Elizabeth Loh

DOL Proposed Rule Describes New Safe Harbor for Electronic Delivery of ERISA Group Health Plan Documents

On July 23, 2026, the Department of Labor (the “DOL”) published a proposed rule (the “proposed rule”) describing an additional electronic disclosure safe harbor (the “new safe harbor”) that administrators of ERISA group health plans may rely on when distributing their required plan documents and notices electronically. These rules are long overdue, as information sharing has advanced tremendously since the last electronic disclosure safe harbor for group health plans was published in 2002 (the “2002 safe harbor”).

Background. ERISA requires that certain documents be provided to participants and beneficiaries either automatically or upon request. When distributing these materials, the ERISA plan administrator (the “administrator”) must use measures that are “reasonably calculated to ensure actual receipt of the material.” To meet these distribution requirements, the 2002 safe harbor assumed that the default method for sending plan materials would be by paper (e.g., by regular mail or hand delivery). If an administrator wanted to send documents out electronically (e.g., by email or through posting on its intranet website), it would have to (1) determine whether the intended recipient had work-related access to electronic systems (i.e., was “wired at work”), or (2) obtain affirmative consent from the participant or beneficiary to receive documents electronically if the participant was not “wired at work” (e.g., was a COBRA-qualified beneficiary, retiree, worked in manufacturing, etc.).

In its proposed rule, the DOL recognizes that technology and communications have changed substantially since the DOL first published the 2002 safe harbor 20+ years ago. Currently, an increasing share of the public relies on electronic communication and internet-based platforms as their primary method of receiving information. Accordingly, the new safe harbor assumes that the administrator’s default method of document delivery will be electronic (e.g., through posting on an internet website), instead of by paper copy. The rules are meant to ease the administrative burden faced by administrators when distributing group health plan documents and notices.

Note: The new safe harbor is optional and administrators have the option of either utilizing the 2002 safe harbor, or the new safe harbor when distributing group health plan materials electronically.

Which plans are subject to the new electronic disclosure requirements? This new safe harbor applies to ERISA group health plans (e.g., medical, dental, vision, employee assistance program, etc.). The proposed rule clarifies that the new safe harbor would not apply to ERISA welfare benefit plans (e.g., life insurance, disability, accidental death and dismemberment, prepaid legal services, etc.).

Note: Plan sponsors frequently create plan documents and notices that cover both group health and welfare benefit plans. For example, ERISA wrap plan summary plan descriptions include both group health plan and welfare benefit plan related information. We will need further guidance regarding whether documents such as ERISA wrap plan documents may be electronically delivered under the new safe harbor, or whether they will have to meet the 2002 safe harbor requirements as well.

 What types of ERISA group health plan documents may be electronically disclosed using the new safe harbor? The new safe harbor may be used by a plan sponsor when distributing its ERISA-required group health plan documents and notices. Group health plans are subject to a variety of notice and distribution requirements. For example, these notices include summary plan descriptions, summary of material modifications, plan documents, COBRA notices, HIPAA special enrollment notices, Newborns’ and Mothers’ Health Protection Act notices, Women’s Health and Cancer Rights Act notices, and claim denial notices. An administrator may use the new safe harbor when distributing these types of group health plan materials.

Note: This new safe harbor applies to documents the plan administrator has an affirmative obligation to furnish (e.g., ERISA summary of material modifications, annual legal notices, etc.), as well as those documents that must be furnished only upon request (e.g., the ERISA wrap plan document).

Who is a covered individual? A plan administrator may electronically distribute required ERISA group health plan notices under the new safe harbor to “covered individuals.” The proposed rule describes a “covered individual” as a participant or beneficiary who has provided the employer, plan sponsor, or administrator with an email address or smartphone number (e.g., using Short Message Service). This information should be collected by the employer when the individual enrolls in the group health plan. The email address could include the employee’s assigned work email address.

Note: The proposed rule reflects that dependent children who have reached age 18 should have the right to independently receive ERISA group health plan-related documents. If such a dependent child has provided the employer, plan administrator, or plan sponsor with their electronic address, then the administrator may use the new safe harbor when electronically distributing group health plan materials to the dependent.

Electronic delivery method. Under the new safe harbor, group health plan documents may be distributed by posting these documents on an internet website where the covered individual is able to access the document. When posting on the website, the administrator must meet the following requirements:

    • Documents must be timely posted. Each covered document must be available on the website no later than the date it is legally required to be provided to participants.
    • Documents must stay up for at least a year. Covered documents must remain on the website for at least one year to allow covered individuals a reasonable window to review their plan materials.
    • Document must be written clearly. The covered document must be written in a manner calculated to be understood by the average plan participant.
    • Document must be in a format that is readable. The document must be posted in a format that is suitable to be both read online and printed clearly on paper (e.g., in PDF format).
    • Document must be searchable. A covered individual must be able to search the covered document electronically by numbers, letters or words. For example, a scanned document where a participant could not search by letters or words would not satisfy this requirement.
    • Document must be saveable. The document must be in a format that allows the covered individual to download and save a copy of the covered document for their records.
    • Website must be secure. The administrator must take reasonable steps to ensure that the website protects the covered individual’s personal information.
    • The proposed rule defines the type of “website” where covered documents may be posted broadly to include an “internet website” or “other internet-based information repository, such as a mobile app.” The website must be available to covered individuals at work as well as outside of the workplace (e.g., at home).

Note: The administrator is responsible for establishing and maintaining the internet website. However, the proposed rule recognizes that employers have existing administrative arrangements in which third party administrators (TPAs) host participant-facing portals and document repositories for the plans they assist with administering. Employers will need to coordinate and confirm with their TPAs that they are complying with these new electronic safe harbor requirements.

Note Further: The proposed rule only anticipates that an administrator will use an internet website to distribute plan materials. Unlike the 2002 safe harbor, the new safe harbor does not include email as an alternative method of group health plan document distribution because of concern that group health plan materials may include protected health information that cannot be securely sent via email.

Initial notification required before new safe harbor may be used. Before relying on the new safe harbor, the administrator must provide an “initial notice” of electronic delivery to covered individuals. This notice serves as a “heads up” to individuals of the plan’s electronic delivery procedures. The notice will need to contain the following information:

    • Notice of electronic delivery. A statement that covered documents will be furnished electronically;
    • Identification of the email address. The notice must identify the electronic address that will be used for the individual.
    • Instructions. Any instructions necessary to access the covered documents;
    • Statement regarding how long documents will be posted. A warning that covered documents are not required to be available on the company website for more than one year or, if later, after it is superseded by a subsequent version of the covered document;
    • Right to paper copy. A statement of the individual’s right to request and obtain a paper version of the document free of charge, and an explanation of how to exercise this right; and
    • Right to opt out. A statement of the right to opt out of electronic delivery and receive only paper versions of the covered documents.

Note: Participants and beneficiaries for whom the administrator intends to use electronic delivery must receive a paper copy of this initial notice before any covered documents are delivered electronically using this new safe harbor. However, the proposed rule contemplates whether a paper copy of the initial notice is necessary for covered individuals already receiving plan materials electronically under the requirements of the 2002 safe harbor, and the DOL has solicited comments on this issue. We anticipate that the final rule will address this open issue.

Notice of Internet Availability. Before posting a covered document on its internet website, the administrator must provide covered individuals with a Notice of Internet Availability (NOIA). This notice must be distributed to the email address or cell phone number provided by the covered individual. Further, the NOIA must meet the following requirements:

    • A title or subject line that reads, “Disclosure About Your Health Plan.”
    • A separate statement reading, “Important information about your health plan is now available. Please review this information.”
    • Identify the covered document that is being posted by name (e.g., “Your Notice of HIPAA Special Enrollment Rights is now available.”).
    • Include the internet address (or hyperlink) where the covered document is posted.
    • Describe the covered individual’s right to request and obtain a paper copy of the covered document free of charge.
    • Explain the covered individual’s right to opt out of electronic delivery and receive only paper copies of the covered documents.
    • Include a cautionary statement that the covered document is only required to be posted on the website for one year.
    • Provide a telephone number to contact the administrator or other designated representative of the plan.

As a general rule, a separate NOIA must be furnished each time a covered document is posted on the administrator’s internet website (for example, a NOIA must be furnished before the administrator posts on its website a mid-year ERISA summary of material modifications). However, the proposed rule provides exceptions to this general rule where one NOIA may be provided describing the posting of multiple covered documents. For example, the NOIA may be provided at open enrollment and describe the posting of the ERISA group health plan’s annual required ERISA group health plan notices.

Note: The combined NOIA is an exception to the stand-alone rule and is limited to recurring annual disclosures that do not demand time-sensitive participant action. For example, if the administrator plans on posting a COBRA election form online, it must send the COBRA qualifying beneficiary a stand-alone NOIA notifying the participant of the COBRA election form posting.

Invalid addresses. If the administrator is alerted that a covered individual’s email address has become invalid (e.g., because the NOIA is returned as undeliverable), the administrator must take steps to cure the problem. For example, the administrator should obtain a new email address for the covered individual where the NOIA can be properly delivered.

Severance from employment. When a covered individual terminates employment with the employer, the employer will need to take steps to make sure it has an up-to-date email address for the terminating employee. For example, if the individual will no longer have access to a company email address, the employer will need to obtain the individual’s personal email address to ensure that the covered individual has the ability to receive covered documents post-employment.

Comments on the proposed rule are due by September 21, 2026. If the proposed rule is finalized in its current form, the new safe harbor would become effective as of the first day of the first calendar year following publication of the final rule in the Federal Register.

Next steps. We will continue to monitor developments and provide updates as the DOL finalizes the safe harbor rules for electronic delivery of group health plan notices and disclosures. Please contact us if you have any questions about the proposed rule or how it may impact your group health plan practices.

August 4, 2026

Cryptocurrency No Longer a Non-Starter for 401(k) Plans – Real World Implications

On May 28, 2025, the U.S. Department of Labor Employee Benefits Security Administration (EBSA) released its first compliance assistance bulletin under the new presidential administration, Compliance Assistance Release No. 2025-01 (the “New Guidance”), announcing and memorializing EBSA’s revocation of its 2022 guidance cautioning against 401(k) plan investments in cryptocurrencies (Compliance Assistance Release No. 2022-01 (the “Prior Guidance”).

The Prior Guidance was issued by EBSA during the last presidential administration in response to a growing number of firms marketing cryptocurrencies as potential 401(k) plan investment options. Citing concerns that cryptocurrencies may have volatile returns, are subject to an evolving regulatory environment, present unique challenges for participants in making informed investment decisions, and have unique custodial, recordkeeping and valuation concerns, EBSA cautioned plan fiduciaries to exercise “extreme care” before considering adding a cryptocurrency to a 401(k) plan investment menu. Notably, in light of EBSA’s concerns, the Prior Guidance warned plan fiduciaries that EBSA expected to conduct an investigative program aimed at plans offering participant investments in cryptocurrencies and related products. More specifically, EBSA informed 401(k) plan investment fiduciaries permitting cryptocurrency investments that they “should expect to be questioned about how they can square their actions with their duties of prudence and loyalty in light of the [associated] risks . . .”  This resulted in an immediate and significant chilling effect on pursuing cryptocurrency offerings in 401(k) Plans.

It comes as little surprise that the new presidential administration is a proponent of cryptocurrency, with Vice President Vance announcing the same day as the release of the New Guidance that “crypto finally has a champion and an ally in the White House…  crypto and digital assets… are part of the mainstream economy, and are here to stay.”  But what does the New Guidance mean for plan fiduciaries and the prudent analysis they must undertake in considering whether cryptocurrencies are an appropriate 401(k) plan investment options?

The New Guidance focuses on the reference to “extreme care” in the Prior Guidance as a rationale for its revocation, stating that “extreme care” is not a standard found in ERISA, and differs from ordinary fiduciary principles thereunder. Under ERISA, the fiduciary principles describing standards of care are the duties of loyalty and prudence. Specifically, ERISA’s duty of loyalty provides that fiduciaries must act solely in the interest of plan participants and beneficiaries with the exclusive purpose of providing benefits and defraying reasonable plan expenses, and the duty of prudence provides that fiduciaries are to carry out their duties with the care, skill, prudence, and diligence that a prudent person familiar with such matters would use (described by the courts as an expert standard). 

The New Guidance emphasizes that the Prior Guidance deviated from EBSA’s “historic neutral approach to investment types and strategies” (e.g., imposing a uniform standard of care for different investments), and that revocation of the Prior Guidance “restores [EBSA’s] historical approach by neither endorsing, nor disapproving of, plan fiduciaries who conclude that the inclusion of cryptocurrency in a plan’s investment menu is appropriate.” 

For a responsible 401(k) plan fiduciary, the revocation of the Prior Guidance does not give the green light to add cryptocurrency as an investment option; rather, it simply places cryptocurrency on a level playing field with any other potential investment option.  In other words, it removes EBSA’s prior heightened scrutiny of cryptocurrency as a 401(k) plan investment option.  This means a potential cryptocurrency investment should be reviewed and vetted by plan fiduciaries in the same manner as any other investment, by conducting a prudent process and adhering to the duty of loyalty. Such process may include analyzing and documenting whether the investment option:

  • provides participants with diversified alternatives, expanding on risk and return characteristics;
  • offers returns that can be effectively monitored (correlated to a benchmark);
  • possesses reasonable expenses;
  • provides adequate disclosure for participants to evaluate the investment; and
  • is permitted under the plan’s investment policy statement.

In issuing the New Guidance, EBSA did not dismiss the concerns listed in the Prior Compliance release regarding returns, regulatory development, participant comprehension, and unique custodial, recordkeeping and valuation considerations, which will still present challenges when evaluating cryptocurrencies in the same way as other investment options. However, EBSA was clear that it no longer “disapproves” of cryptocurrency as an investment consideration, and a plan fiduciary’s decision should consider all relevant facts and circumstances and will “necessarily be context specific” (referencing Fifth Third Bancorp v. Dudenhoeffer, 573 U.S. 409, 425 (2014)).  In other words, the appropriateness of cryptocurrency as an investment should focus on the specific needs of the plan, the unique characteristics of the population, and the reasonableness of the fiduciaries’ judgment.

In light of these changes, those in charge of plan administration must carefully review the applicable disclosure obligations and work closely with the plan actuary and legal counsel to ensure accurate and timely compliance. Plan fiduciaries that wish to consider cryptocurrency as a potential 401(k) plan investment option should work with their investment advisor to evaluate whether such an investment option is appropriate for their plan, taking into account the relevant facts and circumstances for their plan population, and analyzing the various considerations solely in the interest of plan participants in a prudent manner with a well-documented demonstration of their decision-making process.  This should include a process to appropriately monitor the cryptocurrency investment, understand and evaluate the reasonableness of its fees, and assess whether sufficient education on the investment can be provided to the participant population.

If you have questions about the New Guidance, please contact us.

The Prior Guidance was issued by EBSA during the last.

PERSONAL ATTENTION AND SERVICE, AND A COLLABORATIVE APPROACH.

Since its founding in 1980, Trucker Huss has built its reputation on providing accurate, responsive and personal service. The Firm has grown in part through referrals from our many satisfied clients, including other law firms with which we often partner on a strategic basis to solve client challenges.

Publication info:

The Trucker Huss Benefits Report is published monthly to provide our clients and friends with information on recent legal developments and other current issues in employee benefits. Back issues of the Benefits Report are posted on the Trucker Huss website (www.truckerhuss.com)


Editor: Nicholas J. White, nwhite@truckerhuss.com


In response to IRS rules of practice, we inform you that any federal tax information contained in this writing cannot be used for the purpose of avoiding tax-related penalties or promoting, marketing or recommending to another party any tax-related matters in this Benefits Report.

San Francsico

135 Main Street, 9th Floor

San Francisco, California 94105-1815

LOS ANGELES

15760 Ventura Blvd, Suite 910

Los Angeles, California 91436-3019

Portland

329 NE Couch St., Suite 200

Portland, Oregon 97232-1332

Tel: (415) 788-3111
Fax: (415) 421-2017

Email: info@truckerhuss.com

Website: www.truckerhuss.com

Copyright © 2026 Trucker Huss. All rights reserved. This newsletter is published as an information source for our clients and colleagues. The articles are current as of the date of publication, are general in nature and are not the substitute for legal advice or opinion in a particular case.

Office Locations

SAN FRANCISCO


135 Main Street, 9th Floor

San Francisco, CA 94105-1815

LOS ANGELES


15760 Ventura Boulevard, Suite 910

Los Angeles, CA 91436-2964

PORTLAND

329 NE Couch Street, Suite 200

Portland, OR 97232-1332

Awards & Recognition