This document is the testimony of Carol Buckmann of Cohen & Buckmann P.C. on the challenges faced by small and medium-sized employers in developing appropriate cybersecurity practices for their health plans. Buckmann provides recommendations to the DOL on ways to assist these employers, including issuing further guidance, clarifying fiduciary duties, and providing sample contract language and educational materials.