CMS Issues Final Rule for Implementing Sunshine Act

by Wilson Sonsini Goodrich & Rosati

On February 8, 2013, 16 months after the statutory deadline, the Centers for Medicare & Medicaid Services (CMS) published in the Federal Register the final regulation implementing the physician payment transparency provisions—collectively known as the Physician Payment Sunshine Act—of the Patient Protection and Affordable Care Act of 2010 (the ACA). The rule becomes effective on April 9, 2013, 60 days after the publication date.

Drug and device manufacturers will be required to track payments or transfers of value to physicians and teaching hospitals, and physician ownership and investment interests in such manufacturers, beginning on August 1, 2013, and their first report of such payments and ownership and investment interests (covering the last five months of 2013) will be due on March 31, 2014. Companies would be well advised to begin implementing systems, practices, and procedures that will allow them to begin tracking all relevant transactions and ownership and investment interests, if they have not started already. Transparency will impose a major burden on manufacturers, as compliance with the rule will exact from them considerable time and resources.

CMS had published a proposed rule in December 2011 and received 373 comments from various stakeholders. In response, CMS made some significant changes to the proposed rule, narrowing its scope somewhat, and clarified many of its provisions. Nevertheless, the final regulation keeps intact most of the proposed rule.

Executive Summary

The ACA requires manufacturers to submit two separate but related reports to the Department of Health and Human Services (HHS). First, applicable manufacturers of drugs, devices, biologicals, or medical supplies that are available for coverage under Medicare, Medicaid, or the Children's Health Insurance program (CHIP) must report annually to HHS certain payments or other transfers of value1 to covered recipients, namely, physicians and teaching hospitals. The rule provides definitions of numerous terms, such as "applicable manufacturer" and "covered drug, device, biological, or medical supply." In addition, it clarifies how applicable manufacturers should report and characterize payments or other transfers of value, including rules for research payments and indirect payments provided to a covered recipient through a third party. The rule also finalizes which payments are excluded from the reporting requirements.

Second, applicable manufacturers and group purchasing organizations (GPOs) must report information on ownership and investment interests in such entities held by physicians or their immediate family members. The rule details what constitutes an ownership or investment interest and defines for whom they must be reported. The rule also clarifies the content of the report concerning ownership of investment interest.

The rule finalizes the processes and requirements for applicable manufacturers and GPOs to submit their reports to CMS, including the specific data elements that are required to be included in the reports and the report format. It also details the processes for the review, dispute, and correction period when applicable manufacturers and GPOs, covered recipients, and physician owners or investors are provided the opportunity to review, dispute, and propose corrections to the reported payments, or ownership or investment interests, attributed to them.

The rule clarifies the information to be included on the publicly available website, as well as the usability of the public website. In addition, the rule includes details on the processes for reporting and publishing payments that are eligible for delayed publication.

Finally, the rule includes details regarding the statutorily authorized civil monetary penalties for failure to report payments, or physician ownership or investment interests. It also clarifies the statutory requirements for the preemption of state laws.

Notable Changes to the Proposed Regulation

Among the more significant changes to the proposed regulation issued by CMS in December 2011 are the following:

  • The definition of "applicable manufacturer" has been slightly narrowed by excluding hospitals, hospital pharmacies, and compounding pharmacies that prepare drugs or devices for their own patients, and companies that have no physical presence or activities in the United States.
  • The reporting burden has been reduced for companies:
    • that only manufacture products under contract;
    • whose gross revenue from covered products is less than 10 percent of total gross revenue;
    • that assist corporate affiliates with manufacturing, marketing, promotion, sale, or distribution; and
    • with operating divisions that do not manufacture covered products.
  • Payments for continuing medical education programs that are accredited by the Accreditation Council for Continuing Medical Education (ACCME) or other specified accrediting organizations need not be reported, as long as the manufacturer neither pays faculty directly nor suggests or recommends faculty members.
  • Manufacturers will not be charged with knowledge of the identities of physicians paid by third parties to participate in blinded market research studies.

Nonetheless, CMS does not have much to show for the 16 months it took to finalize the proposed regulation issued in December 2011. One wonders whether CMS will have sufficient resources to monitor thousands of manufacturers for compliance with the ACA and final regulation.

The remainder of this WSGR Alert summarizes some of the key provisions of the final rule.

Reports on Payments and Other Transfers of Value (Transparency Reports)

Who Must Submit Reports?

Transparency reports must be submitted by "applicable manufacturers," which CMS defines as entities operating in the United States and falling into one of these two categories:

  • An entity that is engaged in the production, preparation, propagation, compounding, or conversion of a covered drug, device, biological, or medical supply, but not if such [product] is solely for use by or within the entity itself or by the entity's own patients. This definition does not include distributors or wholesalers (including, but not limited to, repackagers, relabelers, and kit assemblers) that do not hold title to any covered drug, device, biological, or medical supply.
  • An entity under common ownership with an entity described above, which provides assistance or support to such entity with respect to the production, preparation, propagation, compounding, conversion, marketing, promotion, sale, or distribution of a covered drug, device, biological, or medical supply.2

What Is a Covered Drug, Device, Biological, or Medical Supply?

Any drug, device, biological, or medical supply for which "payment is available" under Medicare, Medicaid, or CHIP, either separately or as part of a bundled payment, is covered by the rule. Covered drugs or biologicals include only those that require a prescription, so over-the-counter (OTC) drugs are not covered. Devices or medical supplies are covered only if they require premarket approval by the U.S. Food and Drug Administration (FDA) or premarket notification (i.e., 510(k) clearance), so 510(k) Class I-exempt devices and 510(k) Class II-exempt devices are not covered. A product that is not approved or cleared nevertheless may be a covered product if "payment is available" for it under Medicare or Medicaid. For example, payment is available under Medicare for certain devices covered under an investigational device exemption (IDE), and payment may be available under Medicaid for certain unapproved pre-1962 prescription drugs. When a manufacturer's first product becomes eligible for payment under Medicare, Medicaid, or CHIP, CMS will allow a grace period of 180 days after the product becomes "covered" before the manufacturer must begin complying with the data collection and reporting requirements.

Who Are Covered Recipients and How Are They Identified?

"Covered recipients" are either physicians (other than bona fide employees of a manufacturer) or teaching hospitals.

CMS defines "physicians" as doctors of medicine and osteopathy, dentists, podiatrists, optometrists, and chiropractors who are licensed by the state in which they practice. Other provider types, such as nurse practitioners or residents, are not included in the definition. Manufacturers must report a physician recipient's name, business address, National Provider Identifier (NPI), and specialty. If the physician's NPI is not available on the National Plan and Provider Enumeration System (NPPES) website, an applicable manufacturer must make a good-faith effort to obtain the NPI from the physician; a "good-faith effort" is requesting an NPI from a physician, checking the NPPES database, and calling the NPPES help desk. If a manufacturer cannot determine the physician's NPI or the physician does not have one, the space may be left blank.

CMS defines "teaching hospitals" as any institutions that received Graduate Medical Education payments under Medicare in the most recent year for which information is available. CMS will publish a list of all such hospitals annually, and manufacturers may rely on the list for the entire reporting year.

What Payments or Transfers of Value Must Be Reported?

The regulation requires manufacturers to report "direct and indirect payments or other transfers of value" to a covered recipient, or to a third party at the request of a covered recipient. It defines a "payment or other transfer of value" as "a transfer of anything of value." In determining reported value, CMS considers "value" to mean the discernible economic value on the open market in the U.S. All aspects of the value, such as taxes or shipping, should be included in the reported value. Beyond this, CMS declines to provide rules for calculating value. Manufacturers must make a reasonable, good-faith effort to determine the value of a payment or transfer of value, and may include the methodology used in a voluntary assumptions document that is submitted to CMS.

A payment made "at the request of" a covered recipient means that the covered recipient has directed the manufacturer to provide the payment to another entity or individual rather than receiving it personally—for example, a fee waived by a physician and then donated by a manufacturer to a charity on behalf of the physician. Such payments are to be reported under the name of the covered recipient, but the report also should include the name of the entity that received the payment, or, if an individual received it, the designation "individual" (so as to preserve the privacy of such individuals).

The rule sets forth a number of exclusions, which are described later in this alert.

What Are the Contents of the Report?

Manufacturers must report to CMS the following information regarding any payment to a covered recipient:

  • Name
  • Primary business address
  • Physician specialty, license number, and NPI
  • Amount of each payment
  • Date of payment
  • Related covered drug, device, biological, or medical supply
  • Payment to physician with ownership interest
  • Delayed publication
  • Form of payment
  • Nature of payment. The nature of each payment must be indicated using only one of the following categories:
    • Consulting fees
    • Compensation for services other than consulting, including serving as faculty or as a speaker at other than a continuing education program (discussed below)
    • Honoraria
    • Gift
    • Entertainment
    • Food and beverage (discussed below)
    • Travel and lodging (including the specified destinations)
    • Education
    • Research (discussed in next section)
    • Charitable contribution (discussed below)
    • Royalty or license
    • Current or prospective ownership or investment interest
    • Compensation for serving as faculty or as a speaker for an unaccredited medical education program (discussed below)
    • Compensation for serving as faculty or as a speaker for an accredited medical education program (discussed below)
    • Grant
    • Space rental or facility fees (teaching hospital only)

The rule elaborates further on the "nature" of payments to be reported in general and for certain of the above categories:

Payments with multiple categories: Only one nature may be indicated for each payment. If a payment could fit within several categories, the manufacturer should select the most suitable one, but should not bundle payments belonging to separate categories into a single payment. For example, a meal should be reported as a meal, even if it is associated with travel or a consulting contract.

Charitable contributions: This category should only be used where an applicable manufacturer makes a payment to a charity on behalf of a covered recipient, but not in exchange for any service or benefit. For example, if a physician requests that his or her consulting fee be paid to a charity, this should be reported not as a charitable contribution, but as a consulting fee with the physician as the covered recipient and the charity as the entity paid.

Meals and beverages: The cost of meals provided in a group setting must be divided by the total number of individuals who ate the meal (both physicians and non-physicians, such as office staff), with the resulting per-person cost reported for each physician who actually participated in the meal. Additionally, CMS is excluding the reporting of buffet meals, snacks, soft drinks, or coffee made generally available to all participants at large-scale conferences or similar events.

Payments for CME and speaker fees: Payments for CME that is accredited by the ACCME or other specified accrediting organizations are exempt from reporting if the manufacturer does not pay faculty directly and does not select or recommend individual faculty members. If a CME program is accredited, but the manufacturer directly pays or recommends the faculty, the payments must be reported as "Compensation for serving as faculty or as a speaker for an accredited or certified continuing education program." If a program is not accredited, the payment is reported as "Compensation for serving as faculty or as a speaker for an unaccredited and non-certified continuing education program." Finally, where a payment is made to a physician speaker at an event that is not continuing medical education (for example, a promotional speaker program), the payment should be reported as "Compensation for services other than consulting, including serving as faculty or as a speaker at other than a continuing education program."

"Other" Category Deleted: The final rule omits the "other" nature category in the proposed rule because it would dilute the usefulness of the "nature" categories. CMS cautions that all payments to covered recipients must be reported, and failure to identify a nature category could result in penalties. Therefore, manufacturers should select the nature category that most closely describes the payment.

Research Payments

Under the final rule, payments for research are reported separately from other payments and transfers of value, using a different reporting format. "Research" includes basic and applied research, preclinical research, Phase I through IV studies, and investigator-initiated studies. If a payment falls within the definition of "research" and is subject to a written agreement, a protocol, or both, it is reported as research. Research-related payments that do not meet these requirements must be reported using other "nature" categories.

Manufacturers will not be required to attribute the entire research payment made to a facility to each principal investigator. Instead, the manufacturer will report each research payment once, identifying the name and address of the institution (whether or not a teaching hospital) or individual physician paid, the amount, the name of the study, the name of the related product, and information about each principal investigator. At their option, manufacturers may report explanatory information about the study. The requirements for reporting payments for pre-clinical studies are similar, but no associated product or study name need be reported.

The ACA requires CMS to delay publication of payments from manufacturers to covered recipients made (1) pursuant to a product research or development agreement or (2) in connection with a clinical investigation regarding a covered product. Delayed publication will apply to payments for both research and development, and clinical investigations, where they relate to a new product. However, where a new application of an existing product is concerned, publication will be delayed for a research and development payment but not for a clinical investigation payment. In other words, payments to clinical investigators will be entitled to delayed publication if the investigation is for a new product, but not if it is for a new indication of a currently marketed product. The only payments for "research" of new indications of marketed products that would be subject to delayed disclosure would be payments for non-clinical studies.

CMS clarifies that products for which approval or clearance will be sought under an abbreviated new drug application (ANDA) or a 510(k) notification are considered new products, rather than new applications of existing products.

Despite comments that CMS should not publish the payments until after FDA approval, licensure, or clearance, CMS stated in the preamble to the final rule that it believes "Congress clearly intended that all payments should be included on the public website, even if a product never received FDA approval, licensure or clearance."

For publication to be delayed, the manufacturer must indicate in its transparency report whether a payment is eligible for a delay in publication. The failure to indicate eligibility will result in the payment being posted publicly in the following year. The manufacturer also must continue to indicate annually that FDA approval, license, or clearance is pending, and subsequently must notify CMS if the FDA approves or clears the product.


Under the statute and the final regulation, the following payments are excluded from the reporting requirements:

(1) Transfer through a third party. No reporting is required for a transfer of value made indirectly to a covered recipient through a third party in cases where the applicable manufacturer does not know the identity of the covered recipient. Awareness of the identity of a recipient on the part of a legal agent acting on behalf of the manufacturer is attributed to the manufacturer itself.

(2) De minimis payments. Payments and transfers of value less than $10 are not reportable, unless the aggregate amount transferred to, requested by, or designated on behalf of a covered recipient exceeds $100 in a calendar year. Small items that are under $10 (such as pens and notepads) that are provided at large-scale conferences and similar large-scale events are exempted from the reporting requirements, and also do not need to be tracked for purposes of the $100 aggregate threshold.

(3) Samples. Product samples that are not intended to be sold, yet intended for patient use, including coupons and vouchers, are not reportable.

(4) Educational materials. Educational materials that directly benefit patients or are intended to be used by or with patients are not reportable. CMS has clarified that this exemption does not cover materials provided to physicians for their own education, nor does it cover marketing or promotional materials. This narrow interpretation imposes a considerable burden on manufacturers, which must report the value of all reprints and promotional materials provided to physicians if they exceed the de minimis threshold throughout the year.

(5) Devices for evaluation. Manufacturers need not report the loan of a covered device for a short-term trial period, not to exceed 90 days, or the provision of a limited quantity (i.e., 90 days of average use) of disposable or single-use devices or medical supplies, to permit evaluation of the covered device by the covered recipient. The exemption for disposable or single-use devices or supplies was added in the final rule.

(6) Warranty items. Items or services provided under a contractual warranty (including a service or maintenance agreement), including the replacement of a covered device, are not reportable where the terms of the warranty are set forth in the purchase or lease agreement for the covered device. The exemption applies even if the warranty period has expired.

(7) Charity care. Manufacturers are not required to report in-kind items used for the provision of charity care, defined as care for a patient who is unable to pay or for whom payment would be a significant hardship, where the covered recipient does not receive or expect to receive payment. This exemption does not include in-kind items provided to a charitable organization for the care of all of its patients, both those who can and cannot pay. Moreover, the exemption covers only in-kind items, not financial support for charity care.

(8) Covered recipient who is a patient. Reporting is not required for a payment or transfer of value to a physician who is a patient, research subject, or participant in data collection for research, and not acting in the professional capacity of a physician.

(9) Discounts and rebates are not reportable.

(10) Publicly traded securities. A dividend or other profit distribution from, or ownership or investment interest in, a publicly traded security or mutual fund is not reportable.

(11) Health care for employee. In the case of a manufacturer that offers a self-insured plan, payments for the provision of health care to employees under the plan are not reportable.

(12) Payments for non-medical services. Where a physician is also a licensed non-medical professional, a payment to the physician is non-reportable if it is solely for the non-medical professional services of the individual.

(13) Payments for services in judicial proceeding. Manufacturers need not report a payment to a physician if the payment is solely for the services of the physician with respect to a civil or criminal action or an administrative proceeding.

(14) Personal relationship. A payment to a physician is not reportable if it is made solely in the context of a personal, non-business-related relationship.

Reports on Physician Ownership and Investment Interests

In addition to transparency reports, the ACA requires manufacturers and GPOs to separately report information on ownership or investment interests in such entities held by physicians or their immediate family members.

CMS finalized its proposed definition of "applicable GPO" as an entity that operates in the United States and purchases, arranges for, or negotiates the purchase of a covered drug, device, biological, or medical supply for a group of individuals or entities, but not solely for use by the entity itself. CMS states that this definition includes purchasers and physician-owned distributors of covered drugs, devices, biologicals, and medical supplies, but does not include bulk purchasers for commonly owned entities.

An "immediate family member" is defined as one of the following:

  • Spouse
  • Natural or adoptive parent, child, or sibling
  • Stepparent, stepchild, stepbrother, or stepsister
  • Father-, mother-, daughter-, son-, brother-, or sister-in-law
  • Grandparent or grandchild
  • Spouse of a grandparent or grandchild

An ownership or investment interest in a manufacturer or GPO may include stock, stock options (when exercised), partnership shares, loans, and bonds. However, an ownership or investment interest does not include any publicly traded security or mutual fund. Manufacturers and GPOs need not report indirect ownership or investment interests held by physicians or their immediate family members about which the manufacturers or GPOs did not know.

Manufacturers and GPOs must report the following information for each physician ownership or investment interest:

  • Manufacturer's or GPO's name
  • Physician owner or investor's:
    • Name
    • Specialty
    • Primary business street address
    • NPI
    • State professional license number for at least one state where the physician maintains a license, and the state(s) in which the license is held
  • Whether the ownership or investment interest is held by the physician or an immediate family member of the physician
  • Dollar amount invested
  • Value and terms of each ownership or investment interest
  • Any payments or other transfers of value provided to the physician owner or investor, including:
    • Amount of payment or other transfer of value in U.S. dollars
    • Date of payment or other transfer of value
    • Form of payment or other transfer of value
    • Nature of payment or other transfer of value
    • Name(s) of related covered drugs, devices, biologicals, or medical supplies
    • NDCs of related covered drugs and biologicals, if any
    • Name of entity that received the payment or other transfer of value, if not provided to the physician owner or investor directly
    • Statement providing additional context for the payment or other transfer of value (optional)

To avoid duplicative reporting, manufacturers should report the payments provided to physician owners or investors in the report for payments, and should note that the covered recipient receiving the payment or other transfers of value is a physician owner or investor. Additionally, an individual may be both a covered recipient and a physician owner or investor. A manufacturer should only report a payment once, regardless of whether it is required to be reported as a payment or an ownership interest.

Report Submission and Correction

Manufacturers and GPOs must submit their reports for the preceding calendar year electronically to CMS by March 31, 2014, and by the 90th day of each calendar year thereafter. Only manufacturers that made a payment to a covered recipient or had a physician owner or investor in the previous calendar year need to register and submit a report to CMS. Similarly, only GPOs with a physician owner or investor are required to submit a report. In other words, even if an entity meets the definition of "applicable manufacturer" or "applicable GPO," it need not register or submit a report if it has no payments or other transfers of value to report.

A manufacturer under common ownership with separate entities that are also applicable manufacturers may, but is not required to, file a consolidated report of all payments, and physician ownership or investment interests, for all entities. All manufacturers with payments to report must register individually, even if they intend to be part of a consolidated report submitted by another manufacturer. Manufacturers submitting data as part of a consolidated report that will be submitted by another manufacturer may indicate during registration that they intend to be part of the report submitted by another manufacturer. The entity submitting the consolidated report must indicate all of the manufacturers for which it is reporting.

An authorized representative must submit a signed attestation at the time of data submission certifying the truthfulness, accuracy, and completeness of the data submitted to the best of the signer's knowledge and belief. An entity submitting a consolidated report must attest on behalf of itself and each of the other manufacturers included in the report. While the attestation must be provided at the time of data submission, it also must be provided any time the data is changed or updated. Data without an attestation will not be considered an official submission. For a manufacturer with payments or other transfers of value to report, if covered products represent less than 10 percent of total (gross) revenue for the preceding year, the attestation must indicate that fact.

CMS will not grant submission extensions, and any late data will be considered a failure to report, which may be subject to penalties.

The statute requires that, following submission of the reports, CMS must providemanufacturers, GPOs, covered recipients, and physician owners and investors with the opportunity to review the data for at least 45 days prior to publication on the public website. If a covered recipient or physician owner or investor disagrees with the data, he can initiate a dispute, and applicable manufacturers or GPOs may begin resolving the dispute and correcting the data. After the end of the 45-day review-and-correction period, manufacturers and GPOs will have an additional 15 days to correct data for the purposes of resolving disputes, after which they may submit, and provide attestation for, the updated data to CMS to finalize the submission. Payments or ownership or investment interests that cannot be resolved by the end of the 15-day resolution period will be marked as "disputed," but the manufacturer's or GPO's most recent attested data subject to the dispute will be the only information published.

The 45-day review-and-correction period and 15-day dispute-resolution period will not be the only opportunities to dispute the contents of the public website. CMS will allow physicians and teaching hospitals, and physician owners and investors, the opportunity to sign in to the system to review or dispute officially submitted and attested transactions any time during the year. Any disputes resolved outside the 45- and 15-day time periods, however, will not be reflected on the public website until the next update of the data.

Civil Monetary Penalties

If a manufacturer or GPO fails to submit the required information, it may be subject to penalties of not less than $1,000, but not more than $10,000, for each payment or ownership or investment interest not reported. The maximum penalty that can be assessed for failure to report is $150,000 each year. For knowing failures, a manufacturer or GPO will be subject to penalties of not less than $10,000, but not more than $100,000, for each payment or ownership or investment interest not reported. The maximum penalty for a knowing failure to report is $1,000,000 each year. The penalties imposed on each manufacturer or GPO are aggregated separately, and subject to separate aggregate totals for failures to report and knowing failures to report, with a maximum combined total of $1,150,000.

The factors that CMS will consider in determining the amount of a penalty include, but are not limited to, the following:

  • The length of time the manufacturer or GPO failed to report
  • The amount of payment or other transfer of value or the value of the ownership or investment interest the manufacturer or GPO failed to report
  • The level of culpability
  • The nature and amount of information reported in error
  • The degree of diligence exercised in correcting information reported in error

For consolidated reports, the manufacturer that submits the consolidated report will be required to attest on behalf of all the entities included in the consolidated report, and therefore will be subject to the maximum penalties for each individual manufacturer included in the report. The submitter of the consolidated report therefore could be subject to a penalty greater than $1,000,000 depending on the violations of the manufacturers for whom it submitted the report and attested as to the data.

HHS, CMS, the Office of the Inspector General (OIG), or their designees have the right to audit or inspect manufacturers or GPOs to assess their compliance with the requirement to provide timely, complete, and accurate submissions of the information. In order to facilitate the auditing and inspection process, manufacturers and GPOs must maintain books, records, and documents to enable an audit or inspection for a period of at least five years from the date the payment or other transfer of value, or ownership or investment interest, is published on the website.

CMS Website

The statute requires CMS to publish the data collected from manufacturers and GPOs on a publicly available website by June 30 of each year. Due to the timing of the final rule, the first publication will be in June 2014 for data collected in 2013.

In the preamble to the final rule, CMS stated that it plans to engage stakeholders regarding the content of the website, since it recognizes that stakeholders and the public must be part of the website-development process. CMS will ensure that the website "accurately and completely describes the nature of relationships between physicians and teaching hospitals, and the industry, including an explanation of beneficial interactions," and that it will clearly state that disclosure on the website "does not indicate that the payment was legitimate nor does it necessarily indicate a conflict of interest or any wrongdoing."

Annual Reports

CMS must submit annual reports to Congress and the states. The annual report is due to Congress on April 1 of each year, and must include aggregated information on each manufacturer and GPO submitted during the prior year, as well as any enforcement actions taken and penalties paid. The state reports will be state-specific.

Relation to State Laws

The ACA preempts any state or local laws requiring the reporting of the same type of information regarding payments made by applicable manufacturers to covered recipients. However, this does not prevent a state from collecting this information for public-health surveillance, investigation, or other public-health purposes or health oversight. The public-health goal must be one other than transparency in order for the state reporting to avoid preemption.

State and local governments may require the reporting of information other than that required under the ACA. The additional information may include other types of information (except payments that fall below the $10 individual or $100 aggregate thresholds), or payments to health care providers other than physicians and teaching hospitals.


Manufacturers and GPOs must begin tracking payments to physicians and teaching hospitals, as well as physician ownership and investment interests, starting on August 1, 2013, in order to report them to CMS by March 31, 2014. They would be well advised to implement systems, practices, and procedures to accomplish these tasks in the six or so months remaining.

Please contact David Hoffmeister, Farah Gerdes, or Jon Nygaard in Wilson Sonsini Goodrich & Rosati's life sciences/FDA and healthcare practice with any questions about the Physician Payment Sunshine Act.

1 Generally, this alert will refer to "payments or transfers of value" simply as "payments."

2 Henceforth in this alert, "manufacturers" will mean "applicable manufacturers."

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Wilson Sonsini Goodrich & Rosati | Attorney Advertising

Written by:

Wilson Sonsini Goodrich & Rosati

Wilson Sonsini Goodrich & Rosati on:

Readers' Choice 2017
Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide

JD Supra Privacy Policy

Updated: May 25, 2018:

JD Supra is a legal publishing service that connects experts and their content with broader audiences of professionals, journalists and associations.

This Privacy Policy describes how JD Supra, LLC ("JD Supra" or "we," "us," or "our") collects, uses and shares personal data collected from visitors to our website (located at (our "Website") who view only publicly-available content as well as subscribers to our services (such as our email digests or author tools)(our "Services"). By using our Website and registering for one of our Services, you are agreeing to the terms of this Privacy Policy.

Please note that if you subscribe to one of our Services, you can make choices about how we collect, use and share your information through our Privacy Center under the "My Account" dashboard (available if you are logged into your JD Supra account).

Collection of Information

Registration Information. When you register with JD Supra for our Website and Services, either as an author or as a subscriber, you will be asked to provide identifying information to create your JD Supra account ("Registration Data"), such as your:

  • Email
  • First Name
  • Last Name
  • Company Name
  • Company Industry
  • Title
  • Country

Other Information: We also collect other information you may voluntarily provide. This may include content you provide for publication. We may also receive your communications with others through our Website and Services (such as contacting an author through our Website) or communications directly with us (such as through email, feedback or other forms or social media). If you are a subscribed user, we will also collect your user preferences, such as the types of articles you would like to read.

Information from third parties (such as, from your employer or LinkedIn): We may also receive information about you from third party sources. For example, your employer may provide your information to us, such as in connection with an article submitted by your employer for publication. If you choose to use LinkedIn to subscribe to our Website and Services, we also collect information related to your LinkedIn account and profile.

Your interactions with our Website and Services: As is true of most websites, we gather certain information automatically. This information includes IP addresses, browser type, Internet service provider (ISP), referring/exit pages, operating system, date/time stamp and clickstream data. We use this information to analyze trends, to administer the Website and our Services, to improve the content and performance of our Website and Services, and to track users' movements around the site. We may also link this automatically-collected data to personal information, for example, to inform authors about who has read their articles. Some of this data is collected through information sent by your web browser. We also use cookies and other tracking technologies to collect this information. To learn more about cookies and other tracking technologies that JD Supra may use on our Website and Services please see our "Cookies Guide" page.

How do we use this information?

We use the information and data we collect principally in order to provide our Website and Services. More specifically, we may use your personal information to:

  • Operate our Website and Services and publish content;
  • Distribute content to you in accordance with your preferences as well as to provide other notifications to you (for example, updates about our policies and terms);
  • Measure readership and usage of the Website and Services;
  • Communicate with you regarding your questions and requests;
  • Authenticate users and to provide for the safety and security of our Website and Services;
  • Conduct research and similar activities to improve our Website and Services; and
  • Comply with our legal and regulatory responsibilities and to enforce our rights.

How is your information shared?

  • Content and other public information (such as an author profile) is shared on our Website and Services, including via email digests and social media feeds, and is accessible to the general public.
  • If you choose to use our Website and Services to communicate directly with a company or individual, such communication may be shared accordingly.
  • Readership information is provided to publishing law firms and authors of content to give them insight into their readership and to help them to improve their content.
  • Our Website may offer you the opportunity to share information through our Website, such as through Facebook's "Like" or Twitter's "Tweet" button. We offer this functionality to help generate interest in our Website and content and to permit you to recommend content to your contacts. You should be aware that sharing through such functionality may result in information being collected by the applicable social media network and possibly being made publicly available (for example, through a search engine). Any such information collection would be subject to such third party social media network's privacy policy.
  • Your information may also be shared to parties who support our business, such as professional advisors as well as web-hosting providers, analytics providers and other information technology providers.
  • Any court, governmental authority, law enforcement agency or other third party where we believe disclosure is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals' personal safety, or to detect, prevent, or otherwise address fraud, security or safety issues.
  • To our affiliated entities and in connection with the sale, assignment or other transfer of our company or our business.

How We Protect Your Information

JD Supra takes reasonable and appropriate precautions to insure that user information is protected from loss, misuse and unauthorized access, disclosure, alteration and destruction. We restrict access to user information to those individuals who reasonably need access to perform their job functions, such as our third party email service, customer service personnel and technical staff. You should keep in mind that no Internet transmission is ever 100% secure or error-free. Where you use log-in credentials (usernames, passwords) on our Website, please remember that it is your responsibility to safeguard them. If you believe that your log-in credentials have been compromised, please contact us at

Children's Information

Our Website and Services are not directed at children under the age of 16 and we do not knowingly collect personal information from children under the age of 16 through our Website and/or Services. If you have reason to believe that a child under the age of 16 has provided personal information to us, please contact us, and we will endeavor to delete that information from our databases.

Links to Other Websites

Our Website and Services may contain links to other websites. The operators of such other websites may collect information about you, including through cookies or other technologies. If you are using our Website or Services and click a link to another site, you will leave our Website and this Policy will not apply to your use of and activity on those other sites. We encourage you to read the legal notices posted on those sites, including their privacy policies. We are not responsible for the data collection and use practices of such other sites. This Policy applies solely to the information collected in connection with your use of our Website and Services and does not apply to any practices conducted offline or in connection with any other websites.

Information for EU and Swiss Residents

JD Supra's principal place of business is in the United States. By subscribing to our website, you expressly consent to your information being processed in the United States.

  • Our Legal Basis for Processing: Generally, we rely on our legitimate interests in order to process your personal information. For example, we rely on this legal ground if we use your personal information to manage your Registration Data and administer our relationship with you; to deliver our Website and Services; understand and improve our Website and Services; report reader analytics to our authors; to personalize your experience on our Website and Services; and where necessary to protect or defend our or another's rights or property, or to detect, prevent, or otherwise address fraud, security, safety or privacy issues. Please see Article 6(1)(f) of the E.U. General Data Protection Regulation ("GDPR") In addition, there may be other situations where other grounds for processing may exist, such as where processing is a result of legal requirements (GDPR Article 6(1)(c)) or for reasons of public interest (GDPR Article 6(1)(e)). Please see the "Your Rights" section of this Privacy Policy immediately below for more information about how you may request that we limit or refrain from processing your personal information.
  • Your Rights
    • Right of Access/Portability: You can ask to review details about the information we hold about you and how that information has been used and disclosed. Note that we may request to verify your identification before fulfilling your request. You can also request that your personal information is provided to you in a commonly used electronic format so that you can share it with other organizations.
    • Right to Correct Information: You may ask that we make corrections to any information we hold, if you believe such correction to be necessary.
    • Right to Restrict Our Processing or Erasure of Information: You also have the right in certain circumstances to ask us to restrict processing of your personal information or to erase your personal information. Where you have consented to our use of your personal information, you can withdraw your consent at any time.

You can make a request to exercise any of these rights by emailing us at or by writing to us at:

Privacy Officer
JD Supra, LLC
10 Liberty Ship Way, Suite 300
Sausalito, California 94965

You can also manage your profile and subscriptions through our Privacy Center under the "My Account" dashboard.

We will make all practical efforts to respect your wishes. There may be times, however, where we are not able to fulfill your request, for example, if applicable law prohibits our compliance. Please note that JD Supra does not use "automatic decision making" or "profiling" as those terms are defined in the GDPR.

  • Timeframe for retaining your personal information: We will retain your personal information in a form that identifies you only for as long as it serves the purpose(s) for which it was initially collected as stated in this Privacy Policy, or subsequently authorized. We may continue processing your personal information for longer periods, but only for the time and to the extent such processing reasonably serves the purposes of archiving in the public interest, journalism, literature and art, scientific or historical research and statistical analysis, and subject to the protection of this Privacy Policy. For example, if you are an author, your personal information may continue to be published in connection with your article indefinitely. When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
  • Onward Transfer to Third Parties: As noted in the "How We Share Your Data" Section above, JD Supra may share your information with third parties. When JD Supra discloses your personal information to third parties, we have ensured that such third parties have either certified under the EU-U.S. or Swiss Privacy Shield Framework and will process all personal data received from EU member states/Switzerland in reliance on the applicable Privacy Shield Framework or that they have been subjected to strict contractual provisions in their contract with us to guarantee an adequate level of data protection for your data.

California Privacy Rights

Pursuant to Section 1798.83 of the California Civil Code, our customers who are California residents have the right to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes.

You can make a request for this information by emailing us at or by writing to us at:

Privacy Officer
JD Supra, LLC
10 Liberty Ship Way, Suite 300
Sausalito, California 94965

Some browsers have incorporated a Do Not Track (DNT) feature. These features, when turned on, send a signal that you prefer that the website you are visiting not collect and use data regarding your online searching and browsing activities. As there is not yet a common understanding on how to interpret the DNT signal, we currently do not respond to DNT signals on our site.

Access/Correct/Update/Delete Personal Information

For non-EU/Swiss residents, if you would like to know what personal information we have about you, you can send an e-mail to We will be in contact with you (by mail or otherwise) to verify your identity and provide you the information you request. We will respond within 30 days to your request for access to your personal information. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why. If you would like to correct or update your personal information, you can manage your profile and subscriptions through our Privacy Center under the "My Account" dashboard. If you would like to delete your account or remove your information from our Website and Services, send an e-mail to

Changes in Our Privacy Policy

We reserve the right to change this Privacy Policy at any time. Please refer to the date at the top of this page to determine when this Policy was last revised. Any changes to our Privacy Policy will become effective upon posting of the revised policy on the Website. By continuing to use our Website and Services following such changes, you will be deemed to have agreed to such changes.

Contacting JD Supra

If you have any questions about this Privacy Policy, the practices of this site, your dealings with our Website or Services, or if you would like to change any of the information you have provided to us, please contact us at:

JD Supra Cookie Guide

As with many websites, JD Supra's website (located at (our "Website") and our services (such as our email article digests)(our "Services") use a standard technology called a "cookie" and other similar technologies (such as, pixels and web beacons), which are small data files that are transferred to your computer when you use our Website and Services. These technologies automatically identify your browser whenever you interact with our Website and Services.

How We Use Cookies and Other Tracking Technologies

We use cookies and other tracking technologies to:

  1. Improve the user experience on our Website and Services;
  2. Store the authorization token that users receive when they login to the private areas of our Website. This token is specific to a user's login session and requires a valid username and password to obtain. It is required to access the user's profile information, subscriptions, and analytics;
  3. Track anonymous site usage; and
  4. Permit connectivity with social media networks to permit content sharing.

There are different types of cookies and other technologies used our Website, notably:

  • "Session cookies" - These cookies only last as long as your online session, and disappear from your computer or device when you close your browser (like Internet Explorer, Google Chrome or Safari).
  • "Persistent cookies" - These cookies stay on your computer or device after your browser has been closed and last for a time specified in the cookie. We use persistent cookies when we need to know who you are for more than one browsing session. For example, we use them to remember your preferences for the next time you visit.
  • "Web Beacons/Pixels" - Some of our web pages and emails may also contain small electronic images known as web beacons, clear GIFs or single-pixel GIFs. These images are placed on a web page or email and typically work in conjunction with cookies to collect data. We use these images to identify our users and user behavior, such as counting the number of users who have visited a web page or acted upon one of our email digests.

JD Supra Cookies. We place our own cookies on your computer to track certain information about you while you are using our Website and Services. For example, we place a session cookie on your computer each time you visit our Website. We use these cookies to allow you to log-in to your subscriber account. In addition, through these cookies we are able to collect information about how you use the Website, including what browser you may be using, your IP address, and the URL address you came from upon visiting our Website and the URL you next visit (even if those URLs are not on our Website). We also utilize email web beacons to monitor whether our emails are being delivered and read. We also use these tools to help deliver reader analytics to our authors to give them insight into their readership and help them to improve their content, so that it is most useful for our users.

Analytics/Performance Cookies. JD Supra also uses the following analytic tools to help us analyze the performance of our Website and Services as well as how visitors use our Website and Services:

  • HubSpot - For more information about HubSpot cookies, please visit
  • New Relic - For more information on New Relic cookies, please visit
  • Google Analytics - For more information on Google Analytics cookies, visit To opt-out of being tracked by Google Analytics across all websites visit This will allow you to download and install a Google Analytics cookie-free web browser.

Facebook, Twitter and other Social Network Cookies. Our content pages allow you to share content appearing on our Website and Services to your social media accounts through the "Like," "Tweet," or similar buttons displayed on such pages. To accomplish this Service, we embed code that such third party social networks provide and that we do not control. These buttons know that you are logged in to your social network account and therefore such social networks could also know that you are viewing the JD Supra Website.

Controlling and Deleting Cookies

If you would like to change how a browser uses cookies, including blocking or deleting cookies from the JD Supra Website and Services you can do so by changing the settings in your web browser. To control cookies, most browsers allow you to either accept or reject all cookies, only accept certain types of cookies, or prompt you every time a site wishes to save a cookie. It's also easy to delete cookies that are already saved on your device by a browser.

The processes for controlling and deleting cookies vary depending on which browser you use. To find out how to do so with a particular browser, you can use your browser's "Help" function or alternatively, you can visit which explains, step-by-step, how to control and delete cookies in most browsers.

Updates to This Policy

We may update this cookie policy and our Privacy Policy from time-to-time, particularly as technology changes. You can always check this page for the latest version. We may also notify you of changes to our privacy policy by email.

Contacting JD Supra

If you have any questions about how we use cookies and other tracking technologies, please contact us at:

- hide

This website uses cookies to improve user experience, track anonymous site usage, store authorization tokens and permit sharing on social media networks. By continuing to browse this website you accept the use of cookies. Click here to read more about how we use cookies.