Court Holds Insurer Must Cover FCA Settlement Despite “Fraudulent Acts” Exclusion
In a significant decision for policyholders facing False Claims Act (“FCA”) claims, the Eastern District of Virginia granted judgment on the pleadings to a government contractor against its professional liability insurer. Guidehouse Inc. v. Continental Casualty Co., No. 1:25-cv-1601 (E.D. Va. Sept. 29, 2026). The court held that the insurer must cover the contractor’s $7.6 million qui tam settlement (less a $5 million retention) and its costs of responding to two DOJ civil investigative demands (“CIDs”). Notably, in so holding, the court determined that the policy’s Deliberate Acts exclusion for “dishonest” or “fraudulent” acts did not apply.
The contractor administered New York’s federally funded Emergency Rental Assistance Program (“ERAP”). In June 2021, the state shut down its online ERAP portal hours after launch because applicants’ personal information was exposed. DOJ then served two CIDs concerning the contractor’s cybersecurity practices and the data incident. The CIDs related to a qui tam complaint alleging that the contractor used outdated, insecure software, hid the deficiencies from the state, and falsely certified compliance with the contract. The contractor settled without admitting liability, and the insurer denied indemnity coverage under the policy’s Deliberate Acts exclusion, which prompted the contractor’s lawsuit.
The court first held that the qui tam action (but not the CIDs) fell within the policy’s Technology and Professional Liability coverage, which covers “Damages and Claim Expenses resulting from any Claim . . . alleging Wrongful Acts by the Insured.” A “Wrongful Act” includes “any actual or alleged act, error or omission . . . committed solely in the conduct of Professional Services or Technology Services for others.” The court found that the qui tam allegations, which concerned the design, testing, implementation, and operation of the contractor’s ERAP technology, met the definition of Technology Services. That the relator proceeded under the FCA did not change the result because, as the court explained: “[t]he legal theory professed does not displace the underlying conduct for purposes of the Policy.”
The court then addressed the Technology and Professional Liability coverage’s Deliberate Acts exclusion, which bars coverage for any Claim “based upon or arising out of any dishonest, fraudulent, criminal or malicious act or omission . . . intentional wrongdoing or knowing violation of any contract or agreement.” The exclusion also provides that “only the facts pertaining to and knowledge possessed by an Executive Officer shall be imputed to the Insured Entities,” and that the insurer must still pay Claim Expenses “unless or until a final, non-appealable adjudication in any proceeding establishes” that the excluded conduct occurred. The court determined that the exclusion did not apply for three reasons:
- The FCA’s “knowingly” standard includes deliberate ignorance and reckless disregard and requires no specific intent to defraud. The qui tam complaint pleaded those alternatives, so the relator could have prevailed without proving intentional fraud or a knowing breach of contract.
- Under the imputation provision, only an Executive Officer’s knowledge could be attributed to the contractor. The complaint alleged that the contractor’s Chief Information Officer learned of the security deficiencies, but not that he made, directed, or knew the contents of the allegedly false certification. The court declined to “combine an Executive Officer’s knowledge of one fact with another employee’s allegedly intentional conduct.”
- Under the final-adjudication provision, the insurer had to pay Claim Expenses because the matter settled without any adjudication of excluded conduct.
Separately, the court held that the CIDs fell within the policy’s Privacy Regulation Investigation coverage, which reimburses “all reasonable and necessary expenses . . . to respond to or effectuate compliance with a Privacy Regulation Investigation.” That term includes a governmental investigation “in connection with any law governing Protected Information . . . arising from an actual or alleged Privacy Injury.” Although DOJ issued the CIDs under the FCA, the court reasoned that their focus on ERAP cybersecurity and the data incident made them “in connection with” ERAP. ERAP’s privacy and confidentiality provisions, in turn, are laws “governing Protected Information.”
A copy of the decision can be found here.
This post is as of the posting date stated above. Sidley Austin LLP assumes no duty to update this post or post about any subsequent developments having a bearing on this post.

