This document is the testimony of Mimi Blanco-Best of the AICPA on how CPAs can assist health benefit plans in addressing cybersecurity risks. It covers the cybersecurity risks faced by health plans, the role of financial statement auditors, and the AICPA's System and Organization Controls (SOC) suite of services that can help plans assess the cybersecurity practices of their service providers.