Wulf A. Kaal

The Role of Corporate Integrity Agreements in the Expansion of Fiduciary Duties

Full text for verification

The Role of Corporate Integrity Agreements in the Expansion of Fiduciary Duties

Canonical record: https://ssrn.com/abstract=2317580

40 protected claims are extracted from this work.

Source extraction SHA-256: b7b93e31814e25088dd8beb18090fe5ca72a0652050506976fbccc6f30ec8ba4


# 金

## UNIVERSITY of ST.THOMAS MINNESOTA

**SCHOOL OF LAW**

**Legal Studies Research Paper Series**

**THE ROLE OF CORPORATE INTEGRITY AGREEMENTS IN THE EXPANSION OF FIDUCIARY DUTIES**

**Working Paper, 2013**

### **Wulf A. Kaal Associate Professor of Law**

### **Elizabeth R. Malay Associate, Winthrop & Weinstine Minneapolis, MN**

#### **University of St. Thomas School of Law Legal Studies Research Paper No. 13-25**

This paper can be downloaded without charge from The Social Science Research Network electronic library at: http://papers.ssrn.com/abstract=2317580

- A complete list of University of St. Thomas School of Law Research Papers can be found at:

http://www.ssrn.com/link/st-thomas-legal-studies.html

CORPORATE INTEGRITY AGREEMENTS

THE ROLE OF CORPORATE INTEGRITY AGREEMENTS IN THE EXPANSION OF FIDUCIARY DUTIES

> * Associate Professor, University of Saint Thomas School of Law (Minneapolis). The author wishes to thank research librarians Valerie Aggerbeck and Megan McNevin for their outstanding support.

> * J.D.  2013, University of St. Thomas School of Law; Associate at Winthrop & Weinstine, P.A., Minneapolis.

CORPORATE INTEGRITY AGREEMENTS

# ABSTRACT

Academics have long debated the purpose and scope of fiduciary duties. The academic debate has mostly ignored the role of Corporate Integrity Agreements (CIAs). CIAs can blur the line between the law and aspirational governance. As a contractual arrangement, the terms of CIAs between health care companies and the government require heightened compliance duties. Unlike regular contractual arrangements, however, the enforcement of CIAs goes beyond contractual remedies. The breach of a CIA can be treated like a breach of law for purposes of the duty of care.

Courts are increasingly recognizing the role of CIAs and their implications for directors’ fiduciary duties. A prominent recent decision, _In re Pfizer_ , illustrates the role of CIAs in the evolution of fiduciary duties. Although the court in Pfizer did not conclude that the CIAs actually created fiduciary duties, the court opined that the CIAs “imposed affirmative obligations on Pfizer's board that went well beyond the basic fiduciary duties required by Delaware law.” A broader reading of this phraseology suggests that fiduciary duties could perhaps be augmented by contractual arrangements such as CIAs. It seems possible that future courts, in following this reasoning, may interpret CIAs as expanding the basic legal duty of care.

CORPORATE INTEGRITY AGREEMENTS

# TABLE OF CONTENTS

|I.<br>I|NTRODUCTION............................................................................................................................................... 4|
|---|---|
|II.|EXPANDINGFIDUCIARYDUTIES............................................................................................................. 6|
|III.|CORPORATEINTEGRITYAGREEMENTS............................................................................................... 8|
|_1._|_Background ...................................................................................................................................................... 8_|
|_2._|_Characteristics .............................................................................................................................................. 10_|
|_3._|_Reach and Scope .......................................................................................................................................... 11_|
|IV.|THEROLE OFCIAS INEXPANDINGFIDUCIARYDUTIES............................................................. 13|
|_1._|_Contractual Addendum to Increase Duties ....................................................................................... 13_|
|_2._|_Delineating the Role of CIAs in Fiduciary Duties ......................................................................... 14_|
|_3._|_Limitations ...................................................................................................................................................... 18_|
|V.|CONCLUSION............................................................................................................................................... 19|

CORPORATE INTEGRITY AGREEMENTS

# **I.** Introduction

Traditional fiduciary duty doctrine is among the most amorphous concepts in the law and leads to confusion, inconsistency, and to cases with somewhat problematic outcomes.<sup>1</sup> The standard for liability is so high that it is hard for courts to find directors in violation of their fiduciary duties.<sup>2</sup> Only a board’s sustained or systematic failure to exercise oversight can result in liability.<sup>3</sup> Academics have debated ways to improve the fiduciary duty doctrine for decades.<sup>4</sup> There is some agreement that fiduciary duties are too vague and should be better defined.<sup>5</sup> Despite various nuances on side issues,<sup>6</sup> the

> 1 Lisa Firfax, _Disney, Good Faith, and Structural Bias,_ 32 J. CORP. LAW 833, 850 (2007 <u>)</u> (discussing the various _Disney_ cases).

> 2 _Id._ at 846.

> 3 Lyman Johnson & Mark A. Sides, _Sarbanes-Oxley Act and Fiduciary Duties_ , 30 WM. MITCHELL L. REV. 101, 142 (2004) [hereinafter Johnson & Sides]; _see alsoIn re_ Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 971 (Del. Ch. 1996).

> 4 _See, e.g._ , Claire A. Hill & Brett H. McDonnell, _Fiduciary Duties and Emerging Jurisprudence, in_ RESEARCH HANDBOOK ON THE ECONOMICS OF CORPORATE LAW 133 (Claire A. Hill & Brett H. McDonnell, eds., 2012) [hereinafter Hill & McDonnell]; Lyman P.Q. Johnson & Mark A. Sides, _The Sarbanes-Oxley Act and Fiduciary Duties_ , 30 WM. MITCHELL L. REV. 1149, 1192-95 (2004) (In “corporate law, the duties are broad and usefully ill-defined—decision-makers must act with “loyalty” and “care” and in “good faith,” but are accorded wide latitude in discharging their governance responsibilities in conformance with these standards.”); Cheryl L. Wade, _Fiduciary Duty and the Public Interest_ , 91 B.U. L. REV. 1191 (2011) [hereinafter Wade] (citing Tamar Frankel, FIDUCIARY LAW 166 (2011) [hereinafter Frankel] (“[W]hen the public interest conflicts with shareholder primacy and wealth-maximization goals, courts may enforce duties that fiduciaries owe shareholders rather than enforce fiduciaries' compliance with law and regulation that protect the public interest.”)).Thomas J. Moloney, Paul R. St. Lawrence, III & Angela F. Hamarich, _Fiduciary Duties, Broker-Dealers and Sophisticated Clients: A Mis-Match That Could Only Be Made in Washington_ , 3 J. SEC. L. REG. & COMPLIANCE 336 (2010) [hereinafter _Fiduciary Duties, Broker-Dealers and Sophisticated Clients_ ] (providing an overview of the fiduciary duty debate); Lisa M. Fairfax, _Spare the Rod, Spoil the Director – Revitalizing Directors’ Fiduciary Duty through Legal Liability,_ 42 HOUS. L. REV. 393 (2005-2006) [hereinafter Fairfax] (asserting that “legal liability represents an essential mechanism for ensuring directors' fidelity to their fiduciary duties and for questioning reform efforts that do not include such liability.”); Margaret M. Blair, _Stakeholders as Shareholders, Ownership and Control: Rethinking Corporate Governance for the Twenty-First Century_ , 109 HARV. L. REV. 1150 (1996) [hereinafter Blair].

> 5 _See, e.g._ , Claire A. Hill & Brett McDonnell, _Executive Compensation and the Optimal Penumbra of Delaware Corporate Law,_ VA. L. & BUS. REV. 334, 334, 336 (2009) [hereinafter _Optimal Penumbra_ ]; Johnson & Sides, _supra_ note 3, at 101, 139; Larry E. Ribstein, _Fencing Fiduciary Duties,_ 91 B.U. L. Rev. 859, 899 (2011) [hereinafter Ribstein].

6 One group of scholars emphasizes the differences between the duties of corporate officers and directors, _see e.g._ Paul E. McGreal, _Corporate Compliance Survey_ , 64 Bus. Law. 253, 273 (2008) [hereinafter _Compliance Survey_ ]. (“Some commentators, taking their cue from agency law, have suggested that an officer’s fiduciary duties should be more demanding [than a director’s].”) (citing Lyman P.Q. Johnson & Robert V. Vicca, _(Not) Advising Corporate Officers About Fiduciary Duties_ , 42 WAKE FOREST L. REV. 663 (2007)); Lyman P.Q. Johnson & David Millon, _Recalling Why Corporate Officers Are Fiduciaries_ , 46 WM. & MARY L. REV. 1597, 1600 & n.10 (2005) (“[C]ourts and commentators routinely describe the duties of directors and officers together, and in identical terms.”).  For cases that discuss officers’ fiduciary duties, _see generally_ Hill & McDonnell, _supra_ note 4, at 133. Another group of scholars evaluates the practical limitations of fiduciary duties, _see e.g._ Lisa M. Fairfax, _Managing Expectations – Does the Directors’ Duty to Monitor Promise More than it Can Deliver?_ , [___] U. ST. THOMAS L.J. [___] (forthcoming 2013) (on file with author); Wulf A. Kaal, _A Comparative Perspective on The Limitations of The Duty of Oversight – A Comment on Lisa Fairfax_ , [__] St. Thomas L. J. [__] (forthcoming 2013).

CORPORATE INTEGRITY AGREEMENTS

main debate focuses on whether improvements to the fiduciary duty doctrine can be attained through expansion<sup>7</sup> or curtailment<sup>8</sup> of the doctrine.

The academic debate on options for improvement of the fiduciary duty doctrine has ignored the possible role of Corporate Integrity Agreements (CIAs).  CIAs are administratively-enforced compliance programs funded by health care companies but enforced by the government. In other words, they are contracts between health care companies and the federal government and can involve costly mandatory compliance measures and penalties.<sup>9</sup> Because the directors contractually agree to increase compliance by way of an open door policy for the government,<sup>10</sup> CIAs can substantially increase the risk of liability for companies whose directors did not act in accordance with their fiduciary responsibilities. While CIAs are outside the traditional legal framework that formally defines fiduciary duties, they fit into the penumbra of extra-legal forces<sup>11</sup> that helps to clarify the expectations for directors.

The contractual obligations in CIAs can enhance directors’ fiduciary default duties, expanding the duty of care for directors of health care corporations beyond the legal standard under _Caremark_ and _Ritter_ .<sup>12</sup> The duties imposed in a CIA can include, among others: the passing of specific resolutions, appointment of a chief compliance officer (CCO); agreement that the CCO will increase the frequency of reports to the board; board certification of compliance with the CIA; reporting of compliance issues to the relevant authorities; and annual reviews through an independent review organization.<sup>13</sup>

Courts are increasingly recognizing the role of CIAs and their implications for directors’ fiduciary duties. A prominent recent decision, _In re Pfizer_ ,<sup>14</sup> illustrates the role

> 7 _See_ Claire A. Hill & Brett H. McDonnell, _Stone v. Ritter and the Expanding Duty of Loyalty_ , 76 FORDHAM L. REV. 1769 (2007); _see, e.g._ , Frankel, _supra_ note 4 (clarifying the theory behind an expansive version of fiduciary duties); Cynthia A. Williams & John M. Conley, _Is There an Emerging Fiduciary Duty to Consider Human Rights?_ , 74 U. CINCINNATI  L. REV. 75, 77 (2005).

> 8 Ribstein, _supra_ note 5, at 899 (arguing for a more precise definition and more limited application of fiduciary duties).

> 9 GREG LUCE, HEALTH CARE LITIGATION STRATEGIES: LEADING LAWYERS ON ANALYZING RECENT HEALTH CARE LITIGATION TRENDS, DEVELOPING SUCCESSFUL CASE STRATEGIES, AND PROTECTING CLIENT RIGHTS, DEFENDING THE HEALTH CARE INDUSTRY AGAINST THE GOVERNMENT’S EXPANDING AND NOVEL THEORIES OF LIABILITY (2011) [hereinafter HEALTH CARE LITIGATION STRATEGIES]. 10 A board that executes a CIA agrees to increased government scrutiny, including but not limited to granting permission for government site visits during the term of the CIA. U.S. Dept. Health and Human Servs. Office of Inspector Gen., _Corporate Integrity Agreement FAQ_ , https://oig.hhs.gov/faqs/corporate- <u>integrity-agreements-faq.asp (last visited Aug. 1, 2013) [hereinafter</u> _<u>Corporate Integrity Agreement FAQ</u>_ ] (“[The purpose of a site visit is] to verify the entity's compliance with the terms of its Corporate Integrity Agreement and to provide OIG with an opportunity to observe an entity's compliance program in practice. The first-hand observations obtained while on site provide the OIG with a more accurate and comprehensive assessment of an entity's compliance program. The site visit also offers the entity the unique, one-on-one opportunity to educate us regarding the entity's operations. OIG has also found that site visits help foster more effective communication between the entity and the OIG.”).

> 11 _See Optimal Penumbra_ , _supra_ note 5, at 334.

> 12 Stone v. Ritter, 911 A.2d 362,364 (Del. 2006) (quoting _In re_ Caremark Int’l Inc. Derivative Litig., 698 A.2d 959, 971 (Del. Ch. 1996)).

> 13 _Corporate Integrity Agreements_ , U.S. DEPT. HEALTH AND HUMAN SERVS. OFFICE OF INSPECTOR GEN., <u>https://oig.hhs.gov/compliance/corporate-integrity-agreements/index.asp (last visited Aug. 5, 2013)</u>

[hereinafter _Corporate Integrity Agreements_ ].

> 14 _In re_ Pfizer, 722 F. Supp. 2d 453, 461 (S.D.N.Y. 2010)

CORPORATE INTEGRITY AGREEMENTS

of CIAs in the evolution of fiduciary duties. Although the court in Pfizer did not conclude that the CIAs actually created fiduciary duties, the court opined that the CIAs “imposed affirmative obligations on Pfizer's board that went well beyond the basic fiduciary duties required by Delaware law.”<sup>15</sup> A broad reading of this phraseology suggests that fiduciary duties could perhaps be augmented by contractual arrangements such as CIAs. Should other courts follow this reasoning, fiduciary duties—and more specifically directors’ basic legal duty of care—could over time expand in the CIA context.

This article includes five parts. Part II introduces the academic debate on the scope and expansion of fiduciary duties. Part III explores the main characteristics of CIAs, their reach and scope, and common denominators in executed CIAs. Part IV outlines the role of CIAs in expanding the law of fiduciary duties both as a contractual addendum and as a hybrid form of aspirational corporate governance. The authors delineate the role of CIAs in fiduciary duties by discussing relevant case law. After exploring the benefits of CIAs for the expansion of fiduciary duties, the authors outline possible limitations. Part V concludes.

# **II. Expanding Fiduciary Duties**

The law of fiduciary duties has evolved as a result of both judicial decisions (traditional legal holdings as well as non-adjudicatory writings) and traditional equity and standards-based approaches to governance duties.<sup>16</sup> Traditionally only two fiduciary duties existed, the duties of loyalty and care.<sup>17</sup> But, fiduciary duty law has evolved in the past few decades and fiduciary duties have expanded.<sup>18</sup> Today, courts recognize intermediate standards, particularly the duty of good faith, making directors responsible for a triad of fiduciary duties.<sup>19</sup> In addition to judicial decisions, the recent financial crises and their legislative fallout have played a role in changing the law of fiduciary duties. The Sarbanes-Oxley Act<sup>20</sup> and the Dodd-Frank Act have influenced and shaped fiduciary duties but have not necessarily improved and clarified them.<sup>21</sup>

> 15 _Id._

> 16 Johnson & Sides, _supra_ note 3, at 104.

> 17 _Id._

> 18 Claire A. Hill & Brett McDonnell, _Introduction: The Evolution of the Economic Analysis of Corporate Law_ , _in_ RESEARCH HANDBOOKS IN LAW AND ECONOMICS 5 (Claire A. Hill & Brett H. McDonnell, eds., 2012); _see also Optimal Penumbra_ , _supra_ note 5, at 347, 353 (claiming that despite the evolution of fiduciary duties, the changes as of yet are incomplete and of disputable value and arguing that because market forces alone cannot create an optimal director mindset, and courts alone cannot micro-manage businesses, fiduciary duty law can and should be supplemented by extra legal forces).

> 19 _Optimal Penumbra, supra_ note 5, at 338; _see also_ Claire A. Hill & Brett McDonnell, _Disney, Good Faith, and Structural Bias_ , 32 J. CORP. L. 833, 834, 845 (2007) [hereinafter _Disney, Good Faith, and Structural Bias_ ] ( _citing In re_ Walt Disney Co. Derivative Litig., 906 A.2d 27, 66-67 (Del. 2006)).

> 20 _Disney, Good Faith, and Structural Bias_ , _supra_ note 19, at 848.

> 21 Johnson & Sides, _supra_ note 3. Johnson and Sides point out that, rather than assessing whether directors followed specific rules, judges review the manner in which directors acted. This “process” approach allows a “tailored” response to breach of fiduciary duty claims, resulting in incremental changes to fiduciary duty norms over time. _Id_ . at 140. Because of this “process” approach, Johnson and Sides argue that laws such as Sarbanes-Oxley are incapable of providing a comprehensive, clearly-defined approach to proper governance – fiduciary duties are much more nuanced and norm-driven than the duties required by such statutes. _Id_ . Johnson and Sides agree that federal statutes can breathe new meaning into our understanding of proper oversight or reasonable care. _Id_ . at 143. For example, the duty of due care requires directors to monitor the corporation and act with appropriate oversight. _Id_ . at 141. One often overlooked issue is

CORPORATE INTEGRITY AGREEMENTS

The academic debate on the scope and reach of fiduciary duties has endured for more than three decades. There is some consensus that fiduciary duties are too vague and should be better defined.<sup>22</sup> A minority of scholars prefers a limited application of fiduciary duties,<sup>23</sup> citing as a particular concern the expansion of fiduciary duties via federal law.<sup>24</sup> To avoid confusion and inconsistency in the law of fiduciary duties, these scholars conceptualize fiduciary duties as a type of contract<sup>25</sup> and a duty of unselfishness.<sup>26</sup> This narrower definition of fiduciary duties is rooted in the concept of entrustment: when the control of an organization is separated from the ownership of that organization, the fiduciary duty owed by the controllers protects the owners.<sup>27</sup> In these relationships, it would be costly or impracticable for the owner to fully monitor the controller.<sup>28</sup> Hence, fiduciary duties exist to compensate for owners’ inability to fully monitor the controllers.<sup>29</sup>

Chancellor Allen’s admonition in _Caremark_ that directors have an “obligation to be reasonably informed,” that they must “exercise reasonable oversight,” and that directors must “assure a reasonable information and reporting system” exists. _Id_ . at 142-43 (citing _Caremark_ at 970-71).  What this means is that directors have an obligation to be “reasonably informed” and what that obligation means will shift as the legislature passes federal laws setting new norms. _Id_ . at 143. Further, part of due care requires directors to ensure their corporation’s compliance with various regulatory schemes. _Id_ .  This duty will also shift as more laws are passed. _Id_ . Johnson and Sides, while arguing that fiduciary duties are not federalized, acknowledge the impact that federal laws have on governance responsibilities, even though the responsibilities are still broad and open to interpretation.

> 22 _See, e.g._ , Ribstein, _supra_ note 5, at 899; _Optimal Penumbra_ , _supra_ note 5, at 336; Johnson & Sides, _supra_ note 3, at 139.

> 23 Ribstein, _supra_ note 5, at 899 (arguing for a more precise definition and more limited application of fiduciary duties).

> 24 _See_ Roberta Romano, _The Sarbanes-Oxley Act and the Making of Quack Corporate Governance_ , 114 YALE L. J. 1523, 1529 (2005) [hereinafter _Quack Corporate Governance_ ]; Stephen M. Bainbridge, _DoddFrank: Quack Corporate Governance Round II_ , 95 MINN. L. REV. 1779 (2011) [hereinafter _Dodd-Frank_ ]; Roberta Romano, _Answering the Wrong Question: The Tenuous Case for Mandatory Corporate Laws_ , 89 COLUM. L. REV. 1599, 1601 (1989) [hereinafter _Answering the Wrong Question_ ] (arguing that corporate governance laws should not be mandatory even before SOX was passed).

> 25 Ribstein, _supra_ note 5, at 859.

> 26 Ribstein, _supra_ note 5, at 858 (arguing that a broader view of fiduciary duties has significant limitations and that the strictness of the duty of unselfishness requires a limited scope).  Justice Cardozo, in _Meinhard v. Salmon_ famously described fiduciary duties (164 N.E. 545 (N.Y. 1928)):

Joint adventurers, like copartners, owe to one another, while the enterprise continues, the duty of the finest loyalty. . . .  A trustee is held to something stricter than the morals of the market place.  Not honesty alone, but the punctilio of an honor the most sensitive, is then the standard of behavior. _Id_ . at 546.

Ribstein found such a strict duty to be “only rarely appropriate in a competitive marketplace” so therefore only required in relationships where power was entrusted to a non-owner. Ribstein at 861. Instead of a broad, vague approach to fiduciary duties, Ribstein believed parties should be able to contractually adjust the duties promised and be held to a simple duty of unselfishness in relationships where there is an entrustment of power. _Id_ . at 865.

> 27 Ribstein, _supra_ note 5, at 859.

> 28 Larry E. Ribstein, _The Structure of the Fiduciary Relationship_ 8 (U. Illinois Law & Econ. Research <u>Paper No. LE03-003, 2003),</u> _available at_ <u>http://papers.ssrn.com/sol3/papers.cfm?abstract_id=397641.</u>

> 29 _Id_ . at 10.

CORPORATE INTEGRITY AGREEMENTS

A substantial part of the literature supports the expansion of fiduciary duties.<sup>30</sup> The leading argument for the expansion of fiduciary duties is that the traditional fiduciary duty doctrine is inconsistent and can result in cases with problematic outcomes.<sup>31</sup> An increasing number of scholars argue that extra-legal forces can further shape and expand corporate law.<sup>32</sup> The law alone may not always require corporate directors to fulfil their fiduciary duty to shareholders, but extra-legal forces can help fill the gaps.<sup>33</sup> Because state fiduciary duty law is permissive rather than regulatory, fiduciary standards can develop from non-legislative sources.<sup>34</sup> The overall umbrella of fiduciary responsibilities is arguably non-binding, more akin to corporate ‘best practices,’ and aspirational in nature, making extra-legal forces a legitimate source that can help shape fiduciary duties.<sup>35</sup> Extra-legal sources include, among others, the advice given by a corporation’s law firm, judicial pronouncements made outside the traditional legal opinion, and influential academic views in today’s corporate governance scholarship.<sup>36</sup> These extralegal forces can create norms that help guide directors.<sup>37</sup>

# **III. Corporate Integrity Agreements**

Corporate integrity agreements can have an impact on fiduciary duties and corporate governance. CIAs are administratively-enforced compliance programs funded by health care companies but enforced by the government. CIAs can enhance directors’ fiduciary duties if directors contractually agree to increase compliance for the companies they manage. Through this mechanism, CIAs increase the stakes for companies whose directors did not act in accordance with their fiduciary responsibilities, as enhanced by CIAs. CIAs can result in costly mandatory compliance measures and penalties.<sup>38</sup>

The enhanced duties that can be imposed on boards include: appointment of a chief compliance officer (CCO); agreement that the CCO will increase the frequency of reports to the board; board certification of compliance with the CIA; reporting of compliance issues to the relevant authorities; and annual reviews through an independent review organization. CIAs are not part of the legal framework that defines fiduciary duties. However, CIAs are part of the penumbra of extra-legal forces<sup>39</sup> that can expand and help clarify the scope of fiduciary duties.

# _1. Background_

CIAs are a relatively new phenomenon.  Beginning in the 1990s, the Department of Health and Human Services Office of the Inspector General (OIG) started using CIAs

> 30 _See, e.g._ , Hill & McDonnell, _supra_ note 4; Johnson & Sides, _supra_ note 3; _see also_ Wade, _supra_ note 4; _Fiduciary Duties, Broker-Dealers and Sophisticated Clients_ , _supra_ note 4; Fairfax, _supra_ note 4; Blair, _supra_ note 4; _Optimal Penumbra_ , _supra_ note 5.

> 31 _Disney, Good Faith, and Structural Bias_ , _supra_ note 19, at 850 (discussing the various _Disney_ cases).

> 32 _Optimal Penumbra_ , _supra_ note 5, at 334, 336; Johnson & Sides, _supra_ note 3, at 104.

> 33 _Optimal Penumbra_ , _supra_ note 5, at 352.

> 34 Johnson & Sides, _supra_ note 3, at 137-38.

> 35 _Id_ . at 138.

> 36 _Optimal Penumbra_ , _supra_ note 5, at 357-58.

> 37 _Id_ . at 364.

> 38 HEALTH CARE LITIGATION STRATEGIES, _supra_ note 9.

> 39 _See Optimal Penumbra_ , _supra_ note 5 , at 334.

CORPORATE INTEGRITY AGREEMENTS

to resolve False Claims Acts investigations.<sup>40</sup> CIAs have evolved from an informal set of self-disclosure programs into a formalized process,<sup>41</sup> requiring the OIG to negotiate CIAs with health care providers and other entities as part of settlements in the context of health care program investigations under false claims statutes.<sup>42</sup> In exchange for providers’ agreement to be bound by the CIA’s substantive provisions, the OIG does not exclude the providers from participation in federal health care programs, including Medicare and Medicaid.<sup>43</sup> In effect, the OIG uses providers’ participation in federal health care programs, and the revenues generated through participation, as leverage to negotiate substantive provisions in CIAs that increase compliance with expected conduct and overall welfare.

The provisions in CIAs are diverse and depend on the specific terms of the settlement. CIAs are generally adjusted to the fact-specific requirements of the individual company and take preexisting compliance programs into account.<sup>44</sup> During the term of a CIA the company that executed the CIA with the government is required to increase compliance functions, including upgrades to the internal compliance structure, increased third-party oversight, and enhanced reporting requirements.<sup>45</sup> In effect, a company that executes a CIA agrees to increased government scrutiny including OIG site visits during the term of the CIA.<sup>46</sup>

Noncompliance with a CIA carries serious penalties.  Upon noncompliance with the terms of a CIA, the OIG can prosecute the company or seek its exclusion from federal health care programs.<sup>47</sup> The penalties under CIAs affect the respective entity and individuals who work for the entity. For instance, companies subject to supervision by the Food and Drug Administration (FDA) may not employ individuals who were

> 40 Cristie Ford & David Hess, _Can Corporate Monitorships Improve Corporate Compliance?_ , 34 J. CORP. L. 679, 686 (2009) [hereinafter _Corporate Monitorships_ ].

> 41 _Id_ . at 685 (discussing, specifically, the Defense Industry Initiative).

> 42 _Corporate Integrity Agreements_ , _supra_ note 13; _see also Compliance Survey_ , _supra_ note 6, at 265.

> 43 _Compliance Survey_ , _supra_ note 6, at 265.

> 44 _See Corporate Integrity Agreements_ , _supra_ note 13 (“A comprehensive CIA typically lasts 5 years and includes requirements to: hire a compliance officer/appoint a compliance committee; develop written standards and policies; implement a comprehensive employee training program; retain an independent review organization to conduct annual reviews; establish a confidential disclosure program; restrict employment of ineligible persons; report overpayments, reportable events, and ongoing investigations/legal proceedings; and provide an implementation report and annual reports to OIG on the status of the entity’s compliance activities.”).

> 45 James N. Czaban, _Meeting the Challenge of Increased Enforcement for Food and Drug Industry Clients_ , _in_ RECENT DEVELOPMENTS IN FOOD AND DRUG LAW (2012) [hereinafter Czaban]

> 46 _Corporate Integrity Agreement FAQ_ , _supra_ note 10 ("[The purpose of a site visit is] to verify the entity's compliance with the terms of its Corporate Integrity Agreement and to provide OIG with an opportunity to observe an entity's compliance program in practice. The first-hand observations obtained while on site provide the OIG with a more accurate and comprehensive assessment of an entity's compliance program. The site visit also offers the entity the unique, one-on-one opportunity to educate us regarding the entity's operations. OIG has also found that site visits help foster more effective communication between the entity and the OIG.”).

> 47 Jeffrey Fitzgerald, _Employer Beware: Hidden Risks of Medicare-Excluded Workers_ , DENVER BUS. J., Dec. 11, 2005, _available at_ <u>http://www.bizjournals.com/denver/stories/2005/12/12/focus2.html?page=all [hereinafter</u> _<u>Employer Beware</u>_ <u>] (“In legal circles, Medicare exclusion is referred to as the ‘death penalty’</u> because without Medicare reimbursement, a business can be essentially forced out of the health care industry.”).

CORPORATE INTEGRITY AGREEMENTS

dismissed for CIA violations. The careers of directors and officers in the pharmaceutical industry who were prosecuted in the context of CIA violations can be severely affected.<sup>48</sup> CIAs can also facilitate the pursuit of increased sanctions against noncompliant companies. Certification requirements in CIAs, which require directors and officers to certify compliance with the CIA’s provisions, can lower procedural and enforcement hurdles.<sup>49</sup> The number of individuals who are required to provide certifications under CIAs has dramatically increased in the past few years and the certification requirements go well beyond the certification requirements for the CCO.<sup>50</sup> With the increased number of individuals certifying compliance with CIA provisions, the potential for false certifications and corresponding liability intensifies.<sup>51</sup>

# _2. Characteristics_

Corporate Integrity Agreements have several core characteristics that distinguish them from other contractual arrangements between companies and the government. CIAs often become the standard for expected conduct in a civil or criminal trial.<sup>52</sup> CIA certification requirements can be a powerful tool for prosecutors if the government finds that the certifications misstate the corporation’s true compliance.<sup>53</sup> Once a CIA has been executed, it is much easier for the government to reopen a case than to pursue a new one.<sup>54</sup> The OIG’s increased scrutiny, the potential for crippling penalties, and the ease of further prosecution can have a substantial impact on the knowledge, monitoring, and management of boards of companies that operate under a CIA.

A CIA increases the stakes for directors choosing to eschew their governance responsibilities.  A company operating under a CIA is essentially on parole.<sup>55</sup> CIAs give the government direct access to a health care corporation, facilitating the detection of compliance issues.<sup>56</sup> A corporation that executed a CIA often gives the OIG permission to inspect the company’s compliance documents and conduct on-site inspections to assess its compliance with the CIA.<sup>57</sup> Should the government find problems upon inspection, it

> 48 Czaban, _supra_ note 45, at 3.

> 49 Kathleen McDermott & Arianne Callender, _Compliance Certifications and the Era of Accountability – A Forecast to Debate_ , 5 J. HEALTH & LIFE SCI. L. 158, 160-61 (2012) [hereinafter _Compliance Certifications_ ].

> 50 _Id_ . at 172.

> 51 _Compliance Certifications_ , _supra_ note 49, at 162.  (“There is potential for criminal liability under 18 U.S.C. § 1001, making a material false statement to the United States, if the false certifications are made knowingly.  There is also potential for False Claims Act liability for false certifications.”); _see also_ Thomas Beimers, _Caught by the CIA: Corporate Integrity Agreement Violation is Grounds for False Claims Act Liability_ , BEYOND HEALTCARE REFORM (Mar. 7, 2012), _available at_ <u>http://beyondhealthcarereform.com/caught-by-the-cia-corporate-integrity-agreement-violation-is-groundsfor-false-claims-act-liability/ (The 11th Circuit found that false certifications made as part of CIA</u> obligations could form the basis for False Claims Act liability) (discussing US ex rel. Matheny v. Medco Health Solutions, 671 F.3d 1217, 1224 (11th Cir. 2012)).

> 52 Gabriel L. Imperato & Marc S. Raspanti, _Compliance and Governance for Health Care Organization and Marketing and Sales Activities_ , 11 J. HEALTH CARE COMPLIANCE 5, 7 (2009).

> 53 _Compliance Certifications_ , _supra_ note 49, at 162.

> 54 Czaban, _supra_ note 45, at 3.

> 55 _Id_ . at 3.

> 56 _See Corporate Integrity Agreement FAQ_ , _supra_ note 10

> 57 _See, e.g._ , _Corp. Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and Allergan, Inc_ ., 50-51 (Aug. 30, 2010), _available at_

CORPORATE INTEGRITY AGREEMENTS

can increase the penalties beyond the CIAs’ substantive provisions.<sup>58</sup> These penalties include criminal prosecution, fines, additional CIAs, and exclusion from federally funded health care programs.<sup>59</sup> The $2.3 billion Pfizer settlement in 2009 illustrates how significant possible ramifications can be for companies that engage in illegal activities after executing a CIA.<sup>60</sup>

# _3. Reach and Scope_

By imposing stringent and detailed compliance requirements, CIAs can take an active role in the day-to-day compliance functions of corporations.  CIAs affect the dayto-day compliance operations by increasing the role of the Chief Compliance Officer (CCO). Should a regulated entity not have a CCO, a CIA typically mandates the appointment of a CCO.<sup>61</sup> The CCO is responsible for implementing the CIA and must generally report directly to the Chief Executive Officer (CEO), not to the General Counsel or Chief Financial Officer (CFO).<sup>62</sup> CCOs under CIAs usually have direct access to the boards of directors.<sup>63</sup> CIAs typically require companies to create or maintain a compliance committee that supports the CCOs in fulfilling the additional obligations and duties imposed by the CIA.<sup>64</sup> The compliance committee is usually chaired by the CCO.

CIAs can include specific provisions prescribing the conduct of the boards of directors.<sup>65</sup> For instance, CIAs can mandate the number of board meetings dedicated to

<u>http://oig.hhs.gov/fraud/cia/agreements/Allerga_Executed_CIA_with_Appendices.pdf</u> [hereinafter Allergan CIA].

> 58 _See_ HEALTH CARE LITIGATION STRATEGIES, _supra_ note 9.

> 59 _See Employer Beware_ , _supra_ note 47.

> 60 _In re_ Pfizer, 722 F. Supp. 2d 453, 457 (S.D.N.Y. 2010).

> 61 _See, e.g._ , _Corp. Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and Pfizer Inc_ ., 4 (Aug. 31, 2009), _available at_ http://oig.hhs.gov/fraud/cia/agreements/pfizer_inc_08312009.pdf [hereinafter Pfizer CIA] (“Prior to the Effective Date, Pfizer appointed a Chief Compliance Officer and Pfizer shall maintain a Chief Compliance Officer during the term of the CIA.  The Chief Compliance Officer shall be responsible for developing the requirements set forth in this CIA and with Federal health care program requirements and FDA requirements.”).

> 62 _Id_ .  (“The Chief Compliance Officer shall be a member of senior management of Pfizer, [. . .] shall make periodic (at least quarterly) reports regarding compliance matters directly to the [Audit Committee], and shall be authorized to report on such matters to the Audit Committee at any time [. . .]. The Chief Compliance Officer shall be responsible for monitoring the day-to-day compliance activities engaged in by Pfizer as well as for any reporting obligations created under this CIA.”).

> 63 _See, e.g._ , _Corporate Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and Medtronic Sofamor Danek USA, Inc_ ., 5 (Jul. 14, 2006), _available at_ http://oig.hhs.gov/fraud/cia/agreements/Medtronic_and_MSD_CIA.pdf [hereinafter Medtronic CIA].

> 64 _See, e.g._ , Allergan CIA, _supra_ note 57.

> 65 _See, e.g._ , Allergan CIA, _supra_ note 57, at 6; Pfizer CIA, _supra_ note 61, at 5; _Corporate Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and AstraZeneca LP_ , 6 (Apr. 26, 2010), _available at_

http://oig.hhs.gov/fraud/cia/agreements/astrazeneca_04272010.pdf [hereinafter AstraZeneca CIA]. Other CIAs are silent on board-specific requirements _see, e.g._ , _Corporate Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and Zimmer, Inc._ (Sep. 27, 2007), _available at_ http://www.justice.gov/usao/nj/Press/files/pdffiles/Older/ZimmerCIA92707.pdf [hereinafter Zimmer CIA]; _Corporate Integrity Agreement Between the Off. of the Inspector Gen. of the U.S. Dep’t of Health & Human Servs. and DePuy Orthopaedics, Inc._ (Aug. 27, 2007), _available at_

CORPORATE INTEGRITY AGREEMENTS

the review of the company’s compliance program.<sup>66</sup> CIAs may even require boards to adopt specific resolutions to certify the company’s compliance with the CIA and increase reporting obligations.<sup>67</sup> In effect, these provisions allow the government to contractually determine how and when a board will interact. The certification requirements can lead directors to require more detailed reports from the corporate officers and take a greater role in overseeing the company’s compliance with both the CIA and federal regulations.

In addition to increasing board obligations and duties of the CCO, CIAs can require a number of other compliance measures.  Companies operating under a CIA may be required to develop and implement a written code of conduct,<sup>68</sup> often used to define and explain the role of the CCO.<sup>69</sup> A code of conduct implemented under a CIA may merely require the company’s full compliance with federal, state, and local laws,<sup>70</sup> but it can also demand compliance with FDA requirements,<sup>71</sup> or require compliance with voluntary codes.<sup>72</sup> Codes of conduct also list the consequences of noncompliance with the company’s policies and procedures, the federal health care program, or FDA requirements.<sup>73</sup> Codes of conduct should encourage disclosure of compliance issues and protect whistle blowers from retaliation by maintaining the anonymity of disclosures.<sup>74</sup>

Other CIA provisions require companies to self-report compliance issues to the government, notify the government of communications with the FDA, field force monitoring, monitor non-promotional activities, provide mandatory compliance training and education for employees, upgrade review procedures, increase disclosure programs, define ineligible persons for employment, and report physician payments.<sup>75</sup> All of these additional requirements, especially the self-reporting provisions, require companies to

<u>http://www.justice.gov/usao/nj/Press/files/pdffiles/Older/DePuyCIA92707.pdf</u> [hereinafter DePuy CIA]; Medtronic CIA, _supra_ note 63.

> 66 _See, e.g._ , Allergan CIA, _supra_ note 57, at 6 (“The Board must meet at least quarterly to review and oversee Allergan’s Compliance Program, including but not limited to evaluating its effectiveness and receiving updates about the activities of the Chief Compliance Officer and other compliance personnel.” ).

> 67 _See, e.g._ , AstraZeneca CIA, _supra_ note 65, at 6-7 (“[This resolution] shall be signed by each individual member of the Board or the Committee, summarizing its review and oversight of matters relating to AstraZeneca’s compliance with Federal health care program requirements, FDA requirements, and the obligations of this CIA. […The CIA goes on set forth the required minimum language to be used in this resolution:] The Board of Directors [or a Committee of the Board] has made a reasonable inquiry into the operations of AstraZeneca LP and AstraZeneca Pharmaceuticals LP’s Compliance Program for the Corporate Integrity Agreement AstraZeneca period ____, including but not limited to evaluating its effectiveness and receiving updates about the activities of its U.S. Compliance Officer and other compliance personnel.  Based on its inquiry, the Board [or the Committee] has concluded that, to the best of its knowledge, AstraZeneca LP and AstraZeneca Pharmaceuticals LP have implemented an effective U.S. Compliance Program to meet Federal health care program requirements, FDA requirements, and the obligations of the Corporate Integrity Agreement. If the Board cannot certify such a conclusion in the required resolution, it must set forth the reasons why it is unable to do so and the steps it is taking to ensure compliance with the CIA.”).

> 68 _See, e.g._ , Medtronic CIA, _supra_ note 63, at 6.

> 69 _See, e.g._ , Pfizer CIA, _supra_ note 61, at 8.

> 70 _See, e.g._ , DePuy CIA, _supra_ note 65, at 4.

> 71 _See, e.g._ , Allergan CIA, _supra_ note 57, at 8.

> 72 _See, e.g._ , DePuy CIA, _supra_ note 65, at 4.

> 73 _Id_ .

> 74 _See, e.g._ , AstraZeneca CIA, _supra_ note 65, at 9.

> 75 _Id._ at 37-39.

CORPORATE INTEGRITY AGREEMENTS

spend additional resources and, at times, alter their day-to-day operations after signing a CIA.<sup>76</sup>

# **IV. The Role of CIAs in Expanding Fiduciary Duties**

Courts differentiate between the law and aspirational corporate governance.<sup>77</sup> Corporate fiduciary duties and remedies for duty violations are not aspirational goals of ideal corporate governance practices.<sup>78</sup> Aspirational ideas for boards’ corporate governance practices do not define standards of liability.<sup>79</sup> Although CIAs are not laws, they do go beyond aspirational governance standards.  CIAs set forth concrete governance rules that expand the fiduciary duties of directors. CIAs more clearly define the duties of directors to be informed, exercise oversight, and establish effective reporting systems – requiring a higher standard of care for directors operating under a CIA.

Several characteristics distinguish CIAs from both the fiduciary duties doctrine and from regular contracts. Unlike the traditional fiduciary duties doctrine, CIAs set out mandatory and clearly defined best practices for companies. Unlike private contracts, companies execute CIAs to avoid further prosecution by the government for various health care fraud charges and to avoid being excluded from Medicaid and Medicare. If the government decides a CIA is warranted, the company’s hands are tied if it wants to continue to operate within its industry.  CIAs combine elements of contractual and public enforcement. As a contractual arrangement, the terms of the CIA between the company and the government dictate heightened compliance duties for the company. Unlike regular contractual arrangements, however, the enforcement of CIAs goes beyond contractual remedies. The OIG may enforce CIAs and private rights of action may also come into play. Because of the combination of enforcement mechanisms, CIAs are more than contractual arrangements. A breach of a CIA may be treated like a breach of law for purposes of the duty of care. Under Delaware law, CIAs may not only be enforced by the OIG, but also by the courts via a derivative suit.

# _1. Contractual Addendum to Increase Duties_

In lieu of a special hybrid category for CIAs, they are first and foremost contracts. As contracts, CIAs can create a contractual addendum to existing legal duties. To the extent that CIAs mandate specific actions in the day-to-day operations of boards of directors, CIAs can expand boards’ duties. For instance, while there is no federal law mandating the reporting of payments to physicians, CIAs can and often do require such disclosures.<sup>80</sup> Another example entails boards’ liability for illegal marketing. Although

> 76 _See Corporate Integrity Agreements_ , METRICSTREAM,

> <u>http://www.metricstream.com/solution_briefs/corporate-integrity-agreements.htm (last visited Aug. 5, 2013) (explaining that the additional costs and day-to-day impact of CIAs is enough that some</u>

> entrepreneurial companies are targeting companies operating under a CIA in order to help them streamline their compliance processes)..

> 77 _In re_ Johnson & Johnson Derivative Litig., 865 F. Supp. 2d 545 (D. N.J. 2011).

> 78 Brehm v. Eisner _,_ 746 A.2d 244 (Del. 2000).

> 79 _Id_ . at 255-56; _In re_ J & J, 865 F. Supp. 2d. at 11.

> 80 Medicare, Medicaid, Children's Health Insurance Programs; Transparency Reports

> and Reporting of Physician Ownership or Investment Interests, 78 Fed. Reg. 9,458 (Feb. 8, 2013) (to be codified at 42 C.F.R. Pts. 402 and 403); _see also_ AstraZeneca CIA, _supra_ note 65, at 37-39.

CORPORATE INTEGRITY AGREEMENTS

federal law prohibits off-label marketing of drugs and devices,<sup>81</sup> boards are consistently held not liable for companies’ illegal marketing efforts.<sup>82</sup> However, boards that certify compliance with a CIA are certifying that the company is properly monitoring the promotional activities of its sales teams. Through such certifications, CIAs contractually expand the applicable legal standards for boards.

CIAs can contractually expand directors’ duties beyond the _Caremark_ standard and its progeny. Several CIA features suggest that directors are held to a higher standard after a CIA has been executed. Individual CIA provisions can put boards on notice, highlight extra care requirements in specific areas of operation, and enable the board to increase their knowledge of the corporation’s activities and corresponding compliance requirements, making it easier to carefully and effectively monitor the organization. More specifically, because CIAs often mandate a CCO and dictate how the CCO interacts with the board, CIAs can increase boards’ knowledge and monitoring of the company’s compliance.<sup>83</sup> If a board possesses such knowledge, it should play a bigger role in ensuring that the company meets federal and state standards. Moreover, CIAs often require boards to pass specific resolutions certifying compliance.<sup>84</sup> Besides increasing boards’ operational knowledge (thus allowing for a more comprehensive approach to governance), CIAs also demand assurances that boards are meeting their fiduciary duties.

CIA provisions can create economic incentives that affect directors’ diligence in exercising their duties. CIAs can have harsh economic consequences for companies. CIAs provide for penalties in cases of noncompliance. Companies agree in their respective CIA to pay penalties for each day of noncompliance with the agreement. Penalties can add up to thousands of dollars per day.<sup>85</sup> Additionally, most federal health law regulations provide for monetary penalties in cases of noncompliance. Because of the required self-reporting, a company operating under a CIA may be required to report violations of the False Claims Act, Sunshine, Stark, AKS, HIPAA, or other federal health laws. Adding the stipulated penalties in CIAs to the monetary penalties under federal health laws, companies that executed CIAs face significant financial ramifications.

# _2. Delineating the Role of CIAs in Fiduciary Duties_

_Caremark_ underscores that a lack of oversight claim “is possibly the most difficult theory in corporation law upon which a plaintiff might hope to win judgment.”<sup>86</sup> Courts dismiss duty of care cases routinely at the pleading stage.<sup>87</sup>

> 81 The Criminal and Civil False Claims Acts, 18 U.S.C. § 287 (2006), 31 U.S.C. 3729 et. Seq. (2006), and

> 31 U.S.C. § 3730 (2006).

> 82 _See_ Markewich v. Collins _,_ 622 F. Supp. 2d 802 (D. Minn. 2009); _In re_ J & J, 865 F. Supp. 2d.; King v. Baldino, 648 F. Supp. 2d 609 (D. Del. 2009). _._

> 83 _See, e.g._ , Pfizer CIA, _supra_ note 61, at 4.

> 84 _See, e.g._ , AstraZeneca CIA, _supra_ note 65, at 6.

> 85 _Id_ .

> 86 _In re_ Caremark Int’l. Inc. Derivative Litig., 698 A.2d 959, 967 (Del. Ch. 1996).

> 87 A number of recent cases illustrate that courts have not allowed breach of fiduciary duty suits to proceed when plaintiffs did not make demand upon the boards and failed to adequately plead demand futility. _See King v. Baldino,_ 648 F.Supp.2d 609, 610 (D. Del. 2009) (dismissing the complaint on the basis that plaintiff did not adequately plead demand futility; quoting _Stone v. Ritter_ , 911 A.2d at 373.)

> With the benefit of hindsight, the plaintiffs’ complaint seeks to equate a bad outcome with bad faith.  The lacuna in the plaintiffs’ argument is a failure to recognize that the directors’ good faith exercise of oversight responsibility may not invariably prevent employees from

CORPORATE INTEGRITY AGREEMENTS

Courts, however, treat companies that executed a CIA differently. Courts are increasingly recognizing the role of CIAs and their implications for directors’ fiduciary duties. A prominent recent decision, _In re Pfizer_ ,<sup>88</sup> illustrates the role of CIAs in the evolution of fiduciary duties. Although the court in _Pfizer_ did not conclude that the CIAs actually created fiduciary duties, the court opined that the CIAs “imposed affirmative obligations on Pfizer's board that went well beyond the basic fiduciary duties required by Delaware law.”<sup>89</sup> A broader reading of this phraseology suggests that fiduciary duties could perhaps be augmented by contractual arrangements such as CIAs. Following this reasoning, it seems possible that future courts could interpret CIAs as expanding the basic legal duty of care.

In a case with fairly egregious facts, the New Jersey District Court dismissed a derivative complaint against the Johnson & Johnson (J&J) board for failure to plead demand.<sup>90</sup> Plaintiffs alleged that the J&J directors breached their fiduciary duty “by permitting and fostering a culture of systematic, calculated and widespread legal violations.”<sup>91</sup> No CIA had been executed before the alleged misconduct.  Plaintiffs did not make demand on the board before filing suit.<sup>92</sup> Plaintiffs’ allegations state that directors should have known about the company’s questionable acts because J&J received FDA warning letters, an FDA report, subpoenas from the state attorney general, qui tam complaints, a criminal plea, and a settlement agreement with the Department of Justice.<sup>93</sup> The court looked to _Brehm v. Eisner_<sup>_94_</sup> to analyze the case, given the “weighty allegations of corporate misconduct and director inaction.”<sup>95</sup> The _Brehm_ court described its case as a case concerning whether directors may be held personally liable for lack of due care in the corporate decision-making process – not as a case about whether the directors failed to establish and implement ideal corporate governance practices.<sup>96</sup> The _Brehm_ court stipulated: “the law of corporate fiduciary duties and remedies for violation of those duties are distinct from the aspirational goals of ideal corporate governance practices,” meaning that “aspirational ideas of good corporate governance practices for boards of directors . . . are not required by the corporation law and do not define standards of liability.”<sup>97</sup> The court explained that it found these words appropriate when the complaint alleged that the J&J board failed to live up to aspirational ideals, but failed

violating criminal laws, or from causing the corporation to incur significant financial liability, or both, as occurred in . . . this very case.

_See also Markewich v. Collins,_ 622 F.Supp.2d 802 (D. Minn. 2009) (finding that the complaint did not plead sufficient facts to allow the inference that the directors operated under a “sustained or systematic failure” to exercise oversight; quoting _Desimone v. Barrows_ , 924 A.2d 908, 940 (Del. Ch.  2007) “Delaware courts routinely reject the conclusory allegation that because illegal behavior occurred, internal controls must have been deficient, and the board must have known so.”) In a pre-CIA setting, both the _Baldino_ and the _Markewich_ court did not allow an assumption of director wrongdoing just because improper behavior occurred.

> 88 _In re_ Pfizer, 722 F. Supp. 2d 453, 461 (S.D.N.Y. 2010).

> 89 _Id._ at 461.

> 90 _In re_ Johnson & Johnson Derivative Litig., 865 F. Supp. 2d 545, 549 (D. N.J. 2011).

> 91 _Id._

> 92 _Id_ .

> 93 _Id_ . at 550.

94 Brehm v. Eisner, 746 A.2d 244 (Del. 2000). 95 _In re_ Johnson & Johnson Derivative Litig., 865 F. Supp. 2d. at 559. .

> 96 _Id_ . (quoting Brehm, 746 A.2d at 255-256).

> 97 _Id_ .

CORPORATE INTEGRITY AGREEMENTS

to allege that the directors acted in bad faith in order violate their fiduciary duties.<sup>98</sup> The court here differentiates between the law and aspirational corporate governance. However, when a company is operating under a CIA, the distinction between the law and aspirational governance is less clear.

The _In re Pfizer_ derivative suit followed a number of settlement agreements between Pfizer and the Department of Justice, including a 2009 settlement of $2.3 billion, consisting of the largest criminal fine ever imposed in the United States ($1.195 billion) and the largest civil fraud settlement in history against a pharmaceutical company of $1 billion.<sup>99</sup> Following settlement agreements in 2002, 2004, and again in 2009, Pfizer signed three separate CIAs with the OIG.<sup>100</sup> Among other allegations, Plaintiffs alleged that Pfizer’s directors breached their fiduciary duties by causing or consciously disregarding the illegal marketing activities that led in part to the staggering 2009 settlement.<sup>101</sup> Plaintiffs did not issue a demand upon the board of directors.<sup>102</sup> When analyzing whether demand was futile, the court noted that “many of [the] disturbing reports [of noncompliance] were received during the same time that the board was obligated by the 2002 and 2004 CIAs to pay special attention to these very problems.”<sup>103</sup>

This language is significant. The court stipulates that in the case of a company that executed a CIA, it will allow an assumption that the directors were fully informed, and thus, willing participants in the corporate malfeasance.  For this reason, the court found that the “plaintiffs have pleaded with sufficient particularity that a majority of directors faced a substantial likelihood of personal liability because they deliberately disregarded reports of the illegal marketing practices eventually resulting in the 2009 settlement.”<sup>104</sup> In this case, the CIAs became the court’s proof that the directors could very well have breached their fiduciary duties.

The court in _In re Pfizer_ cited _In re Abbott Laboratories Derivative Shareholders Litigation_<sup>_105_</sup> [hereinafter _Abbott Labs_ ], a case that perhaps sets the stage for the _In re Pfizer_ holding.  In _Abbott Labs_ , the Seventh Circuit reversed the dismissal of a shareholder suit for breach of fiduciary duty for failure to adequately plead demand futility.<sup>106</sup> In their complaint, Plaintiffs alleged that Abbott directors breached their

> 98 _Id._

> 99 _In re_ Pfizer, 722 F. Supp. 2d 453, 455-57 (S.D.N.Y. 2010).

> 100 _Id_ . at 457.

> 101 _Id_ .

> 102 _Id_ . at 458.

> 103 _Id_ . The court explained: “As illustrated by the sheer size of the 2009 fines, the wrongdoing here alleged was not only pervasive throughout Pfizer but also was committed in the face of the board's repeated promises to closely monitor and prevent such misconduct, as required by the 2002 and 2004 CIAs. These CIAs, which were part of larger settlements approved by the Pfizer board, imposed affirmative obligations on Pfizer's board that went well beyond the basic fiduciary duties required by Delaware law. Among other things, these agreements obligated Pfizer's chief Compliance Officer to report directly to the board the allegations of misconduct here at issue so that the board could deal with them directly, rather than relying on management. There is no reason to believe this reporting requirement was not fully complied with, thus guaranteeing that each member of the board was bombarded with allegations of continuing misconduct of the very kind that the prior settlements looked to the board to prevent.” _Id_ . at 460-61.

> 104 _Id_ . at 462.

> 105 _In re_ Abbott Labs. Derivative S’holders Litig , 325 F.3d at 795.

> 106 _Id_ . at 811.

CORPORATE INTEGRITY AGREEMENTS

fiduciary duty when directors were aware of a six-year history of noncompliance with the FDA yet failed to take corrective action to prevent further problems, leading to a $100 million fine – then the largest penalty ever imposed for FDA violations.<sup>107</sup> Plaintiffs alleged directors were aware of and should have corrected the problems because Abbott entered into a Voluntary Compliance Plan with the FDA to address areas of noncompliance six years prior to the FDA filing the injunction that led to the $100 million fine.<sup>108</sup> Plaintiffs argued that demand would have been futile because the board members knew of the continuing noncompliance with the FDA regulations. Furthermore, they knew that such noncompliance would lead to severe penalties because of the enhanced government oversight facilitated by Abbott’s Voluntary Compliance Program (VCP) with the FDA, yet still ignored the FDA’s repeated warnings and chose not to stop the problematic conduct.<sup>109</sup> The Seventh Circuit agreed and held that it was possible the Abbott directors breached their duty.<sup>110</sup> Although the Voluntary Compliance Plan was not a CIA, the Seventh Circuit used it as evidence that the directors knew of and should have stopped noncompliant activities.

To summarize, courts assume that the boards of companies that executed a CIA have more knowledge and can exercise more control and should thus act with a heightened fiduciary duty. Directors are held to a higher standard if the company executed a CIA. The courts in _In re Pfizer_ and _Abbott Labs_ found that Pfizer’s CIA and Abbott’s VCP increased the boards’ knowledge about compliance issues and the directors should have increased their monitoring to prevent further violations.<sup>111</sup> Both courts did not accept the directors’ arguments that they did not know about the noncompliance because executing a CIA or CIA-like agreement means directors do know or should know about the respective noncompliance issues.

The _Pfizer_ and _Abbot Labs_ decisions suggest that CIAs and VCPs can change courts’ evaluations of fiduciary duties. Courts assume that boards operating under CIAs have more knowledge and exercise more control. However, it is unclear if corporations with CIAs will be uniformly affected.  In light of the Pfizer precedent, future courts could hold directors of corporations that executed CIAs to a higher standard and thereby expand their basic legal duty of care if the facts suggest that CIAs provided directors with more knowledge about compliance activities.<sup>112</sup>

> 107 _Id_ . at 801-02.

> 108 _Id_ . at 800-01.

> 109 _Id_ . at 802.

> 110 _In re_ Abbott Labs. Derivative S’holders Litig , 325 F.3d at 809 (“Given the extensive paper trail in _Abbott_ concerning the violations and the inferred awareness of the problems, the facts support a reasonable assumption that there was a ‘sustained and systematic failure of the board to exercise oversight,’ in this case intentional in that the directors knew of the violations of law, took no steps in an effort to prevent or remedy the situation, and that failure to take any action for such an inordinate amount of time resulted in substantial corporate losses, establishing a lack of good faith. We find that six years of noncompliance, inspections, 483s, Warning Letters, and notice in the press, all of which then resulted in the largest civil fine ever imposed by the FDA and the destruction and suspension of products which accounted for approximately $250 million in corporate assets, indicate that the directors’ decision to not act was not made in good faith and was contrary to the best interests of the company.”)

> 111 _See In re_ Pfizer, 722 F. Supp. 2d 453, 461 (S.D.N.Y. 2010); _In re_ Abbott Labs. Derivative S’holders Litig., 325 F.3d at 809.

> 112 _See_ Pfizer CIA, _supra_ note 61, at 4-5 (The Pfizer CIA contains a number of requirements that seem to ensure a well-informed board.  First, the CIA requires the Chief Compliance officer to report directly to the

CORPORATE INTEGRITY AGREEMENTS

# _3. Limitations_

Several important conceptual and legal distinctions separate the fiduciary duties created under Delaware precedent and the contractual obligations under CIAs. CIAs have so far been predominantly used in the health care industry.<sup>113</sup> Health care companies serve the greater good and their mission goes beyond the mere maximization of shareholder value.<sup>114</sup> Directors acting on behalf of corporations in the health care industry face unique challenges. Like other directors, directors in the health care industry are required to make well-informed decisions, oversee the business,<sup>115</sup> and ensure their respective corporations comply with the law.<sup>116</sup> However, the unique features of a health

Chief Executive Officer of Pfizer and make at least quarterly reports on compliance matters to the Audit Committee of the Board. Second, the CIA requires the Audit Committee to meet at least quarterly to review Pfizer’s Compliance Program, including receiving updates on its effectiveness. And third, the CIA requires the Audit Committee to certify that it has made reasonable inquiries into the Compliance Program and that Pfizer is meeting the obligations of the CIA. With each certification, Pfizer’s directors are promising that they are exercising proper oversight, and acting with adequate knowledge); _see also In re_ Pfizer, 722 F. Supp. 2d at 461 (“[T]here is no reason to believe this reporting requirement was not fully complied with, thus guaranteeing that each member of the board was bombarded with allegations of continuing misconduct of the very kind that the prior settlements looked to the board to prevent.”).

> 113 _See_ Barnali Choudhury, _Serving Two Masters: Incorporating Social Responsibility Into the Corporate Paradigm_ , 11 U. PA. J. BUS. L. 631 (2009) (“[T]he purpose of the corporation shapes the normative content of corporate law and the roles and obligations of corporate managers.”). 114 The Medtronic Mission Statement illustrates the idea that a health care corporation can (and should) strive for more than just profits:

To contribute to human welfare by application of biomedical engineering in the research, design, manufacture, and sale of instruments or appliances that alleviate pain, restore health, and extend life.  To direct our growth in the areas of biomedical engineering where we display maximum strength and ability; to gather people and facilities that tend to augment these areas; to continuously build on these areas through education and knowledge assimilation; to avoid participation in areas where we cannot make unique and worthy contributions.  To strive without reserve for the greatest possible reliability and quality in our products; to be the unsurpassed standard of comparison and to be recognized as a company of dedication, honesty, integrity, and service.  To make a fair profit on current operations to meet our obligations, sustain our growth, and reach our goals.  To recognize the personal worth of employees by providing an employment framework that allows personal satisfaction in work accomplished, security, advancement opportunity, and means to share in the company's success.  To maintain good citizenship as a company

Our Mission, MEDTRONIC (Jan. 23, 2013), http://www.medtronic.com/about-medtronic/our- <u>mission/index.htm</u> [hereinafter Medtronic Mission Statement].

The directors are an essential part of such mission: “The corporate director . . . is a bedrock of the health care delivery system.  The oversight activities provided by the director help form the corporate vision, and at the same time promote an environment of corporate responsibility that protects the mission of the corporation and the health care consumers it serves.” OFFICE OF THE INSPECTOR GEN. OF THE U.S. DEP’T HEALTH & HUMAN SERVS. AND AM. HEALTH LAWYERS ASS’N, CORPORATE RESPONSIBILITY AND CORPORATE COMPLIANCE: A RESOURCE FOR HEALTH CARE BOARDS OF DIRECTORS 11 (last visited Aug. 5, 2013)[hereinafter _Corporate Responsibility_ ]

<u>http://www.healthlawyers.org/hlresources/PI/InfoSeries/Documents/OIG_CorpRespCorpCompliance.pdf.</u> 115 _Corporate Responsibility_ , _supra_ note 114, at 8-9 (“In the health care context, the duty of care arises in either the decision-making function or the oversight function.  The decision-making function applies to a particular situation or a specific action.  The duty of care principle in the oversight function pertains to the general activity of overseeing the day-to-day functions of the business.”).

> 116 Gabriel L. Imperato & Marc S. Raspanti, _Compliance and Governance for Health Care Organization and Marketing and Sales Activities_ , 11 J. HEALTH CARE COMPLIANCE 5, 8 (2009).

CORPORATE INTEGRITY AGREEMENTS

care corporation, in combination with a complex array of federal and state health care legislation,<sup>117</sup> create special challenges for directors in the health care industry.  Directors of health care corporations balance the needs of many stakeholders: patients, physicians, taxpayers, the government, shareholders, and many more. Even small health care companies have a global reach and their directors’ decisions can affect a broad array of constituents.<sup>118</sup> Substantial government involvement and liability through Medicare and Medicaid further complicates governance of health care providers because the taxpaying public is a stakeholder.<sup>119</sup>

Given the public good or quasi-public good character of the health care industry, the application of CIAs in industries outside of health care could be limited. Without broader application in other industries, the impact of CIAs on corporate law may be limited.

# **V. Conclusion**

CIAs add an important element to the academic debate on the expansion of fiduciary duties. As a unique hybrid category, CIAs transcend the law of fiduciary duties and aspirational corporate governance.  Courts are increasingly recognizing the role of CIAs and their capacity to expand directors’ fiduciary duties.  A broad reading of _In re Pfizer_ suggests that CIAs can augment fiduciary default duties. Given the characteristics of CIAs and courts’ increasing recognition of CIAs and VCPs, courts may interpret CIAs and other hybrid forms, such as deferred prosecution agreements, as expanding the basic legal duty of care. More research and empirical work may be needed to explore how CIAs and other hybrid forms may change or expand directors’ obligations.

> 117 _See_ Federal Anti-Kickback Statute (“AKS”), 42 U.S.C. § 1320a-7b (2006). Physician Self-Referral Statute, 42 U.S.C. § 1395nn(a) (2006); Criminal and Civil False Claims Acts, 18 U.S.C. § 287 (2006); 31 U.S.C. 3729 et. seq. (2006); 31 U.S.C. § 3730 (2006); Health Insurance Portability and Accountability Act, 18 U.S.C. § 1347 (2006); or Patient Protection and Affordable Care Act, Pub. L. No. 111-148, 124 Stat. 119-124 (codified as amended in scattered sections of 42 U.S.C.).

> 118 The decisions made by health care corporations have real costs for American taxpayers. _See Preventing Health Care Fraud: New Tools and Approaches to Combat Old Challenges: Testimony Before the S. Comm. on Fin._ (Mar. 2, 2011) (statement of Daniel R. Levinson, Inspector General), _available at_ <u>http://www.hhs.gov/asl/testify/2011/03/t20110302i.html (“For example, in August 2010, Allergan, Inc.,</u> agreed to plead guilty to misdemeanor misbranding and paid $600 million (including a $375 million criminal fine and forfeiture and a $225 million civil settlement) to resolve criminal and civil liability arising from the company’s promotion of Botox®.  Our investigations found that the company illegally marketed the drug for indications that, during the relevant time periods, had not been approved as safe and effective by the Food and Drug Administration (FDA).  These unapproved indications included headache, pain, spasticity and juvenile cerebral palsy.  In addition, the settlement resolved allegations that Allergan misled doctors about the safety and efficacy of Botox®, instructed doctors to miscode claims to ensure payment by Government health care programs, and paid kick backs to doctors.”).

> 119 _See_ Social Security and Medicare Boards of Trustees, _Status of the Social Security and Medicare Programs: A Summary of the 2013 Annual Reports_ , SOC. SEC. ADMIN., <u>http://www.ssa.gov/oact/TRSUM/tr13summary.pdf (last visited Aug. 5, 2013)  (explaining that the annual</u> total cost of Medicare is projected to begin exceeding the total non-interest income in the near future).