---
title: Cybersecurity and ERISA
description: Learn about the Department of Labor's updated 2024 cybersecurity guidelines for ERISA plans and their impact on plan sponsors’ fiduciary duties.
image: https://1652561.fs1.hubspotusercontent-na1.net/hubfs/1652561/Cybersecurity%20and%20ERISA%20Adobe%20Stock.jpeg
---

[![Novaura](https://novaurains.com/hs-fs/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png?width=250&height=39&name=01819-Novaura-Logo-NoTag-CC.png "Novaura")](https://novaurains.com)

- [Home](https://novaurains.com)
- Services 
    - [Benefits & HR](https://novaurains.com/services)
    - [Case Study: Increased participation by 30%](https://novaurains.com/case-study-rebuilding-trust-in-ancillary-benefits-novaura)
    - [Case Study: Avoiding 120% Rate Increase](https://novaurains.com/case-study-employer-saves-over-221000-in-benefits-spend-novaura)
- About 
    - [About us](https://novaurains.com/about-us)
    - [Our journey to Novaura](https://novaurains.com/our-journey-to-novaura)
- Resources 
    - [Blog](https://novaurains.com/blog)
    - [Guide: Self-funding 101](https://novaurains.com/self-funding-101-a-beginners-guide)
- [Contact](https://novaurains.com/contact)

[![](https://novaurains.com/hs-fs/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png?width=200&height=31&name=01819-Novaura-Logo-NoTag-CC.png)](https://novaurains.com)

<https://novaurains.com/blog/cybersecurity-and-erisa#growfast-header__mobile-nav__mmenu>

[![01819-Novaura-Logo-NoTag-CC](https://novaurains.com/hs-fs/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png?width=300&height=47&name=01819-Novaura-Logo-NoTag-CC.png "01819-Novaura-Logo-NoTag-CC")](https://novaurains.com)

- [Home](https://novaurains.com)
- Services 
    - [Benefits & HR](https://novaurains.com/services)
    - [Case Study: Increased participation by 30%](https://novaurains.com/case-study-rebuilding-trust-in-ancillary-benefits-novaura)
    - [Case Study: Avoiding 120% Rate Increase](https://novaurains.com/case-study-employer-saves-over-221000-in-benefits-spend-novaura)
- About 
    - [About us](https://novaurains.com/about-us)
    - [Our journey to Novaura](https://novaurains.com/our-journey-to-novaura)
- Resources 
    - [Blog](https://novaurains.com/blog)
    - [Guide: Self-funding 101](https://novaurains.com/self-funding-101-a-beginners-guide)
- [Contact](https://novaurains.com/contact)

[![](https://novaurains.com/hs-fs/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png?width=200&height=31&name=01819-Novaura-Logo-NoTag-CC.png)](https://novaurains.com)

<https://novaurains.com/blog/cybersecurity-and-erisa#growfast-header__mobile-nav__mmenu>

- [Home](https://novaurains.com)
- Services 
    - [Benefits & HR](https://novaurains.com/services)
    - [Case Study: Increased participation by 30%](https://novaurains.com/case-study-rebuilding-trust-in-ancillary-benefits-novaura)
    - [Case Study: Avoiding 120% Rate Increase](https://novaurains.com/case-study-employer-saves-over-221000-in-benefits-spend-novaura)
- About 
    - [About us](https://novaurains.com/about-us)
    - [Our journey to Novaura](https://novaurains.com/our-journey-to-novaura)
- Resources 
    - [Blog](https://novaurains.com/blog)
    - [Guide: Self-funding 101](https://novaurains.com/self-funding-101-a-beginners-guide)
- [Contact](https://novaurains.com/contact)

# Cybersecurity and ERISA

 2 Minutes Read

[![MZQ Logo](https://1652561.fs1.hubspotusercontent-na1.net/hub/1652561/hubfs/MZQ_logo_2019_FINAL-01%20copy%202.jpg?width=254&height=130&name=MZQ_logo_2019_FINAL-01%20copy%202.jpg)](https://www.mzqconsulting.com/)

*Prefer to listen instead of read? No problem! [Listen to the blog post at any time by clicking here](https://1652561.fs1.hubspotusercontent-na1.net/hubfs/1652561/Cybersecurity%20and%20ERISA%20Blog%20Narration.mp3).*

---

 

On September 6th, 2024, the Department of Labor (DOL) issued a press release reminding ERISA plan fiduciaries that it considers cybersecurity to be an area of “great concern.” Due to a rash of cybersecurity incidents, the DOL has increased its investigations of violations in this area. The DOL also published [updated cybersecurity guidance](https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/compliance-assistance-release-2024-01) that builds on documents the Department released in 2021. Most importantly, these new publications clarify that the DOL’s cybersecurity guidelines apply to all types of ERISA plans, including health and welfare plans.

### Overview of 2021 DOL Cybersecurity guidance 

The guidance the DOL released in 2021 consists of three documents: 

- *Cybersecurity Program Best Practices*, which includes a detailed set of twelve best practices that organizations should adopt to mitigate cybersecurity risks; 
- *Tips for Hiring a Service Provider with Strong Cybersecurity Practices*, which offers six tips to help organizations select service providers with strong cybersecurity practices; and 
- *Online Security Tips*, which lists nine online security tips to help individuals protect their accounts against fraud and loss. 

### Clarification and notable enhancements in 2024 guidance 

Some service providers interpreted that this guidance only applied to retirement plans, prompting the DOL to affirm in the 2024 iteration of their guidance that the cybersecurity recommendations apply to all plans subject to ERISA. Aside from new language to this effect, the 2024 versions of the documents listed above remain largely the same. One notable enhancement is the inclusion of additional language specifying that plan sponsors should ensure their vendors’ insurance covers cybersecurity breaches and incidents involving the plan. The updated guidance now also reflects specific multifactor authentication process recommendations, a participant notification requirement if a cybersecurity breach occurs, and a list of additional cybersecurity resources. 

Given the DOL’s clarification that their cybersecurity guidelines apply to all plans subject to ERISA *and* that they find this topic to be of great concern, we would encourage employers as plan sponsors to audit their existing cybersecurity protocols for any plan data that is stored or accessed internally against these updated requirements and recommendations and to take reasonable steps to address any gaps. In addition, the employer should confirm that their vendors/service providers are separately implementing these requirements for any plan data they handle. Doing so will help employers fulfill their fiduciary duties towards participants, highlight potential areas of improvement, and reaffirm which of their cybersecurity practices are already in alignment with DOL guidance. 

### HIPAA's role in cybersecurity compliance 

Of note, while HIPAA privacy and security compliance efforts for group health plans may not address all ERISA plans sponsored by an employer, they will provide a meaningful framework to apply to any plans that fall outside HIPAA’s scope. Employers that have not yet addressed HIPAA’s privacy and security requirements, including developing written policies and procedures and conducting a HIPAA security risk analysis, may want to prioritize this in light of the updated cybersecurity guidance. 

 

*© 2024 MZQ Consulting, LLC. All rights reserved.*

*Content provided to [Q4intelligence](https://www.q4intel.com) members by MZQ Consulting, LLC*

Photo by [K Seisa](https://stock.adobe.com/contributor/210716081/k-seisa-peopleimages-com?load_type=author&prev_url=detail) 

[Next post](https://novaurains.com/blog/compliance-corner-webinar-the-top-10-compliance-topics-you-must-know-or-do-for-2025)

[All posts](https://novaurains.com/blog)

[Previous post](https://novaurains.com/blog/how-balance-and-kindness-lead-to-lasting-inclusion)

## Recommended For You

[![](https://1652561.fs1.hubspotusercontent-na1.net/hubfs/1652561/146740172_m_normal_none.jpeg)](https://novaurains.com/blog/aca-affordability-percentage-remains-below-9-5-for-2025)

 2 Min Read

#### [ACA Affordability Percentage Remains Below 9.5% for 2025](https://novaurains.com/blog/aca-affordability-percentage-remains-below-9-5-for-2025)

<https://novaurains.com/blog/author/novaura>

[![](https://q4intel.com/hubfs/One%20Big%20Beautiful%20Bill%20Act%20%28OBBBA%29%20123rf.jpg)](https://novaurains.com/blog/one-big-beautiful-bill-act-obbba)

 3 Min Read

#### [One Big Beautiful Bill Act (OBBBA)](https://novaurains.com/blog/one-big-beautiful-bill-act-obbba)

<https://novaurains.com/blog/author/novaura>

[![](https://1652561.fs1.hubspotusercontent-na1.net/hubfs/1652561/185708248_m_normal_none.jpg)](https://novaurains.com/blog/final-rules-issued-on-employer-sponsored-indemnity-insurance)

 2 Min Read

#### [Final Rules Issued on Employer-Sponsored Indemnity Insurance](https://novaurains.com/blog/final-rules-issued-on-employer-sponsored-indemnity-insurance)

<https://novaurains.com/blog/author/novaura>

![](https://novaurains.com/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-WH.png)

Novaura builds stronger businesses by giving you solutions that go above and beyond the usual numbers and quotes. With our solutions-based benefits approach, you'll be able to invest in your employees and meet everyone’s needs—and then some.

[Follow us on Facebook](https://www.facebook.com/NovauraIns/) [Follow us on LinkedIn](https://www.linkedin.com/company/novaura)

- RESOURCES: 
    - [Read the Blog](https://novaurains.com/blog)
    - [Effective Onboarding Checklist](https://novaurains.com/effective-onboarding-checklist)
    - [Guide: Self-Funding 101](https://novaurains.com/self-funding-101-a-beginners-guide)
    - [Case Study: Increased participation by 30%](https://novaurains.com/case-study-rebuilding-trust-in-ancillary-benefits-novaura)
    - [Case Study: Avoiding 120% rate increase](https://novaurains.com/case-study-employer-saves-over-221000-in-benefits-spend-novaura)

**GET IN TOUCH:**

###### Novaura 718 S. 17th St. Temple, TX 76504 Phone: (254) 791-8221

Copyright © 2025 Novaura

[Privacy Policy](https://novaurains.com/privacy-policy)  | Designed by [Q4intelligence ](http://q4intel.com)

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://novaurains.com/blog/cybersecurity-and-erisa/#article",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Novaura"
  },
  "dateModified" : "2025-09-05T16:47:45Z",
  "datePublished" : "2024-10-31T10:53:13Z",
  "description" : "Learn about the Department of Labor's updated 2024 cybersecurity guidelines for ERISA plans and their impact on plan sponsors&rsquo; fiduciary duties.",
  "headline" : "Cybersecurity and ERISA",
  "image" : {
    "@type" : "ImageObject",
    "height" : "4268",
    "url" : "https://1652561.fs1.hubspotusercontent-na1.net/hubfs/1652561/Cybersecurity%20and%20ERISA%20Adobe%20Stock.jpeg",
    "width" : "6403"
  },
  "inLanguage" : "en",
  "isPartOf" : {
    "@id" : "https://novaurains.com/blog/#blog",
    "@type" : "Blog",
    "name" : "Blog",
    "publisher" : {
      "@id" : "https://novaurains.com/#organization"
    }
  },
  "mainEntityOfPage" : {
    "@id" : "https://novaurains.com/blog/cybersecurity-and-erisa/#webpage"
  },
  "publisher" : {
    "@id" : "https://novaurains.com/#organization"
  },
  "url" : "https://novaurains.com/blog/cybersecurity-and-erisa"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://novaurains.com/blog/cybersecurity-and-erisa/#breadcrumb",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://novaurains.com",
    "name" : "Home",
    "position" : 1
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://novaurains.com/#organization",
  "@type" : "InsuranceAgency",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "US",
    "addressLocality" : "Temple",
    "addressRegion" : "TX",
    "postalCode" : "76504",
    "streetAddress" : "718 S. 17th St."
  },
  "alternateName" : "Texas Benefit Alliance",
  "areaServed" : [ {
    "@type" : "State",
    "name" : "Texas"
  }, {
    "@type" : "City",
    "name" : "Dallas"
  }, {
    "@type" : "City",
    "name" : "Austin"
  } ],
  "contactPoint" : {
    "@type" : "ContactPoint",
    "areaServed" : "US",
    "availableLanguage" : "English",
    "contactType" : "customer service",
    "telephone" : "+1-254-791-8221"
  },
  "description" : "Novaura is an employee benefits and insurance agency based in Temple, Texas, serving businesses throughout the Dallas and Austin area. Formerly Texas Benefit Alliance, the agency helps companies design and manage group health insurance, self-funded health plans, and ancillary benefits while controlling healthcare spend and simplifying HR administration and compliance. Through a consultative, five-step process—analyze, identify, establish, implement, and review—Novaura builds people-first benefits programs that drive employee engagement, retention, and work/life balance.",
  "employee" : [ {
    "@id" : "https://novaurains.com/#person-tim-davis",
    "@type" : "Person",
    "jobTitle" : "President, Agency Principal",
    "name" : "Tim Davis",
    "sameAs" : "https://www.linkedin.com/in/timothy-davis-9879012b/",
    "worksFor" : {
      "@id" : "https://novaurains.com/#organization"
    }
  }, {
    "@id" : "https://novaurains.com/#person-luke-davis",
    "@type" : "Person",
    "jobTitle" : "Benefits Strategist",
    "name" : "Luke Davis",
    "sameAs" : "https://www.linkedin.com/in/luke-davis513/",
    "worksFor" : {
      "@id" : "https://novaurains.com/#organization"
    }
  } ],
  "image" : {
    "@id" : "https://novaurains.com/#logo"
  },
  "knowsAbout" : [ "Employee benefits", "Group health insurance", "Self-funded health plans", "Benefits strategy and consulting", "HR administration", "Employee benefits compliance", "Employee retention and engagement", "Ancillary benefits" ],
  "logo" : {
    "@id" : "https://novaurains.com/#logo"
  },
  "name" : "Novaura",
  "sameAs" : [ "https://www.facebook.com/NovauraIns/", "https://www.linkedin.com/company/novaura/" ],
  "telephone" : "+1-254-791-8221",
  "url" : "https://novaurains.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://novaurains.com/#website",
  "@type" : "WebSite",
  "inLanguage" : "en-US",
  "name" : "Novaura",
  "publisher" : {
    "@id" : "https://novaurains.com/#organization"
  },
  "url" : "https://novaurains.com"
}
```

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://novaurains.com/#logo",
  "@type" : "ImageObject",
  "caption" : "Novaura",
  "contentUrl" : "https://novaurains.com/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png",
  "url" : "https://novaurains.com/hubfs/Novaura%20Logos/01819-Novaura-Logo-NoTag-CC.png"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Organization",
    "name" : "Q4intelligence, LLC"
  },
  "datePublished" : "2024-10-31T10:00:00+00:00",
  "headline" : "Cybersecurity and ERISA",
  "mainEntityOfPage" : {
    "@id" : "https://insights.q4intel.com/employers/cybersecurity-and-erisa",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "name" : "Q4intelligence, LLC",
    "url" : "https://www.q4intel.com"
  }
}
```