Tag: Cybersecurity

  • Ohio Supreme Court Ruling Sends Important Reminder: Long-Standing, Fundamental Principles of Insurance Policy Construction and Law Are Applicable to Cyber Claims

    Ohio Supreme Court Ruling Sends Important Reminder: Long-Standing, Fundamental Principles of Insurance Policy Construction and Law Are Applicable to Cyber Claims

    The Authors

    Judy Selby

    Judy SelbyKennedys

    Judy Selby (judy.selby@kennedyslaw.com) is a Partner at Kennedys (New York) where she focuses her practice primarily on insurance coverage matters with a concentration in coverage for exposures arising out of emerging technology, digital, and compliance risks.

    Tracey Kline

    Tracey KlineKennedys

    Tracey M.Kline (tracey.kline@kennedyslaw.com) is an Associate at Kennedys (Philadelphia) where she focuses her practice primarily on insurance coverage litigation and cyber matters.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Ohio Supreme Court Ruling Sends Important Reminder:

    Long-Standing, Fundamental Principles of Insurance Policy Construction and Law Are Applicable to Cyber Claims

    Abstract: On December 27, 2022, the Ohio Supreme Court unanimously ruled that a business owner’s property insurance policy issued by Owners Insurance Co. to EMOI Services, LLC did not afford coverage for losses sustained in a ransomware attack because computer software is “entirely intangible” and “cannot experience ‘direct physical loss or physical damage.’” EMOI Servs., LLC. v. Owners Ins. Co., 2022-Ohio-4649 (Ohio 2022). In doing so, the court reversed an attention-getting split decision by the lower appellate court. This article takes an in-depth look at the case and discusses its significant implications.

    The Ohio Supreme Court’s decision was based on its commonsense conclusions that software (as intangible property) cannot suffer physical damage, and that coverage for restoration of information under the Electronic Equipment Endorsement could not be triggered absent the threshold requirement of “direct physical loss or damage” to the media on which the information was stored. Although claims involving cyber events may be relatively new, this decision is an important reminder that long-standing, fundamental principles of insurance policy construction and law are applicable to cyber claims.

    Download the article now!

  • Digital Health Care Companies, Beware: Federal Agencies Are Tracking Your Use of Online Tracking Technologies

    Digital Health Care Companies, Beware: Federal Agencies Are Tracking Your Use of Online Tracking Technologies

    The Authors

    Patricia Markus

    Patricia MarkusNelson Mullins

    Patricia A. Markus (trish.markus@nelsonmullins.com) represents health care providers and health technology companies across the country on wide-ranging regulatory compliance, reimbursement, licensure, and operational matters, with a special focus on issues surrounding health information privacy, security, and technology.

    Shane Duer

    Shane DuerNelson Mullins

    Shane Duer (shane.duer@nelsonmullins.com) focuses his practice on healthcare regulatory and corporate matters, with an emphasis on data privacy, cyber security, and information management concerns within and beyond the health care industry.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Digital Health Care Companies, Beware 

    Federal Agencies Are Tracking Your Use of Online Tracking Technologies.

    Abstract: Health care industry stakeholders have regularly used online tracking technologies to help improve patient experience. However, growing scrutiny by the Office for Civil Rights, which enforces the Health Insurance Portability and Accountability Act of 1996 (HIPAA), requires covered entities and business associates to proceed cautiously in their use of such technologies. In addition, recent enforcement actions by the Federal Trade Commission make clear that a wide range of digital health companies, whether or not regulated by HIPAA, must tread carefully when collecting and disclosing personal information related to health, especially where consumers’ location data is to be used for a company’s advertising purposes, as they may be held accountable for failing to maintain the privacy and security of individuals’ protected and individually identifiable health information.

    The increasing number of lawsuits and news articles regarding use of these technologies demonstrates that third-party technology tracking vendors who receive PHI often are not operating under Business Associate Agreements (BAAs). The vendors in most instances disavow any need to collect PHI and accordingly instruct users to avoid sending PHI or other personally identifiable information. Under HIPAA, covered entities and business associates generally may not disclose PHI to third parties for health care operations purposes, unless such disclosure is to a business associate pursuant to a BAA, or the disclosure is made pursuant to an individual’s HIPAA-compliant authorization.

    Not only does sharing PHI through third-party tracking technologies without individuals’ authorizations violate HIPAA, but the FTC has asserted in two recent enforcement actions that the collection and sharing of individuals’ IIHI through these technologies without individuals’ “affirmative express consent” constitutes unfair and deceptive trade practices.

    Download the article now!

  • Pixel Litigation the Latest Craze in Privacy Law

    Pixel Litigation the Latest Craze in Privacy Law

    Meta, Google Face Barrage of Pixel Lawsuits in Digital Privacy War

    Photo by Amal S on Unsplash

    META PLATFORMS INC. AND GOOGLE  are currently facing nearly 70 lawsuits involving large companies and some hospital systems or individual health care providers utilizing Pixel tracking tools embedded on their websites and applications. Sensitive private data such as financial information gathered from filing tax returns online or patient healthcare information stored on patient portals is being actively tracked and sent to Meta and Google for both analytical and advertising purposes.

    Tracking pixels are a 1×1 Pixel graphic that serves as a snippet of code used for tracking user behavior, site conversions, web traffic, and other metrics generated from a site’s server. In 2018, Meta told Congress that there were more than 2 million Pixels across the web, which at the time, was one of the largest data-harvesting operations most internet users had ever seen. Meta makes their Pixel code freely available to anyone and any business – thus the amount of Pixel tracking has exponentially grown since Meta testified before Congress. The analytical information that companies gleam from Pixel tracking is paying off and is featured on everything from fast food companies such as Chick-Fil-A, media companies like iHeart Radio, and even tax-filing websites such as Tax Slayer or TaxAct.

    Pixel Tax Data

    On November 22, 2022, theverge.com co-published a report with The Markup, revealing that Pixel tracking tools located on several renown American tax-filing websites were sending individual tax filers’ contact and financial information to Meta and Google. From January to July 2022, The Markup tracked websites’ use of the Pixel as part of the Pixel Hunt in partnership with Mozilla Rally. Participants of the Pixel Hunt installed a browser extension that provided The Markup with a copy of all data shared with Meta through the Pixel. H&R Block, Tax Slayer, and Tax Act utilized Pixels on their websites and applications that sent financial data to Meta according to the data-driven report.

    TaxAct’s Pixel sent some of their users’ tax data to Facebook, including their filing status, adjusted gross income, and the amount of their tax return, if applicable. TaxAct says it has about “three million consumer and professional users”. The Pixel Hunt also revealed that TaxAct’s embedded Pixels were sending data to Google Analytics as well. The Pixel Hunt also revealed that Tax Slayer, H&R Block, and Intuit were also sending specific types of data to Meta and Google.

    The audit on Tax Slayer revealed that their embedded Pixel was gathering and sharing information such as phone numbers, the name of the user filling out the tax forms, and names of any dependent added to the return.

    An audit on Intuit, America’s largest online filing software, revealed that the company did employ a Pixel but did not send financial information to Meta, but instead sent usernames and information about the last time a device signed into the Intuit account. Whereas the audit into H&R Block revealed that information was being gathered and shared on filers’ health savings account usage as well as dependents’ college tuition grants and expenses.

    Tax filing is estimated to be an $11 billion industry in the United States with nearly 150 million individual returns filed electronically in 2021 according to this article. Free tax filing preparation and filing options do exist, but it’s limited to people making $73,000 or less and tends to be difficult to use.

    Utilizing the Pixel during their tracking, The Markup found that the Internal Revenue Service directs taxpayers attempting to file for free to some of these tax filing websites with embedded Pixels. TaxAct and Tax Slayer are part of an agreement known as the Free File Alliance. TurboTax (“Intuit”) and H&R Block had participated in this program in the past. Several days after this report was published, a class action lawsuit was filed against Meta in the Northern District of California, John Doe and Jane Doe v. Meta Platforms Inc., et al., 3:22-cv-07557.

    Pixel Healthcare and Patient Data

    Pixels are also utilized by some healthcare systems and individual medical providers in the United States. In another lawsuit regarding Pixel litigation against Meta in the Northern District of California, Jane Doe v. Meta Platforms Inc., et al., 3:22-cv-04293-AGT, the plaintiff alleges that at least 664 hospital systems or medical provider websites have sent data to Meta via its Pixel tracking tools. The plaintiff argues that this tracking of her private health information is in violation of the Health Insurance Portability and Accountability Act (“HIPAA”)

    HIPAA protects the privacy of individually identifiable health information by allowing only certain uses and disclosures of health data, such as for research purposes – but only if this data can’t be linked back to a particular patient. Currently under HIPAA, releasing data that is not properly de-identified could be considered a breach of HIPAA.

    Recently on January 30, 2023, a class-action lawsuit was filed in the Tenth Judicial District of Louisiana regarding a local health care provider, Willis-Knighton Medical Center using Pixel tracking tools to send sensitive patient health data to Meta. The plaintiff in Jacqueline Horton, individually and on behalf of others similarly situated v. Willis-Knighton Medical Center, 93767-B, brought action against Willis-Knighton Medical Center for ‘exposing highly sensitive personal information to third parties without their knowledge or consent.’ The Louisiana case differs from California’s because California is one of the handful of states that has passed a statute related to video privacy and consumer protection.

    In Jane Doe v. Meta Platforms Inc., the website allegedly shared information related to scheduling appointments with a doctor and reviewing test results. The California suit is seeking damages paid to consumers under the Video Privacy Protection Act (“VPPA”) 18 U.S.C. § 2710. This case was also brought under the California Confidentiality of Medical Information Act, that allows for damages of $1,000.00 per violation. In addition, the California court could potentially force hospital systems named in the suit to clearly disclose that their website uses Pixels to share data with Meta. The Plaintiff is also asking the judge to order that Meta delete sensitive health information that could be used to generate specific ads. This case will highlight misunderstandings of how HIPAA protects health information that’s in the hands of health care providers, insurers or any other entity currently subject to existing HIPAA provisions.

    Origins of Pixel Litigation Lawsuits

    The VPPA regulates the disclosure of information about consumers’ consumption of video content and imposes prescriptive requirements to obtain consumers’ consent to such disclosure(s). The law was originally enacted in 1988, a year after a journalist published Supreme Court Justice Robert H. Bork’s video rental history during his nominee process in 1987. The rental history contained no salacious details however and Congress quickly acted to pass the VPPA. The act reads:

    The VPPA prohibits a person or business that rents, sells, or delivers prerecorded “video cassette tapes or similar audio visual materials” from “knowingly disclos[ing], to any person, personally identifiable information concerning any consumer of such provider . . . .,” absent informed, written consent as defined by the VPPA. 18 U.S.C. § 2710(a)(3). If liability is found, the VPPA allows consumers to seek the following remedies – (1) statutory damages in the amount of $2,500 per violation, (2) punitive damages, and (3) recovery of attorneys’ fees. 18 U.S.C. § 2710(c).

    The VPPA was originally enacted to address the concept of a video tape service provider (“VTSP”). This was associated with traditional video rental stories and was rarely invoked as of lately. As online video services became more prevalent, the VPPA began to create legal barriers to major businesses and marketing opportunities for them. Prior to Congress amending the VPPA in 2013, the law created a strange legal paradigm: An organization’s business model involving the provisions to consumers, either on a standalone basis or as part of its broader online platform of online video content (such as a social media company), makes the organization qualify as a VTSP.

    Congress amended the VPPA in 2013 to provide that disclosure of consumer data to third parties is not wrongful if the consumer elects to give ‘informed, written consent in a form that is distinct and separate from any form setting forth other legal or financial obligations of the consumer at the time the disclosure is sought, or in advance for set period of up to two years.

    Under the amendment, the VPPA does provide a number exceptions that permit information being disclosed to third parties. Remarkably, one of those exceptions allows the sharing of information about the user ‘to any person if the disclosure is solely of the names and addresses of consumers and if: (i) the VTSP has provided the consumer with the opportunity, in a clear and conspicuous manner, to prohibit such disclosure; and (ii) the disclosure does not identify the title, description, or subject matter of any videos or other audio-visual material; however, the subject matter of such materials may be disclosed if the disclosure is for the exclusive use of marketing goods and services directly to the consumer.’

    These exceptions allow the VPPA to permit the disclosure of the name and address of the user together with the identify of the VTSP and subject matter of the video content so long as the intended purpose is for direct marketing. The VPPA has since been challenged in several distinguishable cases decided in 2015 primarily on the grounds of violation of privacy.

    Recent Developments in Pixel Litigation

    The VPPA has come under consumer and legal scrutiny in recent years. Several important legal rulings have largely curtailed individual and collective efforts to declare violations under the VPPA. In Ellis v. Cartoon Network Inc., 803 F.3d 1251 (11th Cir. 2015), it was opinioned that, Consumers who use free mobile applications do not quality as ‘subscribers’ under the VPPA. The Ninth Circuit Court also opinioned two cases in 2015 regarding exceptions to the VPPA.

    In Rodriguez v. Sony Computer Entm’t Am., LLC, 801 F.3d 1049 (9th Cir. 2015), an intra-corporate disclosure of personal information does not violate the VPPA. Then it was also decided by the 9th Circuit Court in another 2015 opinion Mollett v. Netflix Inc. 795 F.3d 1062 (9th Cir. 2015) that VTSPs cannot be held liable under the VPPA for circumstances where subscribers’ personal information was displayed on devices, such as televisions, that could potentially be viewed by third parties. This Court said that ‘viewing of such devices was beyond the companies’ control.’

    These recent rulings narrowed the scope of the VPPA and helped provide definitions for the outdated video-store era law. Civil lawsuits across the nation related to Pixel litigation continues to barrage the integrity of the VPPA.

    IHEARTMEDIA, Inc. is facing a lawsuit for allegations of violations of the VPPA in the Middle District of Florida Gloria Talley, individually and on behalf of herself and all others similarly situated v. IHEARTMEDIA, Inc., 8:32-cv-00215. Similarly the popular chicken chain, Chick-Fil-A is facing a similar class action lawsuit in the Northern District of California in Keith Carroll, individually and on behalf of all others similarly situated v. Chick-Fil-A, Inc., 3:23-cv-00314.

    As lawsuits continue to mount against Meta and Google, the integrity of the VPPA is thrown into question. It is likely that one of the pending actions across the nation will eventually land the law itself into further judicial review, or if Congress acts, could create an entirely new blanket law altogether to help address the rapid interference and sharing of consumer data.

    By Hunter Schmitz

    By Hunter SchmitzGuest Writer

    Hunter Schmitz is a freelance writer and paralegal with Focus on Property Law and Civil Litigation.

  • Autonomous Vehicles: The New Technology Driving the Litigation Conversation

    Autonomous Vehicles: The New Technology Driving the Litigation Conversation

    The Authors

    Cort Malone

    Cort MaloneAnderson Kill

    Cort T. Malone (cmalone@andersonkill.com) is a shareholder in the New York and Stamford offices of Anderson Kill and practices in the Insurance Recovery and the Corporate and Commercial Litigation Departments. An experienced litigator, he focuses on insurance coverage litigation and dispute resolution, with an emphasis on commercial general liability insurance, directors and officers insurance, employment
    practices liability insurance, advertising injury insurance, and property insurance issues.

    John M. Leonard

    John M. LeonardAnderson Kill

    John M. Leonard (jleonard@andersonkill.com) is a shareholder in Anderson Kill’s New York, New York, office, where he handles a full spectrum of insurance coverage matters, such as business interruption losses, D&O and E&O, commercial general liability, environmental liability.

    Joshua A. Zelen

    Joshua A. ZelenAnderson Kill

    Joshua A. Zelen (jzelen@andersonkill.com) is a law clerk pending admission in Anderson Kill’s New York office. He focuses his practice on insurance recovery.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Autonomous Vehicles: The New Technology Driving the Litigation Conversation

    “The AEV Act requires a policyholder’s insurance company to cover third-party damage caused by a self-driving automated vehicle. A policy may not exclude such damages, except for damages suffered as a direct result of software alterations made without the policyholder’s knowledge, or failure to install safety-critical software updates.”

    Abstract: So far, Congress has not been able to pass regulations governing the emergence of self-driving or autonomous vehicles. Twenty-one states and the United Kingdom are leading the way. As more of these vehicles take to the highway implications will emerge for the insurance industry. Auto
    insurance policies will have to determine how to insure against losses caused by nonhuman operators, commercial general liability policies will be affected when technology developers and car makers are sued for bodily injury and property damage arising from malfunctioning technology, and cyber policies could be implicated in the event of hacks or data breaches. The authors review these subjects and share their insights into what autonomous vehicle producers should consider when it comes to mitigating their risk.

    Download the article now!

    Read, listen, explore more content on the subject!

    Podcast: Biometric Privacy Litigation and Coverage Disputes with John Leonard and Cort Malone

    JEIL: Litigation After Biometric Privacy Law Violations: Policyholder Victories and Their Implications. Co-authors Cort Malone and Abigal Damsky 

    JEIL: Biometric Privacy Laws: Companies Will Need Insurance as Protection From New and Expanding Liability. Co-authors Cort Malone and Jade Sobh

    Podcast: Autonomous Vehicles: The New Technology Driving the Litigation Conversation with John Leonard and Cort Malone

    Tags

    Emerging Litigation & Risk Compliance Litigation & appeals Cybersecurity Data Privacy Artificial Intelligence (AI) Insurance Companies Risk Management Corporate & Securities Insurance Claims Recovery Regulations Data Breach Toxic Torts Antitrust Legal Tech Product Liability Settlements Trial Personal Injury Privacy Healthcare Per- and Polyfluoroalkyl Substances (PFAS) Data Analytics Arbitration Constitutional Law Climate Change Cannabis Labor Law Insurance Fraud Liability Claims COVID Alternative Dispute Resolution (ADR) Mediation Diversity Equity Inclusion (DEI) Claims management Professional Liability Legal Research & Writing Business Interruption Law Practice Management Trial Skills Property and Casualty Drug Laws Copyright Law Catastrophic Loss

  • Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Authors

    Kathryn Rattigan

    Kathryn RattiganRobinson+Cole

    With deep experience in the law and regulation of unmanned aerial vehicles, Kathryn practices in the Providence, R.I., offices of Robinson+Cole. She is a member of the firm’s groups that focus on business litigation, data privacy and security, and drone compliance. Kathryn is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    Blair Robinson

    Blair RobinsonLaw Student

    Blair Robinson is a cybersecurity intern at Robinson+Cole. She will graduate in 2023 with a J.D. from the Roger Williams University School of Law to complement her Masters of Science degree in Cybersecurity also from Roger Williams University.

    Get CLE

    Drone Litigation

    Flying Cameras: Gaps in Drone Regulation and How Courts Can Fill Them … at Least for Now

    Drones have rapidly transformed dozens of industries since hitting the commercial market. International aid groups use medical drones to deliver life-saving medications and vaccines to remote areas. Agricultural drones have revolutionized how farmers tend their fields. Film and television producers embrace drones for their ability to capture once prohibitively expensive or outright impossible camera shots. Hobbyists love the technology for a variety of recreational purposes. 

    However, as drones have become increasingly commonplace, lawmakers and policymakers have struggled with effectively regulating this emerging domain.

    In addition, no federal law, state law, or industry best practice adequately addresses the unique privacy and cybersecurity risks drone operations pose. Until federal regulation catches up with the technology, lawyers could move courts to mitigate the issue by arguing for strict liability for drone operators and manufacturers.

    Although drones may seem like traditional aircraft, they actually pose unique privacy concerns. Drone systems rely on real-time and simultaneous data exchanges between the operator, GPS positioning, cloud-based processing and telemetry, and the drone itself. Each facet in such a complex system presents a new opportunity for attackers. Besides the vulnerability of data traveling between the drone and its control systems, drones are also physically vulnerable. Researchers at the University of Texas Austin successfully hijacked a drone using commercially available equipment. The researchers used a local GPS transmitter to send the drone false GPS coordinates, causing it to fly off its preprogrammed path. The criminal and terror applications are evident – terror groups could use this technique to hijack drones and cause them to fly into buildings, thieves could intercept consumer drone deliveries, and militant groups could capture and ransom critical medical deliveries. Before they can enjoy widespread use, drone operators (and manufacturers) must adequately secure their devices.

    Courts and policymakers have sought to address the obvious and highly publicized issues associated with drone flight, such as irresponsible pilots harassing pedestrians and disrupting airports, while neglecting the novel threat that drones pose to personal privacy.

    Unlike crewed aircraft, drones often use remote cameras and other sensory inputs to guide their operators. In this way, drones are more akin to flying smartphones than traditional crewed aircraft. Additionally, drones can collect visual and other sensory data at a great distance and without alerting the data subject. As a result, individuals whose privacy is infringed will likely never know (or identify) the drone operator, regardless of whether they see the offending device. In addition, the growing ubiquity of drones, such as deliveries to consumers, may further obfuscate a voyeur’s identity.  Was that drone looking through my window or just delivering the neighbor’s package? 

    Surprisingly, the FAA doesn’t have authority to regulate data flow from drones; the Administration considers it outside of its congressional mandate. And while other federal statutes address specific drone data flows, no complete regulatory scheme exists. State-level regulations are similarly lacking. While some states regulate drone use by law enforcement and many smaller localities have piecemeal ordinances regulating drone activity, no state law entirely protects the privacy and security of data flowing to and from civilian drones. While the states have theoretical regulatory authority over drones, they are ultimately ill-suited to address the industry and, in most cases, lack the resources to meet the task. Finally …

    … common tort law falls short here as well. It may address intentional voyeurs, but there’s no common law “negligent invasion of privacy” cause of action to cover accidental disclosures. 

    The courts are the last body that may step in to regulate drone operations in the absence of effective bureaucratic, legislative, or industrial authority. While Supreme Court Associate Justice Samuel A. Alito, Jr. has indicated that legislative action is needed to handle changing technology effectively, the courts have a history of reining in maverick industries. For example, Judge Benjamin N. Cardozo, who would go on to serve on the Supreme Court, famously developed the concept of strict products liability to address unsafe practices in the burgeoning automotive sector. That industry shared many critical elements with today’s drone industry: the emergence of a disruptive new technology promised to both revolutionize human productivity while upsetting traditional notions of public safety. In case before Judge Cardoza, a manufacturer purchased a defective wheel from a third-party supplier. The injured driver had no legal recourse: the automotive manufacturer pointed the finger at their supplier, and the supplier owed no contractual duty to the consumer. Judge Cardozo came up with the legal innovation that underpins modern products liability law: he determined that a manufacturer that enters a product into the stream of commerce must reasonably foresee injury to the ultimate consumer. 

    Faced with another disruptive technology, courts today will likely develop case law that: 1) redefines the duty of care for drone operators for the audio or visual data that they collect in-flight which infringe on the seclusion of others, and 2) imposes strict liability on drone manufacturers for compromises in drone cybersecurity. Under this proposed liability theory, the law would expect drone operators to consider the entire data chain generated by their activities. A bird watcher using a drone to film into a lofty nest, for example, would be held responsible for the content of their video stream if it accidentally spied someone through their bedroom window. This would encourage drone operators to take reasonable care with their flying cameras. While accidental peeks into a neighbor’s home may not be highly offensive, drone-mounted cameras are risky enough to justify a heightened standard of care. This system would also draw attention to the current regulatory gaps and provide a stopgap measure until Congress broadens the FAA’s mandate or enables another regulatory authority. Similarly …

    … this type of strict liability scheme would compel drone manufacturers to consider the possible collateral damage caused by their products.

    For example, the manufacturer of a drone hijacked in a terror plot would be held responsible for failing to protect their product from hackers. Manufacturers are already liable for foreseeable injuries caused by their products, but this proposed modification to products liability law would broaden the definition of reasonably foreseeable injury to include widely publicized exploits such as UT Austin’s GPS spoofing. Again, this burden isn’t unreasonable – manufacturers are in the best position to implement some of the necessary protections and safeguards for widespread drone use. 

    Drones will inevitably become integral to our society; however, without proper regulation the novel legal issues that they raise will stunt the industry’s growth and dampen the many benefits it promises. 

    Congress will need to give the final word on drone use, but the courts – urged by persuasive attorneys – may offer stopgaps to foster sustainable growth in the meantime. Such a model would likely force every participant in the drone data chain to enter privity with the ultimate consumer and give injured individuals a temporary recovery mechanism until Congress empowers the FAA or another agency to regulate drone activity adequately. 

    Download the PDF

  • Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Editor

    Tom Hagy

    Tom HagyHB Founder

    Tom is HB’s Founder and Managing Director. His career in litigation content spans four decades during which he was editor, managing editor, and finally publisher at Mealey’s Litigation Reports. After Mealey’s was acquired by LexisNexis Tom became a vice president involved in creating new content and services at the legal research and services giant. He has always overseen or directly created articles, blogs, conferences, webinars, data collections, and now podcasts — all on litigation. Tom founded HB in 2008, and four years later he founded Custom Legal Content, a boutique content creation shop serving boutique and specialized legal practices and litigation services. In addition to his work at HB and CLC, Tom is Editor in Chief of the Journal on Emerging Issues in Litigation, and host of the Emerging Litigation Podcast. For years he was a leader in an international specialized publishing association, frequently speaking and writing about publishing, and is now active in an open community of content and event producers called Renewd. Sometime during the last millennium Tom proudly graduated with a B.A. in Communications from Bethany College in West Virginia.

    The Journal on Emerging Issues in Litigation

    Emerging Litigation Podcast

    Emerging Litigation PodcastProduced by HB Litigation and Law Street Media

    Interviews with leading attorneys and other subject matter experts on new twists in the law and how the law is responding to new twists in the world.

    Despite Relative Inactivity on the Virtual Front in Ukraine, Russia’s Global Cyber-Attacks are Coming

    Cyber WarSince his cyber-war capabilities seem to have worked well for him, why isn’t Vladimir Putin launching more cyber-attacks against Ukraine and its allies? Reports suggest he didn’t think he’d need them, plus they take time to execute. Other reports suggest he is trying to get some cyber damage on the scoreboard. Maybe the actual disruption to Ukraine from tanks and bombs, even though the Ukrainians aren’t giving him the satisfaction of a clean and easy parade-style invasion, could be redundant.

    But many experts did think that much of Russia’s invasion – and Ukraine’s defense –  would take place in cyberspace. Some of that is happening, but there are reasons Russia hasn’t launched large-scale attacks. Kyle Fendorf and Jessie Miller wrote for the Council on Foreign Relations on March 24, 2022, that reasons include “the higher efficacy of kinetic attacks and difficulties in planning and executing massive cyberattacks in a short timeline.” Ukraine, meanwhile, has taken a novel approach: “attempting to mobilize international sentiment” to “create an army of cybersecurity professionals to attack military and critical infrastructure targets in Russia.” Fendorf and Miller list several Russian efforts, including DDoS attacks on Ukrainian banking and defense websites. And hackers like Anonymous have “declared war” on Russia. The group has taken credit for several successes, including interrupting television broadcasts with clips from the war and leaking thousands of confidential government files.

    According to Reuters, the pro-Ukraine cyber assaults are hitting their targets, saying Russian government websites are facing “unprecedented cyber-attacks.” Relying on the Russian news agency TASS, websites for the Aeroflot airline, the Sberbank bank, and the Kremlin itself have experienced “outages and temporary access.” The Kremlin, facing greater isolation from global financial systems and supply chains, is taking steps to bolster its IT sector, such as tax breaks and easier access to lending, Reuters reports.

    President Biden has warned U.S. organizations to “lock their digital doors” for fear of a Russian cyber-attack, adding that “evolving intelligence” indicates attacks are coming.

    As quoted in Politico, Jen Easterly, director of the Cybersecurity and Infrastructure Security Agency, told 13,000 participants on a recent call that we should “assume that disruptive cyber activity will occur: and “we should consider every sector vulnerable.”

    On March 24, the Department of Justice Department unsealed two indictments charging four Russian nationals working for the Kremlin with “attempting, supporting and conducting” cyber-attacks on the global energy sector between 2012 and 2018. The targets were hundreds of organizations in 135 countries, including the U.S. Nuclear Regulatory Commission and a Kansas power plant.  “The potential of cyberattacks to disrupt, if not paralyze, the delivery of critical energy services to hospitals, homes, businesses and other locations essential to sustaining our communities is a reality in today’s world,” said U.S. Attorney Duston Slinkard for the District of Kansas.

    BBC News reported that Ukraine “has remained relatively untroubled” by Russia’s cyber weapons, but “experts now fear that Russia may go on a cyber-offensive against Ukraine’s allies. The BBC News article reminds us of the three types of Russian cyber-attacks “the West fears most,” detailing Russia’s takedown of Ukraine’s electricity grid in 2015 in an attack called BlackEnergy; the “most costly” attack in cyber history called NotPetya, a worldwide computer killer that caused $10 billion in damage, followed by WannaCry which scrambled data in 150 countries; and the one executed by a Russian criminal organization called DarkSide which caused a state of emergency in the U.S. in May 2021 when their ransomware strike shut down the vital Colonial Pipeline.

    The insurance industry, which is always impacted by any global calamity, man-made or natural, is also worried about a parallel cyberwar. Ben Dyson, a reporter for S&P Global Market Intelligence, wrote on March 28, 2022, that while the industry’s direct exposures to Russian and Ukrainian cyberrisk “is likely small,” the larger risk is the “potential for spillover” to networks in other countries. “The insurance industry can look back to at least one precedent for a cyberattack related to the wider conflict between Ukraine and Russia having global implications: the 2017 NotPetya malware attack. NotPetya spread to thousands of companies globally, handing the insurance industry a $3 billion claims bill and its first taste of a cyber catastrophe. NotPetya occurred in relative peacetime and was largely covered by cyber-specific policies.”

    Attorney Vincent Vitkowsky, in an article for the Insurance Journal posted on March 25, 2022, agreed that Russia may try to turn up the stress of other countries if the war drags on. “After the conflict ends, however it ends, Russia will be the object of extreme resentment and suspicion. It may launch cyberattacks to increase disorder, believing that an environment of disorder would be serve its position as a significant power.” Vitkowsky said new cyber weapons will only make the threats worse, such as “zero click vulnerabilities” which don’t even need the help of an unsuspecting employee to click on a link, and the so-called HermeticWizard, “a new strain of software designed to autonomously spread another strain, HermeticWipe, to computers in a network.”  He writes that carriers face exposure to losses from direct or indirect cyberattacks against their insureds globally, but says the so-called War Exclusions “may mitigate that exposure,” then goes on to explain how in his article. [Vince is a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.]

    FT technology correspondent Hannah Murphy asked Kevin Mandia, the founder of cyber security company Mandiant (which was just acquired by Google for $5.4 billion) about the current state of the cyber conflict between nations.

    The current state feels like, Mandia said, “braced for impact.”

    The cybersecurity expert noted operation “Shields Up” by the Cybersecurity and Infrastructure Security Agency, plus all of the private and public players in the West and NATO, “all watching the cyber domain waiting for what happens.” He sees the war in Ukraine as “an opportunity for us to figure out what is the new normal because we’re used to conflict being air, land, sea, maybe a little bit of space . . . but a cyber domain is part of that conflict, too.” He went on to say, however, he’s “not sure everyone’s got fully fleshed-out strategies for how to do warfare in the cyber domain, and when to bring it to bear.”

    He predicted that if Russia wants to retaliate against sanctions and embargoes, a cyber-attack is “probably the first tool that might be chosen.”

    What do you think?

  • Cybersecurity and Data Privacy Year in Review 2021

    Cybersecurity and Data Privacy Year in Review 2021

    The Authors

    The authors are all attorneys with the Kennedys law firm (kennedyslaw.com). Joshua Mooney (joshua.mooney@kennedyslaw) and Judy Selby (judy.selby@kennedyslaw.com) are partners. Tracey Kline (tracey.kline@kennedyslaw.com) and Alexis Childs (alexis.childs@kennedyslaw.com) are associates. Bridget Mead, associate, and Javier Vijil, senior associate, also contributed to this article.

    Judy Selby is also a member of the Editorial Board of Advisors for the Journal on Emerging Issues in Litigation.

    The Journal on Emerging Issues in Litigation

    Cybersecurity and Data Privacy 2021 in Review

    By Joshua Mooney, Judy Selby, Tracey Kline, and Alexis Childs

    Abstract:

    As the world emerged from lockdown, it should come as no surprise that cybersecurity and data privacy remained dominant topics in the media and legal industry. Some of 2021 was much like 2020—ransomware attacks continued to fill the headlines, and in the aggregate, constituted significant loss paid under cyber insurance policies. OFAC reminded victim companies and incident response firms (and cyber carriers) that it remains unlawful to pay ransom payments to designated organizations. Comprehensive federal legislation addressing cyber defenses and notification requirements never materialized. Yet in 2021, we saw new and significant developments. U.S. law continued its drift toward comprehensive privacy regulation with two new significant pieces of privacy legislation and California’s enforcement of the California Consumer Privacy Act. In the absence of federal legislation, federal agencies either stepped up enforcement actions or signaled that they intend to do so within their realms of governance. Litigation under the Illinois Biometric Information Privacy Act continued its surge while the Illinois high courts rendered two impactful decisions and a circuit court punted to Illinois’s highest court. This review provides a brief synopsis of many events and developments that made the authors’ list.  

    Perhaps one of the most significant developments in U.S. privacy law for 2021 was the enactment of comprehensive data privacy laws in Virginia and Colorado. Both pieces of legislation, which go into effect in 2023, adopt frameworks resembling those in the EU General Data Protection Regulation 2016/679 (GDPR) and the California Consumer Privacy Act (CCPA). Both laws also grant consumers significant rights with respect to their personal data, but neither contains a private right of action. 

    Get the article now!

  • The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The Author

    Vincent J. Vitkowsky

    Vincent J. VitkowskyPartner | Gfeller Laurie LLP

    Vince Vitkowsky is a partner in Gfeller Laurie LLP, resident in New York. He focuses on cyber risks, liabilities, insurance, and litigation. Vince assists insurers and reinsurers in product development, and in all aspects of coverage evaluation and dispute resolution in many lines of business, including cyber, CGL, property, and professional liability. He also assists in complex claim evaluations, and if necessary, the defense of insureds in complex matters.

    Vince is also a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

    Contact: vvitkowsky@gllawgroup.com

    More from Vince and his colleagues.

    Melicent Thompson

    The New LMA War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies

    By Vincent J. Vitkowsky

    On November 25, 2021, the Lloyd’s Market Association released four War, Cyber War and Cyber Operation Exclusions (“Exclusions”). The LMA Cyber Business Panel spent well over two years drafting the Exclusions, which are models for use in standalone cyber insurance policies.  Lloyd’s has agreed that they meet the requirement that all insurance and reinsurance policies written at Lloyd’s must, except in very limited circumstances, contain a clause which excludes all losses caused by war.  The Exclusions address some difficult issues troubling the cyber insurance market for several years, following cyberattacks by nation-states (“states”) and threat actors associated with them.  They attempt to reduce uncertainty for both insurers and policyholders.

    Five interrelated issues.

    • The treatment of collateral damage (borrowing a concept from the traditional Law of Armed Conflict). Some state-sponsored attacks had significant effects on many entities that were not the intended targets.
    • How attribution is to be determined, and whether the insurers have an obligation to make payments while attribution is being determined.
    • The extent to which attacks by non-state actors associated with a state are excluded.
    • The treatment of state and state-sponsored cyberattacks directed at essential services, most notably those disrupting financial institutions and the financial markets infrastructure.
    • As in war exclusions in all lines of business, attempting to limit the aggregation risk.

    The Exclusions.

    The principal innovations in the Exclusions are to introduce the concept of “cyber operation” to insurance, to set processes for determining attribution, to partially clarify the scope of essential service, and to set a structure that de facto mitigates the aggregation risk.

    The key concepts and terms are as follows.

    War.  All four Exclusions contain an identical definition of War, largely based on traditional insurance policy language dating back to the Spanish Civil War.  It is “the use of physical force by a state against another state, or as part of a civil war, rebellion, revolution, insurrection, and/or military or usurped power or confiscation or nationalisation or requisition or destruction or damage to property by or under the order of any government or public or local authority, whether war be declared or not.”  (Emphasis is added, throughout this note.)  In the context of cyber war, this would include a cyberattack with kinetic effects.

    Cyber operation.  All four Exclusions also have an identical and innovative definition of cyber operation.  It is “the use of a computer system by or on behalf of a state to disrupt, deny, degrade, manipulate or destroy information in a computer system of or in another state.”

    Attribution.  All four Exclusions also contain an identical and innovative provision on “Attribution of a cyber operation to a state.”  It provides that the “primary but not exclusive factor” in attribution “shall be whether the government of the state (including its intelligence and security services) in which the computer system affected by the cyber operation is physically located attributes the cyber operation to another state or those acting on its behalf.”  Pending attribution by a state, “the insurer may rely upon an inference which is objectively reasonable as to attribution,” and no loss shall be paid.  If the affected state “takes an unreasonable length of time to, or does not, or declares it is unable to attribute the cyber operation to another state or those acting on its behalf,” the insurer, bearing the burden of proof, must “prove attribution by reference to such other evidence as is available.”

    Specified States.  This term appears in some of the Exclusions.  The specified states are China, France, Germany, Japan, Russia, UK or USA.

    The four exclusions treat cyber operations differently.

    The first Exclusion simply provides a blanket denial of coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation.”

    The other three Exclusions deny coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation that is carried out in the course of war.”

    The second Exclusion has additional provisions denying coverage for “retaliatory cyber operations between any specified states; and/or a cyber operation that has a major detrimental impact on the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity, or delivery of an essential service in that state; and/or the security or defense of a state.”  Although these are excluded, the policy may grant coverage for “any other cyber operations,” with a separately negotiated limit and aggregate.

    Significantly, essential service is defined as “a service that is essential for the maintenance or vital functions of a state including without limitation: financial institutions and associated financial market infrastructure, health services or utility services.”

    The third Exclusion is identical to the second, except it does not grant coverage for “any other cyber operations,” i.e., those not carried out in the course of war, retaliatory cyber operations between specified states, or those having a major detrimental impact.

    The fourth Exclusion is identical to the third, except it introduces the concept of “impacted state,” defined as “any state where a cyber operation has had a major detrimental impact on the functioning of that state [as defined in the third Exclusion], and/or security or defense of that state.”  Moreover, it limits the Exclusion for retaliatory cyber operations to those “leading to two or more specified states becoming impacted states.”  It also provides an exception to the Exclusion for loss from a cyber operation that has a major detrimental impact, so the Exclusion “shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”  That term is defined as “a computer system used by an insured or its third party service providers that is not physically located in an impacted state but is affected by a cyber operation.”

    The complete Exclusions can be found here.

    A serious attempt to reduce uncertainty.

    These Exclusions are not perfect.  Nothing is.  There is scope for dispute about the terms “an inference which is objectively reasonable,” “reference to such other evidence as is available,” “major detrimental impact,” and “essential service,” among others, as applied to specific facts.  But the Exclusions reflect a well-reasoned, serious attempt to reduce some of the uncertainties over the scope of coverage for state and state-sponsored attacks.

    Written Dec. 9, 2021 and posted with permission with minor formatting changes. Copyright 2021 by Vincent J. Vitkowsky.  All rights reserved.

  • Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege IOT Kathryn Rattigan

    Joining me to discuss this emerging area of law is Kathryn M. Rattigan, a member of the Business Litigation Group, the Data Privacy + Cybersecurity Team, and the Drone Compliance Team in the Rhode Island office of Robinson Cole.

    Kathryn provides clients guidance regarding privacy and data protection in connection with mobile devices, data storage technologies, mobile apps, and location-based services. She  assists with the development of website and mobile app privacy policies and  terms and conditions. Kathryn is a frequent contributor to the excellent Robinson Cole Data Privacy + Cybersecurity Insider blog.  She holds a J.D. from the Roger Williams University School of Law and a B.A. (magna cum laude) from Stonehill College.

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the Fastcase legal research family, which includes Full Court Press, Law Street Media, Docket Alarm and, most recently, Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful and informative Kathryn is, please drop me a note at Editor@LitigationConferences.com.

    Finally, yes, “skeevy” is a word. And the law is not settled as to whether Shiloh has privacy rights.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    There are now billions and billions of interconnected devices in the world with more coming online every day. Smart cars. Smart cities. Smart agriculture and so much more. Even our pets are connected.

    And you have to look no further than the Colonial Pipeline ransomware attack to see the real-world consequences of what criminals can pull off by connecting with things large and small.

    Worried about your privacy? Well. There is plenty to worry about.

    Fortunately we also have a lot of people fighting back on the technical, security, law enforcement, and legal fronts.

  • The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar
    Now on-demand at the West LegalEdcenter
    THE COMMERCIAL DRONE INDUSTRY
    Privacy, Security, Threats, and Mitigation of Risk

    Drones have become an increasingly valuable tool for businesses of all types and sizes.

    Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical.

    Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle.

    Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology.

    Topics:

    • Defining drones.
    • Current and future applications.
    • FAA Modernization and Reform Act of 2012.
    • FAA Part 107 Regulations and waivers.
    • Resources, e.g. the FAA Drone Zone and LAANC Portal.
    • Penalties for violations.
    • Privacy implications.
    • Drones as weapons.
    • Vulnerability to cyber attacks.

    Take it now!

    What you get:

    1+ CLE credits (subject to bar rules).

    Insights from an experienced professional who specializes in this area of the law.

    The complete PowerPoint presentation.

    Continued access to the complete recording for later use.

    Answers to your questions.

    Fee:

    No additional charge to subscribers to the West LegalEdcenter.

    Non-subscribers may take the course for $170.

    Meet the Speaker

    Kathryn Rattigan
    Robinson & Cole LLP

    Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and vendor management. She represents clients across all industries, such as manufacturing, insurance, health care, education, energy, and construction.

    Kathryn helps clients comply with all state and federal regulations related to data privacy and cybersecurity. She is also a member of the firm’s Drone Compliance Team. As such, she advises clients on all legal issues surrounding the use of commercial drones, including navigation of Federal Aviation Administration regulations, commercial registration requirements, and Part 107 waivers.

    She is committed to doing pro bono work and being involved in the community. Her recent efforts include assisting Inner Explorer, a non-profit which works to help students focus and succeed through mindfulness practice in the classroom, and College Visions, which helps low-income students pursue a college education.

    She writes for two of the firm’s blogs, Data Privacy + Security Insider and Health Law Diagnosis.

    More about Kathryn

    Also, listen to my interview with Kathryn for the the Emerging Litigation Podcast!

    –Tom Hagy