USDOL updates cybersecurity guidance for retirement plans

***** Photographs taken by the federal government are generally part of the public domain and may be used, copied and distributed without permission. Unless otherwise noted, photos posted here may be used without the prior permission of the U.S. Department of Labor. Such materials, however, may not be used in a manner that imply any official affiliation with or endorsement of your company, website or publication. Photo Credit: Department of Labor Shawn T Moore

The U.S. Department of Labor (USDOL) on Sept. 6 updated current cybersecurity guidance, confirming that it applies to all types of plans governed by the Employee Retirement Income Security Act (ERISA), including health and welfare plans, and all employee retirement-benefit plans. The new compliance assistance release issued by the department’s Employee Benefits Security Administration (EBSA) […]

Already an Subcriber? Log in

Get Instant Access to This Article

Become a Central New York Business Journal subscriber and get immediate access to all of our subscriber-only content and much more.

The U.S. Department of Labor (USDOL) on Sept. 6 updated current cybersecurity guidance, confirming that it applies to all types of plans governed by the Employee Retirement Income Security Act (ERISA), including health and welfare plans, and all employee retirement-benefit plans. The new compliance assistance release issued by the department’s Employee Benefits Security Administration (EBSA) provides best practices in cybersecurity for plan sponsors, plan fiduciaries, recordkeepers and plan participants. The release updates EBSA’s 2021 guidance. It includes tips for hiring a service provider and helps plan sponsors and fiduciaries select a service provider with “strong” cybersecurity practices and monitor their activities, as ERISA requires. The release also includes cybersecurity program best practices and assists plan fiduciaries and recordkeepers in mitigating risks. It also includes online-security tips and offers plan participants who check their online retirement accounts with rules for reducing the risk of fraud and loss. “Today’s Compliance Assistance Release provides an important clarification for plan sponsors and fiduciaries, confirming that our guidance on cybersecurity applies to all plans covered by the Employee Retirement Income Security Act,” Lisa Gomez, assistant secretary for employee benefits security, explained in the announcement. “All ERISA covered plans need to implement appropriate best practices to help protect participants and their beneficiaries from cybercrime and emerging threats. These updates remind plan sponsors and fiduciaries of the critical importance of safeguarding job-based benefits and personal information.” As of June 2024, EBSA estimates ERISA covers 2.8 million health plans, 619,000 other welfare-benefit plans, and 765,000 private pension plans in the U.S. These plans include 153 million workers, retirees, and dependents who participate in private-sector pension and welfare plans with $14 trillion in estimated assets. Without sufficient protections, digital participant, and assets information may be vulnerable to the internal and external risks of computer-related crimes and losses. Federal regulations require plan fiduciaries to take appropriate precautions to mitigate these risks. “The Employee Benefits Security Administration believes cybersecurity is a great concern for all employee benefit plans and we continue to investigate potential ERISA violations related to the issue,” Gomez said. The guidance complements EBSA’s regulations on electronic records and disclosures to plan participants and beneficiaries, USDOL said. These include provisions on ensuring that electronic recordkeeping systems have reasonable controls, adequate records management practices are in place and that electronic disclosure systems include measures calculated to protect personally identifiable information.
Eric Reinhardt: