DOL confirms cybersecurity guidance applies to health and welfare plans
On September 6, 2024, the U.S. Department of Labor (DOL) confirmed its cybersecurity guidance applies to all employee benefit plans, including health and welfare plans. In 2021, the DOL issued guidance providing best practices in cybersecurity for plan sponsors, plan fiduciaries, recordkeepers, and plan participants. The retirement plan industry took notice and has generally made great efforts to improve cybersecurity practices and protect participants’ accounts and data. The new DOL compliance assistance release issued in early September clarifies that the health and welfare plan industry should also follow the prior guidance.
Best practices
Included among the DOL’s guidance are “Tips for Hiring a Service Provider,” which suggest that fiduciaries hiring benefit plan service providers should: