The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently announced a HIPAA enforcement action against an employer-sponsored group health plan. The action resulted in a payment to HHS of $245,000 and a two-year corrective action plan. While HIPAA enforcement is common in the healthcare sector, actions directly against employer-sponsored

Each April, National Employee Benefits Day provides an opportunity to reflect on the rapidly shifting landscape of employer‑sponsored benefits.

From implementing new tax laws, a flurry of executive orders with implications for both retirement and welfare plans, updated agency guidance, increased litigation and enforcement activity, and updates to longstanding requirements, plan fiduciaries

As employers begin 2026, a new wave of Employee Retirement Income Security Act (ERISA) litigation is emerging involving voluntary products that serves as an important reminder that accurate Form 5500 reporting, fiduciary best practices, and good governance procedures are important for all ERISA-governed plans. According to Jackson Lewis’s recent article, several newly filed suits

  • A bipartisan bill introduced in December 2025 would amend ERISA to treat pharmacy benefit managers (PBMs) as fiduciaries when providing services to employer-sponsored group health plans.
  • If enacted, the legislation would impose fiduciary duties, require detailed compensation disclosures, and restrict contractual indemnification provisions that shift fiduciary risk to plans.
  • Employers may gain increased transparency

Introduction

On August 7, 2025, President Donald J. Trump issued an Executive Order designed to broaden access to alternative investments, such as private equity, commodities, real estate, and certain digital assets, for participants in 401(k) and other defined contribution retirement plans. The initiative is framed as an effort to “democratize” investment opportunities that were historically

It is increasingly evident that artificial intelligence (AI) is reshaping all facets of business, and its impact on employee benefit plans is no exception. From automating plan administration to personalizing participant communications, AI introduces both new opportunities and new responsibilities for those overseeing Employee Retirement Income Security Act of 1974 (ERISA)-covered retirement and health plans

  • The 2025 CAR does not alter ERISA’s substantive fiduciary standards and considerations but eases the DOL’s previously hostile enforcement stance toward cryptocurrency and similar digital assets in 401(k) plans, restoring a “neutral” DOL enforcement approach. 401(k) plan fiduciaries must still consider all relevant ERISA factors and apply the necessary care, skill, prudence, and diligence

Our “health plan hygiene” series has focused on steps that fiduciaries of employer-sponsored group health plans can take to ensure they meet their fiduciary responsibilities.  This issue has been brought to the forefront recently due to a wave of class action lawsuits that have been brought against group health plan fiduciaries.  In our last post

A little more than three years ago, the U.S. Department of Labor (DOL) posted cybersecurity guidance on its website for ERISA plan fiduciaries. That guidance extended only to ERISA-covered retirement plans, despite health and welfare plans facing similar risks to participant data.

Last Friday, the DOL’s Employee Benefits Security Administration (EBSA) issued Compliance Assistance Release

The Employee Retirement Income Security Act of 1974 (ERISA) regulates most private employee benefit retirement and welfare plans. This statute’s purview is vast; it governs employer-sponsored defined benefit and defined contribution retirement plans and an array of welfare plans.

Under ERISA, a plan fiduciary is an entity that exercises authority or control over the management