1. Home
  2. |Insights
  3. |Approved: E-Signatures for CDA Claim Certifications Receive the ASBCA’s Stamp of Approval

Approved: E-Signatures for CDA Claim Certifications Receive the ASBCA’s Stamp of Approval

Client Alert | 1 min read | 10.30.19

In URS Federal Services, Inc., ASBCA 61443 (October 3, 2019), the Armed Services Board of Contract Appeals addressed whether a contractor’s digital signature complied with the CDA’s claim certification requirements. The signature in question was electronically affixed to the claim document—along with a digital certificate—using software that required the signer to input a unique password and user identification before signing. The government argued that one “cannot trust the [digital] certificate to prove the identity of the person who applied it,” because there was no “suitable ID” to prove the signer’s identity. While noting that it had previously found typed but unsigned names to be insufficient, the Board rejected the government’s argument, because the digital signature was “discrete” and “verifiable” in accordance with the CDA’s requirements. The Board reasoned that “[n]o ink signature, on its face, includes any way for the reader to know who executed it unless that reader already possesses an intimate familiarity with the certifier’s handwriting” and declined to “impose draconian demands on digital signatures, not required to be met for their ink counterparts.” 


Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....