An employee's FMLA certification says she may need intermittent leave "4x per month for 1 day. ". She's never missed more than four days in a month. But sometimes she takes two of those days consecutively. HR reads the certification as four separate ...
‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

"4x per month for 1 day" is a lawsuit written in shorthand.

An employee's FMLA certification says she may need intermittent leave "4x per month for 1 day."

She's never missed more than four days in a month. But sometimes she takes two of those days consecutively.

HR reads the certification as four separate episodes, each lasting one day. The employee reads it as four total days of leave per month.

Who's right? Maybe neither — at least not conclusively.

A certification describing intermittent leave is often giving an estimate, not imposing a hard attendance cap. And when the need for leave is unforeseeable, employers should be especially careful about treating the frequency or duration listed by the doctor as an absolute limit.

The 6th Circuit recently made exactly that point in Jackson v. USPS. A medical certification estimating intermittent FMLA leave does not necessarily create a hard ceiling on the amount of protected leave an employee may take. If the actual leave materially differs from the doctor's estimate, the employer's remedy is generally to investigate through the FMLA certification process — not simply declare the excess absence(s) unprotected.

That doesn't mean employees get unlimited leave. It just means that HR has to use the proper tool.

If "4x per month for 1 day" is genuinely unclear, the employer may seek clarification of what the provider meant. Clarification is just that: understanding the meaning of an existing response. HR, a leave administrator, another management official, or a health care provider may contact the employee's provider; the employee's direct supervisor may not. And the employer cannot use clarification as a backdoor demand for medical information beyond what the FMLA permits.

The other tool is recertification.

Here's the basic framework:

  1. The general rule is 30 days. An employer ordinarily may request recertification no more often than every 30 days, and only in connection with an absence. If the existing certification states that the condition will last longer than 30 days, the employer generally must wait until that minimum period expires.  

  2. Six months is the outside checkpoint. Even when the certification covers a long-term or indefinite condition, the employer may request recertification every six months in connection with an absence.

  3. A significant change can justify an earlier recertification. This is where our example gets interesting. The regulation itself says that if a certification predicts one-to-two-day migraine episodes and the employee's last two migraines each cause four-day absences, the increased duration may constitute a significant change permitting recertification before 30 days. Frequency, duration, severity, complications, and even certain absence patterns can matter.

  4. Give the provider the actual attendance pattern. As part of a recertification, the employer may provide the health care provider with a record of the employee's absences and ask whether that pattern is consistent with the employee's serious health condition and need for leave. That's a much better question than HR deciding for itself what the certification means.

  5. Give the employee enough time. The employer generally must allow at least 15 calendar days to provide the recertification, unless it is not practicable despite the employee's diligent, good-faith efforts.

Here's where HR gets itself into trouble. Suppose HR tells the employee: "Your new certification needs to say you may take up to four consecutive days, but no more than four total days per month." That's not clarification. That's HR writing the doctor's answer. Don't do that.

Instead, just give the provider the facts and ask the medical question: Is this employee's actual leave pattern consistent with the condition and the need for intermittent leave? Then let the provider answer it.

Most importantly, don't automatically discipline an employee merely because an unforeseeable absence exceeds the frequency or duration estimated on an existing certification. At least in the 6th Circuit, those estimates are not necessarily hard caps. If the pattern materially changes, use the recertification process the regulations give you.

An FMLA certification is medical information, not an attendance points chart. When the employee's actual leave stops matching the doctor's estimate, ask questions before you start issuing discipline.

      

Manchester City, one phishing email, and 114 reasons to train your employees

One email. One click. And, nearly a decade later, 114 guilty verdicts.

The Manchester City financial scandal started with something far less sophisticated than disguised sponsorship agreements, hidden payments, or Premier League financial regulations.

It started with phishing.

In January 2017, a senior Manchester City official received an email that appeared to come from someone at UEFA. It contained a link to what looked like a financial compliance report.

The employee clicked "download."

That was all it took.

The email wasn't from UEFA. It was a phishing attack tied to Rui Pinto, the Portuguese hacker behind Football Leaks. The click gave Pinto access to City's computer systems, from which he obtained thousands of internal emails and documents. Those documents eventually made their way to journalists, helped launch investigations by UEFA and the Premier League, and became part of the story that culminated last month with an independent Premier League commission finding City guilty of 114 of 115 charges. City denies wrongdoing and has appealed.
Think about that for a moment. One employee clicked one bad link. And the rest, as they say, is 114 guilty verdicts.

That happened in 2017. Phishing has gotten a lot more sophisticated since then.

Today's phishing email might perfectly mimic Microsoft, DocuSign, your bank, a customer, your CEO, or one of your vendors. Attackers can scrape LinkedIn and company websites to learn reporting relationships and job responsibilities. Generative AI makes it trivial to write polished, personalized emails without the bad grammar and awkward phrasing that used to give scams away.

And phishing isn't limited to email. It can arrive by text, Teams, Slack, social media, or even a phone call.

So what can an employer do?

Here are eight places to start.

1. Train employees to verify, not just recognize.

"Look for typos" is not a cybersecurity strategy anymore.

Employees need a simple rule: if an email unexpectedly asks you to click a link, download a file, enter credentials, move money, change banking information, or disclose sensitive information, verify the request through another channel.

Call the person. Open the website yourself instead of using the link. Start a new email using an address you already know.

The National Institute of Standards and Technology specifically recommends independently verifying suspicious or urgent requests rather than relying on contact information contained in the message itself.

2. Turn on multifactor authentication everywhere you can.

A stolen password shouldn't equal a stolen account.

Require MFA for email, cloud storage, payroll, HRIS platforms, remote access, financial systems, and especially administrator accounts.

Better still, move toward phishing-resistant MFA such as passkeys or FIDO security keys. Traditional text-message codes and one-time passwords are better than passwords alone, but sophisticated attackers can sometimes steal those, too. CISA and NIST both recommend phishing-resistant authentication for higher-risk accounts.

3. Stop giving everyone access to everything.

If one employee's account gets compromised, the attacker should not inherit the keys to the entire company.

Apply the principle of least privilege. Employees should have access only to the systems and information they actually need to do their jobs. Administrative access should be especially limited.

The smaller the compromised account's footprint, the smaller the potential blast radius.

4. Harden your email system.

Your employees should not be your only line of defense.

Use modern spam and malware filtering, safe-link scanning, attachment screening, and email authentication technologies such as SPF, DKIM, and DMARC.

DMARC, in particular, can make it harder for attackers to impersonate your company's domain in phishing campaigns.

5. Make reporting suspicious messages ridiculously easy.

Give employees a one-click "Report Phishing" button or an obvious place to forward questionable messages.

And don't punish people for raising false alarms.

I'd rather have IT review 50 legitimate emails than have an employee hesitate for 30 seconds over the one malicious email that matters.

Speed also matters after someone clicks. The sooner IT knows, the sooner it can disable accounts, revoke sessions, reset credentials, isolate devices, and determine what the attacker accessed.

6. Phish your own employees.

Run periodic simulated phishing exercises.

Not as a "gotcha." Not so HR can create a list of employees to discipline.

Use them to identify where your training and systems are failing.

Which kinds of messages fool people? Are executives more vulnerable to fake document-sharing notices? Is accounting susceptible to vendor-payment scams? Are employees entering credentials into fake Microsoft login pages?

Train against the attacks your workforce is actually falling for.

7. Protect the people attackers are most likely to target.

Cybercriminals don't choose victims randomly.

Executives, finance employees, HR, IT administrators, and anyone with access to payroll, employee data, banking information, confidential business information, or wire-transfer authority deserve additional safeguards.

Those safeguards might include stronger authentication, transaction verification procedures, tighter access controls, additional training, and alerts for unusual login behavior.

Your CFO should not be able to change a vendor's bank account based solely on an email. Neither should anyone else.

8. Have a plan for the click that gets through anyway.

Because eventually somebody will click something.

Your cybersecurity plan should assume that prevention will sometimes fail.

Know who gets called. Know how accounts get locked. Know who contacts your cyber insurer. Know how you preserve logs and evidence. Know when outside forensic counsel or cybersecurity professionals get involved. Know whether legal or regulatory notification obligations might be triggered.

And practice the plan before you need it.

Cybersecurity isn't just an IT problem. It's an HR problem, a training problem, a risk-management problem, a legal problem, and ultimately a business problem.

Manchester City reportedly spent years and enormous resources fighting over what Rui Pinto found after one employee clicked one link.

Your company probably doesn't have Manchester City's resources.

Train your employees accordingly.

      

"Can I bring my dog to work?" Emotional support animals and the ADA

A firefighter with PTSD asks to bring his dog to work as a reasonable accommodation. The dog helps calm him. His psychologist supports the request.

Does the ADA require the employer to say yes?

Not necessarily.

In Fisher v. City of Lansing, a firefighter claimed that the city violated the ADA when it refused to let him bring his dog, Chet, to the fire station. Fisher had PTSD, and his psychologist recommended an emotional support animal to help manage his symptoms at work.

The court sided with the city.

The problem wasn't whether Fisher had a disability. It was whether the dog was necessary as a reasonable accommodation. To prevail on an ADA failure-to-accommodate claim, an employee must show that the requested accommodation is both reasonable and necessary — that it addresses an obstacle preventing the employee from performing an essential job function.

Fisher couldn't make that showing.

He admitted that he could perform his job without the dog. "Not well," as he put it, but he could perform it. His psychologist likewise couldn't identify any particular job duty Fisher could not perform without the animal. Instead, the doctor testified that the dog had a calming effect on him.

That's where the distinction between a service animal and an emotional support animal becomes important.

Under the ADA regulations governing public entities and public accommodations, a service animal is a dog individually trained to perform work or tasks directly related to someone's disability. Emotional support, comfort, companionship, and a calming presence, standing alone, don't qualify.

But employers need to be careful with that distinction.

Those definitions come from Titles II and III of the ADA. Title I (the part of the ADA governing employment) doesn't contain the same service-animal definition or automatically exclude emotional-support animals from consideration. The Job Accommodation Network therefore recommends that employers treat requests for both service animals and ESAs like other reasonable-accommodation requests: engage in the interactive process and determine whether the animal is needed because of the employee's disability.

In other words: "It's an ESA, not a service dog" should not end the conversation.

For employers, the better approach is:

  1. Start the interactive process. Don't get hung up on labels.

  2. Ask what limitation the animal addresses and how it helps the employee perform the job or access an equal workplace benefit.

  3. Request appropriate medical documentation when the disability or need isn't obvious.

  4. Focus on necessity, not preference. "This helps me" isn't necessarily the same as "I need this because of my disability."

  5. Consider the actual workplace. Safety, sanitation, allergies, disruption, animal control, and essential job duties all matter.

  6. Document the analysis. A categorical "no animals" rule is much harder to defend than an individualized ADA assessment.

The ADA doesn't require employers to turn every workplace into a dog- or peacock-friendly office.

But it does require them to treat "Can I bring my dog to work?" as an accommodation question, not merely a pet-policy question. 

WIRTW #812 (the 'shiny and new' edition)

Nineteen years in, I repainted the walls. Your handbook needs the same.

Your brain is built to notice what's new. That's not a flaw. It's a feature.

Novelty grabs attention and makes people curious. Wharton researchers Hengchen Dai, Katherine Milkman, and Jason Riis describe a "fresh start effect": people are more motivated to act after a clean break, like a new year, a birthday, or a Monday.

The Ohio Employer Law Blog is 19 years old. I built this website in 2007, and it looked like it.

This week, it got a new look. Same content and same opinions, just easier to navigate with better mobile responsiveness. 

Your handbook has the same problem. It hasn't been refreshed in years. Nobody notices it anymore. It's faded paint. Your employees walk past it every day without seeing it. And that faded paint has a cost.

1. Employees stop reading it. A policy no one reads is a policy no one follows.

2. Managers stop enforcing it. The handbook says one thing. The practice says another. A policy you don't follow can become evidence of pretext. Plaintiffs' lawyers love that gap. It's their Exhibit A.

3. The law moves on without it. Remote work. The Pregnant Workers Fairness Act. AI. If your handbook still reads like 2015, it's missing today's rules and today's risks.

4. Patching piles up contradictions. Add-on memos and one-off updates collide with each other. A clean rewrite lets you cut what you don't follow and clarify what you do.

Pick a policy at random.

Can your managers explain it without opening the handbook?
Does your team follow it exactly as written?
Is it current with the law?

If you hesitated on any of them, you have your answer.

A rewrite is a fresh start. Use it. Retrain your workforce. Coach your managers on enforcement. Get new acknowledgments signed. Apply a fresh coat of paint.

If you're ready to repaint your handbook, email me, or contact the Employment & Labor team at Wickens Herzer Panza.


Here's what I read this week that you should read, too.

Wouldn't It Be Nice — via The Norah and Dad Show Podcast

Why Your Employees Override AI — via Harvard Business Review 

When Employees Fear AI Losing Control, HR Needs a Better Answer  — via EntertainHR

Meta employees ordered 'attorney/client privilege' hats while fighting child safety disclosures — via The Verge

Off the Clock, Beyond the Test: Cannabis Use and Workplace Impairment in New York — via The L•E•Jer

AI, And Experts, And Hallucinations, Oh My! — via Above the Law

The Most Dangerous Thing a New Manager Can Say Is 'I'll Fix This' — via Improve Your HR by Suzanne Lucas, the Evil HR Lady

Ways to remove barriers to hiring people with disabilities — via TLNT

The cup meltdown, the "Lost" finale, and other tantrums you've witnessed at work — via Ask a Manager

NLRB Restores Employer-Friendly Standard for Workplace Outbursts During Protected Activity — via Employment Law Letter

'I felt shame': former BA worker locked in legal battle after losing job of 30 years — via The Guardian

"Not Crazy About White People" Allegedly Appeared in an HR Report. What Could Possibly Go Wrong? — via Eric Meyer's Employer Handbook Blog

A New Era of Health Care Noncompetes: Emerging Models and the Future of Labor Mobility — via Trading Secrets

The doctor's note is vague. What should the employer do next? — via HR Dive

Peter Gabriel Reveals Full Details, Release Date for New Album o/i — via Consequence

Some things should be left unseen

"In the workplace, the law requires that some things be left unseen."

That's the 6th Circuit, in a retaliation case that started with a groping complaint and ended with a pornographic slideshow.

Gertrude Crisp, an EMT at the Scioto Ambulance District, had her own take on the place. "[T]he inmates run[] the insane asylum."

Crisp met co-worker Joshua Gullett in 2012, when both worked at the Portsmouth Ambulance Department. She says he commented constantly on her body, asked to see her breasts, and "jokingly" touched her even after she said no. Same for any woman who gave him attention.

Around then, another EMT showed Crisp and others naked photos of Gullett, allegedly from an adult website called Fetlife.

Both Crisp and Gullett later landed at Scioto. In December 2018, Crisp says that while on shift together, Gullett talked about her body, tipped over the recliner she was sitting in, and tried to stuff her into a trash can. She also claimed that he told her they were alone and nobody would hear her scream as he touched her breasts.

That same night, Crisp reported Gullett's actions to her supervisor. In response, the employer made sure the two never worked the same shift. Gullett faced no other consequences. Crisp figured complaining more was futile. She filed no legal claim. She did tell anyone who would listen that he was "a predator."

Four(!) years later, Crisp sat down at work with two new EMTs to talk about "EMS culture." She warned them about predatory men in EMS. Then she showed them nude images of Gullett and his wife, who by then was also a Scioto EMT.

Scioto's board investigated and unanimously fired Crisp for showing nude pictures of a co-worker to other employees while on duty. The board member who led the investigation called it "way over the top." The pictures weren't necessary to warn anyone about Gullett, he said, and they could have made everyone uncomfortable.

Crisp sued for retaliation under Title VII. She lost.

Warning co-workers about harassment is protected activity. So may be sharing explicit material with HR when it's necessary to support a harassment claim. The court acknowledged as much. But in this case, the photos weren't necessary to make her point, and the wife had nothing to do with the alleged workplace misconduct. An employee who mixes protected and unprotected conduct can't use the first as a shield for the second.

Crisp's complaint was protected. Her misconduct in showing the photos wasn't. Your job as an employer is to understand the difference before you fire or otherwise take an adverse action against anyone.

© Jon Hyman. You're receiving this email because you've signed up to receive updates from us.

If you'd prefer not to receive updates, you can unsubscribe.