Online Originals Devon Paige Cobb Online Originals Devon Paige Cobb

Why Your Company’s Cyber Breach Isn’t Currently a Bad Thing

Note | KLJ Note Editor Devon Cobb proposes a mandatory SEC timeline for disclosure of cyber breaches to protect investors, maintain market integrity, and ensure the free dissemination of material information.

Article | 105 KY. L. J. ONLINE 1 | November 14, 2016

Devon Paige Cobb[1]

Introduction

“[T]here are only two types of companies: those that have been breached and those that don’t know they have.”[2] Despite the frequency of these hacks, the stigma associated with cybersecurity breaches of business and customer information is a harsh one. That stigma is imposed before the financial hits are measured, the average cost of which can be as much as $25 per exposed record.[3] Target alone reported a net $17 million in breach-related costs as well as $44 million in insurance payments.[4] While those numbers are substantial, these hacks can cost companies even more in intangibles, such as the decline in a company’s reputation,[5] loss of customer goodwill,[6] and liability flowing from either class action lawsuits by customers whose information has been breached or shareholders’ derivative actions.[7]Cyber breaches of consumer information have plagued the private financial and healthcare sectors for years now, but only recently, in the wake of such scandals as Ashley Madison[8] and big business let downs like Target,[9] have these leaks focused society's attention on the public sector.[10] The Securities Exchange Commission (SEC) has been slow to regulate disclosure of cybersecurity breaches for publicly traded companies. Only in 2011 did it publish guidelines that require publicly traded companies to disclose material cyber attacks, threats of loss, and actual losses.[11] And although the SEC met again in 2014 in a roundtable discussion,[12] it still has failed to mandate a specific timeline for publicly traded companies to follow in making their breach disclosures to the public.[13]So can a cyber breach ever be a good thing for the company? Because there have not been specific regulations from the SEC, companies are free to take their time and consider only their own interests in making breach disclosures to the public; companies may even spin the breach as immaterial to avoid disclosure completely.[14] Without explicit SEC regulation of the timeline for disclosure, companies will inevitably waver on the time they take to make disclosures, creating ambiguity in industry standards and uncertainty in the marketplace following a breach. Furthermore, market distortions — the types that the SEC is most focused on preventing[15]— are likely to result from undisclosed information from data breaches. This Note argues that the SEC should mandate a specific timeline for requiring companies to disclose a cyber breach to maintain its objective of ensuring freely disseminated information, maintaining market integrity, and protecting investors.

I. The Setting: How Investors’ Interests Are Taking a Back Seat

Consumers, companies, and investors have competing interests in regards to a data breach. Unfortunately, investors’ interests are ultimately ignored. Consumers, however, need to be notified of breaches so that they can take remedial and protective post-breach measures to safeguard their information, like cancelling their credit cards. These interests are currently being protected by the Federal Trade Commission (FTC), whose mission is to protect consumers from unfair or deceptive business practices.[16] The Third Circuit recently held that the FTC may bring a claim that a company’s allegedly inadequate data security practices constitute “unfair” business practices in violation of Section 5 of the Federal Trade Commission Act.[17] Furthermore, many states have recognized the need for adequate consumer protection by enacting consumer breach notification disclosure statutes, but consumers are afforded this protection in only three-fourths of states.[18]Companies often perceive that keeping a hack quiet is in their best interest. This allows the company to “save face”[19] and prevent indirect costs of “business lost”[20] from wary consumers, while, in the interim, trying to discover precisely what information was hacked and why. But companies also limit disclosures to avoid “provid[ing] a roadmap for hackers as to where they are vulnerable.”[21] For these same reasons, a company might fear that making a breach public would cause potential investors to shy away from the company.[22] Add to this list of concerns the looming fear of class action lawsuits for consumers who were harmed by the breach,[23] and it is easy to see why companies’ interests are best served when they have all the time in the world (or at least as long as they want) to disclose a breach.These concerns leave investors’ interest in being notified of a data breach ignored under current SEC regulations. Investors care about data breaches being withheld because of the impact it could have on their investment’s stock price. Announcing publicly that a database of consumer information has been hacked would intuitively cause the breached company’s stock price to decrease for a number of reasons: loss of faith in the company’s ability to safeguard sensitive materials, impending liability costs to remedy such breach, including implementing new safeguards to assure breaches become less likely to occur, and costs of future lawsuits, to name just a few. The current regulations, or lack thereof, allow companies to be guided solely by industry standards when it comes to what and when to disclose post-breach.[24]However, announcements of a data breach need not assuredly signal impending doom for a company’s stock price.[25] A few companies have successfully navigated such announcements.[26] Target and Home Depot both faced security breaches but chose to handle the situation differently.[27] Target delayed notifying customers of the breach and its stock dropped nearly 20% while Home Depot’s prompt notification to their larger affected consumer base was viewed as reassuring to the public and did not adversely affect the company’s stock price.[28]These types of positive consumer responses to a breach could in turn be just the kind of uptick that investors would want to know about most. Patrick Malcolm, a digital forensics and security expert commenting on the Ashley Madison leaks, noted the way the breach’s publicity could work in the company’s favor, explaining how a consumer told Malcolm that he was joining Ashley Madison “because it was more secure now.”[29] However, Malcolm explained, “there’s no evidence the company has actually changed its protocols.”[30] On the other hand, notifying the public that a company has been hacked could signal that the company has not been responsible with consumer information they pledged to keep safe.[31] Several companies have lost CEOs following breaches that uncovered corporate irresponsibility, poor business practices, disconcerting management, and the company’s inability to protect consumer data.[32] Regardless of whether the breach indicates a change in consumer confidence in the company or a reflection of poor management, the overall perception of a company post-breach can affect how investors view their investments and thus should fall within the SEC’s realm of regulations.The SEC does play a role, albeit a mildly passive one thus far, in regulating data breaches. The SEC only began specifically addressing cyber breaches in 2011, when it published guidance on disclosure obligations. Unfortunately these guidelines gave no timeline for making disclosures and only mandated that disclosures are required for “material” information.[33] In 2014, the SEC held a roundtable where industry leaders considered making more regulations on disclosures.[34] Political leaders, such as Senator John D. Rockefeller, in his role as Chairman of the Committee on Commerce, are even “urging” the SEC to take more extensive action, noting concerns “about inconsistencies in disclosures, investor confusion, and the fact that many corporate leaders [do] not fully recognize the relationship between their companies’ cybersecurity measures and financial success.”[35] SEC Commissioner Luis A. Aguilar gave a speech at the New York Stock Exchange urging companies to take more steps and encouraging “more public reporting of cyberattacks.”[36] But the SEC has not taken any steps since the roundtable, simply continuing to encourage companies to follow the 2011 guidance, leaving investor interests and protections back-seated when it comes to breach notification.

II. The Problem: How Companies Can Work Around the Current Regulations

The SEC’s purpose is to “protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation,”[37] resting on the foundation that “only through the steady flow of timely, comprehensive, and accurate information can people make sound investment decisions.”[38] Thus, the SEC is charged with regulating and monitoring disclosures made by publicly traded companies to ensure investors have equal access to information. This is done by not only imposing a duty on companies to disclose “material” events, but also by imposing strict timelines under which the disclosures must be made. Under the SEC’s definition, “material”[39] means any information that has a substantial likelihood of being considered important to a reasonable investor when making an investment decision.[40] Because a breach could be of concern to investors, these disclosure mandates would assumedly include notifications when a publicly traded company has been hacked.[41]Although the materiality test dictates an objective standard, companies still have room to deem a data breach “immaterial.”[42] If a company can twist the breach as immaterial, it can completely avoid disclosure, meaning that investors would not be notified even though the breach could influence their investment decisions.[43] SEC guidance has cautioned “a cyber-attack could be material if it causes a company to significantly increase what it spends to defend its systems or when intellectual property is stolen.”[44] This allows management to usurp the SEC’s role of deciding what investors need to know. If the breach results in only “minor intrusions” of consumer data, it likely does not need to be disclosed, whereas confirmed breaches of determinable consumer information definitely need to be disclosed.[45] For everything in between these two categories, management decides if the breach is important enough to warrant disclosing it to investors under the circumstances.[46]Because certain circumstances already require public disclosure, the SEC could address these concerns by utilizing current provisions, including rules 10b-5[47] and 14a-9,[48] which regulate fraud in connection with the purchase and sale of securities and fraud in the solicitation of proxies. Rule 10b-5 prohibits the use of any manipulative or deceptive device in the buying and selling of securities, requiring disclosure of material information or abstention from trading.[49] This includes an obligation to disclose private information when necessary under the circumstances to prevent publicly known information from being misleading by the omission.[50]Rule 10b-5 could potentially be applicable when a company has been the victim of a cyber-attack and serve to safeguard the interest of investors, but only for instances in which securities, such as the company’s stock, are being sold or purchased.>[51] Thus, this regulation does not always mandate a disclosure or require a trader to abstain from the market to ensure that the integrity of the marketplace is maintained if no securities are being exchanged. Under rule 10b-5, as long as the company itself is not buying or selling securities while withholding information regarding a data breach, no duty arises to disclose such a breach to the general public (i.e. investors).[52] Instead, the only duty the company has is to keep their insiders from trading in the market.[53]Even though companies do not have a duty to disclose a breach under rule 10b-5, they could still be required to make these types of disclosures in their annual 10-K forms.[54] However, these reports require companies to only report “the cybersecurity risks that could affect the business or its registrants materially;”[55] they do not require the company to report actual incidents or breaches. The SEC’s 2011 guidance encouraged companies to determine if “the costs or other consequences associated with one or more incidents or the risks of potential incidents [of cyber breaches] represent a material event, trend, or uncertainty that is reasonably likely to have a material effect on the registrant’s results of operations, liquidity, or financial condition or would cause reported financial information not to be necessarily indicative of future operating results or financial condition,” and report this in the Management & Discussion Analysis (MD&A) section of the company’s annual reports.[56] The decision as to whether or not to disclose is complicated by a timing issue: even if companies do disclose a breach in their annual reports, investors are only deemed to have been notified at the end of the year when those reports are filed.[57] Thus, the breach’s impact could affect investment decisions to buy, sell, or trade far sooner than when the year-end report filings roll around.In addition to annual and quarterly reports, public companies must report “certain material corporate events” in an 8-K report to announce major happenings of which shareholders should be aware.[58] Companies are given four days to file these disclosures.[59] Although cyber breaches are not specifically listed as items to be reported on an 8-K, registrants can use section 8 of the form to “report events that are not specifically called for by Form 8-K that the registrant considers to be of importance to security holders.”[60] Guidance has been given that:

… once the facts are gathered, a special filing may be warranted. . . . If the event or incident is a significant one or if it is one that a reasonable investor would expect to hear about outside the cycle of the normal disclosure of risk, it is prudent to do a special filing.[61]

This form alone, however, does not require a cyber breach disclosure to be made, and even if companies choose to disclose under this rule, there is once again an opportunity for work-around regarding the timing of the disclosure. Although the regulations governing 8-K filings mandate a four-day deadline for certain events falling under Sections 1-6 and 9 (covering standard business occurrences), filings regarding cyber breaches, which fall under Section 8’s “other events,” are not given this same four-day deadline, or even any specific deadline.[62]Due to the SEC’s slow response in regulating disclosure, the only real pressure companies feel is to ensure they stay at least somewhat within the shadows of others in their industry.[63] This is currently the best and only standard against which a company can be judged.[64] Choosing to file an 8-K could be in the company’s best interest, especially if that is how others in the industry are treating the incident. However, because these measures are not strict regulations, they allow companies to interpret and set their own standards. This can lead to unequal dissemination of information and inefficient markets, as investors in A corporation could be notified of a breach more quickly than investors in B corporation. Although industry standards could be used to set strict demands for companies, the current standards are so lax as to allow companies to consider their own interests over that of their investors.Piecing together all of this information shows that avoiding breach disclosures may be easier for companies than investors would like. If the SEC set disclosure notification timelines for publicly traded companies, it would communicate to companies that data breach disclosures are not only material and required, but would also remove the uncertainty management faces in determining a breach’s materiality.

III. The Solution: Regulating the Regulators

The SEC should mandate stricter data breach notification requirements and set a rigid timeline to give companies direction when handling a data breach. Tighter regulations will encourage companies to create response plans so that they can act quickly in the face of a breach. Regulations will also incentivize companies to put in place adequate safeguards, such as technological safety measures to protect consumer data, helping prevent breaches in the first place. This, in turn, benefits investors, as a breach would be less likely to have a detrimental effect if handled well.[65] A definite timeline will also move publicly traded companies to uniform and clear guidelines, clarifying the current vague industry standards set by the companies that have already been breached. These standards could also help set guidelines for small and non-public companies in the future.The SEC should not set a flexible rule, such as “companies should disclose data breaches timely,”[66] because this type of rule would not solve the disclosure problem. This standard is no clearer than the current ambiguous guidance and would leave companies uncertain about how such a vague standard would be interpreted. Instead, it would only facilitate the current problems caused by industry standards, which allow companies to set their own disclosure timeframes based on what they believe is the most effective response time, focusing more on their own primary interests rather than their investors’. This type of standard would also allow for workarounds, opening the door to fraudulent practices and delay tactics for each company’s specific situation, avoiding the primary objectives of the SEC — to protect investors by keeping them equally informed and ensuring that they “are provided with material information in order to make informed investment decisions”[67] and to “maintain fair, orderly, and efficient markets.”[68] While a company may have unique circumstances that require a delayed notification timeline, the investor’s interest remains consistent in needing to be timely informed of incidents affecting their investments.The SEC’s data breach notification regulations, enacted primarily to serve investors, would also provide an ancillary benefit of protecting consumers in states that do not afford them any protection through consumer notification laws.[69] Roughly one-fourth of states do not have consumer notification laws on their books.[70] Kentucky, for example, requires only that disclosures be made “in the most expedient time possible and without unreasonable delay.”[71] This type of standard sets no more of a specific deadline than mandating no timeframe at all, but at least requires that companies must eventually disclose the breach to consumers. Even Delaware, the capital of business governance,[72] offers no more of a specific timeline than “the most expedient time possible and without unreasonable delay.”[73]In deciding precisely how long to make the notification timeline, the SEC could look to state consumer notification laws.[74] Ohio, for example, says “in the most expedient time possible but not later than forty-five days.”[75] Florida law is even stricter, saying “as expeditiously as practicable, but no later than 30 days after.”[76] By explicitly regulating notification deadlines, the SEC would integrate consumer and investor interests in building market integrity and in devising a comprehensive system that considers the competing interests of the marketplace as a whole, as SEC Commissioner Aguilar urged back in 2014.[77]Alternatively, because investor concerns can vary widely based on industry, the SEC could consider setting a sliding scale timeline across different industries. For example, investors could need to know right away that a financial services company like American Express has been hacked of consumer credit card information. Consumers may place greater trust in a financial company to protect their sensitive information, and profitability would likely decline as a result of class action litigation costs and loss of customer loyalty. Investors would thus need to know of a breach almost immediately to anticipate how these market effects would impact their investments. Contrast this with a company that has been breached of consumer loyalty information, like Kroger, whose “Kroger Plus Card” records customer’s shopping trends but not financial information.[78] In this case, consumers do not have high expectations for maintaining the integrity of this information nor a cause of action when these types of non-sensitive reports are hacked.[79] Because certain industries are targeted more frequently and seriously, and the consequences of a breach are more detrimental to the health of the company, the SEC could, in considering these fluctuating concerns, create a sliding scale for data breach notifications for different industries.

Conclusion

Data breaches are becoming more frequent and more expensive, and they can have detrimental consequences for companies.[80] Consumers need to know as quickly as possible that an unauthorized access of their sensitive financial information has occurred in order to take proper safeguarding measures. But because the current norms are set by the industry, management is free to allow company-related concerns, such as the potential damage to its reputation and the subsequent effect on stock price, to guide its decision on when to notify the public of a data breach. This leaves investors’ interests unaddressed. A data breach can have a multitude of investment-related consequences, such as fluctuating stock prices, an increase in the company’s liabilities from class action law suits or increased cyber insurance costs, or a downturn in the company’s overall health and public perception.The current state of data breach notification regulations for publicly traded companies allow companies to benefit from not having to disclose a breach to their investors. Without a specific timeline mandating when companies must disclose a breach, companies are free to follow either their state’s notification law, assuming there is one, which even then may be just as ambiguous as the current SEC guidelines, or the industry standards set by similar companies that have responded to data breaches. And if the company is in an industry that has not had many breaches, it would be free to set its own standard. None of these standards provide uniform or efficient markets, strengthen investor security, or ensure equally disseminated information, all of which the SEC is most concerned with promoting.[81] Because the SEC’s utmost objective is that of protecting investors, the regulatory body should set a specific and strict timeline under which companies are required to abide by after a data breach.


[1] J.D. Candidate 2017. The author would like to specially thank Lisa E. Underwood, Andrew K. Woods, Rutheford B. Campbell, Jr., and Gardner Bell for their help in the brainstorming process and mentoring of this Note.

[2] Elena Kvochko & Rajiv Pant, Why Data Breaches Don’t Hurt Stock Prices, Harv. Bus. Rev. (Mar. 31, 2015), https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-prices.

[3] Nicole Perlroth, Ashley Madison Chief Steps Down After Data Breach, N.Y. Times (Aug. 28, 2015), http://www.nytimes.com/2015/08/29/technology/ashley-madison-ceo-steps-down-after-data-hack.html?_r=0 (quoting Larry Ponemon, founder of the Ponemon Institute, whose firm found that “the cost of mega-breaches now averages $23 to $25 per exposed record, which includes the costs of lawsuits.”).

[4] Andria Cheng, Two Months After Damaging Data Breach, Target Stock Has its Best Day in 5 Years, Market Watch (Feb 26, 2014, 2:11 PM), http://blogs.marketwatch.com/behindthestorefront/2014/02/26/two-months-after-damaging-data-breach-target-stock-has-its-best-day-in-5-years.

[5] CF Disclosure Guidance: Topic No. 2, Cybersecurity, U.S. SEC. & Exch. Comm’n (Oct. 13, 2011) [hereinafter SEC Disclosure Guidance], https://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm.

[6] Andrew Ackerman, U.S. Chamber Warns Cyberattack Disclosures Could Hurt Corporate Profits, Wall Street J. (Oct. 29, 2014, 3:00 PM), http://www.wsj.com/articles/u-s-chamber-warns-cyberattack-discosures-could-hurt-corporate-profits-1414609209 (saying companies should disclose attacks to give customers a heads up because it’s the right thing to do in order for customers to protect themselves, even if no material adverse impact on the company itself results).

[7] Cory Bennett, SEC Weighs Cybersecurity Disclosure Rules, The Hill (Jan. 14, 2015, 6:00 AM), http://thehill.com/policy/cybersecurity/229431-sec-weighs-cybersecurity-disclosure-rules.

[8] See generally Robert Hackett, What to Know About the Ashley Madison Hack, Fortune (Aug. 26, 2015, 7:24 AM), http://fortune.com/2015/08/26/ashley-madison-hack.

[9] See generally Cheng, supra note 4.

[10] Nate Lord, The History of Data Breaches, Digital Guardian (Oct. 6, 2016), https://digitalguardian.com/blog/history-data-breaches.

[11] SEC Disclosure Guidance, supra note 5, at n. 3 (“Information is considered material if there is a substantial likelihood that a reasonable investor would consider it important in making an investment decision or if the information would significantly alter the total mix of information made available”); See also Dave Michaels, Hacked Companies Face SEC Scrutiny Over SEC Disclosure, Bloomberg (July 7, 2014, 11:28 AM), http://www.bloomberg.com/news/articles/2014-07-02/hacked-companies-face-sec-scrutiny-over-disclosure (“In guidance issued three years ago, the SEC said a cyber-attack could be material if it causes a company to significantly increase what it spends to defend its systems or when intellectual property is stolen. . . . Materiality is very open to interpretation[.]”).

[12] See Cybersecurity Roundtable, U.S. Sec. & Exch. Comm’n (Mar. 26, 2014), http://www.sec.gov/spotlight/cybersecurity-roundtable.shtml.

[13] Id.; See SEC Disclosure Guidance, supra note 5; See also Rick M. Robinson, Stock Price May Not Tell the Whole Story About Security Breaches, Security Intelligence (Aug. 13, 2015), https://securityintelligence.com/stock-price-may-not-tell-the-whole-story-about-security-breaches (“A further complication for stockholders and their advisers is that reporting of breaches is often delayed, and existing SEC regulation leaves leeway for public companies as to when to disclose cyber incidents.”).

[14]See generally Robinson, supra note 13 (“A company may be able to time the announcement so that it is followed swiftly by corrective action.”).

[15] See What We Do, U.S. Sec. & Exch. Comm’n, https://www.sec.gov/about/whatwedo.shtml (last modified June 10, 2013) (“The mission of the U.S. Securities and Exchange Commission is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation.”).

[16] See generally, About the FTC, U.S. Fed. Trade Comm’n, https://www.ftc.gov/about-ftc (last visited Oct. 11, 2016) (describing mission as “[t]o prevent business practices that are anticompetitive or deceptive or unfair to consumers”).

[17] See FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3rd Cir. 2015); See also Michael S. Dicke and Catherine Kevane, Return of the Cyborg—FTC and SEC Oversight of Cybersecurity Ramps Up, Mondaq (Sept. 21, 2015), http://www.mondaq.com/unitedstates/x/428214/Securities/Return+of+the+CyborgFTC+and+SEC+Oversight+of+Cybersecurity+Ramps+Up.

[18] See Summary of U.S. State Data Breach Notification Statutes, Davis Wright Tremaine, LLP, http://www.dwt.com/statedatabreachstatutes (last visited Oct. 11, 2016).

[19] See Robinson, supra note 13 (“Public news of a data breach can generate negative publicity, but a company may be able to time the announcement so that it is followed swiftly by corrective action.”).

[20] Bill Rigby, Cost of Data Breaches Increasing to Average of $3.8 Million, Study Says, Reuters, (May 27, 2015, 6:03 AM), http://www.reuters.com/article/2015/05/27/us-cybersecurity-ibm-idUSKBN0OC0ZE20150527.

[21] See Amy Terry Sheehan, Meeting Expectations for SEC Disclosure of Cybersecurity Risks and Incidents, Cybersecurity L. Rep., Aug. 12, 2015, at 1. http://www.davispolk.com/sites/default/files/agesser.Cybersecurity.Law_.Report.aug15.pdf.

[22] See Kvochko & Pant, supra note 2.

[23] Class action liability can flow from breach of contract liability. For example, after the Ashley Madison breach many users of the company’s service are suing for breach of contract because the company charged customers $19 to delete their actions without actually deleting the accounts. Perlroth, supra note 3.

[24] See infra, Part II; See also Ben Dipietro, The Morning Risk Report: Cybersecurity Disclosures Are Risky Business, Wall St. J.: Risk & Compliance J. (June 8, 2015, 7:25 AM), http://blogs.wsj.com/riskandcompliance/2015/06/08/the-morning-risk-report-cybersecurity-disclosures-are-risky-business-newsletter-draft (“[C]ompanies that have had breaches are in some respects setting the bar for companies that have not, as far as how to approach what to disclose. Best practices for disclosure are based on industry. . . .”).

[25] Because nearly all companies have been or are eventually breached these days, one source posits that shareholders hardly flinch at the news of data breaches anymore. See Kvochko & Pant, supra note 2 (saying that “[i]ndustry analysts have inferred that shareholders are numb to news of data breaches.”).

[26] See Sean Mason, Impact on Company Stock Following Data Breaches, InfoSec Insights (July 21, 2014), http://seanmason.com/2014/07/21/impact-on-company-stock-following-data-breaches; See also Sean Mason, Impact on Stock Following a Data Breach – Feb 2015 Edition, InfoSec Insights (Feb. 26, 2015), http://seanmason.com/2015/02/26/impact-on-stock-following-a-data-breach-feb-2015 (updating research). To see how many “incidents” versus actual breaches occur, see Verizon, 2015 Data Breach Investigations Report 3 (2015), https://www.arxan.com/wp-content/uploads/2015/05/rp_data-breach-investigation-report-2015_en_xg.pdf.

[27] Nathan Layne, In Wake of Target, Home Depot Tight with Info in Breach Response, Reuters (Sept. 8, 2014 1:28 PM), http://www.reuters.com/article/us-home-depot-dataprotection-disclosure-idUSKBN0H31UC20140908.

[28] See Catey Hill, Home Depot’s Data Breach Is Worse Than Target’s, So Where’s the Outrage? MarketWatch (Sept. 25, 2014 11:28 AM), http://www.marketwatch.com/story/yawn-who-cares-about-home-depots-data-breach-2014-09-24; Customer Data Breach Hits CVS Health Photo Site, Investopedia (July 21, 2015, 1:45 PM), http://www.investopedia.com/stock-analysis/072115/customer-data-breach-hits-cvs-health-photo-site-cvs-cost-hd-tgt-wmt.aspx (explaining that “Target is still recovering from the loss of customer trust that resulted from that breach, but much of the backlash was the result of how it had handled the affair, delaying the notification of customers that a breach had occurred. Companies seemed to have learned from that experience. Home Depot had more customers affected by a hack attack that occurred last year, but it notified consumers right away”).

[29]Paola Loriggio, Ashley Madison Hack Fails to Spur Cybersecurity Overhaul, CBC News (Dec. 25, 2015, 5:00 AM), http://www.cbc.ca/news/business/ashleymadison-hack-web-security-1.3380372 (Malcolm went on to say that “[m]aybe they’ve tightened up a few practices, but again, this is the kind of thing that receives attention only when it’s a screaming baby. After the baby’s not making any noise, everybody goes back to what they were doing.”).

[30] Id.

[31] See generally Data Breach FAQ, Target, https://corporate.target.com/about/shopping-experience/payment-card-issue-faq (last visited Sept. 27, 2016) (stating that Target is “sorry” for the breach).

[32] Perlroth, supra note 3 (reporting that Ashley Madison’s CEO stepped down from his position after the company’s hack, just as Sony Pictures Entertainment’s co-chairwoman and the CEO of Target stepped down after similar network breaches) (“Those ousters have made security a priority among executives. According to a survey . . . which tracks data breaches, only 13 percent of senior management said their concern about a data breach was extremely high before the breach at Target. That jumped to 55 percent after the incident . . . . [The founder of company that tracks data breaches stated,] ‘[t]he board is more concerned now than it has ever been with preserving the reputation of a company after a data breach. If the C.E.O. has to leave the company as a result, that’s the cost of doing business.’”).

[33] SEC Disclosure Guidance, supra note 5.

[34] See Cybersecurity Roundtable, supra note 12.

[35] Craig Calle, Disclosing the SEC’s Cybersecurity Disclosure Guidance, Source Callé (Aug. 10, 2015), http://sourcecalle.com/blog/2015/8/10/disclosing-the-secs-cybersecurity-disclosure-requirements.

[36] See Michaels, supra note 11; Luis Aguilar, Commissioner, Sec. & Exch. Comm’n, Board of Directors, Corporate Governance and Cyber-Risks: Sharpening the Focus (June 10, 2014), https://www.sec.gov/News/Speech/Detail/Speech/1370542057946.

[37] See What We Do, supra note 15.

[38] Id.

[39] “Material” is defined by the SEC in two primary cases: Basic Inc. v. Levinson, 485 U.S. 224, 231-32 (1988) and TSC Industries, Inc. v. Northway, Inc., 426 U.S. 438, 449 (1976).

[40] SEC Disclosure Guidance, supra note 5, at n. 3 (This also includes instances where “the information would significantly alter the total mix of information made available.”).

[41] See supra Part I.

[42] Michaels, supra note 11 (statement of Thomas Sporkin, a former SEC enforcement lawyer) (“Materiality is very open to interpretation.”).

[43] See Joel Schectman, When to Disclose a Data Breach: How About Never?, Wall Street J.: Risk and Compliance Report (Mar. 27, 2014 12:41 PM), http://blogs.wsj.com/riskandcompliance/2014/03/27/when-to-disclose-a-data-breach-how-about-never/ (describing different companies’ response to similar hacks).

[44] Michaels, supra note 11.

[45] See Sheehan, supra note 21, at 3.

[46] Id.

[47] See Securities Exchange Act of 1934, 17 C.F.R. § 240.10b-5 (2016).

[48] See id. § 240.14a-9.

[49] 17 C.F.R. § 240.10b-5. The scope of this note is too limited to warrant a discussion of fraud in the solicitation of proxy statements.

[50] See id.

[51] The definition of a security, as given by the Howey test, involves only “investment contracts” in which money is invested in a common enterprise with the expectation of profits derived solely from the efforts of a third party promoter. See SEC v. W.J. Howey Co., 328 U.S. 293, 298-299 (1946).

[52] See Chiarella v. United States, 445 U.S. 222, 234 (1980); Dirks v. SEC, 463 U.S. 646, 655 (1983); United States v. O’Hagan, 521 U.S. 642, 678 (1997).

[53] 17 C.F.R. 240 §§ 240.10(b), 10b-5 (describing antifraud provisions of the federal securities laws, which apply to statements and omissions both inside and outside of Commission filings).

[54] See Fast Answers for Form 10-K U.S. Sec. & Exchange Comm’n, https://www.sec.gov/answers/form10k.htm (last modified June 26, 2009).

[55] Dipietro, supra note 24 (emphasis added). See Kobi Kastiel, What’s New in 2015: Cybersecurity, Financial Reporting and Disclosure Challenges, Harv. L. Sch. F. on Corp. Governance and Fin, Reg. (Feb. 18, 2015), http://corpgov.law.harvard.edu/2015/02/18/whats-new-in-2015-cybersecurity-financial-reporting-and-disclosure-challenges.

[56] Kastiel, supra note 55.

[57] See generally Researching Public Companies Through EDGAR: A Guide for Investors U.S. Sec. & Exchange Comm’n, (July 18, 2007), https://www.sec.gov/investor/pubs/edgarguide.htm (describing information contained in the annual 10-K filing).

[58] Fast Answers for Form 8-K, supra note 54.

[59] Form 8-K, U.S. Sec. & Exchange Comm’n, https://www.sec.gov/about/forms/form8-k.pdf, §B(1).

[60] See Fast Answers for 8-K, supra note 54 at Item 8.01.

[61] Sheehan, supra note 21. Information given in the SEC’s disclosure guidance is “intended to assist registrants in preparing disclosure required in registration statements” but this does not limit registrants; instead, they should also consider “whether it is necessary to file reports on . . . Form 8-K to disclose the costs and other consequences of material cyber incidents.” SEC Disclosure Guidance, supra note 5, at n. 2.

[62] See Fast Answers for 8-K, supra note 54. See also Form 8-K, supra note 59 at §B(1), (“When considering current reporting on this form, particularly of other events of material importance pursuant to Item 7.01 (Regulation FD Disclosure) and Item 8.01 (Other Events), registrants should have due regard for the accuracy, completeness and currency of the information in registration statements filed under the Securities Act which incorporate by reference information in reports filed pursuant to the Exchange Act, including reports on this form.”).

[63] See Sheehan, supra note 21.

[64] See Dipietro, supra note 24 (quoting Jay Knight, a former SEC staffer and head of his law firm’s capital markets practice group).

[65] See generally Customer Data Breach Hits CVS Health Photo Site, Investopedia (July 21, 2015, 1:45 PM), http://www.investopedia.com/stock-analysis/072115/customer-data-breach-hits-cvs-health-photo-site-cvs-cost-hd-tgt-wmt.aspx (explaining how stores like Wal-Mart, CVS, and Costco have been upfront with their customers about breaches and how this honesty prevents a meltdown in consumer trust and protects investors).

[66] Language such as this can be found in state consumer notification laws. For example, Oregon (Or. Rev. Stat. Ann. § 646A.604(1)(a) (West, LEXIS through 2016 Sess.)) and South Carolina (S.C. Code Ann. § 39-1-90(a) (LEXIS through 2016 Sess.)) provide for the most expedient time possible and without unreasonable delay. Many states, including Pennsylvania (73 Pa. Cons. Stat. and Cons. Ann. § 2303(a) (West, Westlaw through 2016 Sess.)), Mississippi (Miss. Code Ann. § 75-24-29(3) (West, Westlaw through 2016 Sess.), and Missouri (Mo. Rev. Stat. § 407.1500(2)(1)(a)(LEXIS through 2016 Sess.)) say only “without unreasonable delay.” For more state laws, see Summary of U.S. State Data Breach Notification Statutes, supra note 18.

[67] Calle, supra note 35.

[68]What We Do, supra note 15.

[69] See Summary of U.S. State Data Breach Notification Statutes, supra note 18.

[70] See id.

[71] Ky. Rev. Stat. Ann. § 365.732 (Lexis Nexis, LEXIS through 2016 Sess.).

[72] See Why Incorporate in Delaware or Nevada?, BizFilings, http://www.bizfilings.com/learn/incorporate-delaware-nevada.aspx (Sept. 23, 2016).

[73]Del. Code Ann. tit. 6, § 12B-102(a) (LEXIS through 80 Del. Laws ch 399).

[74] See generally Summary of U.S. State Data Breach Notification Statutes, supra note 18 (showing a map of the United States and giving the online user the ability to click on each state and see their particular data breach notification statutes).

[75] Ohio Rev. Code Ann. § 1349.19(B)(2) (LexisNexis, LEXIS through file 123 (HB 483)).

[76] Fla. Stat. Ann. § 501.171(3)(a) (West, Westlaw through 2016 second regular sess.). Of the other states that have consumer notification laws, only these additional states have rigid timelines: Washington (Wash. Rev. Code Ann. § 19.255.010(16) (LexisNexis, LEXIS through 2016 1st Special Sess.) and Vermont (Vt. Stat. Ann. tit. 9, § 2435(b)(1) (LEXIS through 2015 adjourned sess. (2016))) mandate disclosure be made in the “most expedient time possible and without unreasonable delay,” no more than 45 days; Wisconsin (Wis. Stat. Ann. § 134.98(3)(a) (West, LEXIS through Acts of the 2015-2016 legislative sess.) mandates disclosures to consumers be made “within a reasonable time not greater than 45 days.”

[77] See Michaels, supra note 11 (urging firms to increase public reporting and weigh impact on consumers).

[78] Mike Lennon, Kroger Notifies Customers of Data Breach Stemming from Third-Party Email Vendor, Security Week (Apr. 1, 2011), http://www.securityweek.com/kroger-notifies-customers-data-breach-stemming-third-party-email-vendor; see Hayley Peterson & Ashley Lutz, Why Kroger is America’s Most Underrated Grocery Store, Business Insider (Mar. 6, 2015, 10:54 AM), http://www.businessinsider.com/why-people-love-kroger-2015-3 (“Nine out of 10 purchases at Kroger are made with the chain’s popular ‘Kroger Plus Card,’” [which makes] customers eligible for discounts, including fuel savings [and] gives Kroger unprecedented access into the behavior of its customers, and allows it to tailor promotions to individual shoppers.”).

[79] See generally Verizon, supra note 26 at page 3 (noting that the top three industries targeted and affected by security incidents are public, information, and financial services).

[80] Rigby, supra note 20.

[81] See What We Do, supra note 15 (“The mission of the U.S. Securities and Exchange Commission is to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation.”).

Read More
Online Originals Dylan Merrill Online Originals Dylan Merrill

A Fare Deal: The Reasonable Regulation of Ridesharing

Note | KLJ Managing Articles Editor Dylan Merrill discusses the regulation gap in the ride-sharing industry and how legislators should close the gap to ensure public safety while supporting an innovative new industry.

Note | 104 KY. L. J. ONLINE 17 | Sept. 28, 2015

Dylan Merrill[1]

Introduction

On New Year’s Eve 2013, Sayad Muzzafar was driving for the ridesharing company Uber when he struck a mother and her two children while they were crossing the street. That night, one of the children, a six year-old girl, died from her injuries.[2] The Liu family later sued the company, but Uber distanced itself from the accident, arguing it was not liable because Mr. Muzzafar did not have an Uber passenger in his vehicle when he struck the pedestrians.[3] At the time of the accident, policymakers had not implemented regulations for the new rideshare industry, further frustrating the goal of determining who in fact is liable in these circumstances.[4]This sad situation is only one example of how legal grey areas are cloaking ridesharing in uncertainty, creating a dire need for legal and regulatory certainty. However, since the law has historically struggled to keep pace with technological advances, these kinds of legal grey areas and the problems they pose are not anything new. For example, in 1863, the Supreme Court of the United States was faced with the issue of how to regulate steam engines and railroads according to laws that were passed long before the inventions became ubiquitous.[5] Justice Samuel Freeman Miller, writing for the majority, marveled at the complexity of bringing new technologies into the fold:Perhaps the most remarkable invention of modern times, in the influence which it has had, and is yet to have, on the affairs of the world . . . is the railroad system. It is not strange, then, that when we are called to construe a statute relating to this class of subjects, passed before a steam engine or railroad was thought of . . . we should be met by difficulties of the gravest character.[6]Implicit in the Court’s opinion is an insight into the dilemma posed by the creation of transformative technologies. On one hand, technological innovations carry an enormous promise: the potential to transform society for the better. At the same time, even the most promising inventions can bring with them serious threats to the safety of the community. Therefore, there is danger in not regulating a new technology to ensure its safe operation, just as there is danger in regulating it so much that the regulation restricts economic growth.While this language was written decades before the invention of the automobile, the words still ring true today. In the ridesharing context, there are two weighty public policy interests at play. First and foremost, as demonstrated above, there are legitimate public safety concerns inherent in a transportation service like ridesharing. Yet, this must be viewed through an economic lens as well. After all, ridesharing companies offer an innovative service that helps distribute scarce resources by providing a low-cost alternative to traditional taxis. This service benefits customers, and it also creates jobs. Therefore, the fairest and most effective regulatory scheme will carefully balance these two competing policy objectives.This balancing, however, is not easily done. Should ridesharing companies like Uber and Lyft be subject to the same standards as taxicab companies, such as Yellow Cab? How can regulators and legislators put in place rules that promote public safety without undermining the competitive advantage enjoyed by ridesharing? This Note proposes an answer to these difficult questions. Part I asks the question of whether ridesharing should be regulated, and submits that doing so would not only better protect the public, but also shore up the ridesharing business model. Part II lays out the regulatory landscape of ridesharing, focusing on the pressing issue of insurance liability. Ultimately, Part III proposes a roadmap for regulating ridesharing services—one that is fair, practical, and tailored to fit the needs of ridesharing companies, its customers, and the general public.

I. The Need for Ridesharing Regulation

Ridesharing closely resembles the services provided by traditional taxicab companies, although there are important distinctions between the two services. At its most basic, the ridesharing routine is the same as with taxicabs: a customer requests a ride, the driver takes the customer to the destination, and the customer pays for the ride.[7] However, unlike traditional cab services, ridesharing companies do not dispatch drivers, nor do they own the vehicles used to give rides.[8] Furthermore, companies like Uber and Lyft do not employ their drivers or dictate their work schedules, allowing drivers to choose to provide rides as frequently or infrequently as they wish.[9] In essence, these companies self-identify as smartphone application developers that merely license their technology to independent drivers.[10]But the question remains as to whether ridesharing poses risks to consumers and the general public, and if so, how to ensure regulation does not restrict the economic potential of ridesharing. To determine whether ridesharing companies should be regulated, it is useful to examine the impact of such companies, both positive and negative. The foremost benefit such companies provide is a dependable, convenient, and low-cost alternative to traditional taxicabs.[11] Although the competitive advantage of ridesharing has led, at least in part, to a decline in the taxicab industry, ridesharing undeniably gives consumers access to more transportation options.[12] Furthermore, ridesharing has the potential to benefit the general public by combatting widespread transportation and environmental issues such as traffic congestion and pollution.[13]But these economic and social improvements must be considered in light of the potentially harmful effect ridesharing could have on consumers and the general public.[14] Several public policy problems stem from the regulation—or lack thereof—of ridesharing companies, including but not limited to taxation, worker’s rights, licensing, background checks, distracted driving and other safety issues.[15] But perhaps the most pressing issue concerns insurance coverage. There is significant ambiguity regarding who is liable when an accident occurs—the driver or the ridesharing company.[16] If companies like Uber and Lyft are merely smartphone application providers and truly have an indirect involvement in the provision of ridesharing, then their liability for their drivers’ accidents should be minimal.[17] Jurisdictions that have not regulated ridesharing tacitly agree with this argument by allowing ridesharing companies to determine how much insurance—if any—they wish to provide for their drivers. The result is that ridesharing drivers’ liability in the event of an accident depends largely on the whims of their affiliated ridesharing company rather than a standardized and enforceable framework.This regulatory vacuum is dangerous, particularly in the insurance context. A ridesharing company’s commercial insurance covers a driver when the driver’s smartphone application is turned on and there is a customer in the vehicle.[18] However, its insurance does not cover a driver when the application is turned off.[19] In that situation, ridesharing companies argue that the driver is supposed to be covered by his or her personal car insurance.[20] Insurance providers, however, tend to disagree.[21] They consider ridesharing drivers to be involved in commercial activity and thus refuse to let ridesharing drivers use their personal insurance to cover accidents that happen on the job.[22] Insurers have clearly stated that “vehicles used for transporting passengers for a charge” are not covered by personal car insurance policies.[23] Consequently, some insurance providers have actually canceled the policies of customers who drive for Uber and Lyft.[24] And in some instances, insurers have even denied insurance applications based on an applicant’s intent to drive for a ridesharing company.[25] Thus, although ridesharing companies maintain that their drivers are covered by personal car insurance when their smart phone application is turned off, that is often not true.Furthermore, ridesharing drivers run the risk of liability even when their smartphone application is activated.[26] As noted above, drivers are covered by commercial insurance when their smart phone application is on and they are driving customers, but they are not covered by the commercial policy when the application is on and they are not carrying any passengers.[27] Therefore, since personal car insurance does not cover such commercial activity, drivers who are merely seeking customers run the risk of falling into an “insurance gap” in the event of an accident. Such was the case of Syad Muzzafar, the Uber driver who struck and killed Sophia Liu in San Francisco.[28] At the time, the driver was in between passengers but had not yet picked up another customer.[29] As a result, the driver’s insurance policy only provided a maximum of $15,000 to the victim’s family.[30] The company denied any liability for the accident, stating that “[t]he driver in question was not providing services on the Uber system during the time of the accident.”[31] This is only one example of the dire need for insurance standards in the ridesharing industry.Instituting such standards would protect drivers, passengers, and the general public as a whole, and it also has the potential to actually improve the bottom line of ridesharing businesses like Uber and Lyft. The enactment of ridesharing standards will provide regulatory certainty for ridesharing companies, allowing them to continue to grow their companies with less fear of how the government might intervene in the future.[32] This incentive had been demonstrated when ridesharing companies welcome the opportunity to work with local governments toward the regulation of their industry.[33] In turn, such third-party oversight will in theory inspire greater consumer confidence in the safety of ridesharing services.[34] Therefore, the prospect of a win-win-win outcome will incentivize regulators to promptly put in place standards that protect ridesharing companies and those affected by them.

II. Potential Regulatory Frameworks: California and Colorado Case Studies

The law has struggled to keep pace with rapid advance of the ridesharing economy. One reason for this is ridesharing is difficult to regulate, as it exists in a legal gray area.[35] As mentioned above, ridesharing providers are situated somewhere between traditional taxicab companies and smartphone application developers, and thus they have tended to disregard existing laws that are not specifically tailored to ridesharing.[36] Moreover, ridesharing services defy categorization into traditional regulatory frameworks, preventing many governments from developing tailored policy approaches to ridesharing.[37]Some states and municipalities, nevertheless, have begun regulating ridesharing companies. Although Congress has yet to legislate on the issue, some state and local governments have passed legislation or promulgated rules regarding services like Uber and Lyft.[38] The approaches differ greatly. For instance, some jurisdictions have banned most ridesharing services outright.[39] In the Commonwealth of Virginia, for example, ridesharing companies until recently were subject to civil penalties if they continued operating there.[40] In doing so, the state was adhering to its law that requires state authorization for passenger vehicles that are for-hire and it issued cease-and-desist orders to ridesharing companies that continued operations in Virginia.[41] The Department of Motor Vehicles found that, since drivers for companies like Uber get compensation for their services, they are more than just casual carpoolers.[42] Similarly, other state and local governments have suspended the operation of ridesharing services while they devise an appropriate regulatory framework.[43] Several states on the forefront, however, have taken the initiative and passed legislation regulating ridesharing services.[44]

A. California

In 2013, California became the first jurisdiction to legalize ridesharing.[45] Before regulations were put in place, the policy of the California Public Utilities Commission ("CPUC") was to issue fines and cease-and-desist letters to ridesharing companies, but it later allowed the companies to operate on an interim basis while draft regulations were considered.[46] The CPUC ruled that ridesharing services did not accord with any of the three existing regulatory categories: taxicab companies, charter-party carrier services (i.e., livery vehicles), or passenger-stage companies (e.g., airport shuttles).[47] Nevertheless, standards regulating the ridesharing industry were put in place, but they were promulgated under a completely new classification of transportation services called “Transportation Network Companies” (or “TNCs”).[48] According to the CPUC, this new category of services consists of “companies that provide prearranged transportation services for compensation using an online-enabled application (app) or platform to connect passengers with drivers using their personal vehicles.”[49] Ridesharing companies like Uber and Lyft fall under this definition, but traditional taxis and casual carpoolers do not.[50]Under California law, TNCs are subject to five key insurance-related provisions in the new regulations.[51] Perhaps the most important is the requirement that ridesharing companies provide insurance from the moment a driver turns on his or her smartphone application.[52] As noted above, this cuts against the general practice of ridesharing companies, which is to cover their drivers with commercial insurance only when their application is in use and there are passengers in the car.[53] In addition to being responsible for closing this insurance gap, TNCs are required to provide, at a minimum, $1 million in coverage.[54] This requirement lasts from the time a customer is picked up until the passenger has left the vehicle.[55] Drivers for TNCs, however, are also subject to additional insurance regulations. Drivers are responsible for maintaining primary commercial liability insurance coverage of at least $50,000 per person and $100,000 per occurrence of death and personal injury, as well as $30,000 for property damage.[56] In addition, drivers are also required to carry proof of their personal and commercial insurance coverage, and they must be at least twenty-one years of age a year or more of driving experience.[57] Lastly, the regulations call for the expedited review of new insurance policies that are tailored to the needs of TNC drivers.[58] Enforcement of these new regulations was delayed for one year and became subject to review by the CPUC after they were in place for the first year.[59] Although not all ridesharing companies were initially supportive of such regulations, the tide has begun to turn.[60] Notably, ridesharing companies have formed a coalition with insurance providers and government regulators, in order to collaborate on how to best comply with the new ridesharing rules.[61]

B. Colorado

Additionally, the State of Colorado has passed legislation enacting insurance regulations for ridesharing companies.[62] Like the California rules, the legislation puts in place new provisions that are unique to ridesharing companies and also classifies the provisions as “Transportation Network Companies.”[63] The Colorado legislation, however, defined TNCs differently than California’s regulations. Under the Colorado statute, a TNC is a company that “uses a digital network to connect riders to transportation network company drivers for the purpose of providing transportation” and “does not provide taxi service, transportation service arranged through a transportation broker, ridesharing arrangements, . . . or any transportation service over fixed routes at regular intervals.”[64] This definition nevertheless still subjects companies like Uber and Lyft to TNC rules and regulations. At the same time, the legislation exempts TNCs from the regulations imposed on common carriers, contract carriers, and motor carriers.[65] TNCs are also exempt from much of the Colorado Public Utilities Commission’s authority, including its ability to regulate rates.[66] The new legislation, however, does put in place a key regulation: it closes the insurance gap by requiring TNCs to provide commercial insurance coverage once the application is turned on, regardless of whether the driver is carrying a passenger.[67] This emphasis on commercial insurance rather than the driver’s personal policy is notable because, absent such a requirement, insurers would have had to raise rates for all vehicle policies in the state, regardless of whether they were used for ridesharing services.[68]Like California, Colorado requires TNCs to provide a minimum of $1 million in liability coverage.[69] Notably, Uber voluntarily provides $1 million in liability coverage beginning when a driver accepts a trip request.[70] Colorado’s legislation, however, goes further. It requires such coverage whenever the smartphone application is activated, irrespective of whether the driver has been matched with a passenger or is in route to pick one up.[71] This covers a larger portion of the insurance gap than either California’s insurance requirement or Uber’s voluntary commitment, neither of which mandate liability coverage until a passenger is assigned to the driver.[72] In addition, in Colorado, personal insurance policies must cover at least $50,000 per person and $100,000 per occurrence of death and personal injury, as well as $30,000 for property damage.[73] This amount, however, will be the subject of a required state agency study and could be increased in the future.[74] The ridesharing industry reaction to the passage of the legislation was overwhelmingly positive.[75]Although there are differences between California and Colorado’s insurance regulations, both have reclassified ridesharing as a wholly unique service, treating it differently from traditional taxicab providers. Furthermore, both regulatory frameworks agree that ridesharing companies should be responsible for closing the insurance gap. This consensus should not be overlooked as policymakers in other jurisdictions contemplate putting in place ridesharing regulations.

III. Which Regulations Work Best For Ridesharing?

As discussed above, the need for ridesharing standards is clear. Regulation not only protects drivers, passengers, and the general public as a whole, but it also has the potential to actually help the bottom line of ridesharing companies. The more difficult determination is what these regulations should look like.Effective regulation requires legally classifying ridesharing companies as their own unique category of transportation. As understood by states like California and Colorado, it does not make sense to try to regulate ridesharing drivers as if they were taxicabs or livery vehicles.[76] This square-peg-round-hole problem is best solved by developing a completely new classification (i.e., “Transportation Network Companies”) for ridesharing. The definition of a TNC should emphasize that TNCs are neither taxicab companies nor involved in traditional/informal ridesharing, as the Colorado legislature has specifically stated.[77]Furthermore, regulators must close the insurance gap for ridesharing drivers. The surest way of doing so entails, for one, requiring TNCs to provide a minimum amount of $1 million in liability coverage for their drivers.[78] Crucially, this coverage should mirror Colorado’s framework and kick in whenever the smartphone application is activated, irrespective of whether the driver has been matched with a passenger or is in route to pick one up. This will prevent drivers from having to shoulder too much financial risk. Furthermore, by placing more responsibility on TNCs (and therefore less on drivers’ personal policies), it prevents insurers from raising rates for all vehicle policies, regardless of whether they were used for ridesharing services.[79] That said, this arrangement does not work without baseline requirements for ridesharing drivers’ personal insurance policies. State and local governments should follow California’s example and hold drivers responsible for maintaining substantial primary liability insurance coverage.[80] Regulators can help ridesharing drivers comply with this requirement by ensuring expedited review of new insurance policies that are tailored to the needs of TNC drivers.[81] In sum, these insurance fixes will help create a more even distribution of financial risk among ridesharing companies and their drivers. More importantly, these regulations will help ensure that claimants in ridesharing-related actions have a better chance of obtaining full recovery.

IV. Conclusion

By expanding consumer choice and providing an efficient, dependable, and inexpensive alternative to other modes of transportation, ridesharing companies provide a net-benefit to society. At the same time, there are nevertheless dangers that come along with the rise of ridesharing. Governments, then, should not only put in place new ridesharing standards, but also ensure that such regulation does not come at the expense of the viability of the industry. To help achieve this goal, legislators and regulators should focus their efforts on solving pressing policy problems. As a first step, the ridesharing should be classified as a unique service and treated differently than traditional taxicab companies. Other jurisdictions should strongly consider California’s definition of Transportation Network Companies: companies “that provide[] prearranged transportation services for compensation using an online-enabled application (app) or platform to connect passengers with drivers using their personal vehicles.”[82] Furthermore, minimum insurance coverage baselines for companies and their drivers will provide a stronger safety net for those involved in ridesharing-related accidents. Specifically, states should require TNCs to provide at least $1 million in liability coverage for their drivers, and drivers should also need substantial primary liability insurance coverage—at least $50,000 per person and $100,000 per occurrence of death and personal injury. Lastly, ridesharing companies must be required to provide insurance coverage from the moment the smartphone application is turned on so that drivers and accident victims have much fuller legal and financial protection in the event of an accident. With these vital protections in place, we can help the ridesharing industry continue to provide its innovative services while also ensuring they shoulder a fair share of the risk they create. Legislators and policymakers would be wise to adopt this approach as a first—but crucial—step toward the reasonable regulation of ridesharing.


[1] J.D. expected, May 2016, University of Kentucky College of Law.

[2] Josh Constine, Uber’s Denial of Liability in Girl’s Death Raises Accident Accountability Question, TechCrunch (Jan. 2, 2014), http://techcrunch.com/2014/01/02/should-car-services-provide-insurance-whenever-their-driver-app-is-open/.

[3] Patrick Hoge, California May Expand Insurance Rules for Uber, Lyft et al., San Francisco Business Times (Mar. 25, 2014, 10:38 AM), http://www.bizjournals.com/sanfrancisco/blog/2014/03/california-insurance-rules-uber-lyft.html?page=all.

[4] Id.

[5] Bridge Proprietors v. Hoboken Co., 68 U.S. 116, 118 (1864).

[6] Id. at 146-47.

[7] Odette Yousef, Ridesharing vs. Taxicabs: The Inside Story, WBEZ (June 5, 2014), http://www.wbez.org/news/rideshare-vs-taxicabs-inside-story-110296.

[8] Id.

[9] Id.

[10] Adam Cecilon, The Insurance Secret that Uber Doesn’t Want You to Know, PolicyGenius Blog (Oct. 8, 2014), http://www.policygenius.com/blog/insurance-secret-uber-doesnt-want-know/.

[11] Peter Schworm, Passengers in the Middle of Ride-sharing Dispute, Boston Globe (Dec. 2, 2014), http://www.bostonglobe.com/metro/2014/12/02/city-council-hearing-discuss-potential-uber-lyft-regulation/a02o5C5DmnSc2LOarCpC9N/story.html.

[12] See, e.g., Megan Garber, After Uber, San Francisco Has Seen a 65% Decline in Cab Use, The Atlantic (Sept. 17, 2014), http://www.theatlantic.com/technology/archive/2014/09/what-uber-is-doing-to-cabs-in-san-francisco-in-1-crazy-chart/380378/.

[13] The Power of Connection: Peer-to-Peer Businesses: Hearing Before H. Comm. On Small Bus., 113th Cong. 6 (2014) (“Th[e] adoption of ride-sharing has the potential to produce large-scale public benefits, including easing traffic congestion and the strain on existing infrastructure, reducing pollution, and fostering a sense of community, all while providing car owners an opportunity to offset the cost of car ownership.”). These benefits are generated simply by people riding together who would otherwise be in separate vehicles. But ridesharing companies also augment these benefits, especially in the context of traffic congestion. For example, Uber developed a smartphone application that draws on a wealth of traffic-related data to help drivers find the most efficient route. Ryan Lawler, Uber Adds Turn-By-Turn Directions to Its Driver App, TechCrunch (Aug. 13, 2014), http://techcrunch.com/2014/08/13/uber-turn-by-turn-directions/.

[14] See generally Molly Cohen & Corey Zehngebot, What’s Old Becomes New: Regulating the Sharing Economy, 58 Boston Bar J. 34 (2014).

[15] Id.; Cecilon, supra note 10.

[16] Cecilon, supra note 10.

[17] Id.

[18] See, e.g., Nairi Hourdajian, Insurance for UberX with Ridesharing, Uber Blog (Feb. 10, 2014), http://blog.uber.com/ridesharinginsurance (detailing Uber’s insurance policy).

[19] Id.

[20] Id.

[21] Cecilon, supra note 10.

[22] Id.

[23] Jon Brooks, Confusion Over Insurance For “Ride-Sharing” Drivers, KQED.org: News Fix (Nov. 19. 2013), http://ww2.kqed.org/news/2013/11/14/who-pays-when-ride-share-driver-crashes.

[24] Jon Brooks, How Many Ride-Share Drivers Are Hiding Status From Insurers?, KQED.org: News Fix (Jan. 21, 2014), http://ww2.kqed.org/news/2014/01/20/ride-sharing-insurance-lyft-uberx-sidecar/.

[25] Id.

[26] Cecilon, supra note 10.

[27] Id.

[28] Marcus Wohlsen, Why Uber’s Fate Could Hinge on This Tragic Accident, Wired.com (Jan. 29, 2014, 6:30 AM), http://wired.com/2014/01/uber-wrongful-death. Uber and Sophia Liu’s family have since settled the lawsuit. Zach Miners, Uber Settles Suit over Girl Killed by Driver, PC World (July 14, 2015, 5:50 PM), http://www.pcworld.com/article/2948492/uber-settles-suit-over-girl-killed-by-driver.html.

[29] Id.

[30] Alexa Vaughn, Uber, Lyft Expanding Driver Insurance Coverage, Seattle Times (Mar. 14, 2014, 3:00 AM), http://seattletimes.com/html/localnews/2023125386_uberinsurancexml.html.

[31] Wohlson, supra note 28.

[32] The Power of Connection: Peer-to-Peer Businesses, supra note 13 at 6.

[33] Johana Bhuiyan, Here Is Where Uber and Lyft Are Facing Regulation Battles in the United States, BuzzFeed, (Dec. 15, 2014, 4:29 PM), http://www.buzzfeed.com/johanabhuiyan/here-is-where-uber-and-lyft-are-facing-regulation-battles-in#.ftEkba0vVA.

[34] Deven R. Desai, The New Steam: On Digitization, Decentralization, and Disruption, 65 Hastings L.J. 1469, 1477-80 (2013).

[35] Cohen & Zehngebot, supra note 14.

[36] Desai, supra note 34, at 1478.

[37] Id.

[38] Curtis Skinner, New Orleans Authorizes Uber—But Not UberX, Business Insider (Sept. 5, 2014, 8:02 AM), http://www.businessinsider.com/r-new-orleans-council-clears-uber-others-to-offer-luxury-online-taxi-service-2014-9.

[39] Sam Frizell, 5 Places Where Uber Is Fighting for Its Life Right Now, Time.com (Dec. 8, 2014), http://time.com/3623241/uber-battles (discussing locales which have banned or severely constrained Uber operations, including Portland, Oregon, and the State of Nevada).

[40] Paul Frisman, Uber's On-demand Car Service, Conn. Office of Legislative Research 4 (June 19, 2014), http://cga.ct.gov/2014/rpt/pdf/2014-R-0173.pdf (discussing different state approaches, including Virginia). Virginia legalized ridesharing earlier this year. Luz Lazo, Uber and Lyft Are Now Legal in Virginia, Washington Post (Feb. 18, 2015), http://www.washingtonpost.com/blogs/dr-gridlock/wp/2015/02/18/uber-and-lyft-are-now-legal-in-virginia/.

[41] Paul Frisman, Uber's On-demand Car Service, Conn. Office of Legislative Research 4 (June 19, 2014), http://cga.ct.gov/2014/rpt/pdf/2014-R-0173.pdf; Lazo, supra note 40.

[42] Paul Frisman, Uber's On-demand Car Service, Conn. Office of Legislative Research 4 (June 19, 2014), http://cga.ct.gov/2014/rpt/pdf/2014-R-0173.pdf.

[43] Paul Frisman, Uber's On-demand Car Service, Conn. Office of Legislative Research 4 (June 19, 2014), http://cga.ct.gov/2014/rpt/pdf/2014-R-0173.pdf; Lazo, supra note 40.

[44] Josh Richman, Uber, Lyft, Sidecar: New Insurance Requirements Approved by California Legislature (Aug. 28, 2014, 6:55 PM PDT), http://www.mercurynews.com/california/ci_26428057/california-senate-approves-new-insurance-requirements-uber-lyft; Andy Vuong, Colorado First to Authorize Lyft and Uber’s Ridesharing Services, Denver Post (June 5, 2014, 5:06:32 PM MDT), http://www.denverpost.com/business/ci_25907057/colorado-first-authorize-lyft-and-ubers-ridesharing-services?source=infinite.

[45] Tomio Geron, California Becomes First State to Regulate Ridesharing Services Lyft, Sidecar, Uber, Forbes (Sept. 19, 2013, 3:40 PM), http://www.forbes.com/sites/tomiogeron/2013/09/19/california-becomes-first-state-to-regulate-ridesharing-services-lyft-sidecar-uberx/.

[46] Id.

[47] Decision 13-09-045 Adopting Rules and Regulations to Protect Safety While Allowing New Entrants to the Transportation Industry, Cal. Pub. Utilities Comm’n 11 (Sept. 23, 2013), http://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M077/K192/77192335.PDF.

[48] Geron, supra note 45.

[49] Press Release, California Public Utilities Commission, CPUC Establishes Rules For Transportation Network Companies (Sept. 19, 2013), http://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M077/K132/77132276.PDF.

[50] Geron, supra note 45.

[51] Assemb. B. 2293, 2013-2014 Assemb., Reg. Sess. (Cal. 2014), available at http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB2293.

[52] See id.

[54] Id.

[55] Id.

[56] Assemb. 2293 §5433(c)(1), 2013-2014 Assemb., Reg. Sess. (Cal. 2014), available at http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB2293.

[57] Decision 13-09-045 Adopting Rules and Regulations to Protect Safety While Allowing New Entrants to the Transportation Industry, Cal. Pub. Utilities Comm’n 26-27 (Sept. 23, 2013), http://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M077/K192/77192335.PDF.

[58] Id. § 5438.

[59] Geron, supra note 45.

[60] California Welcomes Insurance Coalition for Ride Sharing, Uber Joins In, GovTech.com, (Feb. 10, 2014), http://www.govtech.com/state/California-Welcomes-Insurance-Coalition-for-Ride-Sharing-Uber-Joins-In.html.

[61] Id.

[62] S.B. 14-125, 69th Gen. Assemb., Reg. Sess. (Colo. 2014), available at http://www.leg.state.co.us/clics/clics2014a/csl.nsf/fsbillcont2/70364091166B28FC87257C4300636F6B/$FILE/125_01.pdf.

[63] Id. at 2, 6.

[64] Id. at 6.

[65] Id. at 2.

[66] Id.

[67] Niraj Chokshi, Colorado Passes Nation’s First Law Regulating UberX, Lyft, Washington Post (June 6, 2014), http://www.washingtonpost.com/blogs/govbeat/wp/2014/06/06/colorado-passes-nations-first-law-regulating-uberx-lyft/.

[68] See Vuong, supra note 44.

[69] Kelli Kelty, Colo. Legislative Counsel Staff, Transportation Network Companies, Gen. Assemb. 14-07, Reg. Sess. (2014), available at http://cdn.colorado.gov/cs/Satellite?blobcol=urldata&blobheader=application%2Fpdf&blobkey=id&blobtable=MungoBlobs&blobwhere=1252019169757&ssbinary=true.

[70] Nairi Hourdajian, Eliminating Ridesharing Insurance Ambiguity, Ins. Note (Mar. 14, 2014), http://insurancenote.net/warranty-entitling-the-holder-to-care-at-home/eliminating-ridesharing-insurance-ambiguity/.

[71] Norma B. Levy & Louis H. Kozloff, Ridesharing Presents Challenges and Opportunities for Insurers, Property Casualty 360º, (Oct. 21, 2014), http://www.propertycasualty360.com/2014/10/21/ridesharing-presents-challenges-and-opportunities?page=2.

[72] See id.

[73]Insurance Designed with Uber in Mind, Uber, http://uberxcolorado.com/drive/?page_id=483 (last visited Sept. 17, 2015).

[74] Chokshi, supra note 67.

[75] See Colorado Makes Uber History, Uber Newsroom, (June 5, 2014), available at http://newsroom.uber.com/denver/2014/06/colorado-makes-uber-history-2/ (Uber calling the regulations “stringent” yet “sensible.”). Kathleen Lavine, Colorado Passes Bill Legalizing UberX, Lyft, Denver Bus. J. (Apr. 29, 2014, 5:46 PM MDT), available at http://www.bizjournals.com/denver/blog/boosters_bits/2014/04/colorado-passes-bill-legalizing-uberx-lyft.html (Lyft saying were “thrilled” by the “rigorous set of safety standards.”).

[76] See Decision 13-09-045 Adopting Rules and Regulations to Protect Safety While Allowing New Entrants to the Transportation Industry, Cal. Pub. Utilities Comm’n 2 (Sept. 23, 2013), http://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M077/K192/77192335.PDF.

[77] S.B. 14-125, 69th Gen. Assemb., Reg. Sess. (Colo. 2014), http://www.leg.state.co.us/clics/clics2014a/csl.nsf/fsbillcont2/70364091166B28FC87257C4300636F6B/$FILE/125_01.pdf.

[78] Hourdajian, supra note 70.

[79] Andy Vuong, Colorado Lawmakers Still Wrangling Insurance for Lyft, UberX, Denver Post (Apr. 2, 2014, 6:41:13 PM MDT), http://www.denverpost.com/business/ci_25480333/colorado-lawmakers-still-wrangling-insurance-lyft-uberx.

[80] See Assemb. B. 2293 § 5433, 2013-2014 Assemb., Reg. Sess. (Cal. 2014), available at http://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=201320140AB2293.

[81] See id. § 5438.

[82] See Decision 13-09-045 Adopting Rules and Regulations to Protect Safety While Allowing New Entrants to the Transportation Industry, Cal. Pub. Utilities Comm’n 2 (Sept. 23, 2013), http://docs.cpuc.ca.gov/PublishedDocs/Published/G000/M077/K192/77192335.PDF.

Read More
Online Originals Matthew Hlinka Online Originals Matthew Hlinka

Will Kentucky Fall Victim to the EPA's War on Coal? Examining the Commonwealth's Options Under the Newest Power Plant Emission Standards

Note | KLJ Production Editor Matt Hlinka examines the potential impact of new proposed regulations of coal power plant emissions on Kentucky.

Note | 103 KY. L. J. ONLINE 6 | Apr. 28, 2015

Matthew Hlinka[1]

Introduction

Coal continues to play an integral part in the development of modern society. Coal keeps our families warm, fuels our trains, and provides electricity for our homes, factories, and cities.[2] The United States is currently the second largest consumer of electricity in the world.[3] In order to satisfy this veracious demand for energy, the United States has long relied on its extensive coal reserves, the largest in the world.[4] In fact, approximately half of the electricity generated in the United States over the last fifty years has come from coal.[5]

[Coal’s benefits, however, are accompanied by several serious drawbacks. For instance, the list of undesirable pollutants released by the burning of coal includes mercury, sulfur dioxide, particulate matter, and carbon dioxide.[6] Balancing these issues has been a constant challenge for the industry.The most recent attempt to balance came from the Environmental Protection Agency (EPA), who at the urging of President Barrack Obama, published its two newest proposed regulations for power plant emissions in 2014.[7] These regulations would cap the emissions of carbon dioxide for new coal-fired power plants at 1,100 pounds per megawatt-hour (MW-h),[8] while also reducing the emissions from existing plants by 30% by 2030.[9] Observers speculate that these new emission standards will be so stringent as to render new coal-fired power plants financially impractical to build.[10]Additionally, these new regulations will have a profound impact on the coal industry in Kentucky. A nationwide decrease in demand for coal will directly harm an industry that employs thousands of people. Without the cheap energy that Kentucky residents currently enjoy from coal, it will be difficult to attract new manufacturing employers, indirectly curtailing the economic prosperity of hundreds of thousands of Kentuckians. This is a serious problem because Kentucky’s coal producing counties are already financially depressed.[11] Severe restraints on the coal industry could cripple those areas beyond repair.This note seeks to address the issues caused by the new regulations. Section I of this Note analyzes the history of the Clean Air Act and the EPA’s proposed regulations for new and existing emission sources. Section II examines Kentucky’s political, legal, and technological options in dealing with these regulations in both the short and long term. Section III argues that Kentucky must fight the standards through a combined approach of using both legal and political channels in order to buy the state additional time for researching and implementing new technologies.

I. Background

A. History of the Clean Air Act

In response to growing concerns over poor air quality in industrial areas, Congress passed the Clean Air Act of 1963, the first federal legislation concerning air pollution control.[12] This version of the Act provided funding for air pollution research and cleanup but did not set up a federal regulating authority.[13] Seeking more federal oversight, Congress passed a much stronger version in 1970 creating the EPA and giving it the primary authority in carrying out the Clean Air Act.[14]The 1970 amendments to the Clean Air Act required the EPA to identify air pollutants, determine air pollution criteria, and issue air pollution goals to the states.[15] The EPA must also issue recommended techniques for the states to meet those goals.[16] After receiving the EPA’s national recommendations, each state is required to create and adopt a plan to meet the EPA’s standards by certain statutory deadlines.[17]One exception to this national-state arrangement is that the EPA was required to create federal standards to regulate “new sources.”[18] The statute defines new sources as “any stationary source, the construction or modification of which is commenced after the publication of regulations.”[19] In addition to dividing up the regulatory power over stationary sources among federal and state governments, this exception effectively creates newer, stricter requirements for new plants while allowing existing sources to remain “grandfathered in” and subject to less restrictive standards.[20] In doing so, Congress recognized that it is cheaper to incorporate new technology into the design and construction of new units than to squeeze more efficiency out of existing units. Additionally, industrial facilities do not last forever. As units become obsolete and are replaced, new units will automatically increase in efficiency as they meet the new standards.However, when the grandfathering policy was created, Congress was operating under an erroneous assumption that coal-fired power plants would have a usable life of only thirty years.[21] Yet as statistics show, 74% of coal power plants in existence in 2012 were already more than thirty years old.[22] Some states and environmental groups have criticized the grandfathering policy, arguing that it encourages owners of older, obsolete plants to continue their plants’ operation well beyond their normal lifetimes in order to avoid meeting the stricter requirements.[23]As the pollution standards for coal plants become more and more restrictive, it becomes even less enticing for owners to shut down existing plants and sink large amounts of capital into new, expensive power plants that must meet the New Source benchmarks. This stubborn refusal to submit to the plant turnover once thought to be inevitable has kept the New Source regulations from being as effective as many had hoped. With environmental issues like air pollution and global climate change receiving increased attention from the public, lawmakers have been forced to balance the advantages of having access to an economical, abundant energy source independent of foreign government’s control against coal’s environmental drawbacks.

B. President Obama’s Climate Action Plan

In 2013, President Obama’s announced his Climate Action Plan.[24] One of the goals of the Climate Action plan was to reduce power plant pollution.[25] Power plants account for roughly one-third of all greenhouse gas emissions in the United States, the largest source of emissions in the country.[26]In line with the president’s directive, the EPA proposed new carbon pollution standards for new power plants under 42 U.S.C. § 7411(b) on September 20, 2013.[27] Existing coal-fired power plants currently emit, on average, 1768 pounds of carbon dioxide per MW-h.[28] Under these proposed rules, large natural gas-fired turbines must emit less than 1,000 pounds of carbon dioxide per MW-h, while new, small natural gas-fired turbines must emit less than 1,100 pounds of carbon dioxide per MW-h.[29] New coal-fired units must emit less than 1,100 pounds of carbon dioxide per MW-h or, to provide plants the flexibility and time to optimize technologies, between 1,000 and 1,050 pounds of carbon dioxide per MW-h on average over eighty-four months of operation.[30] If met, these new standards would constitute a massive improvement over current pollution levels.However, critics question whether it is possible to meet these standards with existing coal technology.[31] In order to reach these New Source requirements, utilities would most likely have to utilize carbon capture and sequestration technology, a process in which a portion of the carbon dioxide emitted is captured and stored underground in deep-lying geological layers.[32] Under the right temperature and pressure, the carbon dioxide is maintained in the liquid phase and can be isolated from the Earth’s atmosphere for an extend period of time.[33] Nonetheless, carbon capture technology has not yet advanced to the point where it is commercially feasible and development of this technology has slowed in recent years.[34] Many advocates for coal believe this attempt by Congress to force new plants to use technology that is not feasible is designed to halt new coal plant construction altogether.[35]On June 2, 2014, the EPA unveiled the Clean Power Plan, a proposed regulation intended to cut nationwide carbon emissions by existing power plants 30% by 2030.[36] Rather than achieve this goal through a uniform standard, the EPA issued state-specific targets allowing each state considerable flexibility in determining how they will reach this objective.[37] States that rely significantly on coal, such as Kentucky, are not required to reduce their emission rates as much as the other states. For example, Kentucky would need to reduce its carbon emissions from 2,158 pounds of carbon dioxide per MW-h in 2012 to 1,763 pounds per MW-h in 2030, a decrease of approximately 18%.[38] This goal may not be as difficult to reach as many have feared. State officials estimate that Kentucky has already decreased its emissions to 1,951 pounds per MW-h in 2014, which would put Kentucky slightly more than halfway to meeting its target.[39]

II. Kentucky’s Options

With poverty levels in coal country already at high levels,[40] changes in the coal industry regulations may be overwhelming. Kentucky does, however, have a few options. Kentucky’s first option is to fight, through the political and legal systems, to keep the regulatory standards from being adopted. If the largest coal-producing states can get the proposed regulations weakened or delay the propagation of the regulations until a more coal-friendly administration is in place, the damage could be mitigated. The second option is to focus on researching cleaner energy sources. This includes examining alternative energy sources and searching for technological breakthroughs that would allow coal-fired power plants to meet the EPA standards while remaining economically feasible. Regardless of the choice, Kentucky must act quickly to position itself for long-term success.

A. Fighting the Standards Through the Adequate Technology Requirement

If Kentucky chooses to fight the EPA’s standards, they can make a strong argument that existing technology is not adequate to reach the proposed limits. Under the Clean Air Act, the EPA is required to impose regulations that are achievable based on current technology.[41] If the Administrator does not believe that the standards can be reached with technology that has been “adequately demonstrated,” she can promulgate an alternative that has been adequately demonstrated to be both economically and technically feasible.[42]In the proposed regulation published in January 2014, the EPA references a state-of-the-art coal power plant being built in Kemper County, Mississippi to support the feasibility of carbon capture and sequestration technology.[43] This reference is not without flaws. Although the Kemper County plant is scheduled to begin operations later this year, construction has been repeatedly delayed and the project is already projected to be $2 billion over budget.[44] One could make a strong argument that a plant that is not even generating electricity yet cannot adequately demonstrate the technology. Additionally, even if the plant is able to perform as planned, that does not demonstrate that the technology is feasible nationwide, as the Kemper County plant has certain advantages that other locations may not enjoy, such as a local oil field that can be used for storing the captured carbon.[45]There is evidence that even some internal factions of the EPA feel the agency is going too far. In November 2013, shortly after the proposed standards for existing power plants were released, the EPA’s Science Advisory Board (SAB), whose principle mission is to advise the EPA on scientific and technical matters,[46]released a memorandum discussing the proposal.[47] In that memorandum, the SAB challenges the adequacy of the EPA’s research on the matter calling the studies relied on by the EPA “inadequate” and stating that the “scientific and technical basis for carbon storage provisions is new science and the rulemaking would benefit from additional review.”[48]Interestingly enough, the SAB reversed course on this recommendation two months later in a subsequent memorandum.[49] Citing a fact-finding teleconference, the SAB recommended that it should not review the scientific basis for the proposed rule because the rule does not explicitly require carbon capture and sequestration technology and allows for utilities to reach the standards through other means, if they can.[50] This statement is baseless. In the published proposed standards themselves, the EPA discusses three ways for coal-fired power plants to meet the requirements.[51] Two of these alternatives involve carbon capture and sequestration, and the third involves super-critical or ultra-critical boilers or Integrated Gasification Combined Cycle units.[52] Moreover, the EPA essentially writes off this last option a few sentences later because “they do not provide meaningful reductions in CO2 emissions.”[53] By stating this, the EPA is essentially saying that it has no idea how power plants are going to meet these new standards and little desire to find out. Thus, a strong case can be made that the EPA is failing to meet the Clean Air Act’s “current technology” requirement.

B. Federal Authority to Regulate Existing Sources

Kentucky can also argue that the federal government does not have the power to directly regulate existing power plants under the Clean Air Act. The Clean Air Act only authorizes the EPA to promulgate standards for new emission sources.[54] While the Clean Air Act does allow the EPA to require states to issue standards for existing power plants, the EPA is only allowed to guide states procedurally in the endeavor, such as requiring states to apply the factors under 42 U.S.C. § 7411(a)(1).[55] Furthermore, § 7411(d) does not give the EPA the authority to reject a state plan that contains a standard of performance as defined by the statute.[56] States have the ultimate authority to define the substantive standards.Although the June 2014 Clean Power Plan gives more deference to the states than most anticipated, the EPA may have still overstepped its bounds under the Clean Air Act. An argument can be made that its actions violate public policy and the principles of cooperative federalism clearly defined by § 7411(d). Intuitively, the states are generally in a better position to determine the feasibility of any proposed changes and can more accurately measure how those changes will affect local communities.The EPA’s failure to follow the Clean Air Act’s requirements for issuing standards based on existing technology and allowing states to promulgate regulations for existing emission sources can be challenged in court. A lawsuit can be expected whenever a more concrete proposal is in place. In fact, the attorneys general of seventeen states, including Kentucky, submitted a letter to the EPA in September of 2013 detailing their concerns with the EPA’s actions.[57] This letter contends that the “EPA, if left unchecked, will continue to implement regulations which far exceed its statutory authority to the detriment of the states, in whom Congress has vested authority under the Clean Air Act, and whose citizenry and industries will ultimately pay the price of these costly and ineffective regulations.”[58] This letter is clearly an announcement that the states will challenge the EPA’s authority.Locally, United States Senator Mitch McConnell (R-Ky.) has already taken steps to challenge the EPA standards. After the EPA published its rule for new power plants in January, 2014, McConnell announced his plans to force a vote to stop the regulations.[59] McConnell aims to stop the regulations through the Congressional Review Act, which allows Congress to review new federal regulations issued by agencies and overrule them through a joint regulation.[60] Although the Review Act can usually only be applied to final rules, McConnell argues that the mere publication of the new rules are enough to immediately impact any plans for the construction of new power plants and, therefore, the Review Act can be utilized now.[61]Regardless of the outcome of these attempts to impede the EPA’s regulations, it is encouraging to see Kentucky’s leaders at the forefront of the effort. At the very least, these efforts at slowing down the rulemaking process buys the state time. Considering the large differences in policy between the Bush administration and the Obama administration in regards to coal, Kentucky’s solution may be as simple as stalling until the 2016 presidential election in hopes that a more coal-friendly candidate is elected. Alternatively, if the states succeed in their argument that the EPA does not have the authority to regulate existing power plants under the Clean Air Act, the states can procrastinate issuing their own standards in hopes that either a technological breakthrough is made or the EPA decides to soften their stance on coal. For these reasons, Kentucky’s current plan of action appears to be a step in the right direction for the short term. However, with the current political focus on global climate change, stricter emission standards are inevitable. To best position itself for the future, Kentucky needs to investigate both technological improvements in clean-coal usage and alternative energy sources.

III. Kentucky’s Best Approach

As the EPA finalizes its carbon regulations for existing and new emission sources, Kentucky must be proactive in seeking solutions to Kentucky’s future energy issues. Although fighting the proposed standards in court and through the political and rulemaking processes is a short-term strategy that should be pursued in order to buy the state time, it has become abundantly clear that large emitters of greenhouse gases are becoming less and less politically acceptable. It is only a matter of time before existing coal technology is no longer feasible in this country. Kentucky needs to prepare itself for that day.Kentucky’s immediate short-term strategy should be to fight the standards in court. There are at least two main arguments that can be used to attack the EPA’s actions. The first is the “adequately demonstrated” technology requirement. As it currently stands, carbon capture and sequestration is the only way that coal plants can meet these emissions standards, but that technology is not yet feasible and may not be for decades.[62] The EPA is presenting the Kemper County plant as a model of carbon capture and sequestration technology, but that project is extremely over budget, still under construction, and that technology may not even be compatible with Kentucky’s natural geographical and geological characteristics.[63] Thus, Kentucky should argue that the EPA must be forced to follow the statutory requirements of § 7411 so that Kentucky has a fighting chance to succeed.Kentucky’s second legal option is to attack the EPA’s attempts to directly regulate existing sources because this power belongs to the states. Although this argument will not help Kentucky deal with the New Sources requirements that have already been published, attempting to retrofit existing coal plants or being forced to shut down non-compliant plants altogether may be catastrophically expensive and burdensome. The EPA must be forced to operate within the limits of its statutory authority.Regardless of whether coal remains a feasible source of electricity, Kentucky needs to start moving towards alternative energy sources. If the EPA’s standards are successful, this shift will be out of necessity, but even if the EPA’s standards are not allowed in their current form this time around, it certainly appears that it is only a matter of time before a major crackdown on carbon emissions is promulgated. Considering the political climate, it is too risky to continue depending on coal for over 90% of the state’s electricity.

IV. Conclusion

This Note has explored the effect that the EPA’s proposed New Source emission requirements, and its forthcoming existing source emission requirements, will have on Kentucky. These standards have the potential to devastate Kentucky’s coal mining industry and the affordable electricity rates Kentuckians currently enjoy.This Note proposes that Kentucky’s leadership continue to fight the EPA’s standards politically and legally. It is in Kentucky’s best interests to do everything possible to keep the standard from being adopted or, at the very least, delay their implementation for as long as possible in order to give the state more time to prepare. This Note advocates for Kentucky’s vigilance in seeking out viable alternative energy sources. It is unwise to be so heavily reliant on coal in this current political climate and Kentucky must work to reduce this dependence. Natural gas is the most attractive option in the short term, but it may be only a matter of time before carbon emission standards strangle that option as well. Kentucky would be wise to maintain a diverse energy portfolio, fully examining the local feasibility of nuclear, biomass, and solar energy resource.


[1] University of Kentucky College of Law, J.D. May 2015.

[2] Roberta Mann, Another Day Older and Deeper in Debt: How Tax Incentives Encourage Burning Coal and the Consequences for Global Warming, 20 Pac. McGeorge Global Bus. & Dev. L.J. 111, 111 (2007).

[3] The United States ranks second only to China. CIA, The World Factbook: Country Comparison: Electricity – Consumption, CIA, https://www.cia.gov/library/publications/the-world-factbook/rankorder/22… (last visited April 14, 2015).

[4] See Coal Proved Reserves by end of 2011, Europe’s Energy Portal, http://www.energy.eu/stats/energy-coal-proved-reserves-total.html (last visited April 14, 2015).

[5] Approximately 46% of all electricity nationwide in 1970 was generated from coal. See U.S. Energy Info. Admin., Monthly Energy Review: Electricity Net Generation, (March 2015), available at http://www.eia.gov/totalenergy/data/monthly/pdf/sec7_5.pdf. This number rose to 57% in 1985, and 52% in 2000. Id.

[6] Patricia Glick, The Toll from Coal: Power Plants, Emissions, Wildlife, and Human Health, 21 Bull. of Sci., Tech. & Soc’y 482, 482 (2001); Thomas O. McGarity, When Strong Enforcement Works Better Than Weak Regulation: The EPA/DOJ New Source Review Enforcement Initiative, 72 Md. L. Rev. 1204, 1209–10 (2013).

[7] See Carbon Pollution Emission Guidelines for Existing Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 34, 830 (June 18, 2014) (to be codified at 40 C.F.R. pt. 60); Standards of Performance for Greenhouse Gas Emissions from New Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 1430 (Jan. 8, 2014) (to be codified at 40 C.F.R. pt. 60).

[8] Standards of Performance, 79 Fed. Reg. at 1448.

[9] Press Release, EPA, EPA Proposes First Guidelines to Cut Carbon Pollution from Existing Power Plants (June 2, 2014), available at http://yosemite.epa.gov/opa/admpress.nsf/bd4379a92ceceeac8525735900400c2.

[10] Keith Johnson & Tennille Tracy, EPA Plan to Curb New Coal-Fired Power Plants, Wall St. J. (Sept. 11, 2013, 9:00 PM), http://online.wsj.com/article/SB1000142412788732386460457906955091602126.

[11] Office of Press Secretary, Fact Sheet, The White House (Jan. 8, 2014), https://www.whitehouse.gov/the-press-office/2014/01/08/fact-sheet-presid.

[12] EPA, Understanding the Clean Air Act, EPA.gov, http://www.epa.gov/airquality/peg_caa/understand.html (last updated Oct. 28, 2014).

[13] Id.

[14] Id.

[15] 42 U.S.C. § 7408 (2013).

[16] Id.

[17] Id. § 7410 (2013).

[18] Id. § 7411(b) (2013).

[19] Id. § 7411(a)(2).

[20] Jonathan R. Nash & Richard L. Revesz, Grandfathering and Environmental Regulation: The Law and Economics of New Source Review, 101 Nw. U. L. Rev. 1677, 1678 (2007).

[21] Shi-Ling Hsu, Reducing Emissions from the Electricity Generation Industry: Can We Finally Do It?, 14 Tul. Envtl. L.J. 427, 435 (2001).

[22] Todd Woody, Hitting the Gas: Most coal-fired power plants in the US are nearing retirement age, Quartz (Mar. 12, 2013), http://qz.com/61423.

[23] Nash & Revesz, supra note 20, at 1678.

[24] Executive Office of the President, The President’s Climate Action Plan (2013), available at http://www.whitehouse.gov/sites/default/files/image/president27sclimatea.

[25] Id. at 6.

[26] Id.

[27] Jeff Postelwait, Gina McCarthy Introduces EPA’s Revised Rules for New Power Plants, Electric Lights & Power (Sept. 20, 2013), http://www.elp.com/articles/2013/09/gina-mccarthy-introduces-epa-s-revis…].

[28] Id.

[29] Standards of Performance for Greenhouse Gas Emissions from New Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 1430, 1446 (Jan. 8, 2014) (to be codified at 40 C.F.R. pt. 60).

[30] Id. at 1448.

[31] See Joanna M. Foster, EPA Publishes First Rule Limiting Carbon Pollution From New Power Plants, Think Progress (Jan. 9, 2014, 12:48 PM), http://thinkprogress.org/climate/2014/01/09/3139921/epa-carbon-rule-powe.

[32] Id. The three main types of geological formations that are being considered for carbon sequestration include: oil and gas reserves, deep saline reservoirs, and unmineable coal seams. Peter Folger, Cong. Research Serv., Carbon Capture and Sequestration (CCS): A Primer 4 (2013), available at https://www.fas.org/sgp/crs/misc/R42532.pdf. It is also theoretically possible to store large amounts of carbon deep beneath the ocean’s surface. Id. at 13. Deep ocean sequestration involves injecting the captured carbon dioxide at depths around 3000 meters. Id. At these depths, carbon dioxide is a liquid denser than seawater, so the injected carbon dioxide would remain at the bottom. Id. However, there are a number of environmental concerns associated with deep ocean sequestration because large-scale implementation could cause the ocean to become more acidic. Id. at 14.

[33] In Clean Coal We Trust – or Do We?, ParisTech Rev. (Oct. 15, 2013), http://www.paristechreview.com/2013/10/15/clean-coal-trust.

[34] Matthew L. Wald, Despite Climate Concern, Global Study Finds Fewer Carbon Capture Projects, N.Y. Times (Oct. 10, 2013), http://www.nytimes.com/2013/10/11/science/earth/study-finds-setbacks-in-.

[35] Foster, supra note 31.

[36] The 30% reduction is from 2005 levels. Using 2005 as the baseline is beneficial for carbon emitters, as the EPA’s proposal is actually only a 17% decrease from 2012 levels. David Doniger & Derek Murrow, The Clean Power Plan: NRDC’s Initial Analysis of EPA’s Landmark Proposal to Curb Carbon Pollution from the Nation’s Power Plants, Switchboard (June 7, 2014), http://switchboard.nrdc.org/blogs/ddoniger/the_clean_power_plan_nrdcs_in.

[37] Press Release, EPA, supra note 9.

[38] James Bruggers, Kentucky, Indiana Get Head Start on Global Warming Regs, Courier J. (June 13, 2014, 4:55 AM), http://www.courier-journal.com/story/tech/science/environment/2014/06/12…. Some environmentalists had been pushing for a 45% decrease in Kentucky’s carbon dioxide emission rate. Id. Other states face much larger reductions. Washington state, for example, has been called upon to reduce reductions by 84% by 2030. Coral Davenport & Peter Baker, Taking Page From Health Care Act, Obama Climate Plan Relies on States, N.Y. Times (June 2, 2014), http://www.nytimes.com/2014/06/03/us/politics/obama-epa-rule-coal-carbon.

[39] Bruggars, supra note 38.

[40] Annie Lowrey, What’s the Matter with Eastern Kentucky?, N.Y. Times Mag. (June 26, 2014), http://www.nytimes.com/2014/06/29/magazine/whats-the-matter-with-eastern.

[41] See 42 U.S.C. § 7411(h) (2013).

[42] Id.

[43] Standards of Performance for Greenhouse Gas Emissions from New Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 1430, 1435 (Jan. 8, 2014) (to be codified at 40 C.F.R. pt. 60).

[44] Reality vs. EPA’s Carbon Capture Dreams, Inst. for Energy Research (Jan. 8, 2014), http://www.instituteforenergyresearch.org/2014/01/08/reality-vs-epas-car.

[45] Southern Cautions on Kemper Coal Unit as EPA Carbon Model, Reuters (Sept. 20, 2013, 5:01 PM), http://www.reuters.com/article/2013/09/20/us-usa-energy-emissions-kemper.

[46] EPA Science Advisory Board (SAB), EPA.gov, http://yosemite.epa.gov/sab/sabpeople.nsf/webcommittees/BOARD (last visited Aug. 21, 2014).

[47] Memorandum from James R. Mihelcic, Chair, SAB Work Group on EPA Planned Actions for SAB Consideration of the Underlying Science, (Nov. 12, 2013), available at http://yosemite.epa.gov/sab/sabproduct.nsf/18B19D36D88DDA1685257C220067A…$File/SAB+Wk+GRP+Memo+Spring+2013+Reg+Rev+131213.pdf.

[48] Id. at 3.

[49] See Memorandum from James R. Mihelcic, Chair, SAB Work Group on EPA Planned Actions for SAB Consideration of the Underlying Science (Jan. 7, 2014), available at http://yosemite.epa.gov/sab/sabproduct.nsf/F43D89070E89893485257C5A007AF…$File/SAB+work+grp+memo+w+attach+20140107.pdf.

[50] Id. at 2–3.

[51] Standards of Performance for Greenhouse Gas Emissions from New Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 1430, 1435 (Jan. 8, 2014) (to be codified at 40 C.F.R. pt. 60).

[52] Id.

[53] Id.

[54] 42 U.S.C. § 7411(b) (2013).

[55] Id. § 7411(d). One of the main reasons that Congress made this distinction between new and existing sources was to protect states that were ahead of the curve in enacting stringent pollution controls. See H.R. Rep. No. 95-294, at 184 (1977), reprinted in U.S.C.C.A.N. 1079, 1263. Congress was concerned that industries would avoid the states with stricter standards and primarily build new plants in states that are more lenient or take longer to implement new standards. Id. By giving the EPA the authority to enact uniform national standards for new plants, this concern was significantly mitigated. See id. However, because industry has fewer incentives to leave a state where a plant has already been constructed, and in some cases fully capitalized, the states retained the power to regulate existing sources. See id.

[56] Id. § 7411(d).

[57] Letter from Jon Bruning, Attorney Gen., Neb., to Gina McCarthy, Adm’r, EPA 1, 12 (Sept. 11, 2013), available at http://energycommerce.house.gov/sites/republicans.energycommerce.house.g.

[58] Id. at 1.

[59] Laura Barron-Lopez, McConnell to Force Vote on EPA Carbon Regs, The Hill (Jan. 16, 2014, 11:19 AM), http://thehill.com/blogs/e2-wire/e2-wire/195669-mcconnell-to-push-vote-b.

[60] Id.

[61] Id.

[62] See Standards of Performance for Greenhouse Gas Emissions from New Stationary Sources: Electric Utility Generating Units, 79 Fed. Reg. 1430, 1435 (Jan. 8, 2014) (to be codified at 40 C.F.R. pt. 60); Southern Cautions on Kemper Coal Unit as EPA Carbon Model, supra note 45.

[63] Reality vs. EPA’s Carbon Capture Dreams, supra note 44; Southern Cautions on Kemper Coal Unit as EPA Carbon Model, supra note 45.

Read More
Archive