Justin A. Chiarodo and Daniel A. Broderick

On Wednesday, March 12, 2014, the Department of Defense (DOD) and General Services Administration (GSA) Joint Working Group on Improving Cybersecurity and Resilience Through Acquisition (Working Group) requested public comments on its draft implementation plan (draft plan) for federal cybersecurity acquisition. See 79 Fed. Reg. 14042 (Mar. 12, 2014). The draft plan is the first of several steps toward implementing the recommendations outlined in the Working Group’s recently finalized report on Improving Cybersecurity and Resilience Through Acquisition (summarized here).
As comments are due on April 28, 2014, federal contractors and other stakeholders should act quickly to submit their views on what will have a significant and lasting impact on federal cybersecurity acquisition practices.
The draft plan proposes a repeatable, scalable, and flexible framework for addressing cyber risk in federal acquisitions, and by design, it will affect nearly all contracting entities. The draft plan proposes a “taxonomy” for categorizing procurements so that the government can effectively prioritize those in need of additional resources, attention, and safeguards. As proposed, the taxonomy is modeled on Federal Information and Communications Technology (ICT) acquisitions—though the Working Group has asked whether this framework is a workable model for the categorization of all acquisitions. The Working Group would use the ICT framework to categorize all acquisitions that present cyber risk, after which it would separately assess the risks within each category. Categories that present greater cybersecurity risk (based on threats, vulnerabilities, and impacts) would receive more and faster attention in acquisitions. The taxonomy is, in our view, the most significant new development in the draft plan, as it will serve as the principal basis for categorizing the extent of cyber regulations for procurements. This aspect of the plan accordingly warrants particularly close attention. Continue reading “DOD and GSA Seek Comments on Draft Cybersecurity Implementation Plan”

The American Arbitration Association (AAA) recently adopted optional Appellate Rules which significantly change the resolution of post-award issues. The new Appellate Rules, effective November 1, 2013, permit appeals of arbitration rulings directly to an AAA appellate panel. Given the difficulty in overturning traditional arbitration awards, these new rules could help protect against factually and legally flawed outcomes. However, they also could add both time and expense to an arbitration, limiting the efficiencies and cost savings that often lead contractors to use arbitration provisions in the first place. This alert discusses the new Appellate Rules, and some things to keep in mind when evaluating whether to use them.
Two recent regulatory actions by the Department of Labor will impose significant new affirmative action and data collection requirements on federal contractors and subcontractors. The final rules will impact many federal prime and subcontracts performed in the United States and warrant close attention by contractors of all sizes. This alert highlights key provisions in those rules, which are presently set to go into effect on March 24, 2014.
False Claims Act (FCA) suits against health care providers have dramatically risen during the last three years. However, recent decisions indicate that courts are becoming increasingly skeptical of suits which allege that technical violations of Medicare regulations are actionable FCA violations. The most recent decision indicating such increasing skepticism was issued by the Eighth Circuit Court of Appeals last week in U.S. ex rel. Ketroser v. Mayo Foundation, 2013 WL 4733986, No. 12-3206 (8th Cir. Sept. 4, 2013). In that case, relators brought a qui tam action under the FCA against the Mayo Clinic and several related entities (Mayo). Relators asserted that Mayo falsely billed Medicare for surgical pathology services when it did not submit written reports for each surgical pathology service billed, which was allegedly required by Medicare regulations. The Eighth Circuit found that the regulations at issue did not require such written reports. However, the Eighth Circuit also signaled that even if Mayo was noncompliant with Medicare’s rules and requirements, the relators had not established the “scienter” necessary to show that Mayo “knowingly” submitted false or fraudulent claims for Medicare payment in violation of the FCA. The court concluded that because Mayo’s interpretation of the applicable requirements was at least reasonable, it did not violate the FCA even if it did make a technical mistake under the rules, because it did not act “with the knowledge that the FCA requires before liability can attach…” 