
The U.S. Department of Labor (DOL) has confirmed that its cybersecurity guidance applies to all employee benefit plans, including retirement plans and health and welfare plans. Employee benefit plans covered by ERISA often hold millions of dollars or more in assets and store and transfer participants’ personally identifiable data, which can make them tempting targets for cybercriminals.
Plan fiduciaries of ERISA-covered plans have an obligation to ensure proper mitigation of cybersecurity risks. Because employers often rely on service providers to maintain employee benefit plan records and keep participant data confidential and secure, they should ensure they use service providers that follow strong cybersecurity practices.
The DOL’s cybersecurity guidance includes tips for hiring plan service providers, cybersecurity program best practices, and online security tips.
A new wave of litigation highlights the importance of employers’ adherence to their fiduciary duties when managing their group health plans, especially as it relates to prescription drug benefits. These lawsuits remind employers that they must act prudently to select and monitor health plan service providers, such as pharmacy benefit managers (PBMs). The cybersecurity guidance can help employers decide on the service providers they use, including PBMs.
Contact us to see how you could minimize risk:
- Employee Benefits|
Recent News
Construction Industry Fatalities Decline in 2024
In 2024, total workplace fatalities in the United States fell to 5,070, the lowest number since 2020.
How an Extra Biweekly Payroll Period in 2026 Impacts Payroll
For employers that run biweekly payroll, 2026 introduces a unique scheduling challenge.
Employee Spotlight: Lane Trust
Please help us welcome Lane to the Seubert Team as a Strategic Risk Advisor!
Employers Should Prepare for 2026 RxDC Reporting
Group health plans and health insurance issuers must annually submit detailed information on prescription drug and health care spending to the CMS.
DOL Announces Proposed Independent Contractor Rule
The DOL announced a proposed rule to rescind its 2024 final independent contractor rule and replace it with an analysis of employee classification under the FLSA.
Improving the Effectiveness of Cybersecurity Training
Workforce cybersecurity training is a critical part of a company’s security risk management program.

