Following a data breach, regulators often review and evaluate the role of the service provider, the due diligence that was performed before selecting the service provider, and the contract provisions with respect to privacy and data security obligations and responsibilities.
Without a concerted approach to address these issues, plan fiduciaries can be vulnerable on many fronts.