Explore Legal.io

For Clients
Legal.io company logo
Hire Talent
Find the best fit for any legal role
For Members
Jobs
The best legal jobs, updated daily
Salaries
Benchmark compensation for any legal role
Learn
Learn and grow with our community
Events
Connect with peers at exclusive events
Apps
Tools to streamline legal work
Advertise on Legal.io
Post a job for free
Reach more qualified applicants quickly
Advertise with Us
Reach a targeted audience

For Clients

Hire Talent
Legal.io company logo
Solutions
Find the best fit for any legal role
New Hire
Get highly qualified candidates in days
Popular Roles
Data & Tools
Budget Calculator
Plan and manage your legal budget
Salary Insights
Compensation data for legal roles
Vendor Directory
The ultimate list of legal tech tools

Cyber-Related False Claims Act Cases on the Rise

A notable case involves Penn State University, which is accused of non-compliance with DoD cybersecurity obligations and falsely attesting to DFARS compliance since 2018.

Cyber-Related False Claims Act Cases on the Rise

In recent weeks, there has been a significant increase in cyber-related False Claims Act (FCA) activity. This surge in activity signals that contractors and universities should brace for additional scrutiny and potential whistleblower claims in this area.

One notable example is a qui tam lawsuit against Penn State University, which was unsealed on September 1, 2023. The lawsuit alleges non-compliance with Department of Defense (DoD) cybersecurity obligations. Specifically, it is claimed that Penn State University failed to provide “adequate security” for Covered Defense Information (CDI), as contractually required by the DFARS 252.204-7012 clause.

Under this clause, “adequate security” is defined as implementing all 110 controls outlined in NIST SP 800-171. Federal regulations require DoD contractors to conduct a self-assessment of compliance with these controls and report a compliance score in DoD’s Supplier Performance Risk System (SPRS).

The lawsuit alleges that Penn State falsified at least 20 documents related to its NIST SP 800-171 self-assessment and other self-attestations. Despite never reaching DFARS compliance, the university had been falsely attesting to compliance since January 1, 2018.

Furthermore, the lawsuit alleges sensitive information was put at risk when the university migrated some of its data to a commercial cloud-storage service. The relator in the case served as the interim Chief Information Officer at Penn State’s Applied Research Laboratory in 2015 and was a part of a team assigned to evaluate Penn State University’s compliance in early 2022.

Implications

These cases suggest that the number of enforcement actions and publicity associated with previously-sealed qui tam cases will continue to increase. They also signal that contractors and universities should brace for additional scrutiny in this area.

In light of these developments, it is crucial for organizations to examine their cybersecurity practices and ensure they are in compliance with all relevant regulations. This includes conducting regular self-assessments of compliance with controls such as those outlined in NIST SP 800-171.

Moreover, organizations must be transparent about their cybersecurity practices. Falsifying documents or attesting to compliance without actually meeting the necessary standards can lead to serious consequences, as seen in the Penn State case. Failure to comply with these standards can result in significant legal and financial consequences.

Legal.io Logo
Welcome to Legal.io

Connect with peers, level up skills, and find jobs at the world's best in-house legal departments

More from Legal.io

Legal Market Data: Job Opportunities in Times of Pandemic

A look into the legal job market, and how COVID-19 has affected job prospects for individuals seeking work, based on data from The US Bureau of labor statistics, Indeed, LinkedIn, and the Legal.io Community.

Legal Market Data: Job Opportunities in Times of Pandemic
CareerLabor and Employment
Former FTX Executive Ryan Salame Pleads Guilty to Charges

The plea comes ahead of the trial of former FTX founder, Sam Bankman-Fried

Former FTX Executive Ryan Salame Pleads Guilty to Charges
TechnologyBanking and FinanceFraud
AI Legal Battles Voice Rights

Recent legal cases, including Scarlett Johansson's accusation against OpenAI and a class action lawsuit against LOVO, highlight the need for legal regulation in voice AI technology.

AI Legal Battles Voice Rights
Technology
Community Perspectives: What does a legal metrics dashboard look like on your team?

Legal Operations professionals talk through what legal metrics dashboards work for their teams.

Community Perspectives: What does a legal metrics dashboard look like on your team?
Legal OperationsTechnologyLegal Software
FTC’s Non-Compete Ban Blocked Nationwide by Federal Court

The Federal Trade Commission's non-compete ban has been blocked nationwide after Texas Federal Judge Ada Brown ruled that the agency lacked the authority to enact the “unreasonably overbroad” regulation.

Antitrust and Trade RegulationBusiness and CorporateLitigation
Legal.io Newsletter - July 29, 2022

Published weekly on Friday, the Legal.io Newsletter covers the latest in legal, talent & tech.

Legal.io Newsletter - July 29, 2022
Legal OperationsTechnologyIn-House Counsel
Community Spotlight: Stacy Lettie, Director of Legal Operations at Adtalem Global Learning

Join our host and CEO, Pieter Gunst, as he explores the career journey of Stacy Lettie, Director of Legal Operations at Adtalem Global Learning.

Community Spotlight: Stacy Lettie, Director of Legal Operations at Adtalem Global Learning
Spotlight
LexisNexis Acquires Henchman

LexisNexis has announced its acquisition of Belgian startup Henchman with the goal being to enhance its AI-powered legal solutions and integrate Henchman's advanced contract drafting capabilities.

LexisNexis Acquires Henchman
TechnologyMergers and Acquisitions
Legal.io Logo
Welcome to Legal.io

Connect with peers, level up your skills, and find jobs at the world's best in-house legal departments