Target Breach a Threat to All
Computer security breaches that enable the theft of confidential financial information are no laughing matter. Just ask the 110 million or so people who have been affected by the infamous hack into Target’s customer-facing systems. So why should we in the insurance industry be sitting up and taking notice?
Internet sources report that this particular break-in used a form of memory-scraping malware technology that captures information as it is being input at the point of sale, but before it can be encrypted in the retailer’s systems.
We in the seemingly safe insurance sector may feel bad for our friends in retail, but before we get to feeling too comfy, it would be wise to consider that retail isn’t the only industry using point-of-sale (POS) devices. In fact, such input devices are used in lots of industries — retail, hospitality and health care among them.
It is that final class of users that should give us pause in the insurance sector. In case you weren’t paying attention, the Affordable Care Act requires electronic record-keeping. This naturally involves uncountable points of sale in doctors’ offices, clinics, and hospitals, not to mention places like Wal-Mart that are beginning to offer insured health care services.
Many of the individuals affected by the Target, et al., breach are promising never to do business with the involved retailers again. But what if the breached party was a major broker or insurer?
In the Target heist, an executive reported that someone had actually installed the malware on its POS systems. How that was done is a mystery at this writing, but one has to assume that these systems were connected to the Internet — which would allow the thieves to then retrieve the stolen data remotely. So, it seems likely that the malware was also remotely introduced into Target’s systems, as well as those of Nieman Marcus and other affected retailers.
These kinds of attacks are not exactly on the cutting edge of technology, however. According to InformationWeek, “Memory-scraping attacks date from at least 2011, when security researchers first spotted an advanced version of the Trackr (a.k.a. Alina) malware, which can be controlled via a botnet.” So, it won’t just be the most advanced thieves who pull off these kinds of crimes. The less-sophisticated, whether here or abroad, will likely be able to do the same.
Personal financial information is an extremely valuable commodity on the black market, and if you’re a criminal, it seems surprisingly easy to steal. Hackers can sell the credit card numbers for $35 to $100 each, while gold or platinum credit cards go for $60 each, business credit cards for $80 and some platinum cards for $100, said Cisco security researcher Levi Gundert in a blog posting. Interestingly, the information stolen in the Target incident includes names, addresses, credit card numbers, PINs and other data that enable thieves to assume an individual’s identity — which could lead to far bigger losses for those who are victimized.
Here’s the bottom line. Many of the individuals affected by the Target, et al., breach are promising never to do business with the involved retailers again. But what if the breached party was a major broker or insurer? Can insurance companies and brokers — already involved in a dog-eat-dog competition for insureds — afford to have that kind of backlash aimed at them?
The answers remain to be seen, but it is clear that with cyber crime escalating and becoming easier to perpetrate, our industry cannot stand back and hope the boogeyman goes away.
Coping with Cancellations
Airlines typically can offset revenue losses for cancellations due to bad weather either by saving on fuel and salary costs or rerouting passengers on other flights, but this year’s revenue losses from the worst winter storm season in years might be too much for traditional measures.
At least one broker said the time may be right for airlines to consider crafting custom insurance programs to account for such devastating seasons.
For a good part of the country, including many parts of the Southeast, snow and ice storms have wreaked havoc on flight cancellations, with a mid-February storm being the worst of all. On Feb. 13, a snowstorm from Virginia to Maine caused airlines to scrub 7,561 U.S. flights, more than the 7,400 cancelled flights due to Hurricane Sandy, according to MasFlight, industry data tracker based in Bethesda, Md.
Roughly 100,000 flights have been canceled since Dec. 1, MasFlight said.
Just United, alone, the world’s second-largest airline, reported that it had cancelled 22,500 flights in January and February, 2014, according to Bloomberg. The airline’s completed regional flights was 87.1 percent, which was “an extraordinarily low level,” and almost 9 percentage points below its mainline operations, it reported.
And another potentially heavy snowfall was forecast for last weekend, from California to New England.
The sheer amount of cancellations this winter are likely straining airlines’ bottom lines, said Katie Connell, a spokeswoman for Airlines for America, a trade group for major U.S. airline companies.
“The airline industry’s fixed costs are high, therefore the majority of operating costs will still be incurred by airlines, even for canceled flights,” Connell wrote in an email. “If a flight is canceled due to weather, the only significant cost that the airline avoids is fuel; otherwise, it must still pay ownership costs for aircraft and ground equipment, maintenance costs and overhead and most crew costs. Extended storms and other sources of irregular operations are clear reminders of the industry’s operational and financial vulnerability to factors outside its control.”
Bob Mann, an independent airline analyst and consultant who is principal of R.W. Mann & Co. Inc. in Port Washington, N.Y., said that two-thirds of costs — fuel and labor — are short-term variable costs, but that fixed charges are “unfortunately incurred.” Airlines just typically absorb those costs.
“I am not aware of any airline that has considered taking out business interruption insurance for weather-related disruptions; it is simply a part of the business,” Mann said.
Chuck Cederroth, managing director at Aon Risk Solutions’ aviation practice, said carriers would probably not want to insure airlines against cancellations because airlines have control over whether a flight will be canceled, particularly if they don’t want to risk being fined up to $27,500 for each passenger by the Federal Aviation Administration when passengers are stuck on a tarmac for hours.
“How could an insurance product work when the insured is the one who controls the trigger?” Cederroth asked. “I think it would be a product that insurance companies would probably have a hard time providing.”
But Brad Meinhardt, U.S. aviation practice leader, for Arthur J. Gallagher & Co., said now may be the best time for airlines — and insurance carriers — to think about crafting a specialized insurance program to cover fluke years like this one.
“I would be stunned if this subject hasn’t made its way up into the C-suites of major and mid-sized airlines,” Meinhardt said. “When these events happen, people tend to look over their shoulder and ask if there is a solution for such events.”
Airlines often hedge losses from unknown variables such as varying fuel costs or interest rate fluctuations using derivatives, but those tools may not be enough for severe winters such as this year’s, he said. While products like business interruption insurance may not be used for airlines, they could look at weather-related insurance products that have very specific triggers.
For example, airlines could designate a period of time for such a “tough winter policy,” say from the period of November to March, in which they can manage cancellations due to 10 days of heavy snowfall, Meinhardt said. That amount could be designated their retention in such a policy, and anything in excess of the designated snowfall days could be a defined benefit that a carrier could pay if the policy is triggered. Possibly, the trigger would be inches of snowfall. “Custom solutions are the idea,” he said.
“Airlines are not likely buying any of these types of products now, but I think there’s probably some thinking along those lines right now as many might have to take losses as write-downs on their quarterly earnings and hope this doesn’t happen again,” he said. “There probably needs to be one airline making a trailblazing action on an insurance or derivative product — something that gets people talking about how to hedge against those losses in the future.”
Mitigating Fraud, Waste, and Abuse of Opioid Medications
There’s a fine line between instances of fraud, waste, and abuse. One of the key differences is intent and knowledge. Fraud is knowingly and willfully defrauding a health care benefit program for personal gain or profit. Each of the parties to a claim has opportunity and motive to commit fraud. For example, an injured worker might fill a prescription for pain medication only to sell it to a third party for profit. A prescriber might knowingly write prescriptions for certain pain medications in order to receive a “kickback” by the manufacturer.
Waste is overuse of services and misuse of resources resulting in unnecessary costs, whereas abuse is practices that are inconsistent with professional standards of care, leading to avoidable costs. In both situations, the wrongdoer may not realize the effects of their actions. Examples of waste include under-utilization of generics, either because of an injured worker’s request for brand name medication, or the prescriber writing for such. Examples of abusive behavior are an injured worker requesting refills too soon, and a prescriber billing for services that were not medically necessary.
Actions that Interfere with Opioid Management
Early intervention of potential fraud, waste, and abuse situations is the best way to mitigate its effects. By considering the total pharmacotherapy program of an injured worker, prescribing behaviors of physicians, and pharmacy dispensing patterns, opportunities to intervene, control, and correct behaviors that are counterproductive to treatment and increase costs become possible. Certain behaviors in each community are indicative of potential fraud, waste, and abuse situations. Through their identification, early intervention can begin.
- Prescriber/Pharmacy Shopping – By going to different prescribers or pharmacies, an injured worker can acquire multiple prescriptions for opioids. They may be able to obtain “legitimate” prescriptions, as well as find those physicians who aren’t so diligent in their prescribing practices.
- Utilizing Pill Mills – Pain clinics or pill mills are typically cash-only facilities that bypass physical exams, medical records, and x-rays and prescribe pain medications to anyone—no questions asked.
- Beating the Urine Test – Injured workers can beat the urine drug test by using any of the multiple commercial products available in an attempt to mask results, or declaring religious/moral grounds as a refusal for taking the test. They may also take certain products known to deliver a false positive in order to show compliance. For example, using the over-the-counter Vicks® inhaler will show positive for amphetamines in an in-office test.
- Renting Pills – When prescribers demand an injured worker submit to pill counts (random or not), he or she must bring in their prescription bottles. Rent-a-pill operations allow an injured worker to pay a fee to rent the pills needed for this upcoming office visit.
- Forging or Altering Prescriptions –Today’s technology makes it easy to create and edit prescription pads. The phone number of the prescriber can be easily replaced with that of a friend for verification purposes. Injured workers can also take sheets from a prescription pad while at the physician’s office.
- Over-Prescribing of Controlled Substances – By prescribing high amounts and dosages of opioids, a physician quickly becomes a go-to physician for injured workers seeking opioids.
- Physician dispensing and compounded medication – By dispensing opioids from their office, a physician may benefit from the revenue generated by these medications, and may be prone to prescribe more of these medications for that reason. Additionally, a physician who prescribes compounded medications before a commercially available product is tried may have a financial relationship with a compounding pharmacy.
- Historical Non-Compliance – Physicians who have exhibited potentially high-risk behavior in the past (e.g., sanctions, outlier prescribing patterns compared to their peers, reluctance or refusal to engage in peer-to-peer outreach) are likely to continue aberrant behavior.
- Unnecessary Brand Utilization – Writing prescriptions for brand medication when a generic is available may be an indicator of potential fraud, waste, or abuse.
- Unnecessary Diagnostic Procedures or Surgeries – A physician may require or recommend tests or procedures that are not typical or necessary for the treatment of the injury, which can be wasteful.
- Billing for Services Not Provided – Since the injured worker is not financially responsible for his or her treatment, a physician may mistakenly, or knowingly, bill a payer for services not provided.
- Compounded Medications – Compounded medications are often very costly, more so than other treatments. A pharmacy that dispenses compounded medications may have a financial arrangement with a prescriber.
- Historical Non-Compliance – Like physicians, pharmacies with a history of non-compliance raise a red flag. In states with Prescription Drug Monitoring Programs (PDMPs), pharmacies who fail to consult this database prior to dispensing may be turning a blind eye to injured workers filling multiple prescriptions from multiple physicians.
- Excessive Dispensing of Controlled Substances – Dispensing of a high number of controlled substances could be a sign of aberrant behavior, either on behalf of the pharmacy itself or that injured workers have found this pharmacy to be lenient in its processes.
Clinical Tools for Opioid Management
Once identified, acting on the potential situations of fraud, waste, and abuse should leverage all key stakeholders. Intervention approaches include notifying claims professionals, sending letters to prescribing physicians, performing urine drug testing, reviewing full medical records with peer-to-peer outreach, and referring to payer special investigative unit (SIU) resources. A program that integrates clinical strategies to identify aberrant behavior, alert stakeholders of potential issues, act through intervention, and monitor progress with the injured worker, prescriber, and pharmacy communities can prevent and resolve fraud, waste, and abuse situations.
Proactive Opioid Management Mitigates Fraud, Waste, and Abuse
Opioids can be used safely when properly monitored and controlled. By taking proactive measures to reduce fraud, waste, and abuse of opioids, payers improve injured worker safety and obtain more control over medication expenses. A Pharmacy Benefit Manager (PBM) can offer payers an effective opioid utilization strategy to identify, alert, intervene upon, and monitor potential aberrant behavior, providing a path to brighter outcomes for all.