The following boardroom briefing was prepared in partnership with Clyde & Co.
Insurance and legal perspectives on the issues and likely exposures
In lieu of a public health order, employers who wish to mandate vaccinations in their workplace will need to consider a legal, health and operational response. Boards across Australia are asking tough questions and there are multiple considerations and risks that employers need to navigate.
Key takeaways:
· There are a number of claims that might arise from mandatory vaccination programs and we anticipate these would be covered by different types of policies, some of which are mentioned in this briefing paper.
· There are current litigation proceedings in the NSW Supreme Court, primarily against the NSW Health Minister, challenging the legality of mandated COVID vaccinations for NSW workers. This could potentially provide some guidance for private enterprises.
· There are calls from some stakeholders, in particular business groups, for federal and state governments to adopt a nationally consistent approach to mandatory vaccinations in the workplace and to provide legislation to protect employers from industrial action and litigation over the issue.
EMPLOYMENT PRACTICES LIABILITY AND DIRECTORS AND OFFICERS INSURANCE
Discrimination claims
Discrimination claims are a potential area of concern when considering a mandatory vaccination program. The merits of these are fact specific. We believe any discrimination claims would typically fall within the cover provided by an ordinary EPL (Employment Practices Liability) policy.
If EPL cover is incorporated into a Directors and Officers or Management Liability policy (i.e. by an extension), then these policies would also likely cover these types of discrimination claims. EPL cover often extends to Directors and Officers (and potentially other employees) as well as the organisation itself (subject to the policy wording).
Discrimination claims could also potentially be covered under a Directors and Officers policy without express EPL cover, however, that may be less straightforward and would be subject to policy wording, including the definition of “Claim and/or “Wrongful Act”). Some Directors and Officers policies may expressly exclude cover for EPL type claims (including discrimination).
MANAGEMENT LIABILITY
Unfair dismissal claims
There may be unfair dismissal claims arising from the termination of employment of an employee because of their refusal to follow a reasonable and lawful direction to be vaccinated in order to perform a role. We anticipate these would be covered by Management Liability policies.
Similarly, there may be claims of discrimination because of a mandatory vaccination requirement applying to someone with a medical contraindication in relation to the vaccine or a religious objection. We anticipate these would be covered by Management Liability policies.
In the event the claim is made in relation to the refusal to provide goods or services, other policies may be applicable.
GENERAL AND CIVIL LIABILITY
Claims for failure to mandate vaccinations
There may be civil claims for compensation or prosecutions by Work Health and Safety authorities arising from a failure to have proper systems in place to manage the risk of COVID-19 (in the circumstances of an outbreak). Civil liability will likely to covered by a General Liability policy whereas the cost of defending prosecutions is likely to sit in a Statutory Liability/Management Liability/Directors and Officers policy. Directors and other officers would also be liable for such prosecutions and their liability is generally covered by a Directors and Officers policy.
CYBER
Data breach considerations
In the context of a cyber incident, the Privacy Act defines an eligible data breach i.e. a notifiable data breach, as occurring based on three key questions:
Question 1: has there been unauthorised access to, unauthorised disclosure of, or loss of, personal information held by an entity?
Question 2: is the access, disclosure or loss likely to result in serious harm to any of the individuals to whom the information relates?
Question 3: can the likely risk of serious harm be prevented with remedial action?
In response to Question 2, if there is any evidence of actual harm, the Privacy Act requires the impacted entity to assess whether the breach would be likely (which it defines as more probable than not) to result in serious harm to an individual whose personal information formed part of the breach.
Section 26WG of the Privacy Act provides a non-exhaustive list of relevant considerations to assist entities with this assessment. While they overlap to a certain extent, these considerations can be broadly categorised into the following groups:
a) the type or types of personal information involved in the data breach. This includes a consideration of the kind and sensitivity of the information at risk;
b) the circumstances of the data breach. This includes a consideration of the kinds of persons who have or could obtain the information; and
c) the nature of the harm that might result from the data breach. This includes a consideration of the likely type of harm that could flow as a result of the access to information including potential physical, psychological, emotional, financial or reputational harm.
Type of data
At a high level, the type of data involved in a data breach has a large bearing on any risk of harm assessment. For example, credit card details are immediately available to perpetuate financial harm in the form of credit card fraud. Further, Government & other identifiers (including Tax File Numbers, Medicare card, membership numbers), and in particular scanned copies of those documents, can be readily misused to perpetuate identity misuse events. Login credentials can also be exploited to gain access to systems (including work systems, personal email accounts, banking systems).
Some types of data carry a lower risk, such as basic contact and employment information. This information is relatively benign and is usually already in the public domain i.e. employment history, work experience, training qualifications are often available on LinkedIn and other public search engines. Further, this sort of information usually is not sufficient to enable the threat actor to perpetrate identity fraud.
The data in the scenario provided i.e. details of a vaccination exemption is likely to be considered health information under the Privacy Act. At a base level, medical information is considered to be a form of sensitive personal information under section 6(1) of the Privacy Act. Understandably, the disclosure of medical information (and in particular, an individual’s vaccination status) may be concerning for those individuals impacted.
Cyber actors are not known to exploit medical information for gain
However, while the publication of the information in the public sphere has the potential to cause emotional or reputational harm, it is unlikely that the information in the hands of third parties would seek to cause this type of harm. Cyber actors are known to misuse information that allows that actor to perpetuate invoice fraud; use credentials to log on to systems and extort individuals/ businesses; and or use/sell biographical, contact and ID document information to open up lines of credit in the names of the affected individuals. Cyber actors are not known to exploit medical information for gain. There are also a number of further factors that decrease the likelihood of serious harm following a breach of health information, including the following:
· medical information about a particular individual cannot be amended or changed in the same manner that banking institutions and government departments are able to amend financial and identity credentials; and
· the presence of medical information alone is not necessarily enough to meet the serious harm threshold (however when combined with other personal information about an individual, this does have the possibility to increase the identity risks that an individual faces).
Assess cyber breaches on a case by case basis
The above assessment is high level and rudimentary. Each cyber breach needs to be assessed under the above framework on a case by case basis to determine whether the incident is notifiable and if so, what affected individuals require consumer notifications (as well as the content of any consumer notifications). There are also further considerations that may be relevant including whether the employee exemption would be applicable. This provides an exemption for the entity to not disclose to or notify current or former employees with respect to employee records it holds relating to those employees. The circumstances of each individual breach must also be considered.
Most cyber policies provide cover when complying with privacy obligations
In the context of cyber insurance, most policies provide cover for complying with the relevant privacy obligations following a cyber breach. Such coverages are usually framed as privacy breach costs, privacy wrongful acts costs, costs to comply with privacy obligations etc. Ordinarily these insuring clauses will provide cover to undertake the required assessment under the Privacy Act (or similar overseas regulation) to determine whether a breach is notifiable and the costs associated with notifying the OAIC (or similar overseas regulator) and affected individuals.
At a glance, we consider such policies would likely provide cover for the assessment of whether medical information (i.e. details of a vaccination exemption) meets the serious harm threshold for notification, and if so, the costs associated with issuing any notification statements.
The conclusion
We do not see there being a higher risk profile in relation to entities that hold details of a vaccination exemption in the context of a data breach that affects that information. If there is a data breach, that entity is required to work through the threshold questions detailed above. This includes all personal information that may be affected by the data breach, including medical information and employee records.
Claims/regulatory action risk
Cyber policies also usually provide cover for third party claims risk in relation to the loss/ disclosure of personal information. These coverages usually provide indemnity for claims by affected individuals (whose data was lost or disclosed) and for regulatory investigations/ prosecutions in relation to a data breach. Again, we consider the claims risk in relation to the loss/ of disclosure of this sort of information to be commensurate to claims risk for other types of sensitive personal data.
WORKERS’ COMPENSATION
Complications from vaccinations
Any medical complications arising from vaccinations where vaccination has been mandated by the Government or the business is considered an injury or illness arising during the course of employment or where employment is a substantial contributing factor. As such it is covered by workers compensation.
Federal Government indemnity scheme
The Federal Government has an indemnity scheme (opens a new window). The scheme covers the costs of injuries $5,000 and above due to administration of a TGA approved COVID-19 vaccine or due to an adverse event that is considered to be caused by a COVID-19 vaccination.
Expect workers’ compensation claims
Although the Federal Government has announced a scheme to support adverse reactions but will only respond to costs of injuries above $5,000. It is therefore reasonable to expect that workers’ compensation claims will be lodged in the first instance to cover smaller absences and medical costs.
The recognised side effects to the COVID-19 vaccines are included in the approved Product Information and include thrombosis with thrombocytopenia syndrome (TTS) associated with the AstraZeneca vaccine and myocarditis and pericarditis associated with the Pfizer vaccine.
For claims between $5,000 and $20,000, claimants need to have been hospitalised for at least one night, will need to nominate they are seeking less than $20,000 and provide applicable evidence of:
· the nature of the injury and medical documentation of its likely relationship to a COVID-19 vaccination
· hospitalisation, due to a vaccine-related injury
· medical costs
· lost wages.
The evidence requirements for claims $20,000 and over, including death, are still being developed and will be advised as part of additional information on the scheme in the future. Claims relating to a death will not require evidence of hospitalisation.
Subsequent mental health injuries
Some employees may be vaccinated under protest because they cannot afford to change jobs. There is a school of thought at present that any subsequent mental health injuries which arise out of this could be accepted under workers’ compensation if people were struggling with the perception of being forced to have a vaccine they otherwise would not have had.
Opportunity for exceptions
There will always be some exception to mandating vaccinations, for example on medical or religious grounds. It is important to make available an exception method that employees can apply for.

