Here's What ERISA Plans and Fiduciaries Need to Know
Cybersecurity lawsuits are growing in number and scope, reaching across industries, and impacting every entity that handles personal information and uses computer technology.
Though brought under different theories and laws, common themes emerge. Individuals sue entities for harm following a data breach. Companies sue each other to determine liability to the individuals and to each other. Government agencies sue to enforce regulations, bringing civil and criminal actions against entities and individuals. In a quickly developing cause of action, participants impacted by a breach of private information bring ERISA fiduciary breach actions against plans, trustees, and plan service providers. The biggest cases involve millions of records spanning years and reaching across the country, setting the framework for how multiemployer plans could be targeted if a breach occurs. Because the potential damages involved are enormous, most cases involving actual harm are settled before the lawsuit is resolved.
Data breach lawsuits are general liability cases brought by groups of individuals as class actions, claiming harm to similar individuals because their private information was accessed and/or stolen. Claims are made for direct financial losses, the cost of repairing credit and monitoring credit activity, value of time spent dealing with fraud and, in some cases, emotional distress.
Courts are making it clear that, in the general liability context, procedural violations without quantifiable harm are not sufficient to support a cause of action. Potential risk of future harm is not enough. Thus, plaintiffs will need to show actual financial impact in order to make it past the legal hurdles to relief. Though this is a step in the right direction for plan sponsors, these cases do not prevent other types of lawsuits from proceeding. Thus, impacted companies often offer settlements to help manage risk and control cost of litigation and potential damages.
Corporate liability lawsuits are between an entity holding private information (such as an ERISA plan) and other entities (such as third-party administrators, recordkeepers, or HIPAA Business Associates), to determine which entity is ultimately liable for damages. Damages involve reimbursing participants and beneficiaries for actual harm; paying regulatory penalties to government agencies; and the cost of hardware, software, and labor in mitigating current damages, preventing future damages, updating policies and procedures, and notifying government entities and impacted individuals of the breach and actions taken. The terms of written services contracts are crucial to these cases. A clear written agreement can displace liability from statutory or regulatory defaults. This can work for or against the entity that would otherwise be at fault.
Regulatory action is the legal action by a government agency, in state or federal court, to respond to allegations of breaches, enforce regulatory standards, and force regulated entities to comply with rules, including making impacted individuals whole for breaches and assessing penalties to deter future bad actions. Often, individual complaints, news releases, or mandatory reporting of incidents initiate regulatory action.
Fiduciary actions are a new trend gaining momentum as cybersecurity rules become more wide reaching and complex. Of the 155 ERISA fiduciary lawsuits filed in 2025, 35 (22%) were against health plans. Cybersecurity violations can be brought as an independent cause of action or as part of a bigger lawsuit over other fiduciary violations. Fiduciary liability is alleged under various theories: Failure to protect confidential information that leads to or risks unauthorized access. Allegations of fiduciaries failing to evaluate and monitor the cybersecurity practices of third-party administrators and other service providers. The existence of unnecessary and unmonitored “ghost networks” (stated simply, old data that is not properly purged) are alleged as an additional breach.
Because ERISA specifically provides for equitable remedies, litigation can be brought under ERISA Section 501(a)(3), which could cause issues with fiduciary insurance liability coverage that has not been updated with recent trends. It is crucial to know and understand policy coverage and exclusions, and to purchase whatever riders or additional coverage is necessary to protect impacted individuals and fiduciaries.
With all of the potential legal theories, it can be difficult to keep up with the status of various lawsuits. Here are some of the more notable class action cases from recent years:
The best and most efficient use of money when considering potential lawsuits is prevention.
With so many potential plaintiffs and causes of action available, it is crucial to prepare an action plan to protect your plans and trustees — and especially their assets. Though not all lawsuits are successful, every lawsuit must be defended, and defense is expensive. The potential cost of defense may be best mitigated with settlement, which carries its own cost. As shown on the previous page, this cost can be exponential if the impacted population is large.
The best and most efficient use of money when considering potential lawsuits is prevention. Understanding and following the U.S. Department of Labor best practices using an ongoing, dynamic process is an important first step. Carefully interviewing, selecting, and continuing to monitor third parties creates protection from fiduciary claims.
Aggressively negotiating clear contract language to address potential liabilities, indemnification, regulatory penalties, and control over litigation decisions insulates from service provider disputes. Implementing and updating solid internal procedures and technological safeguards helps prevent the incidents and breaches that create the basis for lawsuits to be filed. Carefully reviewing fiduciary and cybersecurity insurance policies and knowing applicable coverage and exclusions, while keeping abreast of new legal theories and litigation trends, provides financial protection if the process fails and a breach occurs. Every service provider to a plan should, at minimum, agree to protect member personal information at a level equal to or exceeding that of the plan.
Even with the best protections in place, no program is perfect. Incidents happen. The goal is to prevent as much as possible in the most cost-efficient way possible. When an issue arises, identify, isolate, mitigate, and eradicate as quickly as possible. Then, adjust the system to improve it with what was learned.
Filter articles

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don’t leave your prudent process to chance. Reasonable safeguards, independently checked and documented — Cyber Prudence™ for union funds.