Published by the Public Risk Management Association
www.primacentral.org
MAY/JUNE 2013
A University Risk Manager Becomes PRIMA's President:
MEET
BETTY COULTER
Director of Risk Management and Insurance University of North Carolina at Charlotte PLUS CAN GATORS REALLY BE SAFE? YOU BET THEY CAN! HOW A PUBLIC ENTITY CAN HELP PROTECT ITS CITIZENS AND COMMUNITY FROM SEXUAL PREDATORS PUBLIC ENTITIES AT RISK FROM PRIVACY AND NETWORK SECURITY BREACHES
Going Above and Beyond “Sometimes I have to go above and beyond—literally. “Traveling the Alaskan bush to over 150 cities, boroughs and school districts is daunting, but I love what I do. Helping our members is hugely rewarding. They aren’t just risk partners, they’ve become personal friends. “To protect them from risk and losses, we rely on Genesis for reinsurance. When we encounter a little turbulence — or worse— it’s comforting to know we can trust their specialized expertise and top notch security. “With Genesis, we can always count on safe landings no matter what risks cross our path.”
Visit our website at www.GenesisInsurance.com
— Kevin Smith, Executive Director Alaska Municipal League Joint Insurance Association
Genesis Management and Insurance Services Corporation, 120 Long Ridge Rd, Stamford, CT 06902
A.M. Best A++ XV
S&P AA+
A Berkshire Hathaway Company
Volume 29, No. 5 | May/June 2013 | www.primacentral.org
The Public Risk Management Association promotes effective risk management in the public interest as an essential component of public administration.
PRESIDENT Dan Hurley, CSP, ARM-P, MS Senior Director, Risk Management & Safety Norfolk Public Schools Norfolk, VA
CONTENTS
PAST PRESIDENT Cindy B. Mallett, AIC, CWCP, ARM-P Risk Manager City of Gainesville Gainesville, GA PRESIDENT-ELECT Betty Coulter Director of Risk Management and Insurance University of North Carolina at Charlotte Charlotte, NC
6
12
DIRECTORS Ed Beecher Risk Manager City of Pompano Beach Pompano Beach, FL
6 A University Risk Manager Becomes PRIMA’s President:
Dean Coughenour, ARM Risk Manager City of Goodyear Goodyear, AZ
Michael Fann, ARM-P, MBA Director of Loss Control TML Risk Management Pool Brentwood, TN
MEET BETTY COULTER By Jennifer Ackerman, CAE
12 CAN GATORS REALLY BE SAFE? YOU BET THEY CAN!
By Bill Dolamore and David Carothers
EXECUTIVE DIRECTOR Marshall W. Davies, Ph.D. EDITOR Jennifer Ackerman, CAE Deputy Executive Director 703.253.1267 • jackerman@primacentral.org
By Kenneth Smith
ADVERTISING Donna Stigler 888.814.0022 • donna@ahi-services.com
25 PUBLIC ENTITIES AT RISK FROM PRIVACY AND NETWORK SECURITY BREACHES
Public Risk is published 10 times per year by the Public Risk Management Association, 700 S. Washington St., #218, Alexandria, VA 22314 tel: 703.528.7701 • fax: 703.739.0200 email: info@primacentral.org • Web site: www.primacentral.org
By Paul Cunney
25 IN EVERY ISSUE
Amy Larson, Esq. Risk and Litigation Manager City of Bloomington Bloomington, MN Regan Rychetsky, ABCP Director, HHS Enterprise Risk Management and Safety Texas Health and Human Services Commission Austin, TX
18 HOW A PUBLIC ENTITY CAN HELP PROTECT ITS CITIZENS AND COMMUNITY FROM SEXUAL PREDATORS
Matt Hansen, MPA Director, Risk Management Division City & County of San Francisco San Francisco, CA
Opinions and ideas expressed are not necessarily representative of the policies of PRIMA. Subscription rate: $140 per year. Back issue copies for members available for $7 each ($13 each for non-PRIMA members). All back issues are subject to availability. Apply to the editor for permission to reprint any part of the magazine. POSTMASTER: Send address changes to PRIMA, 700 S. Washington St., #218, Alexandria, VA 22314. Copyright 2013 Public Risk Management Association Reprints: Contact the Reprint Outsource at 717.394.7350.
4 News Briefs | 31 Advertiser Index | 32 Member Spotlight
MAY/JUNE 2013 | PUBLIC RISK
1
TPA & Risk Services Public Success We partner with our clients to understand their challenges and opportunities. We offer a unique, holistic approach in providing risk management programs and third-party administration services. Many of PMA’s clients have won national awards for their risk management programs. We do everything with a singular focus: bringing tangible value to your business.
PMA Companies TPA & Risk Services: PMA Management Corp. PMA Management Corp. of New England For more information on PMA solutions, visit us at:
Booth #311/313 www.pmacompanies.com Member of Old Republic Companies
Message from PRIMA President Dan Hurley
A REFLECTION ON THE YEAR: PRIMA HAS LANDED ON THE BEACH
S
omewhere in the vicinity of Lemhi Pass, standing near the continental divide, Meriwether Lewis suddenly understood that he had a much bigger challenge ahead than perceived as he faced the Rocky Mountains during the Lewis and Clarke expedition westward. Lewis, according to Clay Jenkinson in his biography, The Character of Meriwether Lewis: Explorer in the Wilderness, may have been overwhelmed after viewing the Rockies as an extraordinary challenge to his journey to the Pacific, the proof evidenced by his lack of writing for several months. In contrast, PRIMA staff and the board had significant mountains of their own to climb over the past year. Where Lewis faltered, at least in his writings, PRIMA was able to move forward to meet each challenge and accomplish so much in a short period of time. The greatest accomplishment, as you all know by now, was PRIMA being named as the supported organization by the Public Entity Risk Institute (PERI). After an arduous request for proposals process that included presentations to the PERI selection committee and lengthy negotiations, PRIMA was selected as the organization that PERI would support. The final affiliation agreement was signed in April. To say that PRIMA staff rose to the occasion, in spite of all the distractions, would not be enough of a compliment. The journey for PERI was long and took many forms but what a wonderful opportunity for PRIMA and PERI, working together to further the education and development of public entity risk managers. You’ll hear more about this new relationship in the future and the expanded services and opportunities benefiting those in public entities. Another mountain, less challenging, but equally fulfilling was the rebirth of PRIMA Institute (PI), held in November 2012 in Charlotte, N.C. The new PI drew almost 100 attendees. The education committee, led by Marilyn Rivers, did an outstanding job putting together a thought-provoking 100-level education program. PI received rave reviews and still another accomplishment within this glorious year, the planning for PI 2013 is complete with two tracks: a 100 level and 200 level.
The PRIMA Cybrary, an impressive collection of documents and best practices submitted by members over the years, was overhauled by a task force from the education committee. Well over 2,000 documents were reviewed, keeping the most current while providing an improved index. An endeavor that was challenging to start but the pluckiness and endurance of these individuals has provided PRIMA a Cybrary that is easier to retrieve documents and providing documents that are most current.
The greatest accomplishment, as you all know by now, was PRIMA being named as
I cannot thank enough the board of directors, the committee chairs and those that served on committees and task forces for their efforts. I also want to thank Executive Director Marshall Davies and his modest-sized staff who have accomplished so much. They dealt with challenges sometimes very large and unexpected but unlike Lewis, who at times became understandably dazed at his task, were able to focus and never falter in going forward and completing a truly impressive journey.
the supported
A few days before the 2011 Annual Conference in Portland, I took a day to follow the Columbia River to the Pacific, to follow the path of Lewis and Clarke in the company of two close friends, fellow board members. When we reached the beach, I stood in awe looking at the ocean and thinking of the feelings of accomplishment that the Corps of Discovery felt completing this phase of their journey. I think you can say the same for PRIMA this year. The organization has crossed many mountains, some impressively large, but has now landed on its own beach, and before turning back to the continued work at hand, all of us can stop and reflect and respect the accomplishments of our board members, serving volunteers and particularly, the PRIMA staff.
about this new
organization by the Public Entity Risk Institute (PERI)… You’ll hear more
relationship in the future and the expanded services and opportunities benefiting those in public entities.
Sincerely,
Dan Hurley, CSP, ARM-P,MS 2012–2013 PRIMA President Senior Director, Risk Management and Safety Norfolk (VA) Public Schools
MAY/JUNE 2013 | PUBLIC RISK
3
News Briefs
NEWS
BRIEFS STATE IT WORKERS MUST PROVE SKILLS TO KEEP JOBS Tennessee Gov. Bill Haslam’s administration is forcing 1,600 information technology workers across state government to re-apply for their jobs in an effort to screen out those who can’t master the skills of a rapidly changing field, reports The Tennessean.
SMART METER FOES RESURRECT COURT FIGHT Opponents of Naperville, Ill.'s smart meter program have re-filed their federal lawsuit to include more evidence to back up their concerns over health, safety and security and show their constitutional rights are being violated.
The state employees association said IT workers are nervous. But the state’s chief information officer said most of them don’t need to worry.
The amended lawsuit now seeks to force the city to replace smart meters with analog meters upon residents' request at no cost, reports the Chicago Tribune.
“This is really not about getting rid of people,” Mark Bengel said. “It’s about making sure that we do have the skills and we have the ability to develop and retain staff in the future.”
"A lot of new information has come out in the past year and a lot of additional bad behavior from the city," said Doug Ibendahl, attorney for the smart meter opponents.
The changes come in the wake of several large-scale computer system problems that have hindered operations in various state offices, including the Department of Children’s Services, the Department of Labor and Workforce Development, and the Department of Human Services. The state’s “Project Edison” system, launched in 2008 to bring outdated payroll, accounting and vendor tracking systems into a single, integrated system, was rife with glitches for a couple of years.
The city has installed smart meters on more than 57,000 homes that officials say will help them operate the electric system in a more efficient, reliable and cost-effective manner.
Haslam told The Tennessean last fall that some computer systems were “in the ditch.” In part due to those difficulties, the governor has established a Business Solutions Delivery office to centralize IT expertise as the state embarks on contracting for future projects. Bengel said the IT challenges at some of the departments “certainly contributed” to the restructuring decision. A year ago, Haslam steered legislation through the General Assembly to rewrite civil service rules and allow the state to lay off employees based on job performance instead of straight seniority. According to a state Office of Information Resources memo obtained by The Tennessean, each state agency with IT operations “will receive a draft, standardized organizational structure that has been aligned with the mission of the agency. This draft organizational structure will be populated with newly created IT job classifications.” The memo says people who already have state IT jobs and meet minimum qualifications “may apply and be interviewed for the new classifications.”
4
PUBLIC RISK | MAY/JUNE 2013
But members of the Naperville Smart Meter Awareness group filed a federal lawsuit in December 2011 citing "a multitude of serious health, safety, security and privacy concerns" over the meters that wirelessly transmit data about electric use to the city, which runs the utility. Judge John Z. Lee questioned both sides about the case for about two hours in September and issued a 24-page written decision last month that dismisses claims residents' constitutional rights are being violated. However, he allowed the smart meter opponents to re-file an amended lawsuit. The revised litigation describes some of the clashes the opponents have had with the city including the January arrests of two of its leaders for interfering with meter installation. It also touches on issues other cities have had with fires related to smart meter installation, points to the hacking of Naperville's Web site to show there are security risks and further details concerns over the effect of radio frequency on health.
W W W.PRIMACENTRAL .ORG
JUDGE TOSSES $750K ANKLE-INJURY LAWSUIT AGAINST CITY A federal judge has ruled that the City of Portsmouth, N.H., is immune from legal liability for an ankle injury a woman suffered by stepping into a hole in Haven Park, reports seacoastonline.com. In an April 3 decision, U.S. District Court Judge Joseph DiClerico Jr. agreed with the city that state "recreational use" law grants landowners who make their property available for free recreational use immunity from liability for personal injury or property damage. The law makes exception for "intentionally caused injury or damage," the judge wrote. Mary Reed of Rockport, Mass., sued the city for $750,000, claiming she suffered "serious and permanent" injuries by stepping in a "deep," grasscovered hole while walking across the park on June 15, 2011, to look at the statue of Civil War Gen. Fitz John Porter. The two-count lawsuit was filed April 26, 2012, in the U.S. District Court of New Hampshire by Reed and her husband, Richard. Through Manchester attorney Peter Hutchins, they sought compensation for Reed's injuries, as well as for her husband's alleged loss of his wife's companionship. Reed claimed the hole was at least a foot deep and 2½ feet wide. Grass had grown from within the hole and was mowed so it was "invisible" to anyone using the public park, she alleged. Scott countered that the city believed there was a depression in the ground that was about an inch or two deep, and 12 or 14 inches wide. Reed alleged her right foot fell into the hole, which was camouflaged by grass and "indistinguishable from the rest of the grass in the park," causing her foot and ankle injury. She claimed she has since suffered "prolonged and continuing pain and suffering, severe emotional distress and mental anguish, loss of enjoyment of life, prolonged and repeated medical procedures, medical expenses and permanent impairment." Reduce the argued device shape to the then from make liability a new clipping The Reeds that the cityrequired was not size, immune under mask. the recreational-use law because the law doesn't apply to municipal property.
But Judge DiClerico ruled the law "applies to publicly owned land."
We know your risks.
At Markel, our policies constantly respond to changes in your industry because the most dangerous risk is the one you never saw coming.
Specialty insurance and reinsurance for public entity pools, reciprocals, trusts, and JPAs publicentitypoolinsurance.com
MAY/JUNE 2013 | PUBLIC RISK
5
A UNIVERSITY RISK MANAGER BECOMES PRIMA’S PRESIDENT:
MEET
BETTY COULTER
Director of Risk Management and Safety University of North Carolina at Charlotte
Photos: Jeff Cravotta
By Jennifer Ackerman, CAE
At its 2013 Annual Conference in Tampa, PRIMA will welcome its new president, Betty Coulter, director of risk management and insurance for the University of North Carolina at Charlotte. Coulter brings more than 20 years of risk management experience to the office of president of PRIMA. “We are incredibly excited for Betty to begin her term as president,” said PRIMA Executive Director Marshall Davies. “Betty is a calm, yet firm, voice on our board and I am looking forward to working closely with her in her capacity as president.” Before she takes office, Coulter spoke to Public Risk about risk management challenges, the benefits of PRIMA membership and what she’s looking forward to during her term as PRIMA president. Q: How long have you been involved with PRIMA? I attended my first national conference in 1996, in Baltimore, Md., and found it to be one of the best educational conferences I ever attended. I have been active in the North Carolina PRIMA chapter since 1989 and was elected as president of the chapter in 2000. I joined the national PRIMA board in 2010. I have also served on the Chapter Relations Committee and as the chair of the Finance and Audit Committee. Q: What is the biggest benefit of being involved with PRIMA committees and board? I think the biggest benefit is the opportunity I have to work with a group of talented people who have an expansive knowledge of risk management, safety, legal, insurance and human resources. The networking opportunities afforded me through PRIMA are invaluable. The great thing about PRIMA’s members is, if you have an issue or are having a problem, you can reach out to a board member, a committee member or the member-
6
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
"I want to make sure we continue to provide opportunities for our membership, increase our strategic partnerships and raise the visibility for the James Amaker, Risk Management Analyst, Betty Coulter, Hank James, Associate Vice Chancellor of Risk Management, Safety, and Security
public employee that holds the responsibility for providing risk,
ship and someone will be able to provide assistance and guidance. I encourage all PRIMA members to get involved on committees, submit proposals for the conference and apply for the board. One of the highlights of my career was being named a Business Insurance Woman to Watch in 2012. I believe my involvement with PRIMA directly impacted the result of being chosen as one of 25 recipients out of more than 400 submissions. Q: What are your goals for the term of your presidency? As you know, PRIMA is the premier public risk organization. I want to make sure we continue to provide opportunities for our membership, increase our strategic partnerships and raise the visibility for the public employee that holds the responsibility for providing risk, safety and insurance management in their respective organizations. As PRIMA continues to transition and evolve, I want to ensure that PRIMA is strategically positioned so that we can continue to sustain ourselves in the ever-competitive and changing market. Continuing the success of our annual conference and PRIMA Institute is on the forefront, but I also want to expand other opportunities for our membership to find value in what PRIMA offers. Q: What are some of the best things PRIMA offers its members? PRIMA has so many valuable resources that it is difficult to pick just one! Education and training resources for members and chapters are provided in multiple formats. Members have an opportunity to participate in Webinars, which are so well-presented and are very cost-effective—they’re free! The Webinars are provided so that organizations can allow participation by employees without the travel and transportation expenses that often hinder organization
from continuing education opportunities. The re-invention of PRIMA Institute has been very successful in meeting the specific training needs of newer risk managers. And of course, the Annual Conference is the flagship educational opportunity of our organization. Q: What is the one thing PRIMA offers that its members do not take enough advantage of? In my opinion, it is the opportunity to participate on committees. Committees are made up of the membership and are voluntary. You gain insight on the organization, but more importantly, you connect with the general membership and get a better understanding of their needs. PRIMA exists because of the members it serves and becoming involved makes a stronger and more diverse organization. Q: What skills do risk managers need today that they did not need in the past? Risk management is continuing to evolve and is not only encompassing the traditional risk management pathway of safety, insurance and loss control, but the risk manager of today is relied upon as a strategic partner. Now you see the titles of enterprise risk manager, chief risk officer or vicepresident of risk management that are now defining names for the evolving risk manager. Additionally, the breadth of what a risk manager is responsible for is continually evolving and there are a number of persons who are not titled as the risk manager, but have responsibilities that are added to their current positions who need the information of a professional risk manager. It may be the human resources director, the emergency manager, or the city administrator who needs the opportunity to learn about risk management because it has been added to their duties. PRIMA offers a number of opportunities to address the needs of the non-traditional risk manager.
safety and insurance management in their respective organizations. As PRIMA continues to transition and evolve, I want to ensure that PRIMA is strategically positioned so that we can continue to sustain ourselves in the ever-competitive and changing market."
MAY/JUNE 2013 | PUBLIC RISK
7
A University Risk Manager Becomes PRIMA’s President: Meet Betty Coulter
"At UNCC, we are approaching the launch of an enterprise risk management program. We will be reaching out to our campus community to seek out a risk champion and develop a campus ERM committee so that we can pull the risk diversities into one focused group. This is a daunting task, but the diversity of the PRIMA board, our corporate partners and our membership offer a breadth of knowledge that can be easily accessed to provide a springboard for this initiative."
Q: You’re somewhat new to the university setting. What are the biggest differences between working for a municipality and a university? In some aspects, there are not many differences at all. Operationally, a university functions similar to a municipality. We have utilities, building and grounds, fleet service, police, parking and finance operations that are similar to a municipality. The biggest differences lie on the academic side—students, research, academic and athletic eligibility and other areas of reputational risks that are specific to a university—such as Study Abroad, international programs, and collegiate sports. University risk management provides a collaborative approach to addressing the needs of the organization. At UNCC, we are approaching the launch of an enterprise risk management program. We will be reaching out to our campus community to seek out a risk champion and develop a campus ERM committee so that we can pull the risk diversities into one focused group. This is a daunting task, but the diversity of the PRIMA board, our corporate partners and our membership offer a breadth of knowledge that can be easily accessed to provide a springboard for this initiative. Q: What can PRIMA do to support the new challenges risk managers face? PRIMA continues to provide the best opportunity for training for the risk management community, both traditional and non-traditional approaches. PRIMA is already doing so many things right: we offer an outstanding Annual Conference, we brought back PRIMA Institute, with amazing results, and our podcast series, which is free to members and non-members, spotlights interesting and timely topics. PRIMA must stay abreast of the changes in the risk management profession and act as a voice on those issues that impact our profession and membership—such as being aware of any legislative changes that impact the duties of a risk manager. PRIMA must be able
8
PUBLIC RISK | MAY/JUNE 2013
to develop and maintain relationships with organizations that can add value to the membership. PRIMA can provide a great service to its members by staying on top of the trends and changes in the marketplace that affect our respective communities. Q: What PRIMA benefits have you taken advantage of? What has been most helpful? I think I have taken advantage of all of them! I have attended the Annual Conference, utilized the Cybrary, podcasts and PRIMAtalk, attended Webinars and PRIMA Institute and volunteered on committees. Although all benefits are important, I find volunteering to be the most rewarding. It provides the opportunity to network with experts in the field and connect people with similar interests and challenges. Connecting with those people and finding solutions to ever-changing issues provides a benefit that is “priceless”—especially when I need a solution in a quick turn around time. Q: What are the biggest challenges risk managers face in the next year? With budget cutbacks and reorganizations, the risk manager is constantly challenged with how to best provide value to the organization that can be quantified as a “return on investment.” Although we are able to provide statistical information addressing claims and training numbers, it is a challenge to address the impact of re-engineering a project, so that a department can provide a service that is imperative in carrying out its mission. As a recent example, the University’s motor sports engineering department had been prohibited from testing their race cars on campus as a result of a past accident. Our insurance underwriter would not underwrite the activity if held on campus and required that testing of the model cars occur on a track designed
W W W.PRIMACENTRAL .ORG
Beth Hardin, Vice Chancellor of Business Affairs, Betty Coulter
for race cars. The department contacted me because the alternative solution was cost-prohibitive and jeopardized the department’s mission. Our risk management team, along with the department, was able to re-engineer the on-campus location and establish guidelines that were accepted by our underwriter so the division was able to continue to meet the expectations of the program. This is only one example of the responsibilities of a risk manager that are challenging to quantify and illustrate in a tangible way. These are the types of problem-solving that risk managers do on a day-to-day basis that are not specifically related to a number on a report. Q: What is the biggest challenge your own entity has faced? How did you deal with it? Did being a member of PRIMA help you? The news continues to report on instances of violence in the workplace and on college campuses. We oftentimes hear about someone who has entered a workplace or campus and proceeded to cause significant damage that impacts lives and families for a lifetime. Protecting those that utilize our facilities daily becomes a constant challenge. Homicides continue to be one of the highest instances of workplace deaths impacting our employees, students and customers. During my tenure at the City of Asheville, I was able to implement a training program addressing workplace violence, improve engineering controls for access, increase surveillance points and develop an executive committee that had the ability to make immediate decisions relative to protecting our employees in the workplace.
resource, a train-the-trainer initiative and educational materials for faculty, staff and students. The challenge with keeping our personnel and students safe is that most people believe that public buildings should have free access, but in these changing times we need to rethink how our buildings are utilized. Our reputational risk is always at stake when these types of incidents occur in at our facilities. Being a member of PRIMA has provided resources to research how other entities are addressing those issues through the utilization of PRIMAtalk, professional contacts provided through networking with the PRIMA membership and committee, and Cybrary. Q: What can PRIMA members do to get the most out of their PRIMA membership? I encourage members to utilize the opportunities provided by volunteering to serve on committees—you will gain a broader understanding of the PRIMA organization and its resources. Become involved in your local chapter. Submit proposals for conferences and podcasts and reach out to our membership and chapter relations committee and let us know how we can be of assistance. Coulter will be sworn in on Wednesday, June 5, during PRIMA’s annual membership luncheon.
Universities have strict guidelines for reporting incidences of violence as indicated with the Clery Act. Here at UNC-Charlotte, we have expanded our notification systems for our employees and students and are preparing a massive training campaign consisting of downloadable applications, a directed video training
MAY/JUNE 2013 | PUBLIC RISK
9
Your Partner in Community Protection At OneBeacon Government Risks, we understand the unique and evolving responsibilities of protecting a community and the people who serve it, and we’re here to help minimize risk, resolve claims and make your community a safer place to live and work. The OneBeacon Insurance Companies can provide you custom property, casualty, and professional insurance solutions.
VISIT US IN TAMPA AT THE PRIMA ANNUAL CONFERENCE, JUNE 2-5. BOOTH 529
Our team is made up of specialized experts in the public sector insurance industry—And we deliver! Come check out our presentations at PRIMA: Monday, June 3: 10:45 a.m. – 12 p.m. Elected Officials: Elected & Now We’re Stuck With ‘Em (Dennis Molenaar) Wednesday, June 5: 9:30 – 10:45 a.m. Ever Wonder Why You Do It Right But Still Get Sued? (Dennis Molenaar) Wednesday, June 5: 11 a.m. – 12:15 p.m. Sexual Predators: Protecting our Citizens, Communities and Entity Reputations (Kenny Smith)
Get OBGR news and conference updates onebeacongov.com | A Member of OneBeacon Insurance Group These policies may be underwritten by the Atlantic Specialty Insurance Company.
The Source for Complex Insurance Coverage ®
CivicRisk specializes in excess casualty coverage for public entities, including cities, counties, school districts, transit districts, utility authorities, joint power authorities/pools and more. Let CivicRisk help you find the right coverage for your public entity. CivicRisk offers commercial excess liability and retained limits liability up to $10 million. Coverage is written by an A.M. Best currently A+ XV (Superior) rated insurer. CivicRisk is a division of WKFC, part of Ryan Specialty Group, LLC, a global holding company that includes a group of highly-specialized underwriting facilities, a Lloyd’s insurer and other specialty insurance services designed specifically for agents, brokers and insurers. For more information about CivicRisk, contact: Tom Curran at marketing@wfkc.com, (480) 329-4919 or www.civicrisk.com. Scan the QR code for the latest RSG industry news! Don’t have a reader, visit us at www.ryansg.com/PR
CivicRisk is a division of WKFC Underwriting Managers, a series of RSG Underwriting Managers, LLC. RSG Underwriting Managers, LLC is a Delaware series limited liability company and a subsidiary of Ryan Specialty Group, LLC, specializing in providing underwriting management and other services to insurance companies, whose insurance products are distributed through agents and brokers. In California: RSG Insurance Services, LLC License # 0E50879. Jubilee Managing Agency Limited is a managing agent for Syndicates 5820 and 779 at Lloyd’s and is authorized and regulated by the Financial Services Authority. Direct Group Limited (Registered No. 2461657) and Millennium Insurance Brokers Limited (Registered No. 3566382) are insurance distribution businesses and are authorized and regulated by the Financial Services Authority. © 2013 Ryan Specialty Group, LLC
CAN GATORS REALLY BE SAFE?
YOU BET THEY CAN! By Bill Dolamore and David Carothers
The University Athletic Association, Inc. (UAA) is responsible for the intercollegiate athletics program at the University of Florida (Gators). The athletics director reports directly to the president of the University and retains overall responsibility for the health and stability of the program. The UAA’s board of directors provides guidance and direction through approval of policies, procedures and the budget. The mission statement, adopted by the board of directors, outlines goals and objectives in the development and delivery of the athletics program at the University of Florida. This "vision" provides the road map for the University’s commitment to be second-to-none in the area of intercollegiate athletics The UAA is a fully integrated 501c(3) not-for-profit organization comprised of several hundred full-time employees, 1,000 part-time employees and approximately 200 volunteers in several discrete departments including: • • • • • • • • • • • •
Athletic Teams—total of 21 teams comprised of approximately 500 athletes Academic Affairs & Student Services Administrative Services (which houses the risk management function) Auxiliary Services—Golf Course and Sport Shop Compliance & Support Services Controller/Accounting Human Resources Communications Marketing & Promotions Operations & Facilities Sports Health—Training Rooms and Nutrition Ticket Operations
The risk management department fulfills duties that are similar to any other public entity risk management organization, including procurement of insurance (property, liability, automobile, workers compensation, D&O and specialty insurances like athlete participation and event cancellation), processing claims, performing safety assessments, safety training and reviewing contractual agreements for risk exposures.
12
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
Today, the Safe Gator program is a full-fledged risk management and safety platform focused on continuously improving employee safety performance and promoting a safe fan experience. FUNDAMENTAL RISK EXPOSURES The UAA has all the direct and indirect risk management exposures related to organizing and conducting worldclass collegiate athletic events. Fan support for individual events can range from several hundred to nearly 91,000 for a home football game (total fan participation per year for all home events ranges from 1.1 to 1.2 million) requiring fan safety, as part of the overall fan experience, to become a key operational and risk management concern. To achieve the goal of providing a safe and enjoyable fan experience, the UAA relies on direct employees, volunteers and third-party service providers. Examples of third-party service providers include medical services (doctors, EMTs), ushering services, food services and security services. Volunteer and third-party relationships create contractual risk transfer exposures. In addition to sporting events, UAA offers sports camps and sports clinics across a variety of sports to help student athletes eight-years-old to high school age improve their performance skills. Maintaining and insuring 10 facilities valued at approximately $350 million is another UAA responsibility; properties include athletic venues and athletic offices such as the football stadium, basketball practice facility and the University of Florida Golf Course.
EVOLUTION OF THE SAFE GATOR PROGRAM At the direction of the athletics director, the risk management department embarked on a thorough baseline analysis of UAA’s casualty risk management exposures. The initial 2009 assessment conducted with an outside risk management consulting firm hired by the UAA consisted of evaluating safety practices and procedures for direct employees and facilities, a review of contractual risk transfer
provisions in third-party service provider contracts, and a physical assessment of each sporting activity. The physical assessment of each sporting activity consisted of a site review for one scheduled competition event for each sport in each venue. Considerations included fan safety, third-party service provider safety, ingress/egress, physical conditions, special event promotions (such as fan participation activities) and emergency medical response. Recommendations from each assessment were shared with appropriate department heads and implemented. UAA’s operations executives were briefed on macro trends that developed. Periodic third-party assessments of selected events and venues continue. In conjunction with the physical risk assessments, the risk management department created a series of performance metrics to begin tracking the safety performance and outcomes of each sporting event. The metrics apply to direct employee safety performance and third-party (fan) incident outcomes. Metrics continue to be updated and refined semi-annually (see Exhibit 1 on next page for metrics sample).
Another benefit of the program has been promoting risk management as part of the organization’s culture, making all departments more conscious of risk and including risk management in both strategic decisions and day-to-day operations.
The UAA’s risk management initiative has continued to evolve since inception. As part of a continuing improvement process, the Safe Gator program was formally branded in 2012 as the UAA risk management and safety initiative. Today, the Safe Gator program is a full-fledged risk management and safety platform focused on continuously improving employee safety performance and promoting a safe fan experience. Another benefit of the program has been promoting risk management as part of the organization’s culture, making all departments more conscious of risk and including risk management in both strategic decisions and day-to-day operations.
MAY/JUNE 2013 | PUBLIC RISK
13
Can Gators Really Be Safe? You Bet They Can!
Key Components—Internal Employee Safety The UAA has included the key components of successful risk management/safety processes as core elements of the Safe Gator program. Examples include: • • • • • • •
New employee orientation Ongoing employee training Facility inspections Accident reporting and investigation procedures Specific employee safety procedures Performance tracking and trending Risk elimination – (Example: In 2011, UAA built six permanent filming towers at the football practice field to replace scissor lifts that caused injuries and a death at other schools).
The UAA continues to develop and refine its risk management practices. Examples of components under development include (but are not limited to): • • • • •
Safe behavior observation and feedback Vehicle safety/driver training Golf cart safety Athlete transportation policy review Human resource policy reviews
As part of the 2012 Safe Gator branding initiative, the risk management department created an employee-oriented Web site to enhance communication and launch future Safe Gator initiatives. The Safe Gator Web site, which is available to leaders and colleagues, is a repository of training, procedural, forms and other risk management information. Key Components—Fan/Third Party Safety Under its 2009 risk management initiative, the UAA began collecting more detailed data concerning fan medical treatment issues and responses (incident reports). First responders are paramedics and emergency medical technicians from the Alachua County Fire/Rescue and Gainesville Fire Departments. In 2010, UAA engaged students from the University’s College of Pharmacy to assist first responders in first aid rooms and completing the paperwork necessary for capturing fan medical treatment data to ensure UAA could more accurately track fan incidents. By 2012, there were more than 40 pharmacy students participating in the program. These initiatives have resulted in upgrades to fan safety and medical response protocols involving “heat games”—home football games that occur during the early part of the season while Florida temperatures and humidity remain
GENERAL LIABILITY PERFORMANCE REPORT (EXHIBIT 1—SAMPLE METRICS) University Athletic Association Claim Frequency Analysis
POLICY PERIOD 2010–11
POLICY PERIOD 2011–12
(Jul. 1, 2010 – Jun. 30, 2011)
DIFFERENCE
(Jul. 1, 2011 – Jun. 30, 2012)
2010–2011 Frequency Fan Rate Attendance
(Previous to Current)
# Claims
Incident Ratio
2011–2012 Fan Estimates
Frequency Rate
Frequency Rate
-
0
100,000
153,484
-
0.00
-
0
100,000
186,878
-
0.00
1,000
-
0
100,000
1,000
-
0.00
633,579
-
0
100,000
623,429
-
0.00
34,653
-
0
100,000
36,503
-
0.00
100,000
25,000
-
0
100,000
31,002
-
0.00
100,000
9,447
-
0
100,000
9,375
-
0.00
0
100,000
13,156
-
0
100,000
21,894
-
0.00
Softball
0
100,000
31,163
-
0
100,000
27,9 26
-
0.00
Swim/Dive (m/w)
0
100,000
2,346
-
0
100,000
2,346
-
0.00
Tennis (m/w)
0
100,000
7,677
-
0
100,000
6,028
-
0.00
Track/Field (m/w)
0
100,000
1,766
-
0
100,000
1,766
-
0.00
Volleyball
0
100,000
45,217
-
0
100,000
48,812
-
0.00
UAA TOTAL
0
1,191,808
-
0
1,113,9 40
-
0.00
0.00
91,678
0.00
88,496
SPORT
# Claims
Incident Ratio
Baseball
0
100,000
153,904
Basketball (m/w)
0
100,000
232,900
Cross Country (m/w)
0
100,000
Football
0
100,000
Golf*
0
100,000
Gymnastics
0
Lacrosse
0
Soccer
UAA DEPARTMENT AVERAGE
Claim Data Valued As Of: Claim Data Valued As Of: (date) Fan total source: UAA Communication Office. Sport Teams Frequency Rate: number of injuries X 100,000 / estimated fans per year. * Golf frequency rate is based on the number of golf rounds per year.
14
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
An elevated perspective, focused on service. With in-depth knowledge comes perspective. At Travelers, we have the expertise to serve businesses across a broad range of industries with our IndustryEdge® suite of products. In addition to industry-specific coverages, Travelers' Umbrella of Services provides customized support based on exposures our clients face every day. • Superior claim resolution • Robust loss-prevention solutions • Extensive loss analytics • Timely, high-quality policy services Deepen the relationship you have with your customers by providing layers of protection beyond the policy. Call your Travelers representative today.
travelers.com ©2013 The Travelers Indemnity Company. All rights reserved. Travelers and the Travelers Umbrella logo are registered trademarks of The Travelers Indemnity Company in the U.S. and other countries. The Travelers Indemnity Company and its property casualty affiliates. One Tower Square, Hartford, CT 06183
Can Gators Really Be Safe? You Bet They Can! high. Examples of upgrades implemented for heat games include use of cooling buses, cool zones consisting of tents and misting fans and the availability of free ice cups. Three years of fan medical aid data has identified temperature limits, times of day and certain games (rival games vs. non-rival) when the UAA can expect to experience a high number of heat/dehydration related cases. The study also identified a natural “break point” for high heat games that occurs around mid-October. The additional data has further allowed better assessment of medical staffing for events and increased reporting for types of risks i.e. trips and falls, cuts/ scrapes, etc., which has led to better risk awareness and response by operations department personnel and increased submission of work orders for repairing items responsible for an injury like a broken seat. Key Components—Organization Protection The risk management department works in collaboration with the senior management and university legal office to protect the organization from various other risk exposures. During the risk management initiative, focus was placed on the following areas: • Creating a review process for all vendor and third-party contracts to insure compliance with contractual risk
transfer policies, including insurance, indemnity and liability requirements. Examples of contracts include all third-party service provider (vendor), bowl game, neutral site venues and half-time entertainment agreements. • Creating/assuring use of liability waiver forms. Examples of liability waiver forms include fan participation in promotion events and camps/clinics. • Implementing policies directed at protecting the UAA-Gator brand/reputation
INITIAL PROGRAM RESULTS The UAA has clearly benefitted from its disciplined risk management approach. Employee injury rates and thirdparty incidents have reduced in the past three years. For example, UAA employee workers’ compensation claims have reduced each year since 2008/09 for a cumulative reduction of nearly 70 percent through the end of the 2011/12 policy year. Incidents related to the general public have also significantly reduced year over year since the program’s inception, resulting in zero fan injury claims related to home football games and only one fan injury claim related to all home events during the past two seasons. This allows the UAA to enjoy a low workers’ compensation experience modification rate, reduced fan/third-party incidents at athletic events (and resulting claims expense), and the risk transfer and other financial efficiencies (such as event staffing) that accompany solid risk management performance.
SAFE GATOR FUTURE
Providing Excess Workers’ Compensation Since 1990 For Single Entities, Groups & Public Entities
Provided by an A.M. Best “A” (Excellent) IX Rated Carrier: • Aggregate Coverage Available • Installment Schedule Available • SIRs starting at $300,000
• Claims Management Available • Minimum Premiums: • Individual: $50,000 • Groups: $100,000
ExcessWorkersComp@midman.com 800.800.4007 midlandsmgt.com
16
PUBLIC RISK | MAY/JUNE 2013
At the beginning of each fiscal year (July 1 to June 30), the director of risk management, with the risk management consultant’s assistance, establishes the strategic risk management action plan for the coming year. Activities and goals are established based on the prior year’s performance, accompanying metrics, and any new/emerging risk issues that have been identified. Progress reviews are conducted and metrics are updated semi-annually (to allow for the completion of football season). If events dictate mid-term changes to the strategic plan, UAA’s risk management platform is flexible enough to accommodate any necessary changes. The UAA’s goal is to continue to provide employees, volunteers, fans and the general public with a safe and positive experience that is consistent with the University’s commitment to be second-to-none in the area of intercollegiate athletics. Bill Dolamore is the director-procurement services and risk management, University Athletic Association, Inc. David Carothers is the managing partner of Praxiom Risk Management, Tampa, Fla.
W W W.PRIMACENTRAL .ORG
Are Your Drivers as Safe as They Could Be? No public fleet is immune from drivers taking risks in their vehicles. Drivers can be distracted, lose sight of driving fundamentals and exhibit any number of behaviors that can cause risk to your fleet. DriveCam saves you money and protects your drivers and your community. Read how one innovative community addressed safety throughout its 2,200-vehicle fleet and join your colleagues at more than 500 companies and communities who have already made the decision to use DriveCam.
To learn more, click here or call or visit DriveCam. 866.419.5861
www.drivecam.com
How a Public Entity Can Help Protect Its Citizens and Community from
SEXUAL PREDATORS By Kenneth Smith
It is an unfortunate truth that news reports of sexual misconduct in our communities have become common. We consistently hear about those we trust with positions of power taking advantage of others— teachers and students; coaches and players; volunteers and participants; service providers and clients; law enforcement and detainees; jailers and prisoners. The headlines are numerous. The details are shocking. The damage far exceeds what money can replace.
18
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
How does this happen? How do criminals rise to such power in our towns and communities? Frankly, many people in hiring roles assume that they would be able to identify a molester or predator during a simple conversational interview. But people who violate a position of trust are successful precisely because they look and act like a person we would trust. There is no dangerous “look” in their eyes or obvious personality glitch. Therefore, there must be processes in place in our communities to help combat the chances of hiring such a person and to create a positive culture where abuse is unacceptable. A public sector’s best defense against predators are its policies, supervision, training and overall culture.
TO PROFILE A PREDATOR
FILL THE GAPS. WRITE IT DOWN
Currently, many public sector positions can be gained with little more than an interview and a standard background check. While this may identify individuals convicted of a sexual crime, it is not only those individuals you need to worry about. Studies of well-known sexual predator cases reveal that predators often begin their behavior as teenagers but are not apprehended until their 40s or 50s, operating under the radar for many years. Just because a predator has not been reported and convicted does not mean they aren’t fully engaged in predatory practices.
Predators look for lax employment rules and minimal supervision. When entities do not have strict operational guidelines and codes of conduct, a predator will substitute their own values and rules. A developing predator will blossom in a system where very few parameters are placed on their conduct and supervision is infrequent. Established predators will purposely seek out such situations. They prefer to operate in the shadows and gaps of procedural guidelines; the bigger the gaps, the better.
However, pre-employment screening is still a “must” in identifying convicted sexual predators. In addition to screening before hiring, background checks should also be repeated every one-to-five years to continue to ensure predators are not sneaking through the cracks once hired. Screening should be conducted for all staff and volunteers. Despite its worth and necessity, it is very difficult to actually “profile” a sexual predator with any degree of accuracy using the screening process. Instead, government entities should focus on other tangible tactics, such as expanding and enforcing polices and training, to enable the identification of a predator.
Organizations can fill these gaps by creating a robust written policy and code of conduct. The excuse, “you never told me not to…” should not apply. Furthermore, to ensure success in enforcing these policies, take the opportunity to get your legal counsel involved in the policy creation process. They should be involved in the development of the policies as they will need to rely on them to defend you in court, in the event of any allegation of misconduct.
BE ON THE LOOKOUT Predators seek to create trusting relationships with their targets, by “grooming” them. Grooming is generally subtle and appears innocent. That acceptable touch on the arm
MAY/JUNE 2013 | PUBLIC RISK
19
Protecting Citizens and the Community from Sexual Predators
To discourage this type of progressively sexual behavior, managers should be highly visible in the organization. They should frequently and randomly visit areas where participants/students/clients interact with staff and volunteers and then compare the conduct they see with the official policy and code of the organization. Management interaction should strive for a proactive approach, not just a response after an event.
may lead to more frequent and escalated contact until the victim (and surrounding adults) becomes used to it and accepts it. Often this trust-bond between the individuals is so strong that assaults are never even reported. To discourage this type of progressively sexual behavior, managers should be highly visible in the organization. They should frequently and randomly visit areas where participants/ students/clients interact with staff and volunteers and then compare the conduct they see with the official policy and code of the organization. Management interaction should strive for a proactive approach, not just a response after an event.
TRAIN, TRAIN, EMPOWER AND THEN TRAIN SOME MORE One of the best ways to enforce your policies, identify problems and ensure a culture of accountability is to train your employees. At the very least, it should be an annual event for managers and employees. Yearly, managers and employees should undergo a review of the entity’s policy and code of conduct to ensure policies are still complete and up-to-date. Discuss how employees should identify misconduct or potential misconduct and how employees should report infractions. Volunteers should be trained
20
PUBLIC RISK | MAY/JUNE 2013
semi-annually, or as appropriate to your organization’s hiring schedule. Arm your employees with the information they need to protect your entity and community. Once you arm your employees with the information, empower them to act. Often nearby adults or staff may have uneasiness about an observed meeting between two individuals but do not feel empowered to interrupt or to voice their concerns. Reinforce the idea that employees should always say something, even at the risk of making a mistake, and make it clear that a culture of protection exists in your organization. These control measures are there for the employee’s protection as well.
INVESTIGATE ALL ALLEGATIONS OF ABUSE When an allegation is made, investigate it promptly and thoroughly. Develop a response plan with your human resources team and legal counsel to make sure you do not violate the rights of the victim or the accused during the investigation. It is important to thoroughly document— and retain—all investigation documentation as your legal counsel will use this to defend you in court, should an allegation arise.
W W W.PRIMACENTRAL .ORG
2013 PRIMA CONFERENCE Visit us at Booth 511 to learn how we can help you with school risks.
winning team
Safety measures
4.0 GPA
Achieve A+ results in your risk management report card From the sports field to the classroom, achievement matters. Our workbook combines knowledge, experience, and creativity to develop custom risk transfer solutions and risk management strategies that protect your assets, your school and your students. Let’s achieve A+ results in your risk portfolio together. Learn more at www.munichreamerica.com/alternativemarket
Not if, but how Products and services provided by Munich Reinsurance America, Inc. Princeton, New Jersey
Protecting Citizens and the Community from Sexual Predators If an allegation is proven to be true, be ready with a plan of action, respond according to your policy and procedures as well as your legal counsel’s advice. This may include termination of employment of the staff member or volunteer and reporting to the authorities. Do not make the mistake of handing the problem off to someone else and hoping they do the right thing. Moving an employee, after an allegation of misconduct, to another location or department in hopes that the employee will behave this time will not likely alter their behavior patterns. In many cases, individuals need professional medical treatment. Similarly, terminating the employee without a formal investigation may ensure a new or fresh flow of potential victims for the predator at a different organization. A new place to work does not mean the predator’s desires go away or that they start over, they will likely pick up where they left off at the new location.
EXPOSE HIDING PLACES In the same way that predators seek employment at an organization with lax rules and supervision, they also seek privacy. Privacy is generally essential to predators
Protect your volunteers
Volunteers Insurance—it’s not just our name; it’s our specialty—and we’ve been at it for over 40 year www.cimaworld.com 800.222.8920
22
PUBLIC RISK | MAY/JUNE 2013
to carry out assaults, often in unobservable areas or off-site. Access to this privacy, along with a trusting relationship and possible grooming can supply a predator or budding predator everything he or she requires. Be acutely aware of such situations or areas within your local government and ensure those areas are thoroughly evaluated, frequently visited and eventually eliminated where possible.
NOT JUST THE YOUNG ARE VULNERABLE Perhaps most importantly, remember that victims are not confined to children and juveniles. There are many other groups of vulnerable citizens that are targeted by sexual predators such as the elderly, individuals with compromised mental abilities, prisoners and detainees. All of the tactics above should apply to those situations as well—particularly training—as handling situations and issues concerning the elderly or those with disabilities can require additional knowledge and skills. Sexual abuse is tragic for all- the victim, their family, the community and the entity. Sadly, abuses will continue to happen until a predator is caught or until an organization tightens its processes to make detection inevitable and the environment inhospitable to those seeking to abuse. Entities have the tools available to accomplish this by developing layers of protection against predators, and the public is demanding that they do so. A predator will learn the weaknesses of their employer’s culture and procedures so they can exploit them. It is critical that public entities minimize such weaknesses by developing sound policies focused on children, elderly and individuals with disabilities. These policies should specifically apply to all employees and volunteers with responsibility for such vulnerable group and should be frequently and vigorously taught and enforced. Appropriate conduct must be clear and outlined for everyone (management, employees, and volunteers) and deemed an important and intrinsic part of the organization’s culture. Sexual predators can, and do, turn up in very good organizations, proving that there is no full-proof method. But the harder your entity can make it for a sexual predator to find comfortable employment within your entity, the safer your citizens and public reputation will be. Kenny Smith is a risk management specialist for OneBeacon Government Risks in Denver, Colo.
W W W.PRIMACENTRAL .ORG
FIND OUT WHO’S BEHIND THE BUSINESS. CLEAR® FOR GOVERNMENT FRAUD
Our customers said they wanted a comprehensive solution that brings all the important information on a person or business into one place. They wanted to understand the risks about a person and entities they are associated with, all at a glance. CLEAR for Government Fraud was built to address the investigative needs of government professionals – just like you. Go to clear.thomsonreuters.com or call 1-800-262-0602.
© 2013 Thomson Reuters L-384184/4-13 Thomson Reuters and the Kinesis logo are trademarks of Thomson Reuters. The data provided to you by CLEAR may not be used as a factor in establishing a consumer’s eligibility for credit, insurance, employment purposes or for any other purpose authorized under the FCRA.
How do you
S TAY C o n f i d e n T in a world where
chaos reigns?
The government agencies and organizations that protect the public take on enormous risks every day. HCC Public Risk has their backs. We have over 30 years of experience, the products and the financial stability you need to get the job done with confidence. What we know and how we work makes a critical difference. We call it Mind over risk.
HCC Public Risk For more information or to obtain a bid on property and liability coverage, contact Cindy Woityra, at (800) 878 9878 or cwoityra@hcc.com. HCC Public Risk is a division of Professional Indemnity Agency, Inc., a subsidiary of HCC Insurance Holdings, Inc.
P UBL IC EN T I T IE S AT RI S K F OR
PRI VAC Y A ND NE T WORK SECURIT Y BRE ACHE S By Paul Cunney
Retailers, banks and technology companies, with their databases full of credit card numbers, bank account information, passwords and other confidential information are often prime targets for computer crime. While privacy and network security attacks on these companies have made headlines in recent years, public entities have been quietly coming under attack as well. Public entities—federal, state and local government agencies, police departments and schools—may not see themselves as targets, but they are not immune to the risk of a security breach.
MAY/JUNE 2013 | PUBLIC RISK
25
Network Security Breaches
Public entities have the responsibility to notify individuals when a breach has occurred. Complying with these regulatory requirements and responding to the crisis itself can be quite costly. By taking steps to improve security, public entities can reduce the risk of a loss. In the event a data breach does occur, insurance can help to mitigate an organization’s losses.
Organizations such as these often keep a wide range of information about people—tax records, Social Security numbers, health records, addresses and drivers’ license numbers—stored in their databases. Unlike many of the biggest corporations, the technology protecting these systems may be often inadequate, opening the door even wider to a potential attack. Additionally, data breaches don’t have to be electronic breaches; they can happen in any format where sensitive information has been compromised from not being properly guarded, locked up or adequately destroyed. Data breaches of public entities happen more often than most organizations might realize. In 2012, for instance, there were 88 breaches in the government sector involving 16.2 million records.1 At educational institutions, there were another 84 breaches involving 1.5 million records. Public entities have the responsibility to notify individuals when a breach has occurred. Complying with these regulatory requirements and responding to the crisis itself can be quite costly. By taking steps to improve security, public entities can reduce the risk of a loss. In the event a data breach does occur, insurance can help to mitigate an organization’s losses.
THE GROWING PROBLEM OF NETWORK SECURITY AND PRIVACY THREATS In today’s day and age, the majority of information is stored in some type of digital format. Organizations depend on their systems for their ongoing operations. It is no surprise then that criminals have also moved into the digital world. In the 2012 U.S. Cost of Cyber Crime Study, the Ponemon Institute found that the 56 organizations in its study experienced 102 successful attacks per week. This represented a 42 percent increase from the prior year’s successful attack experience. For public entities, data breaches can arise in several ways. Human error is still a significant factor. Employees can
26
PUBLIC RISK | MAY/JUNE 2013
often leave computer portals open by accident, fail to change passwords, or leave a laptop or hard drive in a taxi or at an airport. Laptops and other mobile devices are also often stolen – even from locked cars. Other data breaches are the work of rogue or disgruntled employees. These are insiders who have access to information and take advantage of their position to compromise it. Public entities have also been targeted by hackers in retaliatory action for perceived grievances. The Federal Reserve recently acknowledged that it had been infiltrated by the hacktivist group, Anonymous.2 While sophisticated hackers like Anonymous are a concern, ordinary malware, viruses and phishing scams are a much more common problem. Whether it’s because of hacking or human error, public entities are at risk for data breaches. Some recent data breach cases involving public entities included: • A County Tax Department—Tax department files were accidentally placed online. The names, bank account numbers, Social Security numbers and addresses of citizens who had garnishments from the tax department were available online. As many as 1,000 people were affected. • A State Assembly Office—More than 50 employees of a state’s Assembly office were warned that a hacker may have obtained their personal information. • A Department of Jobs and Services—A flash drive containing sensitive information was lost. It contained the names and Social Security numbers of people who had sought assistance from the transition center. • A Police Chief’s Association—Private emails from police officers and other information may have been exposed after the association’s website was hacked. Anonymous claimed responsibility for the attack as retaliation for the arrest of dozens of people suspected of being involved with Anonymous.
W W W.PRIMACENTRAL .ORG
THE PRICE OF A PRIVACY BREACH Organizations pay a big price for failing to adequately protect people’s personally identifiable information. In its 2012 Cyber Claims study, NetDiligence found that the average cost per data breach was $3.7 million. The average cost per record was $3.94 and the average number of records lost was 1.4 million. A total of 46 states currently have regulations requiring organizations, including public entities, to notify individuals when a breach has occurred. The burden of regulatory compliance is also growing with an increase in the adoption of data breach regulations. Since 1999, more than a dozen bills have been introduced in the U.S House of Representatives and the U.S. Senate. Part of the cost of the notification requirements includes the cost of drafting letters, postage, setting up call centers, credit monitoring and legal advice. The breach itself can also involve a number of additional expenses. Businesses and public entities may have to hire forensic teams to determine the scope of the breach. Crisis management and public relations teams may be needed. There are also costs involved with restoring systems and recovering lost records. In addition, organizations also may need legal advice to help them handle a data breach and comply with data breach regulations. Although in some states, public entities have immunity from liability, they may not be immune from the required first party expenses.
• Perform a Payment Card Industry Data Security Standards audit. For entities that accept credit card payments, a PCI DSS audit will help to ensure regulatory compliance. • Establish in-house privacy policies. Make sure that all employees understand the policies and have received training on them. • Implement access controls for mobile devices. • Conduct a regular review of third-party providers. • Develop an incident response plan in case there is a breach and then test it on a regular basis. Identify the decision makers in the organization. Breach response decisions often have to be made very quickly. It is also more cost effective to develop pre-breach relationships with vendors rather than seeking emergency assistance after a breach has occurred. Insurance can provide additional means for risk management and protection from a loss. Many entities believe their general liability or property insurance policies will cover them in the event of a network security or data breach. These policies, however, often do not provide any coverage for these kinds of losses. Property policies, for instance, do not provide coverage unless there is a direct loss to tangible property. Other policies often have strict exclusions for network security and privacy claims.
RISK MANAGEMENT Public entities are at risk and face the potential for significant losses due to the possibility that their defenses against data breach may be inadequate. Antivirus company, Kaspersky Lab, stated that the cyber security measures being taken by businesses are “woefully inadequate.”3 The security technology used by public entities is often outdated. Budget constraints may make it harder for them to upgrade. However, public entities, can take a number of steps to strengthen their defenses and reduce the risk of a breach. To reduce the risk of a loss, public entities should: • Encrypt sensitive data. The cost of encryption has dropped considerably over the years and is a very effective tool in protecting sensitive data. • Establish records and information management guidelines. Classify information as public, for internal use or confidential so that sensitive information is properly identified and protected. • Assess network security regularly. Ensure regular network security assessments are performed by third party providers and fix vulnerabilities when they are identified.
MAY/JUNE 2013 | PUBLIC RISK
27
Network Security Breaches To be sure that they have coverage, public entities may need a separate network security or privacy liability policy. When looking for a policy, public entities should be sure the data breach fund includes coverage for the cost of forensics, compliance and notification expenses, crisis management and credit monitoring.
PRIMA’s calendar of events is current at time of publication. For the most up-to-date schedule, visit www.primacentral.org.
A network security liability policy should cover any liability arising out of the failure of network security, including unauthorized access or unauthorized use of corporate systems, a denial of service attack, or transmission of malicious code. The policy also should include coverage for personal information in any format, including the loss of information as a result of a lost or stolen device.
WEBINARS 2013
The workplace today has become interconnected and digital, with operations run by computers and information stored in the cloud or mobile devices. Information is available with just the click of a mouse, which has made it even more vulnerable.
CALENDAR OF EVENTS
• July 17: Winning Strategies for Contractual Risk Transfer • September 18: Implementing ERM in the Public Sector: Obstacles and Opportunities • November 13: Amendments to Americans With Disabilities Act—Implications for Human Resource Management
PRIMA ANNUAL CONFERENCES June 2–5, 2013 PRIMA 2013 Annual Conference Tampa, FL Tampa Convention Center
Many big businesses have been at the center of the cyber battles for some time. The risk facing public entities, however, is often overlooked, even though these agencies handle all kinds of sensitive data from tax records and court documents to drivers’ licenses and Social Security numbers. By working with their insurers, public entities often gain valuable information in developing policies and implementing new technology that can help them reduce the risk of a loss from a privacy breach. Paul Cunney is vice president of ACE USA’s Public Entity unit, which specializes in underwriting multiple lines of coverage for public entity individual risks and pools.
FOOTNOTES
June 8–11, 2014 PRIMA 2014 Annual Conference Long Beach, CA Long Beach Convention Center
1 Privacy Rights Clearinghouse http://www.privacyrights.org/
June 7–10, 2015 PRIMA 2015 Annual Conference Houston, TX George R. Brown Convention Center
3 Global IT Security Risks: 2012 http://www.kaspersky.com/downloads/pdf/kaspersky_ global_it-security-risks-survey_report_eng_final.pdf
2 Fed Says Internal Site Breached by Hackers, No Critical Functions Affected http://www.reuters.com/article/2013/02/06/net-us-usa-fed-hackersidUSBRE91501920130206
June 5–8, 2016 PRIMA 2016 Annual Conference Atlanta, GA Hyatt Regency Atlanta
OTHER MEETINGS November 4–8 PRIMA Institute 2013 Milwaukee, WI
28
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
Berkley Public Entity Managers Berkley Public Entity Managers provides self-insured individual entities and risk-sharing inter-governmental groups superior service and access to A.M. Best rated A+ (Superior) Financial Size Category XV paper. We are an integrated team that includes underwriting, actuarial, risk control and claims. Together we are focused on one goal – to provide the protection our clients need through a combination of prevention, management and coverage.
For more information, please contact: Berkley Public Entity Managers 30 South 17th Street, Suite 820 Philadelphia, PA 19103
Richard B. Vincelette President T: (215) 553 7366 C: (215) 528 0410 rvincelette@wrberkley.com
© Copyright 2013 Berkley Public Entity Managers – A Berkley Company. All rights reserved.
Brian T. Whooley Sr. Vice President, Underwriting T: (215) 553 7381 C: (215) 528 0374 bwhooley@wrberkley.com
PRIMA’s 2013 Annual Conference
HOLDING RISK
JUNE 2–5, 2013 | TAMPA, FLORIDA Thanks to the generous support of PRIMA's Annual Conference Sponsors! Platinum Sponsors
Gold Sponsors
Silver Sponsors
Bronze Sponsors AIG
Ironshore
CorVel Corporation
Marsh
Poms and Associates Insurance Brokers, Inc.
For more information, visit http://conference.primacentral.org. 30
PUBLIC RISK | MAY/JUNE 2013
W W W.PRIMACENTRAL .ORG
Advertiser Index
ADVERTISER INDEX Berkley Public Entity Managers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 29 CIMA. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 22 CivicRisk. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 11 DriveCam. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .page 17 Genesis Underwriting Management Company.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Inside Front Cover Fingersafe USA, Inc.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 27 HCC Public Risk. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 24 Markel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 5 Midlands Management. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 16 Munich Reinsurance America.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 21 OneBeacon Government Risks. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 10 PMA Companies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 2 Starr Companies. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Back Cover States Self-Insurers Risk Retention Group, Inc.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Inside Back Cover Thomson Reuters. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 23 Travelers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . page 15 Has your entity launched a successful program? An innovative solution to a common problem? A money-saving idea that kept a program underbudget? Each month, Public Risk features articles from practitioners like you. Share your successes with your colleagues by writing for Public Risk magazine! For more information, or to submit an article, contact Jennifer Ackerman at jackerman@primacentral.org or 703.253.1267.
FIND US ON FACEBOOK!
Keep up with what’s happening at PRIMA and connect with your risk management peers! Visit us at www.facebook.com/primacentral. MAY/JUNE 2013 | PUBLIC RISK
31
Member Spotlight
NEW HAMPSHIRE POOL EMPHASIZES MENTAL HEALTH TRAINING FOR LAW ENFORCEMENT Each month, Public Risk features a member who has gone above and beyond in a feature column titled “Member Spotlight.” Do you know someone who deserves recognition, has made a contribution or excelled in their profession? If so, we’d like to hear from you for this exciting column, as PRIMA shines the spotlight on its members. To be considered for the Member Spotlight column, contact Jennifer Ackerman at jackerman@primacentral.org or 703.253.1267.
L
aw enforcement officers are often the first on the scene of a crisis involving someone with mental illness or in extreme emotional distress. Handling these situations requires specific tactical and communication skills to ensure favorable outcomes. The New Hampshire Public Risk Management Exchange (Primex 3) teamed up with the National Alliance on Mental Illness of NH (NAMI NH) to develop a comprehensive police mental health training course to ensure law enforcement officers had the tools they need to achieve these outcomes. “Research has demonstrated that the proper response from law enforcement can reduce the amount of time on a call and increase safety for all involved,” said Ty Gagne, chief executive officer of Primex 3. “A sudden string of deadly use-of-force incidents prompted a discussion about how these incidents could have been avoided or minimized if officers were trained to deal with the mentally ill.” The result of the partnership was a two-day training session conducted throughout the state of New Hampshire. The sessions included interactive case scenarios, role-played interventions, presentations from people with mental illness, discussions on how to engage them mentally and information on community resources to lead to a safe disposition of the situation. The sessions were facilitated by staff and volunteers from NAMI NH. As a result of the training, officers learned: • To recognize behaviors that may result from mental illness. • Skills for intervening with someone at risk, as well as scene assessment and management with individuals exhibiting mental illness.
32
PUBLIC RISK | MAY/JUNE 2013
• Legal procedures related to custody, transport and involuntary hospitalization. • The impact of stigma and trauma with persons with mental illness. • Early warning signs of mental illness, substance abuse and other risk factors leading to suicide. • Roles and responsibilities of local service providers and others in the community to collaborate in building a safety net for persons at risk. • How to respond to a suicide and incorporate post-vention protocols into a suicide response plan. Gagne believes that the program can have not just a positive human impact, but also a positive financial impact. “An outcome that is resolved ‘unfavorably,’ like a deadly force encounter involving an officer and someone suffering from mental illness, can result in both workers’ comp and liability claims,” he said. “A past wrongful death claim in the risk pool involving a mentally ill victim resulted in costs of $537,000, not including legal fees.” Gagne also points out that stress claims from officers suffering from PTSD as a result of being involved in deadly force incidents must also be considered. Primex 3’s mental health training program was awarded PRIMA’s Product Achievement Award for Pools in 2013. For more information, contact Ty Gagne at tgagne@nhprimex.org.
W W W.PRIMACENTRAL .ORG
S TAT E S I S P R O U D T O H AV E
THREE PRIMA P R E S I D E N T S AS MEMBER-OWNERS I N O U R N AT I O N A L P U B L I C E N T I T Y RISK MANAGEMENT
SUCCESS
SARAH PERRY, ARM-P PRIMA PRESIDENT, 2008-2009
DAN HURLEY, ARM-P, CSP, MS PRIMA PRESIDENT, 2012-2013
RISK MANAGER
SENIOR DIRECTOR RISK
CITY OF COLUMBIA, MISSOURI
MEMBER SINCE OCTOBER, 2011
MANAGEMENT AND SAFETY NORFOLK PUBLIC SCHOOLS NORFOLK, VIRGINIA
S T O R Y.
WILLIAM C. KOSTNER, ARM-P PRIMA PRESIDENT, 2007-2008 RISK MANAGER
CITY OF LINCOLN, NEBRASKA
MEMBER SINCE SEPTEMBER, 2007
MEMBER SINCE JULY, 1996
We know the challenges you face... States provides its member-owners with a long and proven history of
reliability, accountability, and well-earned trust. STATES OFFERS YOU: • A broadly interpreted excess liability coverage form that is second to none in the industry. • Premium stability and sound financial results for our partner members – member premiums are investments in their own Company. • Excellent claims and loss control support, including on-site. CO • Specialized public entity-oriented services from experienced, service-driven professionals. AT P ME SE E RIM U AT B A IN T S AM OOT H 32 PA 0
FOR INFORMATION CONTACT: States Self-Insurers Risk Retention Group, Inc. at 1-800-640-0345, extension 3310, or visit our website at www.statesrrg.com
X
We are Starr Companies, a global insurance organization supporting those who not only dare to reach for the farthest shores, but thrive when they get there. That is why, from the East Coast to the Far East, our exceptional teams set new standards for risk management across a broad spectrum of industries. Because we seek out the bold ones. The visionaries. The dreamers and doers. And when we find them, we don’t merely stand by their side. We put our name in ink, below theirs, as they venture forth to explore, discover and achieve the amazing. Starr Companies: Underwriting the future.
starrcompanies.com Accident & Health • Aviation & Aerospace • Casualty • Construction • Crisis Management • Energy • Environmental Financial Lines • Marine • Professional Liability • Property • Public Entity • Specialty Products • Travel Assistance © 2013 Starr Companies. All rights reserved.