In April 2021, the DOL issued guidance for addressing cybersecurity risks associated with benefit plans. The Employee Benefits Security Administration’s (EBSA) 2024 Compliance Assistance Release clarified that the guidance applies to all ERISA-covered plans, including health and welfare plans and employee pension benefit plans. The practical impact is clear: Cybersecurity oversight should no longer be treated solely as a retirement plan recordkeeping issue. It should be addressed as part of overall fiduciary governance for plans that hold participant assets, personally identifiable information (PII), protected health information (PHI), or other sensitive benefit information.
For health and welfare plans, which may also be HIPAA-covered entities, this also means aligning DOL cybersecurity expectations with existing HIPAA Security Rule obligations so that PHI and PII safeguards, business associate oversight, and breach notification workflows aren’t managed in a separate silo from ERISA fiduciary governance. This alignment is becoming increasingly important. The Office for Civil Rights within the U.S. Department of Health and Human Services (HHS OCR) also issued a Notice of Proposed Rulemaking (NPRM) on Jan. 6, 2025, that would tighten HIPAA Security Rule requirements for health plans and their business associates, with final action projected for July 2027.
In addition to millions of dollars in financial assets, ERISA-covered plans contain pertinent personal data on participants. While assets taken from a benefit plan can be quantified, the value of stolen data is effectively unknown. For health and welfare plans, the exposure extends to protected health information, claims and eligibility data, dependent information, and clinical or wellness data shared with third-party administrators, pharmacy benefit managers, and stop-loss carriers. Strong cybersecurity practices and disciplined oversight of third-party providers remain the most reliable way to reduce an organization’s risk and exposure to cybersecurity events.
What are EBSA’s 12 cybersecurity best practices for employee benefit plans?
The DOL guidance states that responsible plan fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks. The agency has provided guidance and best practices for recordkeepers, other service providers responsible for plan-related IT systems and data, third-party administrators, pharmacy benefit managers, and plan fiduciaries making prudent decisions about service providers they hire.
EBSA has outlined 12 best practices for service providers to reduce cybersecurity risks associated with employee benefit plans. While some of these practices should be shared by fiduciaries and service providers, others are specific to service providers.
What changed in the 2024 EBSA cybersecurity guidance update?
The 2024 EBSA cybersecurity guidance update included the following:
- Expanded the scope from retirement plans to all ERISA-covered plans, including health and welfare benefit plans.
- Reframed vendor oversight as an ongoing monitoring obligation, not a one-time selection activity. Plan sponsors should maintain evidence of annual audits, risk assessments, breach history reviews, insurance coverage reviews, and follow-up on findings.
- Update access control language to emphasize phishing-resistant multifactor authentication (MFA) where possible, MFA on internet-facing systems, MFA for sensitive network areas, quarterly access reviews, and additional identity validation before plan distributions or sensitive account changes.
- For health and welfare plans, extended the cyber program to explicitly address PHI risks. This includes mapping DOL best practices to the HIPAA Security Rule’s administrative, physical, and technical safeguards, maintaining current risk analyses, executing and monitoring business associate agreements, and confirming that breach notification obligations under HIPAA and any applicable state laws are integrated with the plan’s incident response (IR) plan.
- Elevated incident readiness. The current DOL best practices call for defined breach notification protocols, internal and external communication procedures, after-action reporting, insurer notification, law enforcement notification, and prompt participant notice when personal data is involved.
What cybersecurity responsibilities do plan sponsors and fiduciaries share?
- Governance and evidence: Keep a documented cybersecurity program, assign accountability, and report cyber risk and remediation status to the appropriate plan governance group.
- Access and fraud prevention: Treat account takeover and fraudulent distribution risk as part of cyber risk. Review MFA, privileged access, change of bank account controls, and participant identity validation.
- Have a formal, well-documented cybersecurity program: A well-designed program protects the infrastructure, information systems, and the information in the systems from unauthorized access, use, or other malicious acts and establishes strong security policies, procedures, guidelines, and standards for the organization to follow.
- Have a reliable annual third-party audit of security controls: Service providers should conduct an independent assessment of the organization’s security controls and report on existing risks, vulnerabilities, and weaknesses. The fiduciary should request information security assessment reports from their service provider, such as SOC examinations and penetration-testing summaries. For service providers that handle PHI, request HITRUST CSF certifications or SOC 2 plus HIPAA reports where available.
- Clearly define and assign information security roles and responsibilities: Assign information security responsibilities to an appropriate leader in the organization with sufficient experience and knowledge to establish and maintain the vision, strategy, and operation of the cybersecurity program.
- Ensure that any assets or data stored in a cloud or managed by a third-party service provider are subject to appropriate security reviews and independent security assessments: Fiduciaries should review security plans and procedures with service providers, hosted in the cloud or with a third party, to ensure appropriate controls are in place for protecting plan data.
- Have an effective business resiliency program addressing business continuity, disaster recovery, and IR: Review and update the business continuity, disaster recovery, and IR plans to account for the organization’s current operational and technology environment.
- Conduct periodic cybersecurity awareness training: Ensure cyber awareness training programs are updated annually to reflect risks identified by the most recent risk assessment and include individuals that interact with participant data. Workforce members with access to PHI should receive HIPAA specific training in addition to general cybersecurity awareness.
- Encrypt sensitive data when stored and in transit: Ensure the proper protection of plan data through strong encryption standards. Data encryption can protect nonpublic information to safeguard the confidentiality and integrity of the data at rest or in transit.
- Cyber insurance alignment: Insurers underwriting health plan sponsors increasingly require evidence of MFA, endpoint detection and response (EDR), tested backups, a tested IR plan, and periodic penetration testing. A sponsor’s DOL documentation and cyber insurance renewal materials should tell the same story.
- Data classification: Apply a formal scheme (public, internal, confidential, restricted) and tie encryption, access, and retention to each tier.
What cybersecurity responsibilities apply to employee benefit plan service providers?
- Conduct prudent annual risk assessments: As outlined by the guidance, a risk assessment should identify threats, establish and review controls, mitigate remaining risks, and be monitored and updated annually.
- Have strong access control procedures: Review privilege access to related IT systems and ensure access is limited based on the principle of least-privilege. Deploy multifactor authentication to related IT systems whenever possible.
- Implement and manage a secure system development life cycle (SDLC) program: Ensure procedures, guidelines, and standards for developing in-house applications are secure. This may include activities such as penetration testing, code review, and architecture analysis.
- Implement strong technical controls in accordance with best security practices: Deploy and secure information systems that interact with plan data, including routine security updates and system hardening standards.
- Appropriately respond to any past cybersecurity incidents: Review ability and effectiveness of responding to a cybersecurity incident or breach. In addition, review contracts to ensure data breach notification responsibilities are defined and processes exist for meeting obligations.
Lessons learned: Examples of DOL cybersecurity guidance in practic
- Defined contribution plan sponsor assessment: A sponsor used the DOL’s best practices as a baseline, then mapped them to U.S. National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) style procedures. The review included policies and procedures, stakeholder interviews, security configuration evidence, vendor contracts, cyber insurance, IR materials, and independent audit reports. The lesson learned: The DOL framework is a strong executive-facing model, but sponsors need an evidence request list to make it operational.
- Portfolio company baseline controls: A sponsor converted cyber expectations into a minimum control set: single sign-on (SSO) and MFA for critical systems, EDR on managed endpoints, secure email controls, domain-based message authentication, reporting and conformance (DMARC) enforcement, tested recovery plans, annual security awareness training with phishing simulations, complete asset inventory, tested IR, annual penetration testing, cyber insurance, vulnerability service level agreements (SLAs), and secure coding expectations. The lesson learned: translating the DOL’s guidance into measurable baseline controls helps management prioritize remediation.
- Cyber risk assessment findings: Recent assessments continue to identify gaps in formal log review, security monitoring procedures, data classification, vendor management documentation, IR role clarity, and leadership reporting. The lesson learned: Many organizations have tools and policies, but the maturity gap is often in governance cadence, evidence, escalation thresholds, and recurring review.
- Health plan cyber and HIPAA alignment: A self-funded plan sponsor used the DOL best practices as the umbrella and mapped them to the HIPAA Security Rule. The review covered the PHI and PII data map, BAAs with the TPA and PBM, participant identity validation, and a tabletop combining ransomware with a HIPAA breach notification decision. The lesson learned: The most common gaps in health plan assessments are stale PHI inventories, outdated BAAs, and unclear ownership of HIPAA breach notification, and aligning DOL and HIPAA language avoids duplicate work.
- Benefit plan cybersecurity oversight requires a coordinated approach: Enforcement continues to focus on the fundamentals from both regulators. Risk analysis remains the most frequently cited deficiency in HHS OCR investigations, followed by access controls, audit logging, and business associate oversight. On the DOL side, EBSA’s fiscal year 2026 enforcement priorities put cybersecurity at the top of the list. Health plan sponsors that view the DOL cybersecurity best practices, the current HIPAA Security Rule, and the proposed 2025 NPRM as one integrated program will find that the same evidence supports all three.
It’s important to note that both plan fiduciaries and benefit plan service providers play a critical role in protecting participant assets, PII, and PHI. Contact a member of our team to align DOL, HIPAA, and other regulatory requirements.
Key takeaways:
- DOL cybersecurity guidance applies to ERISA-covered plans, and plan sponsors are expected to actively manage cyber risks as part of fiduciary oversight.
- Employee benefit plans contain valuable participant assets and data, such as PHI and PII, making them attractive targets for cyberattacks.
- Plan sponsors should perform ongoing due diligence of recordkeepers and other service providers by reviewing security controls, audits, and cybersecurity practices.
- Effective cybersecurity programs include clear security ownership, employee training, incident response planning, and encryption of sensitive data.
- Protecting participant data requires shared accountability between plan fiduciaries and service providers, with ongoing oversight to ensure risks are properly managed.
- Health and welfare plan sponsors should align DOL cybersecurity expectations with HIPAA Security Rule safeguards.