In a significant move, the federal government decided not to intervene – at least for now – in a recently unsealed case against Penn State, which is seen as an indicator of the increasing utilisation of the False Claims Act in cybersecurity enforcement. According to the details available to date, the court allowed the government a month to determine if it would take over the whistleblower’s qui tam complaint.
The United States filed its notice on September 29, stating it “was not intervening at this time,” but highlighted that its “investigation remains active.” This move signals a potential increase in false claims act litigation relating to cybersecurity practices, a concern that could potentially impact many corporations and their legal departments.
This is indeed a development to watch closely, especially for in-house legal professionals working in large corporations that allocate substantial resources decision-making and compliance related to information security. The proceedings and future outcomes of cases such as Penn State’s could provide important guidance for formulating policies and procedures related to cybersecurity compliance and for the management of potential legal risks arising from the application of the False Claims Act and other similar laws.
While gaps exist in the specifics of the case, as the government has not fully intervened, the case’s progression will provide clearer insights on the government’s approach to these issues and could potentially shape future legislation on cybersecurity enforcement.