ERISA Plan Documents vs. SPDs
ERISA-covered health and welfare plans must have certain plan documents and provide participants with information about benefits.
Security should be considered throughout information's entire lifecycle, from collection through disposal.
HR departments handle significant amounts of sensitive employee information, including Social Security numbers, addresses, payroll information, benefit elections, dependent information, and health-related information. Protecting that information requires more than securing the system where it is ultimately stored. Security should be considered throughout the information’s entire lifecycle, from collection through disposal.
Employee information should be collected through approved methods and for legitimate business purposes. When sensitive information is needed, employees should use available secure systems or transmission methods rather than requesting that information be sent through ordinary email or other unapproved channels.
Limiting unnecessary collection also reduces risk. If information is not needed for a business or compliance purpose, consider whether it needs to be collected at all.
Once employee information is collected, access should be limited to individuals who need the information to perform their job responsibilities. Having access to information does not necessarily mean it should be downloaded, printed, copied, or shared.
Employees should also avoid creating unnecessary copies of sensitive information for convenience. Every additional copy creates another location that must be protected.
Sensitive employee information should be stored in company-approved systems and locations with appropriate security protections. Personal email accounts, personal cloud storage, unapproved applications, and other unauthorized storage locations should not be used for company information.
Paper records also require protection. Documents containing confidential information should not be left unattended on desks, printers, conference room tables, or other locations where unauthorized individuals may see them.
Before sending employee information, verify both the recipient and the recipient’s need or authority to receive it. This applies whether information is being shared with another employee, a benefits provider, payroll provider, insurance carrier, or another third party.
Sensitive information should be transmitted using approved secure methods. Extra care should be taken with spreadsheets, census files, reports, and other documents containing information about multiple employees because a single mistake can expose information about many individuals.
Employee information may be appropriately protected in an HR, payroll, or benefits system, while additional copies created during day-to-day work remain elsewhere.
Consider the spreadsheet downloaded to complete a project, an attachment saved to a desktop, a report emailed to a coworker, or a document printed for a meeting. Once the immediate task is complete, these additional copies may no longer be necessary but can continue to create security exposure.
Employees should periodically consider whether working files and other copies of sensitive information are still needed and handle them according to company retention and disposal procedures.
Electronic storage makes it easy to retain information indefinitely, but keeping unnecessary information can increase security risk. Employers should follow applicable legal requirements and established record-retention policies when determining how long employee information should be maintained.
Retention requirements vary depending on the type of information, so records should not be deleted simply because an immediate task has been completed.
When employee information no longer needs to be retained, it should be disposed of using approved methods. Electronic information should be deleted in accordance with company procedures, and paper records containing confidential information should be securely destroyed rather than placed in ordinary trash or recycling.
Protecting employee information does not end when data is entered into a secure system or a particular HR task is completed. Each time information is collected, accessed, downloaded, stored, shared, retained, or disposed of creates another opportunity to protect it.
Before handling sensitive employee information, consider four basic questions: Is the information needed? Who needs access to it? Where should it be stored? What should happen to it when the task is complete?
Applying these questions throughout the information lifecycle can help reduce unnecessary exposure and protect employee information from collection through final disposal.
Benefit Allocation Systems (BAS) provides online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.
MyEnroll360 integrates with major insurance carriers for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and others), and with leading payroll platforms for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and others).
This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.