Selecting and monitoring the vendors who run your plan, holding them to DOL cybersecurity expectations, and insuring the plan and its fiduciaries properly.
Prudence means a documented process — defining needs, comparing candidates, evaluating fees and services, checking references — followed by ongoing monitoring through periodic performance reviews, fee benchmarking, and renewal-time reassessment. The file you build is the proof your process existed.
Read the full answer
A BAA is required whenever a vendor creates, receives, maintains, or transmits protected health information for the plan — TPAs, brokers with claims access, wellness vendors, data analysts. Without a BAA, sharing PHI with that vendor is itself a HIPAA violation.
Read the full answer
DOL guidance — extended explicitly to health and welfare plans in 2024 — expects fiduciaries to assess vendors' cybersecurity practices, ask for their security programs, audit results, and breach history, and include security and breach-notification obligations in contracts. Ignoring cyber risk is now a fiduciary gap.
Read the full answer
An ERISA fidelity bond insures the plan against losses from fraud or dishonesty by people handling plan funds. It's mandatory — at least 10% of funds handled, minimum $1,000 and generally capped at $500,000 per plan — and it is not the same as fiduciary liability insurance.
Read the full answer
Fiduciary liability insurance protects fiduciaries personally against breach claims; D&O covers corporate management decisions; E&O covers professional service errors; cyber insurance responds to breaches. Each answers a different risk — the bond alone protects only the plan against dishonesty.
Read the full answer
Put these answers to work
Fiduciary In A Box walks your team through every one of these requirements step by step —
documenting decisions, organizing files, and keeping your plan compliant year-round.
See how FIAB works