The Department of Labor (DOL) has updated its 2021 package of guidance designed to help ERISA plan sponsors and service providers reduce cybersecurity risks.
The guidance applies to ERISA-covered health and welfare plans in addition to retirement plans. ERISA-covered health and welfare plans include medical, dental and vision plans as well as plans that provide life and accidental death and dismemberment insurance, long-term disability benefits, business travel insurance, certain employee assistance programs and wellness programs, most health flexible spending arrangements, health reimbursement arrangements and other benefit plans covered by ERISA.
As outlined in a recent news release, the latest Compliance Assistance Release continues to provide tips and best practices in cybersecurity for plan sponsors, plan fiduciaries, recordkeepers and plan participants, including:
The DOL did not make many substantive changes to the 2021 guidance, although the latest guidance:
This guidance is “sub-regulatory,” meaning the DOL generally may not treat a party’s noncompliance with it as a violation of law but, rather, must still prove that a violation of an applicable legal standard has occurred. [1]