Employers and other sponsors of health, welfare, 401(k), and other types of pension plans often rely on service providers to maintain plan records and keep participant data confidential and plan accounts secure. Plan sponsors should use service providers that follow strong cybersecurity practices.
To help employers and other plan sponsors and plan fiduciaries meet their responsibilities under ERISA to select and monitor such service providers prudently, we prepared the following tips for plan sponsors of all types and sizes of ERISA plans:
1. Ask about the service provider’s information security standards, practices and policies, and audit results, and compare them to the industry standards adopted by other financial/health institutions.
2. Ask the service provider how it validates its practices, and what levels of security standards it has met and implemented. Look for contract provisions that give you the right to review audit results demonstrating compliance with the standard.
3. Evaluate the service provider’s track record in the industry, including public information regarding information security incidents, other litigation, and legal proceedings related to the vendor’s services.
4. Ask whether the service provider has experienced past security breaches, what happened, and how the service provider responded.
5. Find out if the service provider has any insurance policies that would cover losses caused by cybersecurity and identity theft breaches (including breaches caused by internal threats, such as misconduct by the service provider’s employees or contractors, and breaches caused by external threats, such as a third party hijacking a plan participants’ account).
6. When you contract with a service provider, ensure that the contract requires ongoing compliance with cybersecurity and information security standards – and beware of contract provisions that limit the service provider’s responsibility for IT security breaches. Also, try to include terms in the contract that would enhance cybersecurity protection for the Plan and its participants, such as:
Want to learn more about Group Health Insurance and Employee Benefits? Speak to a TPG Administrative Service Organization specialist at 909.466.7876 today!
Also, learn how to Motivate Employees to Spend More Time on Open Enrollment and The Role of Weight Loss Drugs in the Rising 2025 Health Care Costs visit our blogs/resources page for the full breakdown!