Subscribe (Free) to
Daily or Weekly Newsletters
Post a Job

Featured Jobs

Temporary Document Specialist

BPAS
(Utica NY)

BPAS logo

Regional Vice President, Sales

MAP Retirement
(Remote)

MAP Retirement logo

Retirement Relationship Manager

MAP Retirement
(Remote)

MAP Retirement logo

Retirement Plan Consultant

Sentinel Group
(Remote / Everett MA)

Sentinel Group logo

DC Administrator

Pension Investors Corporation
(Remote / Altamonte Springs FL)

Pension Investors Corporation logo

Retirement Plan Administrator

Pattison Pension
(Albuquerque NM / Hybrid)

Pattison Pension logo

Plan Consultant - DB/CB

MAP Retirement
(Remote)

MAP Retirement logo

Strategic Retirement Plan Consultant

Retirement Plan Consultants
(Urbandale IA / Des Moines IA)

Retirement Plan Consultants logo

Retirement Plan Consultant

MAP Retirement
(Remote)

MAP Retirement logo

Data Administrator II

DWC - The 401(k) Experts
(Remote)

DWC - The 401(k) Experts logo

Plan Administrator, Defined Benefit & Cash Balance

The Pension Source
(Remote / Stuart FL / NY / TX / Hybrid)

The Pension Source logo

Defined Benefit Plan Consultant/Actuarial Analyst

Sentinel Group
(Remote / Everett MA)

Sentinel Group logo

View More Employee Benefits Jobs

Free Newsletters

“BenefitsLink continues to be the most valuable resource we have at the firm.”

-- An attorney subscriber

Mobile app icon
LinkedIn icon     Twitter icon     Facebook icon

105,475 Items Curated by BenefitsLink®

News Archive

All News > Cybersecurity

Get this news and more in our free daily email newsletters.

Tags: Cybersecurity  •  Retirement Plan Administration

Thompson Hine Link to more items from this source
[Guidance Overview]
Jan. 28, 2026

"[T]he Department plans to continue to devote many more resources to health and welfare plan enforcement. In particular, DOL highlights two projects for 2026: [1] barriers to mental health and substance use disorder benefits (MH/SUD), and [2] surprise billing.... DOL continues to pursue a variety of projects to protect the benefits of retirement plan participants.... [T]he Department for the first time included cybersecurity on the national enforcement project list."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Health Plan Design  •  Retirement Plan Administration

American Retirement Association [ARA] Link to more items from this source
Jan. 26, 2026

"Health plan sponsors can expect increased examination activity, particularly in mental health and surprise billing.... Cybersecurity has officially graduated from buzzword to enforcement priority -- and this priority applies to retirement plans.... Service-provider-level reviews of 3(21) and 3(38) fiduciaries.... Investment selection in 404(c) plans.... Underfunded defined benefit plans.... ESOPs and missing participants deprioritized."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Health Plan Administration  •  Retirement Plan Administration

Morgan Lewis Link to more items from this source
[Guidance Overview]
Jan. 21, 2026

"EBSA intends to prioritize investigations in the following health plan areas: [1] Cybersecurity and data protection ... [2] Mental health and substance use disorder parity ... [3] Surprise billing compliance ... [4] Protections of employee contributions ... EBSA reaffirmed its ongoing efforts to identify abusive or fraudulent Multiple Employer Welfare Arrangements (MEWAs)."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Health Plan Design  •  MHPAEA

Proskauer Link to more items from this source
[Guidance Overview]
Jan. 21, 2026

"EBSA stated that its investigations will continue to evaluate how plans and service providers protect against cybersecurity threats.... [T]he Mental Health Parity and Addiction Equity Act and its 2013 regulations, as well as the Consolidated Appropriations Act, 2021, remain ... an enforcement priority.... EBSA will be focusing enforcement efforts on the implementation of the No Surprises Act ... EBSA will be reviewing pension plan practices to notify participants who are approaching normal retirement age and required minimum distribution age[.]"  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Health Plan Administration  •  MHPAEA  •  Retirement Plan Administration

Baker Donelson Link to more items from this source
[Guidance Overview]
Jan. 14, 2026

"[OCR's] January 2026 Cybersecurity Newsletter ... reinforces OCR's continued expectation that HIPAA covered entities and business associates proactively reduce cybersecurity risks to electronic protected health information (ePHI) through ongoing technical and operational safeguards.... Privacy and security officers should also consider these recommendations as a baseline for risk management responsibilities and consider integrating the safeguards into internal auditing programs."  MORE >>

Tags: Cybersecurity  •  HIPAA

Tags: Cybersecurity  •  Retirement Plan Administration

Ogletree Deakins Link to more items from this source
[Guidance Overview]
Dec. 1, 2025

"[T]he New York State Department of Financial Services (NYDFS) issued an industry letter ... which clarifies covered entities' responsibilities when engaging third‑party service providers (TPSPs) that access information systems or nonpublic information (NPI). Although the guidance does not add new rules to the NYDFS Cybersecurity Regulations, it clarifies regulatory requirements with respect to TPSPs, provides suggestions for best practices, and may signal increased regulatory focus on third-party risk management."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

RPAG Link to more items from this source
Nov. 18, 2025

"[M]ore than half of plan sponsors rank cybersecurity as their No. 1 'plan fear,' ahead of poor investment performance (45%) and insufficient participant savings (43%).... High profile breaches, such as the recent attack on a leading recordkeeper affecting more than 1,000 participants and traced to a third-party client management cloud application, demonstrate how a single weak point can compromise participant data and disrupt operations."  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

American Retirement Association [ARA] Link to more items from this source
Nov. 13, 2025

"A professional uniquely positioned to discuss cybersecurity in the context of retirement plans offers her insights on the nuances and hard realities of protecting assets, balances, sensitive information and more from unauthorized access.... She observed that 73% of the organizations that experience a breach of security experience a second one. And this, she said, 'is because they didn't identify the cause and didn't fix it.' "  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

The Rosenbaum Law Firm P.C. Link to more items from this source
[Opinion]
Nov. 11, 2025

"ERISA’s Section 404 talks about acting prudently and solely in the interest of participants. That used to mean watching fees, monitoring investments, and keeping minutes. But in 2025, prudence means locking down your participant data like it’s Fort Knox. Every Social Security number, every date of birth, every account balance—those are plan assets in digital form."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties

EPIC Link to more items from this source
Nov. 11, 2025

"Recent guidance from both the [DOL] and the New York State Department of Financial Services (DFS) underscores the importance of due diligence and ongoing oversight of ... third-party administrators (TPAs), carriers, and technology platforms ... Outsourcing the administration does not absolve you of your fiduciary duty.... Here's a checklist to guide your due diligence related to cybersecurity."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Health Plan Administration

The Rosenbaum Law Firm P.C. Link to more items from this source
Oct. 9, 2025

"[1] Cybersecurity is a fiduciary issue.... [2] Vet and tighten your vendor contracts now.... [3] Look for documentation, not just policies ... [4] Train your people, and document that training.... [5] Check your insurance, and insist on cyber coverage.... [6] Bring cybersecurity into your plan oversight meetings.... Cybersecurity isn't just an IT problem, it's an ERISA oversight issue. "  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Tags: Cybersecurity  •  Retirement Plan Administration

Golan Christie Taglia Link to more items from this source
Aug. 29, 2025

"Cyber-attacks on Section 401(k) plans and their participant accounts are not only increasing in number but, with the use of AI, they are increasing in sophistication. Plan fiduciaries ... need to take steps to protect plan assets from these risks by implementing appropriate cybersecurity measures. All employees (not just HR staff) need to be aware of cybersecurity risks because those risks cannot be managed solely by IT security protocols such as secure messaging and multi-factor authentication."  MORE >>

Tags: 401(k) Plans  •  Cybersecurity  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
[Guidance Overview]
Aug. 20, 2025

"In its ongoing efforts to bolster cybersecurity in ERISA-covered plans, the [DOL] has issued multiple layers of guidance, one of which is a set of Online Security Tips.... These tips aren't directed at plan sponsors or fiduciaries, but the DOL, including them in the broader cybersecurity release, implies a clear expectation: you should inform your participants."  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

Health Affairs Scholar Link to more items from this source
[Opinion]
Aug. 18, 2025

"Over the past decade, the electronic health record (EHR) market has become increasingly consolidated, with the majority of care delivery organizations now using one of two vendors ... This consolidation creates a 'single-point-of-failure' tail risk for cybersecurity ... Given that reversing consolidation is unlikely due to high EHR switching costs, it is critical that policymakers establish safeguards that ensure robust protections for patients' sensitive data.... Sustained investment in regulatory oversight and continued partnerships between policymakers, care delivery organizations, and EHR vendors are essential to contain the catastrophic risk involved from this ongoing market consolidation."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration

PLANSPONSOR; registration may be required Link to more items from this source
July 29, 2025

"Personal data belonging to most of Allianz Life Insurance Co. of North America's 1.4 million U.S. customers was exposed on July 16 ... The breach was discovered one day after a 'malicious threat actor' hacked into a third-party customer relationship management system used by the insurer ... An attorney for Allianz submitted a disclosure of the breach to the office of the Maine attorney general."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Retirement Plan Administration

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Schechter Benefits Law Group LLP Link to more items from this source
June 24, 2025

"As a plan sponsor, taking steps to secure your plan data isn't optional, it's part of your legal duty to act in your participants' best interests.... [1] Review your vendor contracts for cybersecurity language. [2] Request and review audit reports from your service providers. [3] Implement basic security practices for your internal team. [4] Educate your participants about protecting their accounts. [5] Document your efforts as part of fiduciary oversight."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
June 18, 2025

"[1] Establish a formal cybersecurity program ... [2] Conduct annual risk assessments ... [3] Require independent third-party audits ... [4] Define security roles and implement strong access controls ... [5] Ensure secure management of cloud services and vendors ... [6] Implement secure development practices and business resiliency programs ... [7] Encrypt sensitive data and maintain strong technical controls ... [8] Prepare for and respond to cybersecurity incidents."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
June 13, 2025

"Begin by asking providers about their cybersecurity policies and practices. Their protocols should align with standards like NIST or ISO/IEC 27001.... Explore the provider's history of handling security incidents. Transparency is key -- ask how they've responded to breaches in the past, and check for any related legal or regulatory issues.... Strong contracts reinforce good cybersecurity."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

National Conference on Public Employee Retirement Systems [NCPERS] Link to more items from this source
June 10, 2025

"[1] Review daily, weekly, or monthly reports from the vendor's cybersecurity monitoring tools ... [2] Audit the vendor site and perform your own cybersecurity review and/or assessment. [3] Ask the vendor to provide annual copies of approved and objective third-party cybersecurity assessments. [4] Contract with your own cybersecurity experts to do penetration testing against your vendor (with your vendor's knowledge that the tests are occurring, of course)."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Nixon Peabody LLP Link to more items from this source
June 4, 2025

"Ransomware attacks on healthcare organizations surged in 2024, with nearly 400 US providers reporting incidents.... [H]ealthcare breaches now average $9.77 million -- the highest across all industries for the 14th year. [HHS] also noted a sharp rise in ransomware cases, driven by outdated systems, misconfigured devices, and cloud vulnerabilities.... This article outlines key strategies for healthcare organizations to prevent, respond to, and recover from ransomware incidents -- while minimizing legal exposure and reputational harm."  MORE >>

Tags: Cybersecurity  •  HIPAA

Defined Contribution Institutional Investment Association [DCIIA] Link to more items from this source
May 30, 2025

"This paper seeks to help plan sponsors understand today's rapidly changing data risk environment. [The authors] discuss how participant accounts are vulnerable to data breaches, highlight updated regulatory guidance, and offer action steps for plan committee consideration, in partnership with the plan's overall organization, consultant/advisor and counsel as needed.' [Also available: 'Take Action" Checklist]  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration