• Security obligations should be detailed and added to the minimum security requirements as dictated by law.
• The service provider’s reporting obligations should be specified with respect to any compromise of personal data or compromise of a system(s) containing personal data.
• The service provider should be required to reimburse the plan fiduciary for expenses, costs, and the like associated with any data breach occurring under its control.
• The service provider’s auditing requirements must be specified.
• The service provider’s obligations for data retention, disposal, and destruction obligations should be consistent with the plan fiduciary’s regulatory obligations.