1. Home
  2. |Insights
  3. |GSA Finalizes Rule Declaring Certain Commercial Supplier Agreement Terms Unenforceable

GSA Finalizes Rule Declaring Certain Commercial Supplier Agreement Terms Unenforceable

Client Alert | 1 min read | 02.26.18

On February 22, 2018, GSA published a final rule amending its acquisition regulation and declaring certain common Commercial Supplier Agreement (CSA) terms—such as indemnification and arbitration provisions, provisions that subject the U.S. Government to state law, and automatic renewal provisions—unenforceable in government contracts as inconsistent with federal procurement law. GSA published the proposed rule in June 2016 (discussed here) and related class deviation (discussed here) in August 2015.


The final rule makes several noteworthy changes to GSA’s proposed rule, including: (1) it reverts the order of precedence of contract terms to give precedence to “[a]ddenda to [the] solicitation or contract, including any commercial supplier agreements as amended by the Commercial Supplier Agreements—Unenforceable Clauses provision” over “[s]olicitation provisions” and “[o]ther paragraphs of [the] clause”; and (2) it removes the previously proposed requirement to provide full text CSA terms with the offer, paving the way for CSA terms to be incorporated by reference. As GSA maintains, this final rule will eliminate the need for negotiation on the identified unenforceable terms and could facilitate faster procurements.

Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....