<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
     xmlns:georss="http://www.georss.org/georss"
     xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
     xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[Doug Leavitt - Danziger Shapiro, P.C.]]></title>
        <atom:link href="https://www.ds-l.com/blog/tags/doug-leavitt/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.ds-l.com/blog/tags/doug-leavitt/</link>
        <description><![CDATA[Danziger Shapiro, P.C.'s Website]]></description>
        <lastBuildDate>Thu, 10 Jul 2025 21:57:46 GMT</lastBuildDate>
        
        <language>en-us</language>
        
            <item>
                <title><![CDATA[Justice Department Guidance on Corporate Compliance Programs]]></title>
                <link>https://www.ds-l.com/blog/justice-department-guidance-on-corporate-compliance-programs/</link>
                <guid isPermaLink="true">https://www.ds-l.com/blog/justice-department-guidance-on-corporate-compliance-programs/</guid>
                <dc:creator><![CDATA[H. Adam Shapiro]]></dc:creator>
                <pubDate>Tue, 18 Jun 2019 13:48:42 GMT</pubDate>
                
                    <category><![CDATA[Business Law]]></category>
                
                    <category><![CDATA[Business Litigation]]></category>
                
                    <category><![CDATA[Commercial Litigation]]></category>
                
                    <category><![CDATA[Internet Law]]></category>
                
                
                    <category><![CDATA[Business]]></category>
                
                    <category><![CDATA[compliance]]></category>
                
                    <category><![CDATA[compliance programs]]></category>
                
                    <category><![CDATA[Danziger Shapiro & Leavitt]]></category>
                
                    <category><![CDATA[department of justice]]></category>
                
                    <category><![CDATA[Doug Leavitt]]></category>
                
                    <category><![CDATA[employees]]></category>
                
                    <category><![CDATA[implementation]]></category>
                
                    <category><![CDATA[Small Business]]></category>
                
                    <category><![CDATA[third-party risk]]></category>
                
                
                
                <description><![CDATA[<p>The Justice Department Criminal Division recently released guidance on what it considers when deciding how a corporation’s compliance program factors into its investigation and the ultimate decision as to whether to bring charges, negotiate pleas or enter into other agreements with corporations under investigation. The Evaluation of Corporate Compliance Programs, released on April 30, 2019,&hellip;</p>
]]></description>
                <content:encoded><![CDATA[<div class="wp-block-image">
<figure class="alignright size-full"><img loading="lazy" decoding="async" width="340" height="340" src="/static/2019/06/department-40657__340.png" alt="Department of Justice Seal" class="wp-image-1179" srcset="/static/2019/06/department-40657__340.png 340w, /static/2019/06/department-40657__340-300x300.png 300w, /static/2019/06/department-40657__340-150x150.png 150w" sizes="auto, (max-width: 340px) 100vw, 340px" /></figure></div>


<p>The Justice Department Criminal Division recently released guidance on what it considers when deciding how a corporation’s compliance program factors into its investigation and the ultimate decision as to whether to bring charges, negotiate pleas or enter into other agreements with corporations under investigation. <a href="https://www.justice.gov/criminal-fraud/page/file/937501/download" target="_blank" rel="noopener noreferrer"><em>The Evaluation of Corporate Compliance Programs</em></a>, released on April 30, 2019, is an expansion of the <a href="https://web.archive.org/web/20190425144946/https:/www.justice.gov/criminal-fraud/page/file/937501/download" target="_blank" rel="noopener noreferrer">2017 guidance document</a> issued by the Criminal Division Fraud Section.</p>



<h2 class="wp-block-heading" id="h-prosecutors-must-ask-three-fundamental-questions">Prosecutors Must Ask Three Fundamental Questions</h2>



<p>Prosecutors will ask three fundamental questions to determine if a corporation’s compliance program was effective at the time of the offense and at the time of charging:</p>



<ol class="wp-block-list">
<li>Is the compliance program well-designed?</li>



<li>Is the compliance program being implemented effectively?</li>



<li>Does the compliance program work in practice?</li>
</ol>



<h2 class="wp-block-heading" id="h-is-your-compliance-program-well-designed"><strong>Is Your Compliance Program Well-Designed? </strong></h2>



<p><u>An Effective Compliance Program Identifies Specific Risks</u></p>



<p>An effective compliance program will be tailored to the specific risks affecting the company under investigation. Prosecutors will ask if the company identified its own “high-risk” areas, as well as the degree to which the program dedicates resources to monitor these areas. Even a well designed program might not catch every event. Therefore, another important factor is when an event is uncovered, are the lessons learned incorporated into the compliance program going forward?</p>



<p><u>Train Your Employees</u></p>



<p>Prosecutors will analyze how thoroughly and effectively a company has <a href="https://elearningindustry.com/facilitate-employee-compliance-training-busy-employees" target="_blank" rel="noopener noreferrer">trained its employees</a> on its compliance program. Companies should use real-life experiential training scenarios and case studies during employee training. Employees must know when, where and how to report suspected misconduct. Then, once an incident is reported, how does the company identify which complaints merit further investigation? What access is given to the individual investigating the complaint? Is this an employee or an independent outside agency? A well-designed compliance program will also make it clear that no employee retaliation will be tolerated.</p>



<p><u>Third-Party Risk</u></p>



<p>Just as you should be monitoring your employees, it is just as (if not more) important to take your <a href="https://www.hrdive.com/news/developing-an-effective-third-party-compliance-training-program/528520/" target="_blank" rel="noopener noreferrer">third-party vendors</a> into consideration when assessing high-level risks. Your company should be mitigating these risks by using appropriate contracts and agreements for outside work, and doing regular due diligence and compliance training for third-party vendors.</p>



<h2 class="wp-block-heading" id="h-is-your-compliance-program-being-implemented-effectively"><strong>Is Your Compliance Program Being Implemented Effectively? </strong></h2>



<p>Prosecutors will analyse if your compliance program is being <a href="https://www.ganintegrity.com/blog/how-to-monitor-the-effectiveness-of-your-compliance-program/" target="_blank" rel="noopener noreferrer">implemented effectively</a>. A company can spend countless hours developing a compliance program that looks and sounds great, but if, after the initial introduction to employees, it gets forgotten or completely ignored, then prosecutors will not look favorably on your company’s efforts. A successful compliance program must be woven into the fabric of the day-to-day culture from the top down.</p>



<h2 class="wp-block-heading" id="h-does-your-compliance-program-work-in-practice"><strong>Does Your Compliance Program Work in Practice?</strong></h2>



<p>The final question prosecutors will ask is whether the compliance program actually works in practice. Prosecutors will look into : (1) Was investigation into the misconduct conducted in a timely manner? (2) Has the company completed a root cause analysis? (3) Can the program be tested in order to improve? Again, evolution is key here. Does your program have to be perfect? No, no risk will ever be 100% mitigated. However, a program that works in practice needs to have the ability to be updated built into its core.</p>



<p><strong>Take Away</strong></p>



<p>As you can see, the DOJ has shared valuable insight into what prosecutors look for when evaluating compliance programs. This is extremely valuable and companies should take advantage of this intel and honestly self-assess whether its program measures up. Companies that have well-thought-out and designed plans that are capable of evolving will fare better before the Criminal Division than those who do not. If you have any questions regarding your program or compliance in general, or any other aspect of your business, please feel free to contact us at <a href="/">Danziger Shapiro, P.C.</a><br><em>This entry is presented for informational purposes only and is not intended to constitute legal advice.</em></p>
]]></content:encoded>
            </item>
        
            <item>
                <title><![CDATA[DEPARTMENT OF JUSTICE PUBLISHES BEST PRACTICE TIPS TO DEAL WITH CYBER INTRUSION]]></title>
                <link>https://www.ds-l.com/blog/department-of-justice-publishes-best-practice-tips-to-deal-with-cyber-intrusion/</link>
                <guid isPermaLink="true">https://www.ds-l.com/blog/department-of-justice-publishes-best-practice-tips-to-deal-with-cyber-intrusion/</guid>
                <dc:creator><![CDATA[H. Adam Shapiro]]></dc:creator>
                <pubDate>Tue, 04 Aug 2015 13:00:21 GMT</pubDate>
                
                    <category><![CDATA[Business Law]]></category>
                
                    <category><![CDATA[Business Litigation]]></category>
                
                
                    <category><![CDATA[cyber crime]]></category>
                
                    <category><![CDATA[cyber intrusion]]></category>
                
                    <category><![CDATA[Danziger Shapiro & Leavitt]]></category>
                
                    <category><![CDATA[data breach]]></category>
                
                    <category><![CDATA[Doug Leavitt]]></category>
                
                    <category><![CDATA[hacking]]></category>
                
                
                
                <description><![CDATA[<p>Every business owner, large or small, should take time to read the Department of Justice’s Best Practices for Victim Response and Reporting of Cyber Incidents. In today’s cyber world, it seems we cannot go a day without reading about another cyber security incident and its ramifications. For example, the Seventh Circuit Court of Appeals just&hellip;</p>
]]></description>
                <content:encoded><![CDATA[
<p>Every business owner, large or small, should take time to read the Department of Justice’s <u><a href="http://www.justice.gov/sites/default/files/opa/speeches/attachments/2015/04/29/criminal_division_guidance_on_best_practices_for_victim_response_and_reporting_cyber_incidents2.pdf" target="_blank" rel="noopener noreferrer">Best Practices for Victim Response and Reporting of Cyber Incidents</a></u>. In today’s cyber world, it seems we cannot go a day without reading about another cyber security incident and its ramifications. For example, the <a href="http://media.ca7.uscourts.gov/cgi-bin/rssExec.pl?Submit=Display&Path=Y2015/D07-20/C:14-3122:J:Wood:aut:T:fnOp:N:1590360:S:0" target="_blank" rel="noopener noreferrer">Seventh Circuit Court of Appeals</a> just last week certified a class action based upon mere <em>allegations of future harm </em>as a result from the Neiman Marcus data breach. In addition, the DOJ recently disclosed its successful involvement in the largest coordinated enforcement of on line organized cyber crime. This international investigation targeted a group known as Darkode where online cyber hackers shared and sold secrets to hack into other organizations’ computers. Against this backdrop, reviewing the DOJ’s suggestions regarding preventing cyber intrusion would be well worth your time as would be a quick review of my earlier blog post on an employer’s responsibility if you are hacked under the <a href="https://www.ds-l.com/blog/pennsylvanias-breach-of-person/">Pennsylvania Breach of Personal Information Act.</a></p>



<p>Key elements of the DOJ’s suggested response plan prior to intrusion include:</p>



<ul class="wp-block-list">
<li>Having a well-established actionable plan;</li>



<li>Identify your company’s most valuable information; and</li>



<li>Have appropriate technology in place to shut down intrusion.</li>
</ul>



<p>Key elements of the DOJ’s suggested response plan immediately after intrusion include:</p>



<ul class="wp-block-list">
<li>Make initial assessment;</li>



<li>Take steps to minimize continuing damage;</li>



<li>Record all information;</li>



<li>Notify people within Organization, law enforcement and other victims; and</li>



<li><strong>DO NOT</strong> use the compromised system to communicate.</li>
</ul>



<p>At <a href="/" target="_blank" rel="noopener">Danziger Shapiro, P.C. </a>we urge our clients to meet with their technology professionals and develop a plan that deals with both keeping cyber criminals at bay and what to do in the unfortunate event you are hacked. We then work with our clients to make sure that their cyber defense plans are properly worked into employee handbooks and other materials as appropriate. Remember, you do not want to disclose all of your cyber security efforts to your employees and inadvertently provide a roadmap to defeat the measures you have taken. On the other hand, proper training will go a long way in effectively protecting your company’s’ assets. Feel free to contact us at Danziger Shapiro to discuss this or any other aspect of your business organization.</p>



<p><em>This entry is presented for informational purposes only and does not constitute legal advice.</em></p>
]]></content:encoded>
            </item>
        
    </channel>
</rss>