Stuart M. Gerson and Alaap B. Shah, Members of the Firm in the Health Care & Life Sciences practice, in the firm’s Washington, DC, office, co-authored a whitepaper for the Washington Legal Foundation, titled “DOJ’s Civil Cyber-Fraud Initiative: What Contractors Need to Know About Novel Use of False Claims Act.”

Following is an excerpt (see below to download the full version in PDF format):

Cyberattacks and data breaches continue to make front-page news because of their disruptive impact on the operations, finances, and reputations of companies large and small. The COVID-19 pandemic, during which remote business activity and the use of technology to access and transmit sensitive information increased, has magnified this threat. Some industries, health care as a prime example, have been particularly hard hit.

The Biden administration responded to the growth of cybercrime by championing a national response strategy, particularly to thwart ransomware attacks. In furtherance of this effort the Department of Justice (“DOJ”) recently announced an enhanced Civil Cyber-Fraud Initiative (the “DOJ Initiative”). Under this initiative, DOJ plans to leverage its broad enforcement authority under the False Claims Act (“FCA”) to pursue cybersecurity-related fraud involving government contracts and federal grantees. This effort will affect every company—running the gamut from defense contractors to providers who participate in federally funded health care programs. And as any government contractor knows, the threat of treble-damages lawsuits isn’t limited to DOJ action. The FCA is a vehicle for private “relators” to sue in the name of the United States. Indeed, spurred by financial incentives and an industry tendency to settle cases, the vast majority of FCA cases are initiated by private relators. Thus, the DOJ Initiative poses significant risks and increased costs associated with company cybersecurity practices.

We first turn our attention to the nature and scope of the DOJ Initiative, the FCA theory that it purports to rely upon, and the avenues of prevention and response that this victim-as-potential-defendant policy suggests. Finally, we examine policy arguments that suggest that the DOJ Initiative might be misplaced.

Jump to Page

Privacy Preference Center

When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.

Strictly Necessary Cookies

These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

Performance Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.