What's Happening?
In a significant decision for policyholders facing False Claims Act (FCA) claims, the Eastern District of Virginia granted judgment on the pleadings to a government contractor against its professional
liability insurer. The court ruled that the insurer must cover the contractor's $7.6 million qui tam settlement, less a $5 million retention, and its costs for responding to two Department of Justice (DOJ) civil investigative demands (CIDs). The case, *Guidehouse Inc. v. Continental Casualty Co.*, involved a contractor that administered New York’s federally funded Emergency Rental Assistance Program (ERAP). The state shut down its online ERAP portal due to exposed applicant information, leading to DOJ CIDs concerning the contractor’s cybersecurity practices and a qui tam complaint alleging the use of outdated software and false certifications. The insurer denied coverage based on a 'Deliberate Acts' exclusion for 'dishonest' or 'fraudulent' acts, but the court found the exclusion did not apply for three reasons: the FCA's 'knowingly' standard includes deliberate ignorance and reckless disregard, the policy's imputation provision only attributed an Executive Officer's knowledge to the contractor, and the settlement occurred without a final adjudication of excluded conduct.
Why It's Important?
This ruling is highly important for U.S. government contractors and their insurers, particularly those involved in federal programs. It clarifies the scope of 'fraudulent acts' exclusions in professional liability policies, indicating that such exclusions may not automatically apply in FCA cases where 'knowingly' can include deliberate ignorance or reckless disregard, rather than requiring specific intent to defraud. This decision could significantly impact how insurers assess risk and underwrite policies for government contractors, potentially leading to adjustments in policy language or premium structures. For contractors, it offers a degree of protection against the financial burdens of FCA settlements and investigation costs, even when allegations of wrongdoing are present, provided there is no final adjudication of intentional fraud. This could influence contractors' willingness to settle qui tam cases and their strategies for managing cybersecurity and compliance risks in federal contracts.
What's Next?
The decision from the Eastern District of Virginia could set a precedent for similar cases involving FCA claims and insurance coverage, particularly in jurisdictions that may adopt similar interpretations of 'fraudulent acts' exclusions. Insurers may review and potentially revise their policy language to more explicitly define the conditions under which such exclusions apply, especially concerning the 'knowingly' standard in FCA cases and the imputation of knowledge within corporate structures. Government contractors, in turn, may gain more leverage in negotiating insurance coverage and in defending against qui tam complaints, knowing that their professional liability policies might offer broader protection than previously assumed. The ruling also highlights the ongoing legal complexities surrounding cybersecurity incidents and data breaches, particularly when they lead to government investigations and FCA allegations, emphasizing the need for robust cybersecurity practices and clear insurance coverage.
Beyond the Headlines
This case delves into the intricate relationship between corporate liability, insurance coverage, and the False Claims Act, a cornerstone of U.S. efforts to combat fraud against the government. The court's nuanced interpretation of the 'Deliberate Acts' exclusion underscores the legal system's challenge in balancing the need to deter fraud with ensuring fair coverage for policyholders. The distinction between intentional fraud and 'deliberate ignorance' or 'reckless disregard' is crucial, as it acknowledges the complexities of corporate decision-making and oversight. This ruling could encourage a more proactive approach by contractors in managing compliance and cybersecurity risks, as the financial implications of a breach or alleged wrongdoing can be substantial, even with insurance coverage. It also highlights the evolving nature of legal interpretations in response to new forms of corporate risk, such as those arising from technology services and data privacy.








