DOJ's First Intervention In Cybersecurity FCA Qui Tam Case Signals Continued Cyber Enforcement

GT
Greenberg Traurig, LLP
Contributor
Greenberg Traurig, LLP has more than 2750 attorneys in 47 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 500. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.
After a lengthy investigation, in February 2024, the Department of Justice (DOJ) intervened in the case and the original complaint was unsealed.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.
Go-To Guide:
  • In July 2022, two relators brought a False Claims Act (FCA) suit against the Georgia Tech Research Corporation (GTRC) and the Georgia Institute of Technology (GA Tech), alleging the defendants failed to comply with NIST 800-171 mandatory cybersecurity controls in their Department of Defense (DoD) contracts.
  • After a lengthy investigation, in February 2024, the Department of Justice (DOJ) intervened in the case and the original complaint was unsealed.
  • DOJ has until June 24, 2024, to file its own complaint containing allegations against the defendants.

In July 2022, two relators sued the GTRC and GA Tech under the FCA. The allegations include violations of the FCA and employment law based on the relators' claims of "increasing retaliation" experienced after they escalated their concerns.

The relators are a current and former employee of GA Tech's Information Technology Department. Their complaint alleges that GTRC failed to properly implement cybersecurity controls mandated by GTRC's "hundreds of contracts with the DoD." Specifically, relators allege that in 2017, the 110 controls in NIST SP 800-171 became mandatory for all research being performed at GA Tech and its associated labs under DoD contracts. The relators further allege that while the defendants took initial steps to assess compliance with the required controls by creating a team focused on auditing implementation of the controls, the team was unable to accurately assess the IT environments of the labs.

The relators also allege that the team assembled to audit compliance with the required cybersecurity controls was unqualified, pressured to interpret controls inconsistently and in a manner that would find existing practices sufficient, took the word of system administrators assigned to each lab regarding whether a control and any fixes were implemented in the system (rather than simply documented), and did not ensure continuous monitoring of compliance during the entirety of contract performance. As a result, the relators allege that the defendants' attestations of compliance with NIST 800-171 were false. The relators claim that they made detailed reports to the administration regarding the problems they noticed in the implementation of the cybersecurity controls, yet they allege that those reports were consistently ignored by administration officials and that they faced retaliation for raising their concerns. Notably, the relators allege that even after the attestations had been demonstrated to be false in the case of one particular lab, and prior to resolution of the compliance concerns, contract billing and performance continued.

In February 2024, the DOJ intervened in the case, marking the first time it has joined a cybersecurity lawsuit brought by qui tam relators. DOJ has until June 24, 2024, to file its complaint in intervention. The intervention demonstrates DOJ's continued focus on cybersecurity fraud and enforcing contractor compliance with cybersecurity requirements under DOJ's Civil Cyber-Fraud Initiative that was announced by Deputy Attorney General Lisa Monaco in October 2021.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

DOJ's First Intervention In Cybersecurity FCA Qui Tam Case Signals Continued Cyber Enforcement

United States Technology
Contributor
Greenberg Traurig, LLP has more than 2750 attorneys in 47 locations in the United States, Europe and the Middle East, Latin America, and Asia. The firm is a 2022 BTI “Highly Recommended Law Firm” for superior client service and is consistently among the top firms on the Am Law Global 100 and NLJ 500. Greenberg Traurig is Mansfield Rule 6.0 Certified Plus by The Diversity Lab. The firm is recognized for powering its U.S. offices with 100% renewable energy as certified by the Center for Resource Solutions Green-e® Energy program and is a member of the U.S. EPA’s Green Power Partnership Program. The firm is known for its philanthropic giving, innovation, diversity, and pro bono. Web: www.gtlaw.com.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More