Skip to Content
Business professional talking on the phone.

DOL guidance for cybersecurity risks associated with employee benefits plans

The U.S. Department of Labor’s cybersecurity guidance now applies to all ERISA-covered plans, including retirement, health, and welfare plans. Plan sponsors should understand how these 12 best practices affect fiduciary oversight, vendor monitoring, and participant data protection.

In April 2021, the DOL issued guidance for addressing cybersecurity risks associated with benefit plans. The Employee Benefits Security Administration’s (EBSA) 2024 Compliance Assistance Release clarified that the guidance applies to all ERISA-covered plans, including health and welfare plans and employee pension benefit plans. The practical impact is clear: Cybersecurity oversight should no longer be treated solely as a retirement plan recordkeeping issue. It should be addressed as part of overall fiduciary governance for plans that hold participant assets, personally identifiable information (PII), protected health information (PHI), or other sensitive benefit information.

For health and welfare plans, which may also be HIPAA-covered entities, this also means aligning DOL cybersecurity expectations with existing HIPAA Security Rule obligations so that PHI and PII safeguards, business associate oversight, and breach notification workflows aren’t managed in a separate silo from ERISA fiduciary governance. This alignment is becoming increasingly important. The Office for Civil Rights within the U.S. Department of Health and Human Services (HHS OCR) also issued a Notice of Proposed Rulemaking (NPRM) on Jan. 6, 2025, that would tighten HIPAA Security Rule requirements for health plans and their business associates, with final action projected for July 2027.

In addition to millions of dollars in financial assets, ERISA-covered plans contain pertinent personal data on participants. While assets taken from a benefit plan can be quantified, the value of stolen data is effectively unknown. For health and welfare plans, the exposure extends to protected health information, claims and eligibility data, dependent information, and clinical or wellness data shared with third-party administrators, pharmacy benefit managers, and stop-loss carriers. Strong cybersecurity practices and disciplined oversight of third-party providers remain the most reliable way to reduce an organization’s risk and exposure to cybersecurity events.

 What are EBSA’s 12 cybersecurity best practices for employee benefit plans?

The DOL guidance states that responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks. The agency has provided guidance and best practices for recordkeepers, other service providers responsible for plan-related IT systems and data, third-party administrators, pharmacy benefit managers, and plan fiduciaries making prudent decisions about service providers they hire.

EBSA has outlined 12 best practices for service providers to reduce cybersecurity risks associated with employee benefit plans. While some of these practices should be shared by fiduciaries and service providers, others are specific to service providers.

What changed in the 2024 EBSA cybersecurity guidance update?

The 2024 EBSA cybersecurity guidance update included the following:

What cybersecurity responsibilities do plan sponsors and fiduciaries share?

What cybersecurity responsibilities apply to employee benefit plan service providers?

Lessons learned: Examples of DOL cybersecurity guidance in practic

It’s important to note that both plan fiduciaries and benefit plan service providers play a critical role in protecting participant assets, PII, and PHI. Contact a member of our team to align DOL, HIPAA, and other regulatory requirements.

Key takeaways:

Related Thinking