Benefit Plan Fiduciaries and Service Providers Anticipating New Litigation Risks

Experts say COVID-19 could open the door to new a new category of ERISA lawsuits.  

Risk and compliance departments are drafting preventative measures to avoid continued Employee Retirement Income Security Act (ERISA) litigation. That’s according to experts at Seyfarth Shaw, Berkshire Hathaway Specialty Insurance and Mazars, who discussed ERISA complaints and compliance during a webinar hosted by the firms.

But there could be new categories of ERISA lawsuits that plan sponsors should be aware of, panelists cautioned.

For more stories like this, sign up for the PLANSPONSOR NEWSDash daily newsletter.

One new sector of litigation involves COVID-19, and, specifically, its effect on cybersecurity, the panel said. As offices moved to remote work in 2020, the risk for cyberhacks heavily increased—as did the possibility that litigation that could follow.

Candace L. Quinn, senior counsel at Seyfarth Shaw, said there has indeed been a related rise in class action complaints. While it is not specified whether participant data is a protected asset under ERISA, the Department of Labor (DOL) has recognized that there are risks to plans with electronic communications.

Quinn advised employers to identify and assess both internal and external cybersecurity risks. She said they should seek expert advice, negotiate cybersecurity protections in service providers’ contracts, monitor service providers who might be cross-marketing participant data and limit the use of participant data for non-plan products and services. “Take careful steps to protect that data,” she said.

According to Kathleen Cahill Slaught, partner at Seyfarth Shaw, employers should be wary of potential COVID-19 litigation that involves financial distress from employees due to job loss, cybersecurity management and data privacy, business interruptions or continuities, and relations within the workforce.

For example, employers could face litigation over mistakes in offering medical coverage for furloughed workers, which could result in a claim alleging a breach of their fiduciary duty of loyalty. Slaught suggested that to avoid this risk, it’s critical for plan sponsors to check in with their plan administrators or trustees. For self-insured medical plans, employers may need to file an amendment. It is also important to review plan documents to determine benefit eligibility when reviewing COBRA [Consolidated Omnibus Budget Reconciliation Act] benefits, she added.

On the topic of COBRA, the panelists said litigation involving the program is increasing as well. According to the panel, a plaintiff may claim that a company or service provider was not using the DOL model notice, therefore causing some employees to not elect COBRA benefits.

Typical problems with COBRA notices include failures for them to: be written in a manner that is understood by the average plan participant; identify the plan administrator, instead having participants speak to a vendor; explain that a legal guardian may elect continuation coverage on behalf of a minor child, or a minor child who may later become a qualified beneficiary; explain the termination date along with the maximum period of coverage and any events that can cause early termination; thoroughly explain the election process; and include an address where payments would be sent.

Panelists also warned employers that plaintiffs in such cases may seek class certification, damages and daily statutory penalties that will add up quickly in a class case.

When asked what the top three considerations for fiduciaries are to avoid litigation, Slaught recommended plan sponsors regularly review plan documentation and committee members.

“When I’m defending these cases, the court is looking for evidence that fiduciaries are paying attention and were looking at these issues,” she said. “Is there proper governance of your plan? Are your committees working efficiently? Have they been meeting regularly and following investment policy statements [IPS]?”

Dolph also suggested that plan sponsors consider working with ERISA counsel when reviewing these terms, so the examination may potentially be privileged. 

Rhonda Prussack, senior vice president and head of fiduciary and employment practices, liability at Berkshire Hathaway Specialty Insurance, advised employers to think through their fiduciary insurance options. She explained that more issues in a plan means it will have to pay more for insurance.

“If you have fee exposures; if you are in the sweet spot for [current litigation trends] of anywhere of upward of $100 million in plan assets; have not done an RFP [request for proposals] in a long time or have recently done one, then you should probably get an amount of insurance that is at least 10% of your plan assets,” she said. If a fiduciary has other questions about insurance, they can also contact their insurance broker, Prussack concluded.

The DOL Has Begun Retirement Plan Cybersecurity Audits

Attorneys say the requests plan fiduciaries have received ask for a broad amount of information and documentation, and they urge fiduciaries to act on the DOL’s recent guidance.

Attorneys from Morgan, Lewis & Bockius LLP have confirmed that the Department of Labor (DOL) has begun an audit initiative focused on retirement plan cybersecurity practices.

In a blog post, the attorneys say the DOL has issued information and document requests to plan sponsors, “and the requests are probing and indicate serious inquiry by the DOL.”

For more stories like this, sign up for the PLANSPONSOR NEWSDash daily newsletter.

The agency issued cybersecurity guidance for the first time in April. The guidance included three parts:

  • tips for hiring a service provider with strong cybersecurity practices;
  • cybersecurity program best practices; and
  • online security tips for participants.

Although there’s not much new information in the DOL guidance from what had already been suggested by experts, according to Andrew Elbon, a partner with law firm Bradley, plan fiduciaries should ensure they are putting the DOL’s guidance in practice.

The Morgan Lewis attorneys say the DOL audit requests are coming at a fast pace and request a broad amount of information and documentation. The requests that the attorneys have reviewed ask for all cybersecurity and information security program policies, procedures and guidelines that relate to the plan, whether applied by the plan sponsor or by a provider, as well as detailed documentation of specific actions taken by the plan’s fiduciaries and providers, including many that the DOL addressed in its guidance.

“Plan fiduciaries that fail to act promptly on this guidance risk being surprised by the comprehensive nature of the cybersecurity audit requests being issued by the DOL,” the attorneys warn.

«