1. Home
  2. |Insights
  3. |Ode to Boilerplate

Ode to Boilerplate

Client Alert | less than 1 min read | 05.02.14

In DMS Imaging Inc. v. U.S. (CFC Apr. 30, 2014), a boilerplate severability clause may have saved the contractor's claim for damages after equipment it leased to the government was destroyed. The government argued that the contractor's standard lease terms, expressly incorporated into the contract with the government, were invalid because they included an indemnification clause alleged to violate the Anti-Deficiency Act, but the CFC found the government liable for damages to the equipment under a separate, risk-of-loss clause, which was not invalidated because, even if the indemnification clause were unenforceable, a third boilerplate provision provided that unenforceable or void provisions would be deemed severable. 


Insights

Client Alert | 7 min read | 08.17.26

Delayed Notification of Cyberattacks May Trigger HIPAA Breach Notification Rule

After identifying a ransomware attack in 2021, OSF Healthcare System waited until its forensic investigation had concluded before notifying the U.S. Department of Health and Human Services (HHS) — and the affected individuals — of the breach. The 110-day delay (nearly double the 60-calendar-day notification deadline mandated by the HIPAA Breach Notification Rule) triggered an investigation from HHS’s Office for Civil Rights (OCR). The health system’s investigation determined that protected health information (PHI) had been stolen....