also slow down the company’s employee during a torrential downpour. The same check-in procedures that ensure only authorized persons and wanted guests get past the lobby also make the new guy late right before a big meeting when he’s left his badge at home. The same systems that only grant entry to someone with a need-to-access also ruins the forgetful employee’s day when she hears the door click shut behind her just as she notices she left her access card on her desk. Security costs money but doesn’t make it. Security gets in the way of art and gardens and aesthetics. Security is necessary, but it’s also difficult for everyone. By working amicably with as many people as possible throughout an organization and making sure they understand that you’re there to help them get their job done, you are building bridges to better relationships. You’re recruiting ambassadors that can help explain to others why piggybacking is such an issue. You’re educating additional bodies who can come to your team when they notice that outside door isn’t locking when it shuts. You’re expanding the pool of people who will quickly let you know when something doesn’t seem right, rather than just telling you after the fact. And, unlike many teams within many organizations, the social media team is often overwhelmingly comprised of young employees who will be more vocal about their support for you and may even come up with interesting, innovative ways to spread the security word that we may not think of.

    The long and short of it is that the world is always changing and evolving and in a field as vast and dynamic as security, we will always be met with new challenges. The most effective way to deal with such hurdles, at least on the front end, may very well be referring to the expertise of other professionals. By working with them instead of against them, we’ll be more able to understand the threats posed to our organizations and communities, and better ensure the continued safety of those who depend on us.

    Editor’s note: This article was re-published with the generous permission of the author. She is not the poor soul depicted in the photo above, however, who, for my money, is being a bit dramatic. –Tom Hagy


    COURTNEY KLEIN, PSP
    Courtney got her start in security while pursuing her master’s degree in criminal justice. Since then, she has served in a consulting capacity for educational institutions, major law firms, local and federal law enforcement, religious organizations, internationally celebrated entertainers, a number of non-profit organizations, a preeminent entertainment company, and state task forces grappling with innovative standards designs.

    Much of Courtney’s experience also rests in serving on dedicated corporate security teams, focused on everything from basic CPTED design and access control to international travel security and internal fraud investigations. Currently, Courtney proudly serves as the Senior Intelligence Analyst for a major international non-profit, where she uses her experience to identify and monitor individuals who pose a physical or intellectual threat to the organization’s employees, clients, assets and mission.

    Read more about Soteria Risk Consultants.

  • Francoise Gilbert on Colorado’s New Privacy Law: Are You Ready?


    Effective Sept. 1, 2018, Colorado will require all entities that process or store certain personal information of Colorado residents, regardless of whether the entity is located within or outside of Colorado, to have formal data security and data disposal programs. This is the result of the adoption of Bill 18-1128 “Concerning Strengthening Provisions for Consumer Data Privacy,”  signed into law at the end of May 2018, to amend and supplement existing law ….  Previously, the definition of “personal identifying information” under the Colorado law was limited to a resident’s first name or initial and last name in combination with the individual’s Social Security, driver’s license, or identification card number, or a credit or debit card or bank account number, combined with a password or access code. The new definition includes additional forms of identification, such as student, military, passport, and health insurance identification number, as well as other types of information, such as medical information or biometric data. It also includes username or e-email address in combination with a password or security question answers that would permit access to an online account …. Organizations that collect personal identifying information of Colorado residents and that do not yet have the written programs necessary to formalize their data protection practices urgently need to focus on compliance. — Francoise Gilbert, Greenberg Traurig


    Francoise Gilbert, a partner at Greenberg Traurig, is the author of the two volume treatise “Global Privacy and Security Law” (Wolters Kluwer Publishing), covering 68 countries. Her practice has focused on information privacy and security for more than 25 years. She advises clients on the entire spectrum of domestic and international privacy and cyber security issues legal issues, such as Internet of Things, smart cities, artificial intelligence, analytics, digital advertising and other cutting-edge developments that rely on the extensive use of personal data.

    She is one of the featured speakers at the Privacy+Security Forum which takes place Oct. 3-5, 2018, in Washington, DC.


  • McLoughlin on Artificial Intelligence in Banking

    “Capital adequacy requirements are not the only kind of regulation that AI is helping banks to meet. An even bigger area is monitoring of trading activities for misconduct and abuse. The Bank of England estimates that misconduct by traders has cost banks a global cumulative of $320 billion to date. For this very large reason, banks are aggressively deploying machine learning to monitor the behavior of their traders and detect unusual behavior.”

    Read Michael McLoughlin’s post on LinkedIn.

    Michael McLoughlin is Global Digital Transformation Partner & Advocate with Microsoft.

  • Joshua Gold on Cyber Crime and Insurance

    With the amount of trickery going into thefts and embezzlements these days, crime insurance companies too often use the many steps involved in a fraudulent scheme to argue that losses are indirect and otherwise uncovered.

    The recent decisions of the Second Circuit and Sixth Circuit on the “direct loss” argument and the scope of computer fraud coverage are important victories for policyholders generally, making clear that where the predominant step in the chain is some type of covered fraudulent misconduct involving a computer, a court is not going to entertain a direct loss defense to excuse the insurance company from paying.

    As such, policyholders should be familiar with their crime coverage and promptly notify all potentially implicated lines of insurance coverage when a cybercriminal is afoot. — Joshua Gold, Anderson Kill 

    Read Josh’s complete article. 

    Joshua Gold is Chair of Anderson Kill’s Cyber Insurance Recovery Practice and was amicus counsel for United Policyholders in the Medidata Solutions, Inc. v. Federal Insurance Company case before the Second Circuit.

  • Halligan, Weyland on Cybersecurity, Trade Secret Asset Management and the Defend Trade Secret Act of 2016

    “Cybersecurity protection against outsider theft has largely succeeded, if competently crafted business methods are strictly followed. The more intractable problem of insider theft is now the major concern, and traditional cybersecurity methods are unavailing. The ever-higher digital barriers placed around the corporation and its sensitive data are no defense against data theft by people allowed inside the digital walls in the normal course of business.”

    Read their complete post on LinkedIn.

    R. Mark Halligan is a Partner and Trial Lawyer at FisherBroyles, LLP. Mr. Halligan has taught Advanced Trade Secrets Law in the John Marshall Law School LLM program for 24 years.

    Richard F. Weyand is the President of the Trade Secret Office, Inc. www.thetso.com

    See R. Mark Halligan and Richard F. Weyand Trade Secret Asset Management 2018: A Guide to Information and Asset Management Including RICO and Blockchainavailable on Amazon. https://www.amazon.com/dp/0997070986

  • Judy Selby on Improving Cyber and Privacy Board Reporting


    “While general awareness of cyber risks among corporate boards is increasing, even the most motivated and knowledgeable directors cannot effectively fulfill their duties without receiving appropriate data about the organization’s risk profile. Unfortunately, however, there appears to be a disconnect between management and boards when it comes to cyber risk reporting . . .  In order for directors to effectively discharge their duty of active, informed, and engaged oversight, the information they receive must be relevant, understandable, reliable, and objective.”

    Judy Selby, JD

    Judy Selby Consulting

    Read the full article and Judy’s tips for improving board reporting. 


    Judy Selby of Judy Selby Consulting

  • BitSight Releases eBook on Use of A.I. & Big Data in Continuous Cyber Risk Monitoring

    “With every reported data breach or cyberattack, the cyber risk landscape gets a little more complex. Cyber criminals create new attack vectors, cybersecurity professionals develop new controls to protect their systems, the criminals get to work circumventing the controls, and so on.The result of this back and forth is that cyber risk professionals have a huge variety of risk factors to worry about. In response, risk managers and security specialists need to develop extremely complex cybersecurity programs to make sure all of their bases are covered.

    “With so many cybersecurity risks to consider, it’s inevitable that some will receive less attention than they deserve. Unfortunately, these overlooked risk factors could play a role in your next cyberattack, and if your financial services firm isn’t prepared, that could be extremely costly.” Read more. 


    We’re looking forward to seeing the BitSight team in Bermuda Dec. 6-7, 2018, at the International Cyber Risk Management Conference.

  • CBD: Confusing Regulations May Soon Find at Least Some Clarity — But Proceed With Caution

    By Tom Hagy
    July 16, 2018

    Proponents say the medical benefits are many and magnificent.

    You can feel better without feeling stoned.  While that will be disappointing to some, people enduring a variety of ailments may find relief, proponents and some studies say. From inflammation to pain to anxiety. From arthritis to alcoholism to diabetes. From psychoses to seizures. Cannabidiol may cure what ails you. And in many cases the science is there, even studies sponsored by the government, say the folks at Project CBD.

    While the regulations vary from state to state, and the definitions can be confusing, clarity is coming for at least the hemp-derived variety of products – as opposed to its sister cannabis plant, marijuana – with the likely passage of Senate Majority Leader Mitch McConnell’s Hemp Farm Bill. The measure is also noteworthy because it has drawn rare bipartisan support.

    CBD can be found in just about anything, from skin care products to pain medications to anti-seizure drugs—even beer. Companies, including large retailers, like Target, have tried to sell or are selling products containing CBD online or across state lines.

    While small compared to the marijuana industry, CBD is on a serious growth trajectory.

    “Spending on legal cannabis worldwide is expected to hit $57 billion by 2027,” according to an article at Forbes.com, written by Thomas Pellechia, citing the research of Arcview Market Research and BDS Analytics. “The largest group of cannabis buyers will be in North America, going from $9.2 billion in 2017 to $47.3 billion a decade later.”

    In a release from MarketNewsUpdates.com, “A new report by cannabis/legal marijuana market analysts firm Hemp Business Journal projects that the U.S. CBD market will grow to $2.1 billion by 2020, an astronomical jump in value compared to last year’s CBD market of $202 million. As the market continues to swell, it is expected the space will reach the billion-dollar status as product diversification and global demand drive revenue levels. One of the major drivers for the CBD market is the growing list of health benefits of CBD oil.”

    Proceed with Caution

    In his post for the Canna Law Blog – a must-follow for any attorney or company interested in the legal aspects of cannabis – attorney Daniel Shortt of Harris Bricken tells businesses they must know the rules.

    “It is no secret that CBD is having a moment right now. Unlike its cousin tetrahydrocannabinol (THC), which is another cannabinoid found in the cannabis plant, CBD is not psychoactive. It has been growing in popularity for years for medical and other applications, but has really taken off lately.”

    Shortt offered five questions businesses must ask before diving in. Here is a truncated version of that list:

    1. What is the source of the CBD? Is it coming from a licensed source? Is it derived from industrial hemp?

    2. What do the lab tests say? You must be sure the products do not contain THC (or more than .3%).

    3. Where is the CBD going to be sold? State laws vary and if you violate them you could face criminal sanctions. Read more here: https://www.cannalawblog.com/industrial-hemp-dont-forget-about-state-law/

    4. What claims are you making about CBD? Are you claiming the product treats disease? You don’t want to make health claims or allow others to make them via testimonials on your website, for example.

    5. Has the law changed? You must keep up with federal and state laws.

    Read more.

    Writing for the online news service CBD Origin, Aaron Cadena echoes Shortt’s first point, saying legality of CBD has to do with its origin. Does it come from hemp or does it come from marijuana?  “[B]oth are members of the cannabis family,” Cadena writes, “so they do share a lot of characteristics. There is, however, a crucial difference between the two–the amount of psychoactive THC each plant produces …. In other words, marijuana can get you really high, while hemp has such a low amount of THC, that it would be impossible to get high off it.”

    “Botanically speaking, there’s not a shred of difference between the two plants: Both are cannabis Sativa under the Linnean definition*,” writes Chris Roberts for Leafly.com. “Legally speaking, the two do indeed have a binary difference: One is federally legal, and the other is not.” (* Named for Swedish botanist Carolus Linnaeus or his modern system of botany and zoology. Who knew.)

    It is because of these psychoactive differences that CBD taken from hemp – with no such effects – is legal almost everywhere in the U.S., while the legality of marijuana-derived products is a mixed bag.

    Cadena’s article includes a survey of the various state laws regulating both forms of CBD. Read the full article to see which 46 states have legalized CBD with a prescription, the 17 that have specific legislation for THC levels and which conditions it’s to be used for, and the 29 states that have fully legalized medical use of both forms of CBD.

    ProCon.org offered another survey, current as of May 8, 2018, providing summaries of the law in each state. The organization commented that “we do not consider passing a CBD-specific law to be the equivalent of making medical marijuana legal because these laws do not recognize the use of marijuana plant for medical purposes.” (For their survey of medical marijuana states, go here: https://medicalmarijuana.procon.org/view.resource.php?resourceID=000881.)

    The Hoosiers Take the Lead

    Right now, Indiana has “the most robust regulations of hemp-derived CBD products.”  In his post for the Canna Law Blog, Shortt wrote that, as of March 21, 2018, the state allows the distribution and retail sale of “low-THC hemp extract,” defined as a product “(1) derived from Cannabis sativa L. that meets the definition of industrial hemp; (2) that contains not more than 0.3% delta-9-THC (including precursors); and (3) that contains no other controlled substances.”

    This is interesting, Shortt says, because it shows that Indiana is officially aware of CBD products and decided to allow their sale. “The catch is that those sales are restricted to a certain class of CBD products, and they are heavily regulated,” he says.

    The list of labeling requirements will be a challenge for companies distributing across state lines. Some will not be selling in Indiana and others will comply, Shortt predicts.

    “Indiana is unique in the sense that it allows CBD and also regulates its sale so robustly. Let’s hope for more positive cannabis developments in the Hoosier State,” Shortt writes.

    Shortly after the Ninth Circuit’s CBD ruling, on May 22, 2018, the DEA issued an internal directive regarding products derived from cannabis but are not marijuana. They referenced an earlier Ninth Circuit ruling from 2004 which enjoined the DEA from enforcing certain THC regulations  (See Hemp Industries Ass’n v. DEA, 357 F.3d 1012 (9th Cir. 2004)).”

    Responding to various inquires, the DEA issued the following to agency personnel:  

    “Products and materials that are made from the cannabis plant and which fall outside the CSA definition of marijuana (such as sterilized seeds, oil or cake made from the seeds, and mature stalks) are not controlled under the CSA. Such products may accordingly be sold and otherwise distributed throughout the United States without restriction under the CSA or its implementing regulations. The mere presence of cannabinoids is not itself dispositive as to whether a substance is within the scope of the CSA; the dispositive question is whether the substance falls within the CSA definition of marijuana.”

    “[A]ny product that the U.S. Customs and Border Protection determines to be made from the cannabis plant but which falls outside the CSA definition of marijuana may be imported into the United States without restriction under the Controlled Substances Import and Export Act. The same considerations apply to exports of such products from the United States, provided further that it is lawful to import such products under the laws of the country of destination.”

    The DEA explained, though, that its statements regarding the drug code for marijuana extract and regarding resin remain the same. “[T]he drug code for marijuana extract extends no further than the CSA does, and it thus does not apply to materials outside the CSA definition of marijuana.”

    Mona Zhang, writing for Forbes.com, said there are CBD producers who source their hemp from cultivators that operate under the Farm Bill. “But given how widespread these products are, it’s unlikely that all of them were sourced from research hemp. And state laws on CBD and hemp vary widely. Colorado, which legalized adult-use marijuana in 2012, has a robust industrial hemp program and is home to the first U.S.-bred certified hemp seed. But in Massachusetts, where you can now grow marijuana at home, it’s still a crime to grow hemp without a state license …”

    If only someone would do something at the federal level.

    Clarity on the Horizon?

    Harris Bricken attorney Shortt notes that U.S. Senate Majority Leader Mitch McConnell – in an attempt to settle the CBD matter – introduced a bill to legalize hemp on the federal level, an initiative that is getting rare bipartisan support: the Hemp Farming Act of 2018 or S.2667.

    Shortt said that, while subject to change, hemp would be defined as: “the plant Cannabis sativa L. and any part of that plant, including the seeds thereof and all derivatives, extracts, cannabinoids, isomers, acids, salts, and salts of isomers, whether growing or not, with a delta-0 [THC] concentration of not more than 0.3 percent on a dry weight basis.”

    “This proposed definition is significant,” Shortt writes, “because it specifically includes the term ‘extracts,’ thereby undermining the DEA’s much-maligned ‘marihuana extract’ rule, which broadly defines any extract from the cannabis plant as ‘marijuana’ and not hemp. The proposed ‘hemp’ definition also includes ‘cannabinoids’ contained in hemp which could add much needed legal certainty to the already booming CBD market. The Act would also explicitly remove hemp from the Controlled Substances Act’s definition of marijuana.”

    Jason Amatucci, co-founder of CBD producer Anavii Market, said the Hemp Farming Act has bi-partisan support and has a “decent chance of actually getting signed into law this year.”

    “It’s time the federal government changes the way it looks at hemp,” Sen. McConnell said when he announced the measure, adding, it will “modernize federal law in this area and empower American farmers to explore this promising new market.”

    “The future of the legal American hemp derived CBD oil industry looks very bright even though some folks are still confused about the legality nuances. This new law will even further solidify the legality and legitimacy of the hemp derived CBD industry,” Amatucci says.

    Sidebar: Marihuana?

    For the etymology nerds out there, like me, Washington Post writer Christopher Ingraham wrote a piece on the DEA’s insistence on spelling marijuana with an “h” instead of a “j” – something this one-time Spanish student found jarring. I imagine actual Spanish-speaking people would say something like, “Yeah, we have bigger things to worry about,” except in Spanish. Ingraham uncovers some surprising theories but little hope for change. Read it now.

    It’s ironic, I suppose, that the only letter the government is avoiding is the letter “j,” as in “jay” for joint.  Maybe that’s the real reason for their spelling.