ARTICLE
6 August 2003

Analysis of the SAFETY Act and DHS Proposed Rules

Earlier this month, the Department of Homeland Security (DHS) issued a Notice of Proposed Rulemaking (NPRM) to implement the innovative SAFETY (Support Anti-terrorism by Fostering Effective Technologies) Act provisions of the Homeland Security Act (Title VIII, Subtitle G). Piper Rudnick was closely involved in the development of the SAFETY Act, which offer significant liability protections for providers of homeland security products and services.
United States Government, Public Sector

By Steve Phillips, Jim Halpert and Kevin Mullen

I. Introduction and Summary

Earlier this month, the Department of Homeland Security (DHS) issued a Notice of Proposed Rulemaking (NPRM) to implement the innovative SAFETY (Support Anti-terrorism by Fostering Effective Technologies) Act provisions of the Homeland Security Act (Title VIII, Subtitle G). Piper Rudnick was closely involved in the development of the SAFETY Act, which offer significant liability protections for providers of homeland security products and services. Comments regarding the NPRM are due on August 11.

The SAFETY Act is designed to encourage the sale of anti-terrorism technologies and services to both public and private entities, by lessening the legal risks of providing these technologies and services. The SAFETY Act sharply limits sellers’ and other providers’ liability for DHS-approved, "qualified" technology that seek to prevent, respond to or recover from a broad range of terrorist acts, in the event of such an attack.

The proposed rule potentially applies to a very broad range of products and services and should be of great interest to defense, information technology, biotech, and communications companies that sell, integrate or use products, technologies or services that could qualify for the SAFETY Act’s significant protections.

If your company provides any homeland security-related products or services, it should consider whether to take advantage of the broad protections afforded by the SAFETY Act. If you believe that your company could qualify for these protections, consider taking three steps:

• First, consider whether to file comments on the NPRM. The final regulations will determine whether and how companies are able to obtain the SAFETY Act’s significant liability protections. As mentioned above, the deadline for filing comments is August 11. We would be pleased to help you review the regulations in light of your specific business needs and to help develop comments that would best address your concerns. Comments provide an opportunity to address the following issues, among others of interest to companies involved in the Homeland Security market:

— the scope of, and criteria for obtaining, liability protections under the Act;

— the procedures for obtaining liability protection; and

— protection of confidential information submitted to DHS to obtain these protections.

• Second, consider whether, when the SAFETY Act goes into effect September 1, your company is in a position to apply to DHS to have its products or services protected by the law. As described below, there are several contract and insurance considerations that require review prior to applying for DHS designation or certification. Again, we would be happy to work with you to help you comply with these requirements and file applications, should you choose to do so.

• Finally, if you contract with sellers of homeland security products or services, consider whether to ask that they apply for protection under the final rule, and if they have obtained a liability protection from DHS, ensure that they take steps to notify DHS if you license or obtain any interest in that technology.

To help determine whether the SAFETY Act’s protections would affect your company’s products or services, the remainder of this document provides a summary of the statute’s relevant provisions and the proposed implementing regulations.

The SAFETY Act and the DHS proposed rule would:

1. Allow the Secretary of DHS to designate certain "qualified anti-terrorism technologies" that will receive special limits on liability in the event of a lawsuit arising from a terrorist incident when the product or service was deployed. (The definition of qualified technologies includes both products and services.) The proposed rule reserves broad discretion for the Secretary to make case-by-case judgments regarding whether to extend protection.

2. Afford significant protections to products or services designated as a "qualified anti-terrorism technology." In the event of an act of terrorism and ensuing lawsuits, the Act limits the liability of sellers or providers of qualified anti-terrorism technologies in several ways, including: (A) capping liability at the limits of the sellers’ insurance, (B) barring punitive damages, (C) limiting non-economic damages, and (D) expanding the scope of the "government contractor defense" to technologies that meet more stringent DHS review, even if the sale is not to a governmental entity. Very significantly, the proposed rule would make protection "run with" the technology and protect others in the supply chain. This would extend the liability protection to third parties who use, integrate or resell a seller’s technology.

3. Condition the protections of the Act for sellers or providers of qualified technologies on obtaining the maximum amount of third-party liability insurance reasonably available from private sources on the world market needed to cover them for claims arising out of a single act of terrorism. Interpretation of this standard is an important issue in the rulemaking.

4. Apply their protections to the sale of products or services to federal, or non-federal government customers, including "state and local authorities and commercial entities." It is important to ensure that this broad definition of potential customers is clearly explained in the final rule.

In these and other ways, the SAFETY Act and DHS’ final rule could enhance the ability of companies to sell, integrate and use products that qualify as anti-terrorism technologies without fear of costly lawsuits in the event of a terrorist attack.

II. Background

Sellers of anti-terrorism technologies have faced substantial uncertainty in their desire to sell products to federal and state governments, given the potentially enormous liability exposure they faced with their products being deployed throughout the country in the war on terrorism. One solution, of course, was to expand an existing law called Public Law 85-804. Under Public Law 85-804, certain government agencies may indemnify contractors who provide products and services which present an unusually hazardous risk. Public Law 85-804, though, does not apply across the entire federal government, or to companies who sell to state and local governments or sell to private entities. Another, more aggressive solution was to protect sellers through a tort reform approach. The goal was to ensure that all effective anti-terrorism technologies were deployed, and that none remained on the sidelines because of the fear of lawsuits.

Last Congress, the House leadership adopted the tort reform approach, which proved to be quite controversial: the SAFETY Act survived being stripped from the original House Homeland Security Bill by one vote. As an alternative, the Senate considered several different ways of expanding Public Law 85-804 indemnification, but when the President, emboldened by his party’s showing in the mid-term elections, insisted on passing a Homeland Security bill immediately, House negotiators were able to convince the Senate leadership to leave the SAFETY Act in the final bill.

III. Summary of the SAFETY Act and Proposed Rules

Key features of the SAFETY Act and the DHS proposed rule are as follows:

1. "Qualified Anti-Terrorism Technologies"

The SAFETY Act authorizes the Secretary of the Department of Homeland Security to designate certain products, services, and technologies as "qualified anti-terrorism technologies." These technologies must have been "designed, developed, modified, or procured for the specific purpose of preventing, detecting, identifying, or deterring" acts of terrorism, or for limiting the harm of such acts. Terrorism is defined broadly to encompass harm to property and business interruption, and thus encompasses attacks against communications networks.1

In making these designations, the Secretary must consider the following non-exclusive criteria:

1. Prior U.S. government use or demonstrated utility and effectiveness;

2. Availability for immediate public and private deployment;

3. Extraordinarily large or unquantifiable liability risk to the provider;

4. Substantial risk of non-deployment absent liability limits;

5. Magnitude of public risk presented by non-deployment;

6. Evaluation of scientific studies to assess the capability of the technology to substantially reduce the risk of harm; and

7. Effectiveness in preventing, defeating or responding to acts of against terrorism.

The SAFETY Act’s legislative history makes clear that Congress intends the Secretary to interpret this criteria broadly in order to cover as many anti-terrorism technologies as possible. Therefore, the process could result in a "qualified anti-terrorism technologies" list. Whether it is an official or unofficial list is to be determined in the implementation phase. Furthermore, it is important to note that "qualified" technologies may be covered regardless of whether they are sold to the federal government, state and local governments, or private entities.

The proposed rule tracks this broad definition and reserves broad discretion to DHS to weigh the relevance of any of these factors in a particular case, and to consider any other factor he deems relevant. It indicates that DHS may adopt standards to measure the effectiveness of particular categories of homeland security standards, and may decide to rely on scientific studies regarding effectiveness.

2. The Liability Protections Afforded by the SAFETY Act

The SAFETY Act provides certainty to sellers or providers of approved anti-terrorism technologies by limiting liability arising out of, related to or resulting from terrorism incidents in several ways. The Act and proposed rule provide two different levels of protection to anti-terrorism products and services: (1) a "designation of qualified anti-terrorism technology" which confers the standard SAFETY Act limits on liability protection, and (2) for technologies that qualify under the first category and satisfy a further review under additional criteria, certification as "an Approved Product for Homeland Security" entitling the seller or provider of the product (or service) to a rebuttable presumption of protection by the government contractor defense.

First, the Act requires that all third-party claims against sellers and providers of qualified anti-terrorism technologies arising out of an act of terrorism must be brought in federal district court. Such claims will be subject to the laws of the state in which the terrorist act occurred. The proposed rule goes into great depth explaining how the Act intended to create a single cause of action, and how that action is solely against the seller. It makes clear that there can be no suits against a subcontractor or a customer. It will be important to ensure that this correct interpretation of the Act remains in the final rule.

Second, the Act bars punitive damages and permits only claims for injuries proximately caused by sellers of qualified technologies. Non-economic damages may be awarded only if the plaintiff suffered physical harm, and then only on a percentage-of-fault basis. Moreover, any damages received by a plaintiff in such an action must be reduced by any collateral source compensation, and pre-judgment interest is barred.

Third, it is important to note that the SAFETY Act and the proposed rule also cap liability of sellers and providers of these technologies at the amount of the seller’s required insurance.

Fourth, the Act and proposed rule also establish a rebuttable presumption that all sellers and providers of "Approved Products for Homeland Security" are entitled to the "government contractor defense," if approved by DHS after a comprehensive review of the technologies’ performance, adherence to sellers’ specifications, and safety for intended use. The government contractor defense is a common-law concept which has historically provided immunity from liability for companies that manufacture a product to federal government specifications, meet those specifications, and do not have undisclosed knowledge of defects. The SAFETY Act adopts and broadens the coverage of this doctrine by offering the defense to outside of the federal government contractor context, and by establishing the defense as a rebuttable presumption. The Act also instructs that the government contractor defense can only be overcome by evidence showing that a seller acted fraudulently or with willful misconduct in submitting information to the Secretary during the technology examination process.

The Act’s liability provisions do not limit claims against an entity that knowingly commits, participates in, aids and abets, attempts to commit, or conspires to commit an act of terrorism or related criminal act.

Once DHS approves anti-terrorism technology as eligible for the government contractor defense, the Department is to issue a "certificate of conformance" to the seller and place the technology on an "Approved Product List for Homeland Security." It is important to underline that this list includes only those products approved for the government contractor defense, and not the entire universe of qualified anti-terrorism technologies, which need to satisfy fewer requirements.

3. Risk Management and Insurance Requirements

To qualify for the liability protections of the Act, all sellers of qualified anti-terrorism technologies must purchase the maximum amount of "reasonably available" liability insurance sufficient to cover them for third-party claims relating to the deployment of the technologies designed to prevent or respond to an act of terrorism.2 The scope of this insurance must cover the potential liabilities of the contractors, subcontractors, suppliers, vendors, and customers of both the seller and its customers.

However, this mandated coverage must not be so expensive that its cost significantly drives up the price of the seller’s anti-terrorism technologies. As the SAFETY Act provides: "the Seller is not required to obtain liability insurance of more than the maximum amount of liability insurance reasonably available from private sources on the world market at prices and terms that will not unreasonably distort the sales price of Seller’s anti-terrorism technologies."

The Secretary must certify that the coverage purchased in fact meets the Act’s criteria. In addition, the seller must reciprocally waive claims with its contractors, subcontractors, suppliers, vendors, and customers who manufacture, sell, or operate such qualified anti-terrorism technologies.

The proposed rule follows these standards and provides that DHS will determine the amount of liability insurance required for each technology or group of technologies. It would require sellers to provide, upon request, information that assists in determining the amount of liability insurance required. It would provide that in determining the amount of liability insurance required, the Secretary may consider among other factors:

1. the particular technology at issue;

2. the amount of liability insurance the seller maintained prior to its application;

3. the amount of liability insurance maintained by the seller for other technologies or for the Seller’s business as a whole;

4. the amount of liability insurance typically maintained by sellers of comparable technologies;

5. information regarding the amount of liability insurance offered on the world market;

6. data and history regarding mass casualty losses;

7. the intended use of the technology;

8. the possible effects of the cost of insurance on the price of the product and the possible consequences thereof for development, production, or deployment of the technology; and

9. for a self-insurance application, the factors set forth in 48 CFR 28.308(d).

The proposed rule requires sellers to provide a detailed statement of the liability insurance they maintain, to certify annually that the seller has maintained the required amount of insurance for the technology in question, and to notify the DHS of any changes in the seller’s insurance coverage.

4. Procedure for and Effect of Approvals by DHS

The proposed rule provides for separate approval of applications for: (a) designations of qualified anti-terrorism technology and (b) certifications of approved products for homeland security entitled to the presumption of the government contractor defense presumption (which require a comprehensive review of whether the product or service will perform as intended, conforms to seller specifications and is safe for use for use as intended). Each application would follow separate procedures set forth in detail in the proposed rule. Confidential business information submitted under the SAFETY Act would be exempt from FOIA and be protected by confidentiality protocols.

Under the proposed rule, applications may be received starting September 1. The Assistant Secretary for Plans, Programs and Budget is to conduct an initial review within 30 days to ensure that the application is complete. The Assistant Secretary is required within 90 days of receipt of a complete application to recommend approval, denial or a request for additional information. This period may be extended 90 days upon notice to the seller. The Under Secretary has 30 days to review the recommendation and may extend this period an additional 30 days with notice to the seller. Decisions regarding designations are not reviewable.

If either application is approved, the designation or certification would be valid for between five and eight years, as specified by DHS. The designation/certification and attendant liability protections are intended to apply indefinitely with regard to all sales of the qualified technology consummated during this period (although this language is phrased inartfully and should be clarified in the final rule). The designation/certification is transferable together with any title, right or interest in the technology/product, such as intellectual property rights, and applies to licensees of the technology/product, provided that the seller notifies DHS of the license arrangement.

Significant changes in the technology would require a special application for modification of the designation prior to implementation of the change, which should be described more clearly in the final rule.

Finally, according to its legislative history, the SAFETY Act is intended to complement, not replace, the P.L. 85-804 system. Thus, in some cases a seller of qualified technology may have its legal damages limited by the SAFETY Act and indemnified by the U.S. government.

IV. Conclusion

The proposed rule has the potential to be very useful for the wide variety of companies interested in providing Homeland Security products and services, provided that its broad scope is maintained in the final rule, and its approval procedures and conditions are workable.


1 The Act defines an "act of terrorism" as one that: (i) is unlawful; (ii) causes harm to a person, property, or entity in the United States; to a domestic U.S. air carrier in or outside the United States; to a U.S.-flag vessel (or to a vessel based principally in the United States on which U.S. income tax is paid and whose insurance coverage is subject to U.S. regulation) in or outside of the United States and (iii) uses or attempts to use methods designed or intended to cause mass destruction, injury or other loss to citizens or institutions of the United States. (emphasis added)

2 Liability insurance as defined in the Act covers legal liabilities resulting from: (i) loss or damage to others’ property; (ii) ensuing loss of income or extra expense because of loss or damage to others’ property; (iii) bodily injury to the insured, its employees, or others; and (iv) loss caused by the debt or default of another.


This article is intended to provide information on recent legal developments. It should not be construed as legal advice or legal opinion on specific facts. Pursuant to applicable Rules of Professional Conduct, it may constitute advertising.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More