The answer to the question about how are people handling address changes will vary from plan to plan, recordkeeper to recordkeeper, TPA to TPA...
Addresses should be treated a Personally Identifiable Information (PII) and subject to the same data security methods applicable to of PII. At a high level, there should be a clear policy for managing PII shared across all partied involved in plan administration, and a clear delineation of steps each party will take for handling PII, and a clear assignment of accountability for any breaches that expose PII. If the plan is audited, how PII is managed should be part of an independent auditor's review of privacy and cybersecurity practices.
With respect to addresses it, handling address changes for participants who have long since been terminated from employment with the plan sponsor are the most challenging. In this instance, the recordkeeper is more likely to have more recent interaction with the participant than the former employer. This suggests that an approach like @RatherBeGolfing described is appropriate to protect the plan.