The Department of Labor (DOL) has made its expectations unmistakable and in 2026, enforcement has followed. Here is what every health plan sponsor needs to understand about risk, responsibility, and what must happen when there is a breach.
|
|
THE WHY
Why Is Cybersecurity a Health Plan Sponsor Concern?
Anyone who has stood in a concert ticket line knows that despite doing everything right, such as buying your ticket early, you have to trust that the systems will work. And when they don't, it is your night that gets ruined, not the promoter's.
Employees enrolled in a health benefit plan are in the same position. They have done everything asked of them: enrolled during open enrollment, designated their dependents, paid their premiums. Their most sensitive personal data now lives inside systems they will never see, managed by vendors they did not choose. When something goes wrong, they are the ones who bear the consequences: identity theft, fraudulent claims, exposed diagnoses. The health plan sponsor is the promoter in this scenario. And the fiduciary standard says the promoter is responsible for what happens inside the venue.
For years, many plan sponsors treated cybersecurity as someone else's problem — an IT matter delegated to a third-party administrator and never surfaced at the plan governance level. The DOL has been unambiguous that this posture is no longer acceptable.
|
2.8M |
153M |
$14T |
EBSA estimates those 2.8 million health plans collectively affect 153 million Americans and involve $14 trillion in assets. At that scale, cybersecurity is not a niche compliance detail. It’s a systemic risk the federal government has decided requires active enforcement attention.
ERISA's fiduciary duties of prudence and loyalty have always required plan fiduciaries to act in participants' best interests with the care of a prudent expert. Courts, regulators, and the DOL itself have increasingly interpreted that standard to include protecting participant data from digital threats. Failing to implement reasonable cybersecurity safeguards exposes plan fiduciaries to ERISA claims, state data breach litigation, and now, direct DOL enforcement action.
THE REGULATORY LANDSCAPE
What the DOL Actually Requires, and When It Changed
Good sound engineers are invisible when they are doing their job well. You do not think about the person at the mixing board in the back of the room; you just hear a clear, balanced mix and enjoy the show. It is only when something goes wrong, when the vocals are buried or the bass is rattling the walls, that you become suddenly, acutely aware of how much depends on that person's expertise and preparation.
The DOL's cybersecurity framework operates similarly. Most plan sponsors were not thinking about it until the agency made it impossible to ignore.
The 2021 Foundation
In April 2021, EBSA issued the first cybersecurity guidance ever directed at ERISA-covered plans. It addressed three audiences: plan sponsors and fiduciaries selecting service providers, recordkeepers and service providers managing plan IT systems, and participants managing their benefit accounts online. The guidance established a clear principle; fiduciaries have an obligation to ensure proper mitigation of cybersecurity risks but left a critical question unanswered about scope.
The 2024 Expansion
Health and welfare plan service providers had spent the intervening years telling fiduciaries and EBSA investigators that the 2021 guidance was a retirement plan matter. On September 6, 2024, EBSA issued Compliance Assistance Release No. 2024-01 and closed that escape route permanently. The cybersecurity framework applies to every type of ERISA-covered plan: retirement and health and welfare alike.
Two meaningful additions came with the 2024 update.
- First, fiduciaries are now expected to ask service providers not just whether they carry cyber insurance, but whether that policy specifically covers losses involving clients' benefit plan data — a distinction that matters enormously when a claim is filed.
- Second, the guidance reinforced multi-factor authentication (MFA) as a non-negotiable baseline control and called for annual third-party audits of service provider security practices.
2026: EBSA Puts Cybersecurity First
On January 15, 2026, EBSA announced a significant overhaul of its national enforcement priorities for fiscal year 2026. Cybersecurity was listed first above mental health parity, surprise billing, and every other enforcement project on the list. EBSA investigators are now actively examining cybersecurity governance practices, plan system controls, and service provider oversight across all ERISA-covered plans. For health plan sponsors, this is not a future concern. It is a present one.
THE THREAT LANDSCAPE
What Cyber Threats Are Health Plan Sponsors Actually Facing?
Every dedicated concert-goer has a mental map of the venue the moment they walk in … where the exits are, which sections have obstructed views, which bars have the shortest lines. That spatial awareness is not paranoia. It’s the kind of knowledge that comes from experience and pays off when you need it.
Plan sponsors need the same fluency with their threat landscape. The risks are not abstract, and they are not confined to large enterprises. They follow the data, and health plan data is extraordinarily valuable.
|
|
PHISHING + SOCIAL ENGINEERING Attackers impersonate HR staff, benefits administrators, and vendors to extract credentials or authorize fraudulent transactions. A convincing email, sometimes indistinguishable from the real thing, is often the only entry point needed. |
THIRD-PARTY + SUPPLY CHAIN ATTACKS Several breaches have shown this at scale: vulnerability in data transfer tools that cascaded across hundreds of benefit plans and millions of participants. Plan sponsors were never the direct target, but their participants paid the price. |
||
|
RANSOMWARE Attackers encrypt plan systems and demand payment for restoration. Benefits administration halts. Claims go unpaid. Participants lose access to care information. The plan sponsor then faces simultaneous operational crisis, regulatory inquiry, and potential litigation. |
CREDENTIAL THEFT + ACCOUNT TAKEOVER |
What makes health plan environments particularly complex is the number of entities handling participant data at any given time. A single mid-size employer plan might route data through a TPA, a pharmacy benefit manager, a specialty care network, an EAP provider, a wellness platform, and a participant-facing benefits portal. Each is a link in the chain. Each represents a potential point of failure and the fiduciary's responsibility runs through all of them.
The DOL has been explicit: plan fiduciaries cannot outsource their cybersecurity responsibility by outsourcing plan functions. Vendor oversight is a fiduciary obligation, not an administrative one.
WHEN A BREACH OCCURS
How Should a Health Plan Sponsor Handle a Breach?
Most venues post the fire exit signs and call it a day. But anyone who has actually been in a building when an alarm goes off, the real kind, not a drill, knows immediately how much it matters whether the staff knows what to do. The venues that handle it well have a protocol. Someone is already moving toward the exits before the second alarm sounds. The ones that handle it poorly are improvising in front of a crowd, hoping for the best.
A cybersecurity breach is that alarm. Plan sponsors who come through it well are not fortunate — they planned for it. Those without a response framework find themselves improvising in the worst possible conditions: participant data exposed, regulators asking pointed questions, and legal exposure mounting before containment is even achieved.
The First 72 Hours
1. Activate your incident response plan immediately.
If one does not exist, this moment is the most expensive lesson you will ever learn about why it should. Convene your response team (legal, IT, HR leadership, and ERISA counsel) without waiting for the full picture to emerge. The clock is already running.
2. Contain the breach and preserve the evidence.
Work with IT and vendor partners to isolate affected systems and stop ongoing data exfiltration. Resist the impulse to remediate before the forensic picture is complete. Evidence destroyed in cleanup cannot be recovered.
3. Determine what data was affected.
Which participant records? Which data types — claims data, Social Security numbers, banking information, health conditions? The scope of the breach determines every subsequent obligation and decision.
4. Notify the right parties within required timeframes.
HIPAA breach notification, applicable state data breach laws, and DOL notification may all be triggered depending on the breach's nature and scope. Participant notification carries its own timeline requirements. Missing these deadlines compounds both legal exposure and participant harm.
5. Document every decision and action in real time.
The response timeline, communications, containment steps, and remediation actions constitute the evidentiary record that EBSA investigators and plaintiffs' counsel will request. Treat documentation with the same urgency as containment.
|
TICKET STUB I once watched a band handle a complete PA failure mid-set: full silence, no monitors, no front-of-house sound. They kept playing acoustically, the crowd leaned in, and by the time the system came back online three songs later, the room was more engaged than before. The difference was that the band and the crew had clearly talked through contingencies. They did not need to look at each other… everyone already knew their role. That is what a tabletop breach exercise gives a plan sponsor: not a script, but a shared understanding of who does what when the system goes down. |
After Containment
Root cause analysis, vendor remediation, and participant communications are the sustained work that follows immediate response. How plan sponsors communicate after a breach, with clarity, promptness, and accountability, shapes both their legal posture and the trust of the participants who depend on them. Legalese and delay are not a communications strategy. Participants deserve to know what happened and what is being done about it.
PREVENTIVE ACTION
What Can Health Plan Sponsors Do Right Now?
There is a specific kind of concert experience I have chased for years: the show where nothing visibly goes wrong. Not because nothing could, it’s a live event, and live events are inherently precarious, but because every contingency has been thought through in advance. The monitor mix is dialed in before doors open. The cabling is taped and tested. The spare guitar is tuned and in reach. The result is a show that feels effortless, but only because the effort was front-loaded.
That is the goal for a cybersecurity program. The DOL has been clear that it is not expecting perfection, it is expecting prudence. EBSA investigators reviewing plan cybersecurity want to see that fiduciaries engaged experts, asked the right questions of vendors, understood where participant data flows, and took documented, reasonable steps to protect it. Here is what that looks like in practice:
- Establish a formal, written cybersecurity program. Policies should identify roles, responsibilities, and security standards, and be reviewed/updated at least annually. A program that exists only in institutional memory does not exist for fiduciary purposes.
- Conduct annual cybersecurity risk assessments. Identify vulnerabilities across plan systems, data flows, and vendor connections. Risks that are not named cannot be managed and the threat landscape shifts constantly.
- Vet service providers rigorously before signing and on an ongoing basis. Ask about their security standards, audit results, incident history, compliance with recognized frameworks (NIST, ISO 27001, SOC 2), and whether their cyber insurance covers your plan data specifically. The 2024 DOL guidance calls this out explicitly.
- Build cybersecurity requirements into vendor contracts. Service agreements should address data confidentiality, breach notification timelines, incident response protocols, and ongoing compliance monitoring. Generic contracts typically do not go far enough.
- Require multi-factor authentication (MFA) universally. Every system that touches plan data or participant accounts should require MFA. The 2024 EBSA guidance reinforced this as a baseline expectation — not an aspiration, but a floor.
- Commission annual third-party audits of security controls. Independent validation of cybersecurity practices, for both plan sponsor systems and key service providers, is something EBSA investigators will ask about. An outside auditor provides both assurance and documentation.
- Educate participants about their own account security. The DOL includes online security tips as one of its three guidance pillars. Participants who recognize phishing attempts and enable MFA on plan portals add a meaningful layer of defense to the overall security posture.
- Write and rehearse an incident response plan. A plan that has never been tested is almost as dangerous as no plan at all … it creates false confidence. Tabletop exercises involving plan sponsor personnel and key vendors surface gaps before an attacker does.
- Verify that your cyber insurance actually covers plan-related losses. Ask your insurer the same question the DOL now requires you to ask your vendors: does this policy cover losses involving participant health benefit plan data? If the answer is ambiguous, that gap needs to close before a claim arises.
FINAL NOTE
The Safety Briefing Is Not Optional
I will admit I am the person at concerts who actually reads the venue's safety card when they hand it out, who clocks the exit locations when I walk in, who pays attention to the fire marshal's instructions even when everyone else is already pushing toward the stage. Most of the time it feels unnecessary. But the one time it is not unnecessary, it is everything.
Health plan cybersecurity is the safety briefing that plan sponsors have been skipping. The DOL issued the guidance. EBSA clarified that it applies to health plans. The 2026 enforcement priorities put it at the top of the list. The exits are marked. The question is whether plan sponsors have read the card.
The sponsors who are in the best position are not necessarily the ones with the most sophisticated technology. They are the ones who have taken the time to understand where their participant data flows, who touches it, what their vendor contracts actually require, and what their team does when something goes wrong. That is the work. It is not glamorous. But it is exactly what ERISA's prudent expert standard has always asked for, applied to the risk environment that now exists.
The Bottom Line for Health Plan Sponsors
Cybersecurity is a named fiduciary duty — clarified for all ERISA plans by DOL guidance in 2021 and 2024, and now the top enforcement priority for EBSA in fiscal year 2026. Plan sponsors who treat it as an IT delegation rather than a governance responsibility expose both their participants and the organization to serious risk.
Start with where your participant data lives, who has access to it, and what your vendor agreements actually obligate those vendors to do. Document your process. Test your response plan. Verify your coverage. The rest builds from there — and the time to build it is before the alarm sounds, not after.
Kenneth Ralff, SVP, Client, Executive, Boston and Portland, Lockton Companies
LinkedIn: https://www.linkedin.com/in/kennethralff
Email: [email protected]
Sources & References
- DOL Compliance Assistance Release No. 2024-01 (Sept. 6, 2024)
- EBSA 2021 Cybersecurity Guidance (April 2021)
- EBSA National Enforcement Projects FY 2026 (Jan. 15, 2026)
- ERISA §404(a) Fiduciary Standards · HHS Health Industry Cybersecurity Practices (HICP) Guidance
- GAO Recommendation to EBSA on Cybersecurity as Fiduciary Obligation (Feb. 2021)

