Client and Plan Data Must Be Secured

  • Client and data protection is consistent with duty of care
  • An assessment of data security should include the following areas:
    • Personally Identifiable Information (PII)
    • Storage, transmission, and disposal of beneficiary or plan data
    • Data encryption
    • Background checks
    • Document retention policies
    • Data back-ups
    • Physical security controls
    • Terminated employees
    • Procedures for handling security breaches
Scroll to Top