Multiple Cyber Incidents Impact Employee Benefit Plans And Participants

SS
Seyfarth Shaw LLP

Contributor

With more than 900 lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities-no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations-and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce.
By this point, most people in the employee benefits space have heard about the MOVEit and Retirement Clearing House (RCH) cyber incidents, which could directly impact employers' benefit plans.
United States Employment and HR
To print this article, all you need is to be registered or login on Mondaq.com.

By this point, most people in the employee benefits space have heard about the MOVEit and Retirement Clearing House (RCH) cyber incidents, which could directly impact employers' benefit plans. The MOVEit file transfer application is used by a number of vendors, including those that locate missing plan participants or find information regarding deceased plan participants (e.g., PBI Research Services). RCH is often used by retirement plans to facilitate benefit transfers, including for IRA rollovers. Other plan vendors/subcontractors may also use the MOVEit software application or subcontract with RCH for their plan services. Actual and potential victims have included state and federal government agencies as well as companies across a variety of industries (and their benefit plans) who were using MOVEit or RCH, or who engaged with service providers who used these tools.

Initial public reports of the MOVEit and RCH cybersecurity incidents began in May and information about extent the incidents is still being uncovered. RCH has announced that Social Security Numbers, as well as account numbers at Matrix Trust, may have been compromised but the IRA accounts themselves were not actually accessed.

In order to satisfy ERISA fiduciary obligations to safeguard plan participants' personal information, plan fiduciaries should attempt to understand what happened, whether or not the incident impacted plan participants, and what information was compromised. Since neither incident was a direct result of action taken by any plan, plan fiduciaries and administrators are currently in a "trust but verify" situation with their service providers, contractors and subcontractors. However, as of the date of this post, we have already seen a class action filed against PBI as a result of the MOVEit incident.

If a retirement plan has a business relationship with any service provider that uses, used or may have used the MOVEit software application or RCH services, the plan should determine what fields or categories of personal information were shared with the service provider(s), and by extension MOVEit or RCH, to determine the impact on the plan and its participants. Any service agreements with the applicable vendors should also be reviewed with respect to data breach notification, information reporting, and follow up obligations of the service provider(s). This includes any indemnification provisions for data incidents. Also, if the plan carries cyber-liability insurance (increasingly common), there may be a requirement to notify the cyber-liability carrier. If the plan is adversely impacted and does not receive satisfactory responses from its service provider, more direct action may be needed.

The plan's responsibilities and potential avenues for relief depend on a number of factors. Any member of Seyfarth's Global Privacy and Security team is able to assist you to obtain more information about your particular situation in order to evaluate next steps.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

Multiple Cyber Incidents Impact Employee Benefit Plans And Participants

United States Employment and HR

Contributor

With more than 900 lawyers across 18 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities-no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations-and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More