Justin HeldHostAnne Patterson and Stacey Van AlstyneHostHi, I'm Jenny Gartman, Senior Content and Information Specialist at the International Foundation.
This is a reading of my Word on Benefits blog post entitled, Five Ways to Prepare for a Cybersecurity Audit.
Data breaches are not just a risk for IT.
They can affect people, compliance, and fiduciary responsibility.
Health records are valuable targets on the dark web, so health plan administrators and their vendors must protect them.
The U.S. Department of Labor, or DOL's Employee Benefits Security Administration, is prioritizing cybersecurity audits in 2026, according to an update on national enforcement projects.
Investigators are better prepared than ever to evaluate cybersecurity programs, and now we have a clear idea of what they are looking for in audits.
Julie Tracy, manager of cybersecurity advisory at Witham, told the audience during a recent International Foundation webcast.
Tracy highlighted several updates from DOL's cybersecurity program best practices.
To stay compliant, health plan administrators must review five activities annually or more frequently, as noted.
Written policies, role-based access controls, security awareness training, independent assessments of cybersecurity program effectiveness, and vendor assessments.
Please note this list is not exhaustive.
Refer directly to DOL compliance assistance resources.
1.
Review and approve written policies annually.
Policies and procedures set parameters for a cybersecurity program, ensuring consistency and continuity despite personnel changes.
Multi-employer plan trustees must approve policies annually.
If no changes are needed, that's acceptable.
Record approval on the policy cover sheet, trustee meeting agenda, and meeting minutes.
Note the review date and specify that the approval is for the next 12 months.
to review role-based access controls quarterly.
Access control is a method of guaranteeing that access to systems and facilities is limited to authorized users, devices, and activities.
DOL requires access privileges to be role-based and follow the need-to-access principle, ensuring individuals have only the minimum permissions needed for their duties.
DOL's best practice includes reviewing user access every three months to promptly disable or delete accounts of people who left the organization or have excessive permissions.
Hi, I'm Jenny Gartman, Senior Content and Information Specialist at the International Foundation.
This is a reading of my Word on Benefits blog post entitled, Five Ways to Prepare for a Cybersecurity Audit.
Data breaches are not just a risk for IT.
They can affect people, compliance, and fiduciary responsibility.
Health records are valuable targets on the dark web, so health plan administrators and their vendors must protect them.
The U.S. Department of Labor, or DOL's Employee Benefits Security Administration, is prioritizing cybersecurity audits in 2026, according to an update on national enforcement projects.
Investigators are better prepared than ever to evaluate cybersecurity programs, and now we have a clear idea of what they are looking for in audits.
Julie Tracy, manager of cybersecurity advisory at Witham, told the audience during a recent International Foundation webcast.
Tracy highlighted several updates from DOL's cybersecurity program best practices.
To stay compliant, health plan administrators must review five activities annually or more frequently, as noted.
Written policies, role-based access controls, security awareness training, independent assessments of cybersecurity program effectiveness, and vendor assessments.
Please note this list is not exhaustive.
Refer directly to DOL compliance assistance resources.
1.
Review and approve written policies annually.
Policies and procedures set parameters for a cybersecurity program, ensuring consistency and continuity despite personnel changes.
Multi-employer plan trustees must approve policies annually.
If no changes are needed, that's acceptable.
Record approval on the policy cover sheet, trustee meeting agenda, and meeting minutes.
Note the review date and specify that the approval is for the next 12 months.
to review role-based access controls quarterly.
Access control is a method of guaranteeing that access to systems and facilities is limited to authorized users, devices, and activities.
DOL requires access privileges to be role-based and follow the need-to-access principle, ensuring individuals have only the minimum permissions needed for their duties.
DOL's best practice includes reviewing user access every three months to promptly disable or delete accounts of people who left the organization or have excessive permissions.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.