Due to the vast amounts of sensitive data handled, health plans are prime targets for cyberattacks. No longer just a best practice—cybersecurity is now an essential fiduciary responsibility for plan sponsors.

To address these risks, the U.S. Department of Labor (DOL) first issued cybersecurity guidance in April 2021, outlining best practices for retirement plans. In September 2024, the DOL updated this guidance to explicitly apply to health and welfare plans, removing any prior ambiguity about their inclusion.

Key Updates from the Guidance

  • Health Plans Are Officially Covered. The updated guidance clarifies that ERISA-governed health and welfare plans must adhere to cybersecurity best practices. This change recognizes the high value of health data and its vulnerability to cyber threats.
  • Continued Focus on Best Practices. Plan sponsors and fiduciaries must select and monitor service providers with strong cybersecurity controls. The DOL reiterates that critical security measures—risk assessments, data encryption, multifactor authentication, and incident response plans—remain essential.
  • Participant Education is Crucial. Educating plan participants on password security, phishing risks, and multi-factor authentication is a priority to prevent fraud and account breaches.

What Plan Sponsors and Fiduciaries Must Do

  • Strengthen Vendor Oversight. Conduct thorough due diligence on service providers to ensure they have strong cybersecurity programs, third-party audits, and breach response plans. Update contracts to include clear cybersecurity provisions, breach notification timelines, and liability clauses.
  • Enhance Internal Security Controls. Conduct annual cybersecurity audits through an independent third party to assess vulnerabilities and ensure compliance. Deploy essential safeguards, including multifactor authentication, encryption, network segmentation, and access controls. Perform annual penetration testing to proactively identify and address security gaps.
  • Educate Plan Participants. Provide ongoing cybersecurity training on phishing scams, password best practices, and account monitoring. Ensure participants understand how to protect their personal health and financial data.
  • Maintain Documentation for Compliance. Keep detailed records of vendor evaluations, audits, training sessions, and security updates. Proper documentation demonstrates compliance with fiduciary obligations under ERISA.

Next Steps

Plan sponsors should take immediate action to align their cybersecurity policies with the DOL’s updated guidance by:

  • Engaging cybersecurity experts to assess risks and improve security measures.
  • Establishing a monitoring program to oversee vendor cybersecurity compliance.
  • Strengthening internal security protocols to safeguard participant data.

By proactively addressing cybersecurity risks, plan sponsors can fulfill their fiduciary responsibilities, protect sensitive participant data, and build trust in their health plans.