Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherBrowse by ChannelAbout the NetworkJoin the NetworkProductsSub-MenuProducts OverviewBlog ProBlog PlusBlog PremierMicrositeSyndication PortalsAbout UsContactSubscribeSupport
Book a Demo
Search
Close

Update – Penn State to Pay Up for Cyber-Related FCA Case

By Townsend Bourne, Nikole Snyder & Sidney Howe* on October 30, 2024
Email this postTweet this postLike this postShare this post on LinkedIn
Finance-and-Bankruptcy-Blog-Image_Litigation-Costs-660x283

On October 22, 2024, the Department of Justice (“DOJ”) announced that Pennsylvania State University (“Penn State”) has agreed to pay $1,250,000 to settle a False Claims Act (“FCA”) case brought against the University approximately two years ago. The whistleblower in the case, former chief information officer of the Penn State Applied Research Laboratory, alleged that Penn State failed to comply with cybersecurity requirements in fifteen contracts and/or subcontracts with the Department of Defense (“DoD”) and National Aeronautics and Space Administration (“NASA”) between 2018 and 2023.

Specifically, the lawsuit (as discussed in our prior blog) contended that Penn State failed to provide “adequate security” for Covered Defense Information (“CDI”), as contractually required by the DFARS 252.204-7012 clause. Under this clause, “adequate security” is defined as (at least) implementing all 110 security controls outlined in the National Institute of Standards and Technology (“NIST”) Special Publication (“SP”) 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. Moreover, federal regulations require DoD contractors to conduct a self-assessment of compliance with those 110 controls and report a compliance score (out of 110) in DoD’s Supplier Performance Risk System (“SPRS”). The lawsuit further alleged that Penn State falsified at least 20 documents related to its NIST SP 800-171 self-assessment and other self-attestations and put sensitive information at risk in a commercial cloud-storage service.

The DOJ originally declined to intervene in this lawsuit (as discussed in our prior blog). However, DOJ did opt to participate in the settlement negotiations. The settlement amount likely indicates a “cost of litigation” settlement with a desire to avoid further legal proceedings and expenses. There is no admission of wrongdoing on the part of Penn State. The whistleblower will receive a $250,000 share of the settlement amount.

Importantly for government contractors, FCA claims are on the rise. Principal Deputy Assistant Attorney General Brian M. Boynton (head of the DOJ’s Civil Division) announced that, in 2023 alone, DOJ opened 500 new FCA matters (a record high) and began investigating 712 qui tam lawsuits. Boynton also noted that cybersecurity FCA cases are a priority for 2024.

This DOJ settlement highlights the importance of robust contractor compliance systems and a culture that facilitates self-disclosure, internal investigations, and cooperation with the government. If cybersecurity compliance has not been at the top of your list, it is time (and likely past-time) to move it up. Sheppard Mullin’s Governmental Cybersecurity & Data Protection Team has resources and training materials available. If additional information would be helpful to you, or you have any questions, please contact us.

Photo of Townsend Bourne Townsend Bourne

Townsend Bourne is a partner in the Governmental Practice in the firm’s Washington, D.C. office. She also is Leader of the firm’s Government Business Group.

Read more about Townsend BourneEmail
Photo of Nikole Snyder Nikole Snyder

Nikole Snyder is an associate in the Governmental Practice in the firm’s Washington, D.C. office. She is a lead associate of the firm’s Government Business Group.

Read more about Nikole SnyderEmail
Photo of Sidney Howe* Sidney Howe*

*Sidney Howe is a Cybersecurity Fellow in the Governmental Practice in the firm’s Washington, D.C. office. 

Email
  • Posted in:
    Administrative
  • Blog:
    Government Contracts & Investigations Blog
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

LexBlog, Inc. logo
Facebook LinkedIn Twitter RSS
Real Lawyers
99 Park Row
  • About LexBlog
  • Careers
  • Press
  • Contact LexBlog
  • Privacy Policy
  • Editorial Policy
  • Disclaimer
  • Terms of Service
  • RSS Terms of Service
  • Products
  • Blog Pro
  • Blog Plus
  • Blog Premier
  • Microsite
  • Syndication Portals
  • LexBlog Community
  • Resource Center
  • 1-800-913-0988
  • Submit a Request
  • Support Center
  • System Status
  • Resource Center
  • Blogging 101

New to the Network

  • Tennessee Insurance Litigation Blog
  • Claims & Sustains
  • New Jersey Restraining Order Lawyers
  • New Jersey Gun Lawyers
  • Blog of Reason
Copyright © 2025, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo