Providing sensitive personal information to a service provider can expose a plan fiduciary to risk. The service provider will have access to sensitive personal information outside of the protective boundaries, virtual and physical, of the plan. This access triggers additional regulatory obligations that require plan fiduciaries to take certain affirmative steps to protect that sensitive personal information.