Both Sides Now… Must Be Alert to Cybersecurity

Holland & Hart - The Benefits Dial
Contact

Holland & Hart - The Benefits Dial

New guidance from the Employee Benefits Security Administration (EBSA) affirms that both sides—retirement plans and welfare plans—must take steps to secure participant data from cybercrime.

In 2021 the Department of Labor (DOL) introduced new guidance on best practices for maintaining cybersecurity, which included tips to participants who check their retirement accounts online. From this, many plan sponsors and service providers concluded that the guidance was only applicable to retirement benefits (such as 401(k), profit sharing, and pension plans).

On September 6, 2024, the EBSA issued Compliance Assistance Release No. 2024-1, which makes clear that the cybersecurity guidance issued in 2021 is applicable to ALL types of ERISA plans—including health and welfare plans.

The EBSA estimates that there are 153 million participants in private sector ERISA governed plans, which includes 2.18 million health plans. That’s a lot of personal information being maintained in digital format. The federal regulations require that plan fiduciaries take appropriate steps to help mitigate the risks of loss from computer-related crimes.

The Compliance Assistance Release updates the 2021 guidance by specifically calling out health and welfare plans with the following:

As a plan fiduciary, be sure to review the guidance and take any steps necessary to apply the best practices to your health and welfare plan data.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Holland & Hart - The Benefits Dial

Written by:

Holland & Hart - The Benefits Dial
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Holland & Hart - The Benefits Dial on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide