Understanding Health Plans and Cybersecurity Activities

This document is the testimony of James Gelfand of the ERISA Industry Committee (ERIC) on cybersecurity issues affecting group health plans sponsored by large, self-insured employers. Gelfand discusses the existing regulatory framework, including HIPAA and HITECH, the cybersecurity threats facing health plans, and ERIC's recommendations for DOL regarding guidance, coordination with other agencies, and reliance on industry to update best practices.