CyberSecure

THE MAGAZINE FOR UNION FUNDS

Cybersecurity Lawsuits are Surging

 

 

Here's What ERISA Plans and Fiduciaries Need to Know 

Cybersecurity lawsuits are growing in number and scope, reaching across industries, and impacting every entity that handles personal information and uses computer technology. 

Though brought under different theories and laws, common themes emerge. Individuals sue entities for harm following a data breach. Companies sue each other to determine liability to the individuals and to each other. Government agencies sue to enforce regulations, bringing civil and criminal actions against entities and individuals. In a quickly developing cause of action, participants impacted by a breach of private information bring ERISA fiduciary breach actions against plans, trustees, and plan service providers. The biggest cases involve millions of records spanning years and reaching across the country, setting the framework for how multiemployer plans could be targeted if a breach occurs. Because the potential damages involved are enormous, most cases involving actual harm are settled before the lawsuit is resolved.

Data breach lawsuits are general liability cases brought by groups of individuals as class actions, claiming harm to similar individuals because their private information was accessed and/or stolen. Claims are made for direct financial losses, the cost of repairing credit and monitoring credit activity, value of time spent dealing with fraud and, in some cases, emotional distress.  

Courts are making it clear that, in the general liability context, procedural violations without quantifiable harm are not sufficient to support a cause of action. Potential risk of future harm is not enough. Thus, plaintiffs will need to show actual financial impact in order to make it past the legal hurdles to relief. Though this is a step in the right direction for plan sponsors, these cases do not prevent other types of lawsuits from proceeding. Thus, impacted companies often offer settlements to help manage risk and control cost of litigation and potential damages.  


Corporate liability lawsuits are between an entity holding private information (such as an ERISA plan) and other entities (such as third-party administrators, recordkeepers, or HIPAA Business Associates), to determine which entity is ultimately liable for damages. Damages involve reimbursing participants and beneficiaries for actual harm; paying regulatory penalties to government agencies; and the cost of hardware, software, and labor in mitigating current damages, preventing future damages, updating policies and procedures, and notifying government entities and impacted individuals of the breach and actions taken. The terms of written services contracts are crucial to these cases. A clear written agreement can displace liability from statutory or regulatory defaults. This can work for or against the entity that would otherwise be at fault. 


Regulatory action is the legal action by a government agency, in state or federal court, to respond to allegations of breaches, enforce regulatory standards, and force regulated entities to comply with rules, including making impacted individuals whole for breaches and assessing penalties to deter future bad actions. Often, individual complaints, news releases, or mandatory reporting of incidents initiate regulatory action. 


Fiduciary actions are a new trend gaining momentum as cybersecurity rules become more wide reaching and complex. Of the 155 ERISA fiduciary lawsuits filed in 2025, 35 (22%) were against health plans. Cybersecurity violations can be brought as an independent cause of action or as part of a bigger lawsuit over other fiduciary violations. Fiduciary liability is alleged under various theories: Failure to protect confidential information that leads to or risks unauthorized access. Allegations of fiduciaries failing to evaluate and monitor the cybersecurity practices of third-party administrators and other service providers. The existence of unnecessary and unmonitored “ghost networks” (stated simply, old data that is not properly purged) are alleged as an additional breach.


Because ERISA specifically provides for equitable remedies, litigation can be brought under ERISA Section 501(a)(3), which could cause issues with fiduciary insurance liability coverage that has not been updated with recent trends. It is crucial to know and understand policy coverage and exclusions, and to purchase whatever riders or additional coverage is necessary to protect impacted individuals and fiduciaries.  

With all of the potential legal theories, it can be difficult to keep up with the status of various lawsuits. Here are some of the more notable class action cases from recent years:

 

Defendant Equifax 2019
Violation Data Breach
Information Breach of 147 million customers’ personal financial information
Damages Failure to patch vulnerability in software and secure consumer SSNs and other vital information
Dollars $425–$700 Million Settlement
(reports vary)
Defendant Zoom 2021
Violation Regulatory
Information False advertising; failure to follow cybersecurity practices
Damages Misleading claims that video calls were secured by “end-to-end encryption” when they were not; failure to implement adequate security features
Dollars $150 Million Settlement
Defendant CVS Health 2023
Violation Regulatory
Information Personal Health Information
Damages Unauthorized disclosure of users’ sensitive health information to third-party advertisers
Dollars $1.5 Million Regulatory Penalty
Defendant 23andMe 2024
Violation Data Breach
Information Genetic Data (private health information) of 7 million customers leaked
Damages Out of pocket expenses: identity theft protection, mental health services for emotional distress, compromised health information, statutory penalties, identity theft and credit monitoring
Dollars $30 Million Settlement
Defendant McLaren Health Care 2024–2025
Violation Data Breach
(two major incidents spanning several years)
Information Personal and medical information
Damages Data breaches exposing medical/personal information; systematically failing to protect patient information
Dollars $14 Million Settlement
Defendant Kaiser Permanente 2026
Violation Data Breach
Information Personal Health Information
Damages Website and mobile app tracking privacy violations released PHI without consent to Google, Microsoft, Twitter/X.
Dollars $47.5 Million Settlement
Defendant Globe Life 2026
Violation Data Breach
Information Personal Health Information
Damages Failure to protect personal information of 850,000 individuals; policy holder data was exposed in a cyberextortion attempt (company did not pay extortion fee)
Dollars $4.66 Million Settlement
Defendant Yale New Haven Health 2026
Violation Data Breach
Information Names, addresses, Social Security Numbers, medical histories
Damages Sensitive patient health information was exposed to a third party
Dollars $18 Million Settlement

 

The best and most efficient use of money when considering potential lawsuits is prevention.

With so many potential plaintiffs and causes of action available, it is crucial to prepare an action plan to protect your plans and trustees — and especially their assets. Though not all lawsuits are successful, every lawsuit must be defended, and defense is expensive. The potential cost of defense may be best mitigated with settlement, which carries its own cost. As shown on the previous page, this cost can be exponential if the impacted population is large. 

The best and most efficient use of money when considering potential lawsuits is prevention. Understanding and following the U.S. Department of Labor best practices using an ongoing, dynamic process is an important first step. Carefully interviewing, selecting, and continuing to monitor third parties creates protection from fiduciary claims. 

Aggressively negotiating clear contract language to address potential liabilities, indemnification, regulatory penalties, and control over litigation decisions insulates from service provider disputes. Implementing and updating solid internal procedures and technological safeguards helps prevent the incidents and breaches that create the basis for lawsuits to be filed. Carefully reviewing fiduciary and cybersecurity insurance policies and knowing applicable coverage and exclusions, while keeping abreast of new legal theories and litigation trends, provides financial protection if the process fails and a breach occurs. Every service provider to a plan should, at minimum, agree to protect member personal information at a level equal to or exceeding that of the plan. 

Even with the best protections in place, no program is perfect. Incidents happen. The goal is to prevent as much as possible in the most cost-efficient way possible. When an issue arises, identify, isolate, mitigate, and eradicate as quickly as possible. Then, adjust the system to improve it with what was learned.

CyberSecure

Filter articles

Let’s build something better - together.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.

Don’t leave your prudent process to chance. Reasonable safeguards, independently checked and documented — Cyber Prudence™ for union funds.

Thank you for your inquiry. Your submission request has been received.
Onsite Logic