Email
Newsletters
R&I ONE®
(weekly)
The best articles from around the web and R&I, handpicked by R&I editors.
WORKERSCOMP FORUM
(weekly)
Workers' Comp news and insights as well as columns and features from R&I.
RISK SCENARIOS
(monthly)
Update on new scenarios as well as upcoming Risk Scenarios Live! events.

Risk Insider: Bob Morrell

Risk Technology: Risk Managers Lead from Within

By: | April 22, 2014 • 2 min read
Bob Morrell is CEO and Co-Founder of Riskonnect. He oversees the strategic vision and strategy of Riskonnect, a provider of risk management technology. Bob hones his competitive skills practicing mixed martial arts, along with his family. Bob can be reached at bob.morrell@riskonnect.com.

This year marks my twentieth in the risk management field.  Now I would never call myself a risk manager.  Far from it: I’m a computer geek, and proud of it.  Today we refer to the Internet, Cloud, Mobile and Big Data, but I’ve been working with technology my entire life.  So much has changed in those twenty years.  Networking computers together was rudimentary and extremely limited when I started.  Now everything, and everyone, is interconnected, and that has changed everything.

That interconnectivity has allowed organizations to move away from the isolated, siloed processes of the past, and produced dramatic changes in the way we conduct our business and our lives. I’ve watched risk management evolve from a department called upon primarily when things go wrong, to a pervasive philosophy for running a successful business.  Fewer and fewer risk managers I speak to work in isolation, reacting to claims as they come in.  Rather they are a collaborative lynchpin to manage risk.  They don’t wait for bad things to happen.  They proactively put safety programs in place, analyze loss data and make their organizations more risk-aware.  They know an enormous amount about the inner workings of their organization, its suppliers, distributors, vendors and team members.  This is a fundamental transition from a middle management, administrative function, to an executive level function that is key to the organization’s success.

But risk managers are increasingly finding that email and spreadsheets are clumsy, inefficient, and ultimately create obstacles to managing risk throughout their company.  With the speed and global reach of business, when even ‘local’ businesses rely on a far-flung supply chain, yesterday’s technology introduces risk, inefficiencies and increased levels of error. Today’s business demands technology that facilitates decisions for tomorrow’s business challenges. Organizations need a platform – a platform that provides secure, efficient and consistent methods of communicating risk-related events and data.  Fortunately this need comes at a time when we have a convergence of technologies that can make this vision a reality.

 This is a fundamental transition from a middle management, administrative function, to an executive level function that is key to the organization’s success.

Just imagine running your business on technology of twenty years ago.  Sending paper memos (when CC referred to a literal ‘carbon copy’), using a phone tethered to your desk, taking delivery of policy documents in hard copy – oh wait, they still do that.  Would that put your business at a competitive disadvantage?  Of course it would – and risk management would suffer too.

Risk management no longer has to take a back seat to other parts of the organization. Quite the opposite. By leveraging commercial cloud platforms, the pervasiveness of the Internet and the interconnectivity of everyone and everything, the risk management team can be the most modern, forward-looking part of the company. Risk management has become the bellwether of change – actually bearing the standard for technology-enabled collaboration and productivity across the organization. Imagine that.

Share this article:

An Inevitable Threat

Cyber: The New CAT

Cyber risk is a foundation-level exposure that should be viewed similar to a company’s property, liability or workers’ comp risks.
By: and | April 7, 2014 • 6 min read
R4-14p26-28_IntroER.indd

Superstorm Sandy. The Joplin tornado. The Japanese earthquake and tsunami. California wildfires. 9/11. Catastrophes come in many forms. It is universally understood that despite our best efforts, disaster can strike due to forces beyond our control. Cyber threats are equally dangerous and diverse — and just as unstoppable.

Yet even as catastrophe risk management matures and scores of executives join the catastrophe conversation, the dragon known as cyber risk still sits in the middle of the board room, quietly smoldering.

Advertisement




In every industry and at every company size, cyber risk is a foundation-level exposure that every business must confront — one that must be viewed with the same gravity as a company’s property, liability or workers’ comp risks.

As recent as a decade ago, that might have been an overstatement. But not now. Technology and business are fundamentally linked. Computers and the Internet are the primary platform for communicating with customers and vendors, managing profits and expenses, paying employees, operating the machines that produce goods and provide services, and making sure that the end product gets into customers’ hands on schedule. Mobile technology and the Internet of Things are opening new channels, making technology a physical extension of ourselves, both personally and commercially.

“The entire economy is so reliant, in ways that we don’t even see, on technology and the storage, transmission and usage of data, both personal and for analytical purposes, that it’s fundamental to almost every sector,” said Oliver Brew, vice president for professional, privacy, and technology liability at LIU Liberty International Underwriters, the specialty line division of Liberty Mutual in New York.

Video: Computer security expert Mikko Hyppönen explains how he tracked down the creators of the first PC virus, which hit the net 25 years ago, and how to stop the new viruses of today.

That reliance is only going to grow. A January report by Forrester Research described software assets as more critical to business success than financial assets over the next 20 years.

“If you take a look at the public companies’ 10-Ks and publicly disclosed statements, what are they emphasizing that’s going to differentiate them from their competitors, increase sales, decrease costs and maximize efficiency? They focus on the use of technology and the use of information assets,” said Kevin Kalinich, global practice leader for cyber and network risk at Aon Risk Solutions.

With increased technology comes increased opportunity for attack. However, that reality didn’t get a lot of traction in the C-suite until the recent Target breach splashed it across world headlines. Even now, there are still some resting easy, confident that their IT teams have everything under control. Others assume cyber attacks are a threat largely confined to industries such as retail, health care and financial services — sectors with the most data to lose.

Advertisement




Small businesses, in particular, downplay the risk, said Jesse Bessler, an account executive at Lacher & Associates, of Souderton, Pa. “I think it’s that they just don’t understand the risk, and they think that [a cyber policy] is an add-on item they don’t need.”

Increased Sophistication

Security experts, however, are trying to break through the wall of denial. Cyber attacks, they argue, are akin to massive storms or similar to the focused destruction of a tornado — something you can prepare for, but not something you can prevent. Despite firewalls and antivirus programs, experts say, cyber punches will eventually land inside every company.

To grasp the magnitude of the threat, it’s important to recognize that the driving forces behind cyber crime are vast, varied and as uncontrollable as any atmospheric or geologic force. The threat is now ubiquitous, and experts agree that while making an effort to reduce the risk of a breach is important, it is no longer possible to completely prevent cyber attacks.

Kurtis Suhs Ironshore

Kurtis Suhs
Vice President
Ironshore

“It’s like two identical cars in a mall parking lot,” explained Kurtis Suhs, vice president and national technology and privacy product manager for Ironshore. “If one’s locked and one’s unlocked, the bad guy’s going to go to the unlocked car. But if the bad guy really wants to get into the locked car, he will — it’ll just take longer.”

And yet, organizations keep brushing off the threat. That may be because “cyber risk” has become synonymous with data theft. If an entity does not have a significant aggregation of customer financial data, executives assume they won’t be targeted. The reality is that the true exposure is no longer just about credit card or Social Security data. Hackers have expanded their target list, adopted a more patient approach and found deep-pocketed sponsors, whether private-sector or state-sponsored, security experts said.

Sophisticated hackers are conducting long-term surveillance and probing for weaknesses they can exploit for financial gain, said David Remnitz, global and Americas leader of Ernst & Young’s forensic technology and discovery services business. “The end result here is the theft of highly valuable, internal information for significant financial gain,” he said.

While that could mean outright theft of trade secrets or confidential M&A data, it could also mean corporate sabotage, as in corrupting a decade of research and development results or putting competitors out of business. Imagine a market where most of the players used one primary vendor as a source for a key ingredient. An organization could contract with a lesser-used source for that ingredient, then disrupt the operations of the primary vendor via a denial-of-service attack or other type of malware, leaving the rest of the market scrambling for suppliers.

The potential for lost business and liability claims could be devastating for the affected companies. Even those with solid business continuity plans in place could still take heavy hits from the reputational fallout.

Advertisement




“A large company might be able to absorb that risk. A small company can’t,” said Elissa Doroff, a vice president and senior advisory specialist in Marsh’s network security and privacy practice in New York.

To date, breaches have largely been limited to individual companies, but the potential for larger events looms. One concern centers on cloud companies, which could host data for hundreds of businesses. A data breach or network interruption, or the physical destruction of a cloud-service data center could wreak larger havoc on the economy.

“That’s a potentially catastrophic loss,” said Doroff.

The sky’s the limit at this point. Criminals are capable of disrupting a multinational corporation, a transportation or logistics network, a health care system, an entire industry or even an entire region, creating havoc and leading to economic losses in the millions or billions — in many situations even putting lives at risk.

Keep in mind that those with ill intent don’t even need to have an IT background — the proliferation of hackers-for-hire means that anyone intent on doing damage can do so if their pockets are deep enough.

That said, it probably wouldn’t take a well-funded ring of genius-level hackers and a sophisticated attack plan to paralyze the average organization. Three years ago, the U.S. subsidiary of Shionogi, a Japanese pharmaceutical firm, suffered a devastating cyber attack that deleted the contents of 88 computer servers, crippling the company’s operations for several days, disabling its email, BlackBerry servers, order-tracking system, and financial management software. The attacker? A former mid-level employee, working from a public
Wi-Fi network at a nearby McDonalds, calmly sipping coffee while bringing Shionogi to its knees.

An Enterprise Approach

Even organizations that have never been affected by a catastrophe generally do not question the need for CAT planning. At the very least, most probably have a written evacuation plan in place and enough insurance to cover the potential physical damage of a storm. The smartest also address the whole picture from a supply chain and business continuity standpoint, and may have even considered questions about how to manage any reputational damage related to interruption of service to customers.

PwC’s report, Cyber Crisis Management: A Bold Approach to a Bold and Shadowy Nemesis, offers a new philosophy and approach to incidence response. This graphic shows the key elements of a structured cyber crisis response.

PwC’s report, Cyber Crisis Management: A Bold Approach to a Bold and Shadowy Nemesis, offers a new philosophy and approach to incidence response. This graphic shows the key elements of a structured cyber crisis response.

Cyber exposure should be approached in much the same way. It starts with engineering out the risk to whatever extent possible. If your roof is old, for instance, replacing it may be a way to ensure the building is more likely to stay intact if it’s battered by a storm. The cyber equivalent might be replacing old servers or upgrading any existing automated intrusion detection system. Security experts stress, however, that cyber risk is not an IT exposure, it’s an enterprisewide exposure. Therefore vulnerabilities need to be identified across an entire organization, with policies and procedures modified accordingly.

A comprehensive, enterprisewide disaster plan can also go a long way toward helping companies minimize the damage sustained in the event of a cyber attack. For every function of an organization, management needs to ask hard questions about how a cyber attack could disrupt that function, and what kind of back-up plan each department would need. Do you have a way to contact customers and suppliers if your email goes down? Do you have a crisis communication plan for alerting the public about how you’re handling the situation? Are your records backed up and accessible through a secure third-party?

Advertisement




Increasingly, organizations will rely on insurance to ensure their survival after a cyber event. In a February survey by BAE Systems, nearly 30 percent of companies said they expected the cost of a cyber attack to exceed $75 million. Another 20 percent expected the cost to fall between $15 million and $75 million.

“There’s an expectation that this could have an extremely material effect on business performance, and that’s a risk they look to hedge,” said Paul Henninger, global product director for BAE Systems Applied Intelligence, a business unit of BAE Systems.

Taking a realistic approach to cyber attacks could improve underwriting of the risk, he said. Just as carriers evaluate whether clients are prepared for a CAT-5 hurricane, knowing some damage is likely, they could determine whether clients are ready for a cyber storm.

“You can’t make it go away, but you can minimize the impact on the bottom line and customers and reputation,” he said.

Complete coverage on the inevitable cyber threat:

Risk managers are waking up to the reality that the cyber risk landscape has changed. Every sector must prepare to withstand the storm.

042014_02c_hospital_thumbnailCritical Condition. The proliferation of medical devices creates a host of scary risks for the beleaguered health care industry.

042014_03c_cars_thumbnailDisabled Autos. It’s alarmingly easy for a hacker to take control of a driverless vehicle, tampering with braking systems or scrambling the GPS.

Alaska Plane CrashUnmanned Risk. The dark side of remote-controlled drones, which have already been hacked — by students.

dv738024An Electrifying Threat. There is a very real possibility hackers could devastate the nation’s power grids — for a potentially extended period of time.

Related articles:

Heading Off ‘Cybergeddon’. Experts say resistance is futile, but resilience is paramount.

Michelle Kerr is associate editor of Risk & Insurance. She can be reached at mkerr@lrp.com
Share this article:

Sponsored: Healthesystems

Changing the WC Medical Care Mindset

Having a holistic, comprehensive strategy is critical in the ongoing battle to control medical care costs.
By: | November 3, 2014 • 6 min read
SponsoredContent_HES

Controlling overall workers’ compensation medical costs has been an elusive target.

Yet, according to medical experts from Healthesystems, the Tampa, Fla.-based specialty provider of innovative medical cost management solutions for the workers’ compensation industry, payers today have more powerful options for both offering the highest quality medical care and controlling costs, but they must be more thoroughly and strategically executed.

Specifically as it relates to optimizing patient outcomes and controlling pharmacy costs, the key, say those experts, is to look beyond the typical clinical pharmacy history review and to incorporate a more holistic picture of the entire medical treatment plan. This means when performing clinical reviews, taking into account more comprehensive information such as lab results, physician notes and other critical medical history data which often identifies significant treatment plan concerns but frequently aren’t effectively monitored in total.

Healthesystems’ Dr. Robert Goldberg, chief medical officer, and Dr. Silvia Sacalis, vice president of clinical services, recently weighed in on how using a more holistic, comprehensive strategy can make the critical difference in the ongoing medical care cost control battle.

Fragmentation, Complexity Obscure the Patient Picture

According to Dr. Goldberg, fragmentation remains one of the biggest obstacles to controlling overall healthcare costs and ensuring the most successful treatment in workers’ compensation.

Robert Goldberg, MD, discusses obstacles to controlling overall medical costs and ensuring the best treatment in workers’ compensation.

“There are several hurdles, but they all relate to the fact that healthcare in workers’ comp is just not very well coordinated,” he said. “For the most part, there is poor communication between all parties involved, but especially between the payer and the provider. Unfortunately, it’s rare that all the stakeholders have a clear, complete picture of what’s happening with the patient.”

Dr. Goldberg explains that health care generally has become a more complex landscape, and workers’ comp adds another level of complexity. Physicians have less time to spend with patients due to work loads and other economic factors, and frequently there isn’t adequate time to develop a patient specific treatment strategy.

“Often we don’t have physicians properly incentivized to do a complete job with patients” he said, adding that extra paperwork and similar hurdles limit communication among payers, nurse case managers and other players.

In fact, Dr. Sacalis emphasized that it’s not only the payer, but often the healthcare provider who is not getting a complete picture. For example, a treating doctor may not be the primary care physician and therefore they may not have access to the total healthcare picture for the injured worker.

SponsoredContent_HES“Most of all, payers need to adopt a more collaborative approach in their relationships with physicians, employers and patients, as well as networks involved. It will result in getting people back to work through appropriate medical care and moving the case along to a prompt closure.”
– Robert Goldberg, MD, FACOEM, Chief Medical Officer, Healthesystems

“It’s often difficult for multiple physicians to communicate and collaborate about what’s happening because they may not be aware of each-others involvement in that patient’s care,” she said. “Data sharing is lacking, even in integrated healthcare systems where doctors are in the same group.”

Done Right, Technology Can Bridge the Treatment Strategy Gap

Dr. Sacalis explained the role technology advancements can play in creating a more holistic picture of not only an injured workers’ post-accident state or pace of recovery, but also their overall health history. However, the workers’ comp industry by and large is not there yet.

“Today’s technology can be very useful in providing transparency, but to date the data is still very fragmented,” she said. “With technology advancements, we can get a more holistic patient view. However, it is important that the data is both meaningful and actionable to promote effective clinical decision support.”

Silvia Sacalis, PharmD, explains the role that technology advancements can play in creating a more holistic picture of an injured worker’s overall health.

Healthesystems, for example, offers an advanced clinical solution that incorporates a comprehensive analysis of all relevant data sources including pharmacy, medical and lab data as part of a drug therapy analysis. So, for example, the process could uncover co-morbidities – such as diabetes – that may be unrelated to a workplace injury but should be considered in the overall treatment strategy.

“Healthcare professionals must ensure there are no interactions with any
co-morbidities that may limit or affect the treatment plan,” Dr. Sacalis said.

In the majority of cases where Healthesystems has performed advanced clinical analysis, information gathered from the various sources has uncovered critical information that significantly impacted the overall treatment recommendations. Technology and analytics enable the implementation of best practices.

She cites another example of how a physician may order a urine drug screen (UDS), yet the results indicating the presence of a non prescribed drug were not reflected in the treatment regimen as evidenced by the lack of modification in therapy.

“Visibility and transparency will help with facilitating a truly effective treatment plan,” she said, “Predictive analytics are necessary tools for proactive monitoring and detection of trends as well as early identification of cases for intervention.”

Speaking of Best Practices …

Dr. Goldberg highlighted that the most important overall best practice needed to secure the optimal outcome is centered around getting the right care to the right patient at the right time. To him, that means identifying patients who need adjustments in care and then determining medical necessity during the entire case trajectory.

“It means using evidence-based medical treatment guidelines that are coordinated,” he said.

“You must look at the whole patient, which means avoiding the typical barriers in the workers’ comp treatment system, issues such as delays in authorizations, lengthy UR processes or similar scenarios that are well intentioned but if not performed effectively they can get in the way of expedited care.”

Dr. Goldberg and Silvia Sacalis provide recommendations for critical steps payers should take to achieve the best outcomes for everyone.

Dr. Goldberg noted that seeking out the most effective doctors available in geographic locations is another critical best practice. That requires collecting data on physician performance, patient satisfaction and medical outcomes, so payers and networks can identify and incentivize them accordingly.

“This way, you are getting an alignment of incentives with all parties,” Dr. Goldberg said, adding that it also means removing outlier physicians, those whose tendencies are to over-treat, dispense drugs from their office or order unnecessary durable medical equipment, for example.

SponsoredContent_HES“Visibility and transparency will help with facilitating a truly effective treatment plan. Predictive analytics are necessary tools for proactive monitoring and detection of trends as well as early identification of cases for intervention.”
– Silvia Sacalis, PharmD, Vice President of Clinical Services, Healthesystems

“Most of all, payers need to adopt a more collaborative approach in their relationships with physicians, employers and patients, as well as networks involved,” he said. “It will result in getting people back to work through appropriate medical care and moving the case along to a prompt closure.”

Dr. Sacalis added that from a pharmacy perspective, another best practice is becoming more patient-centric, using a customized and flexible approach to help payers optimize outcomes for each patient.

“Focus on patient safety first, and that will naturally drive cost containment,” she said. “Focusing on cost alone can actually drive results in the wrong direction.”

Additional Insights 

Dr. Goldberg explains how consolidation in the health care and WC markets can impact the landscape and quality of care.

Dr. Goldberg and Silvia Sacalis discuss if injured workers today are getting better treatment than they were twenty years ago.

SponsoredContent

BrandStudioLogo

This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Healthesystems. The editorial staff of Risk & Insurance had no role in its preparation.


Healthesystems is a leading provider of Pharmacy Benefit Management (PBM) & Ancillary Benefits Management programs for the workers' compensation industry.
Share this article: