COBRA Consequences of a Dependent Turning 26
Aging out of health coverage can be a COBRA Qualifying Event.
A security review before enrollment begins can help eliminate unnecessary risks.
Open enrollment is one of the busiest times of the year for HR and benefits teams. Employee information is being updated, eligibility files are exchanged, benefit communications increase, and employees are logging into enrollment systems more frequently.
That increased activity can also create additional security risks. Before open enrollment begins, employers should take a few steps to help protect employee information and reduce opportunities for unauthorized access, phishing, and accidental disclosure.
Start by reviewing who has access to benefits and HR systems. Former employees should no longer have access, and employees who have changed positions may no longer need the same permissions.
Access provided to brokers, consultants, vendors, or temporary personnel should also be reviewed. Users should have only the access necessary to perform their responsibilities.
Each authorized user should have an individual account. Shared usernames and passwords make it difficult to determine who accessed or changed information and increase the risk that credentials will be improperly shared.
Open enrollment often generates spreadsheets containing employee names, Social Security numbers, dates of birth, dependent information, benefit elections, and other sensitive data.
Before creating another year’s enrollment files, review what is already being stored. Old census files, reports, enrollment spreadsheets, and downloads that are no longer needed should be securely deleted in accordance with the organization’s retention requirements.
Pay particular attention to files stored on desktops, in download folders, or in locations that may be accessible to more people than necessary.
During open enrollment, HR may exchange information with brokers, carriers, benefits administrators, payroll providers, and other vendors.
Sensitive employee information should be transmitted using approved secure methods rather than ordinary email whenever possible. Before sending a file, confirm both the recipient and the information being requested.
HR should also consider whether all of the requested information is necessary. If a vendor needs only a few specific data fields, there may be no reason to provide a complete employee census containing additional personal information.
Open enrollment creates an ideal environment for phishing because employees are expecting benefits-related emails. A fraudulent message about enrollment deadlines, new benefits, password resets, or required employee action may seem more legitimate at this time of year.
Before enrollment begins, tell employees how legitimate enrollment communications will be sent and how they should access the enrollment system. Employees should be cautious about unexpected links, attachments, QR codes, requests for passwords, or messages asking them to provide personal information.
Employees should also be reminded never to approve an unexpected multifactor authentication request. An MFA request that the employee did not initiate may mean that someone else is attempting to access the employee’s account.
A familiar name in an email does not necessarily mean the request is legitimate. Attackers can impersonate executives, coworkers, brokers, carriers, and vendors.
Requests for employee census files or other sensitive information should be verified, particularly when the request is unexpected, urgent, asks for unusually broad information, or requests that information be sent in a different manner than usual.
Taking a few minutes to verify a request through a known contact method can prevent a much larger problem.
Even with strong safeguards, mistakes and suspicious activity can occur. HR and benefits employees should know what to do if they send information to the wrong recipient, click a suspicious link, approve an unexpected authentication request, lose a device, or notice unusual account activity.
Employees should report potential security concerns promptly rather than attempting to determine on their own whether an incident is serious. Early reporting gives the organization an opportunity to investigate and take steps to limit potential exposure.
Preparing for open enrollment involves more than reviewing benefit plans, rates, eligibility rules, and employee communications. It is also an opportunity to review how employee information will be accessed, transmitted, stored, and protected.
A security review before enrollment begins can help eliminate unnecessary system access, reduce unnecessary copies of sensitive information, prepare employees to recognize suspicious communications, and establish good data-handling practices before the busiest part of the benefits year begins.
Benefit Allocation Systems (BAS) provides online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.
MyEnroll360 integrates with major insurance carriers for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and others), and with leading payroll platforms for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and others).
This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.