Featured Jobs

Regional Vice President Sales - Southeast

The Retirement Plan Company (Remote / AL / FL / GA / MS)

The Retirement Plan Company logo

Retirement Plan Administrator

Aegis Retirement Partners (Remote)

Aegis Retirement Partners logo

401k & Defined Contribution Plan Consultant

Planned Retirement Consultant & Administrators, LLC (Remote / Ridgewood NJ)

Planned Retirement Consultant & Administrators, LLC logo

Defined Contribution Account Manager

Nova 401(k) Associates (Remote)

Nova 401(k) Associates logo

Retirement Plan Service Representative

DeMars Pension Consulting Services, Inc. (Overland Park KS / MO)

Senior Defined Contribution Account Manager

Nova 401(k) Associates (Remote)

Nova 401(k) Associates logo

Free Newsletters

“BenefitsLink continues to be the most valuable resource we have at the firm.”

-- An attorney subscriber

Mobile app icon
LinkedIn icon Twitter icon Facebook icon

Search 97,805 News Items Curated by BenefitsLink ®

News

All News  > Cybersecurity

Get this news and more in our free daily email newsletters .
What ERISA Health Plan Fiduciaries Need to Know in the Wake of the Change Healthcare Cyberattack
Jenny Kiesewetter, via LinkedIn Link to more items from this source
May 16, 2024

"Initially geared towards ERISA-governed retirement plans, the DOL has subsequently stated that its 2021 cybersecurity best practices also apply to ERISA-governed group health plans.... [T]he DOL lists 12 best practices to help ERISA plan fiduciaries to mitigate cybersecurity risks: ... [E]mployers are encouraged to consider adopting these best practices to help withstand any DOL scrutiny related to cybersecurity."

Tags: Cybersecurity   •   Fiduciary Duties   •   Health Plan Administration

Cybersecurity Will Be Part of All DOL Retirement Plan Audits: What Plan Sponsors Must Do to Pass
American Retirement Association [ARA] Link to more items from this source
May 13, 2024

"[T]he assumption some sponsors make that their plan uses Well-Known Vendor X, and so they can simply trust that this large vendor must maintain strong cybersecurity protections, is faulty ... A plan fiduciary still has to ... do their due diligence, document that they've done their due diligence, and make prudent decisions.' "

Tags: Cybersecurity   •   Retirement Plan Administration

Data Breach Victim Files Class-Action Suit Against J.P. Morgan Chase
Pensions & Investments Link to more items from this source
May 7, 2024

"[An] employee of a J.P. Morgan client whose retirement account J.P. Morgan administered, claims that his and other victims' sensitive information was targeted, compromised and unlawfully accessed due to the data breach that occurred in August of 2021.... [The plaintiff] also claims that cyber thieves have already engaged in identity theft and fraud and can in the future commit a variety of crimes, including opening new financial accounts and taking out loans in victims' names, filing fraudulent tax returns and giving false information to police during an arrest." [Valentine v. J.P. Morgan Chase & Co., No. 24-3438 (S.D.N.Y. complaint filed May 3, 2024)]

Tags: Cybersecurity

Cyber Resilience After the Change Healthcare Breach
Fenwick & West LLP Link to more items from this source
May 6, 2024

"In the aftermath of the Change Healthcare breach, healthcare entities should heed cybersecurity recommendations from regulatory bodies to prevent future attacks and mitigate post-attack enforcement actions.... Not only will alignment with agency recommendations prevent or deter future attacks, but it could likely mitigate the severity of enforcement actions imposed by such agencies in the aftermath of an attack."

Tags: Cybersecurity   •   Health Plan Administration

How Should a Plan Sponsor Respond to a Data Breach?
PLANSPONSOR; free registration may be required Link to more items from this source
May 3, 2024

"[B]efore an incident even occurs, plan sponsors should speak with their vendors about having an incident response plan, which is typically a written document, formally approved by an organization's senior leadership team, that helps the organization mitigate risk before, during and after a security incident.... Once the problem is contained and steps have been taken to mitigate the breach, a sponsor needs to have a plan for how the organization will communicate the issue with its participant base."

Tags: Cybersecurity   •   Retirement Plan Administration

AHIP Letter to OCR on Cyber Breach Notification Obligations Following Change Healthcare Incident (PDF)
America's Health Insurance Plans [AHIP] Link to more items from this source
[Opinion]
May 3, 2024

"At [the May 1 hearing ] held by the House Energy & Commerce Committee, United CEO Andrew Witty said, 'we are offering to take full responsibility for all notification obligations for everyone involved in this.' [AHIP supports] this approach and agree that guidance from the Office of Civil Rights should clearly state that only Change has an obligation to perform breach notification in this context. That clarity would avoid tens of millions of Americans being left confused, frustrated and inundated by multiple notifications."

Tags: Cybersecurity   •   HIPAA

Preventing the Next Big Cyberattack on U.S. Health Care
Harvard Business Review; purchase required for full article Link to more items from this source
May 2, 2024

"The cyberattack on Change Healthcare that devastated the U.S. health care sector made painfully clear that much more needs to be done to address vulnerabilities that exist throughout the ecosystem. This article offers five actions that can go a long way to improving cybersecurity throughout the sector and make it much more resilient."

Tags: Cybersecurity   •   Health Plan Administration   •   Health Plan Design

UnitedHealth's CEO Slammed in Senate Hearing About Cyberattack
The New York Times; subscription may be required Link to more items from this source
May 2, 2024

"In a tense Senate hearing  ... lawmakers sharply criticized UnitedHealth Group's handling of the cyberattack that paralyzed the U.S. health care system ... [S]enators questioned whether the cyberattack of Change Healthcare, which manages a third of all U.S. patient records and some 15 billion transactions a year, was so vast because UnitedHealth is too deeply embedded in nearly every aspect of the nation's medical care.... In the afternoon, House lawmakers outlined their concerns, especially given the corporation's enormous scale."

Tags: Cybersecurity   •   HIPAA   •   Health Plan Administration

HHS FAQs Address Change Healthcare Cybersecurity Incident (PDF)
Thomson Reuters / EBIA Link to more items from this source
[Guidance Overview]
May 2, 2024

"The FAQs specifically point to OCR's ransomware guidance, which has information on actions for regulated entities to take to determine if a ransomware incident is a breach (which is a fact-specific determination). OCR highlights that if covered entities are aware of a potential breach by a business associate, there is an obligation to proactively investigate whether a breach occurred, and report the breach to HHS, impacted individuals, and in certain cases, the media."

Tags: Cybersecurity   •   HIPAA

Breach at J.P. Morgan Exposes Data of 451,000 Plan Participants
planadviser Link to more items from this source
May 1, 2024

"The participant information that was exposed included participants' names, addresses, Social Security numbers, payment and deduction amounts, as well as bank routing and account numbers if the participants had set up direct deposit.... [On] February 26, the firm learned of a software issue that caused certain reports run by three authorized system users to include plan participant information that they were not entitled to see."

Tags: Cybersecurity

Change Healthcare Cyberattack: HHS OCR Publishes Early Guidance on Breach
Ropes & Gray LLP Link to more items from this source
May 1, 2024

"Covered entities and business associates should carefully review [OCR's] FAQ webpage , in conjunction with all UHG/Change statements, and consider taking the following steps: [1] Contact Change/UHG about notifications and compromised data.... [2] Prepare to evaluate whether patients are impacted.... [3] Review BAAs with Change.... [4] Conduct a dark web investigation.... [5] Continue to monitor relevant sites for updates."

Tags: Cybersecurity   •   HIPAA

Managing the Impacts of the Change Healthcare Cyberattack
Nelson Mullins Link to more items from this source
Apr. 26, 2024

"UnitedHealth Group (UHC) announced on April 22, 2024, that it had paid a ransom to protect patient data potentially acquired in a late February cyberattack on its subsidiary Change Healthcare.... UHC has not officially notified affected health plans and their participants that a breach had occurred.... UHC reported that it has found files containing protected health information (PHI) or personally identifiable information (PII), which could cover a substantial portion of people in America.... To mitigate any harm resulting from the CHC breach, [the authors] recommend that ERISA-regulated plans which may be impacted by the breach inform their plan participants of the CHC event."

Tags: Cybersecurity   •   HIPAA

CMS FAQs about Change Healthcare Cybersecurity Incident
U.S. Department of Health and Human Services [HHS] Link to more items from this source
[Guidance Overview]
Apr. 22, 2024

"Why is OCR initiating an investigation now and what does it cover? ... Has OCR received breach reports from Change Healthcare, UHG, or any affected health care entities? A: No ... Is OCR's 2016 ransomware guidance applicable to the Change Healthcare cyberattack? A: Yes ... Are covered entities that are affected by the cyberattack involving Change Healthcare and UHG required to file breach notifications? A: Yes ... What HIPAA breach notification duties do covered entities have with respect to the Change Healthcare cyberattack? ... What HIPAA breach notification duties do business associates have with respect to the Change Healthcare cyberattack?"

Tags: Cybersecurity   •   HIPAA   •   Health Plan Administration

House Hearing on Change Healthcare Hack: Providers Testify, but UnitedHealth a No-Show
BenefitsPro; free registration required Link to more items from this source
Apr. 19, 2024

"Witnesses shared stories of interrupted cash flows, high-interest loans, substantial administrative burdens, fragmented care coordination and resulting confusion for patients in testimony before the House Energy and Commerce Committee's Subcommittee on Health.... UnitedHealth Group, the parent company of Change Healthcare, was invited to participate in the session but did not attend. "

Tags: Cybersecurity   •   Health Plan Administration

Change Healthcare Stolen Patient Data Leaked by Ransomware Gang
TechCrunch Link to more items from this source
Apr. 16, 2024

"[A] new ransomware and extortion gang that calls itself RansomHub published several files on its dark web leak site containing personal information about patients across different documents, including billing files, insurance records and medical information. Some of the files ... also contain contracts and agreements between Change Healthcare and its partners."

Tags: Cybersecurity   •   Health Plan Administration

House Committee Leaders Request Information from UnitedHealth Group about Change Healthcare Cyberattack (PDF)
Energy & Commerce Committee, U.S. House of Representatives Link to more items from this source
Apr. 16, 2024

"The health care system is rapidly consolidating at virtually every level, creating fewer redundancies and more vulnerability to the entire system if an entity with significant market share at any level of the system is compromised. It is important for policymakers to understand the events leading up to, during, and after the Change Healthcare cyberattack. In order to understand better the steps UnitedHealth has taken to address this situation, we request information about the impact of the cyberattack, the actions the company is taking to secure its systems, and the outreach to the health care community in the aftermath."

Tags: Cybersecurity   •   Health Plan Administration

Retirement Plan Access and Fraud Prevention Considerations
Spectrum Consultants Link to more items from this source
Apr. 11, 2024

"Plan participants need to take common sense measures to safeguard their accounts. Plan sponsors now face the dual challenge of providing online access to participants' retirement plans while keeping their information secure. Implementing and maintaining a proactive cybersecurity strategy is key for both parties."

Tags: Cybersecurity   •   Retirement Plan Administration

Cybersecurity Best Practices for Employers in the Wake of the Change Healthcare Attack
Burnham Benefits Link to more items from this source
Apr. 11, 2024

"As a group health plan sponsor, an employer's responsive obligations arising in the context of certain cybercrime events depends largely upon the underlying funding status of the employer's core employee benefit plans ... Additional privacy and security related obligations for the employer may be detailed in various state-level statutory mandates or even within certain international laws or other global-scope regulations.... Several notifications may be required as a consequence of a data breach.... Communication with employees is important[.]"

Tags: Cybersecurity   •   HIPAA

Plaintiffs Request Court Approval of $8.7M Settlement in ERISA Cyberattack Class Action Lawsuit
Holland & Knight Link to more items from this source
Apr. 1, 2024

"The agreement, if approved by a Georgia federal judge, would resolve all claims brought against Horizon in response to a cyberattack that exposed the personally identifiable information (PII) of more than 100,000 Horizon customers and a potential settlement class of over four million individuals." [Sherwood v. Horizon Actuarial Services LLC, No. 22-1495 (N.D. Ga. settlement agreement filed Mar. 11, 2024)]

Tags: Cybersecurity   •   Retirement Plan Administration

Hospitals Blame Insurers for Not Helping Enough After Crippling Cyberattack
POLITICO Pro; subscription required Link to more items from this source
Apr. 1, 2024

"Hospitals are still struggling to get paid even as the damage from last month's Change Healthcare cyberattack is slowly remediated -- and they are pointing the finger at insurers. Thirty to 40 percent of claims continue to be denied, compared with 5 percent before the attack[.]"

Tags: Cybersecurity   •   Health Plan Administration

Things to Know About Health Care Cyberattacks
New York Times; subscription required Link to more items from this source
Apr. 1, 2024

"Ransomware attacks ... affected 46 hospital systems last year, up from 25 in 2022 ... Hackers have also taken down companies that provide services such as medical transcription and billing in recent years.... [H]ospital mortality rises in the aftermath of an attack. Scheduled surgeries are canceled, and ambulances are sometimes rerouted to other hospitals even in emergencies because the cyberattack has disrupted electronic communications or medical records and other systems."

Tags: Cybersecurity   •   Health Plan Administration

Change Healthcare Provides Update on 'Impacted Data' Analysis and Notification Plan
BakerHostetler Link to more items from this source
Mar. 29, 2024

"[As of March 27,] CHC is still determining the contents of the 'data that was taken by the threat actor.' ... A third-party vendor has been engaged to assist with data analysis.... It could be some time before CHC announces the scope of data involved.... CHC data has not been found on the dark web.... CHC will be offering to provide notifications for customers 'where permitted.' ... The latest statement from CHC itself does not start any covered entity's '60-day timeline.' "

Tags: Cybersecurity   •   HIPAA

How Insurers Are Communicating About Change Healthcare Security Breach
Corporate Insight [CI] Link to more items from this source
Mar. 28, 2024

"Having created significant challenges for both patients and providers, the cyberattack is spurring new questions and actions in the insurance space regarding digital healthcare security. While the industry response is continuing to evolve, we'll likely see increasingly robust notifications efforts from insurers and health systems as they attempt to keep users in the loop."

Tags: Cybersecurity   •   Health Plan Administration

Investment Firms Reportedly Overlooking AI as a Cybersecurity Risk
American Retirement Association [ARA] Link to more items from this source
Mar. 27, 2024

"44% of respondents surveyed said they are uncertain about how the SEC will enforce the [new cybersecurity] rules, while 36% of compliance professionals cited concerns with complying with cyber-incident reporting requirements and timeframes.... While 38% of respondents have yet to identify AI as a cybersecurity risk, and 27% do not consider AI relevant to cybersecurity, roughly half (49%) said they are in the early stages of exploring AI as a tool for cybersecurity risk management."

Tags: AI   •   Cybersecurity   •   Retirement Plan Investments

Is Your Data Secure? HHS Opens Investigation into Change Healthcare Cyberattack
Haynes and Boone, LLP Link to more items from this source
Mar. 27, 2024

"Although the OCR stated it is not prioritizing investigations of health care providers, health plans or business associates that were impacted by this cyberattack, the OCR did remind entities that have partnered with Change Healthcare and UHG of their regulatory obligations and responsibilities, including ensuring that up-to-date business associate agreements are in effect, and that timely breach notifications to HHS and the affected individuals are provided."

Tags: Cybersecurity   •   HIPAA

© 2024 BenefitsLink.com, Inc.
View Site in Mobile | Classic
Share by: