Get App
Download App Scanner
Scan to Download
Advertisement
This Article is From Jan 24, 2018

Express Scripts Clashes With DiNapoli Over Cyber Disclosures

(Bloomberg) -- The U.S. Securities and Exchange Commission will review a dispute between Express Scripts Holding Co. and New York State Comptroller Thomas DiNapoli over his effort to force the prescription-benefits manager to increase cyber-risk disclosures.

Express Scripts told the SEC last month it would exclude the proposal from its annual proxy statement. DiNapoli, who's pushing for the company's board to report its efforts to prevent and mitigate cyber threats, objected last week in a letter to the regulator.

“We're at the point where everyone -- investors, directors, regulators -- is recognizing that this is a critical issue,” said Gianna McCarthy, director of corporate governance at the comptroller's office, which oversees about $164 million of Express Scripts stock for the $200 billion New York State Common Retirement Fund. “Investors need more disclosure.”

DiNapoli filed the proposal in November, two months after credit-reporting company Equifax Inc. revealed a breach that compromised personal information of about half the U.S. population. He assailed Express Scripts' scant disclosure of how cyber risks are managed and cited a government-commissioned report showing the health care industry incurs a disproportionate share of hacking attacks.

Read also: How much will Equifax pay after massive data breach?

Express Scripts said it devotes significant resources to safeguard confidential patient and client data and to keep up with changes in technology and regulatory standards.

“Such a complex and critical element of our business is properly a matter for our management and board of directors to oversee, as this is who shareholders have entrusted to run the day-to-day operations of the business,” St. Louis-based Express Scripts said in an emailed statement. “Moreover, the effectiveness of our cyber risk management strategy depends upon a measure of confidentiality that could be undermined by the New York State Comptroller's proposed disclosures.”

Judy Burns, an SEC spokeswoman, declined to comment.

Express Scripts is one of the largest managers of drug benefits for employers, unions and state and local governments, using its size to negotiate discounts with drugmakers. In December, the company told the SEC it wouldn't put the proposal up for a vote at its annual meeting because it didn't raise “significant policy” issues that went beyond its ordinary business practices.

Last week, DiNapoli's office rejected those arguments, saying “risks for inadequate cybersecurity measures” can transcend a company's ordinary business.

“Cybersecurity is one of the most critical matters facing businesses today,” DiNapoli said Tuesday in a statement. “This is especially true for health care companies that hold vast amounts of private patient data. While Express Scripts acknowledges that its ability to operate depends on its technology infrastructure, it has provided shareholders with insufficient information about board oversight or actions taken to mitigate cyber risk in its operations.”

To contact the reporters on this story: Anders Melin in New York at amelin3@bloomberg.net, Robert Langreth in New York at rlangreth@bloomberg.net.

To contact the editors responsible for this story: Alicia Ritcey at aritcey@bloomberg.net, Peter Eichenbaum

©2018 Bloomberg L.P.

Essential Business Intelligence, Continuous LIVE TV, Sharp Market Insights, Practical Personal Finance Advice and Latest Stories — On NDTV Profit.

Newsletters

Update Email
to get newsletters straight to your inbox
⚠️ Add your Email ID to receive Newsletters
Note: You will be signed up automatically after adding email

News for You

Set as Trusted Source
on Google Search