You are about to leave Risk Strategies website and view the content of an external website.
You are leaving risk-strategies.com
By accessing this link, you will be leaving Risk Strategies website and entering a website hosted by another party. Please be advised that you will no longer be subject to, or under the protection of, the privacy and security policies of Risk Strategies website. We encourage you to read and evaluate the privacy and security policies of the site you are entering, which may be different than those of Risk Strategies.
The Employee Benefits Security Administration (EBSA), part of the Department of Labor (DOL), recently published compliance assistance guidance confirming that its cybersecurity guidance from April 2021 applies to all ERISA plans, including health and welfare plans.
EBSA published this recent compliance assistance guidance in the wake of confusion amongst ERISA[1] health and welfare plan sponsors who were informed by their plan service providers that the EBSA April 2021 cybersecurity guidance did not apply to them, but rather only to ERISA retirement plans. The DOL’s ERISA Advisory Council recommended in 2022 that the EBSA clarify that the guidance also applies to health benefit plans, resulting in this updated EBSA guidance.
This recent guidance leaves no doubt that the DOL cybersecurity guidance from April 2021 applies to ERISA health and welfare plans as well. It also provides valuable resources, tips, and best practices for all ERISA plans to follow in their fiduciary efforts to protect plan data, personal information, and plan assets.
Notably, the guidance includes links to the following resources for employers sponsoring ERISA benefit plans, including health and welfare plans:
Helps plan sponsors and fiduciaries prudently select a service provider with strong cybersecurity practices and monitor their activities, as required under ERISA.
Key tips include:
Assists plan fiduciaries and record-keepers in their responsibilities to manage cybersecurity risks.
Below is a summary of the best practices (discussed in greater detail in the guidance document):
Offers plan participants and beneficiaries who check their retirement accounts or other employee benefit plan information online basic rules to reduce the risk of fraud and loss, such as:
ERISA health and welfare and retirement benefit plans, which contain sensitive personal data of their plan participants, continue to serve as enticing targets for bad actors. As a result, employers sponsoring all types of ERISA benefit plans are advised to review the updated guidance and resources carefully, and follow the tips and recommended best practices to protect their plans’ data and information.
As reports of data breaches, hacks, and other technology-related incidents become increasingly ubiquitous, this clarifying guidance underscores the DOL’s continued focus on ERISA plans’ cybersecurity risk mitigation measures to protect their plans. As stated in the accompanying EBSA press release, EBSA “believes cybersecurity is a great concern for all employee benefit plans and we continue to investigate potential ERISA violations related to the issue.”
Employers are encouraged to take advantage of this updated EBSA guidance to understand their plans’ cybersecurity requirements and bolster their plans’ cybersecurity hygiene practices.
Risk Strategies is committed to keeping employers informed and up-to-date. Contact us at benefits@risk-strategies.com.
[1] ERISA refers to the Employee Retirement Income Security Act of 1974.
The contents of this article are for general informational purposes only and Risk Strategies Company makes no representation or warranty of any kind, express or implied, regarding the accuracy or completeness of any information contained herein. Any recommendations contained herein are intended to provide insight based on currently available information for consideration and should be vetted against applicable legal and business needs before application to a specific client.