While uncertainty is unavoidable in health plan administration, preparation can make all the difference. From compliance notices and fiduciary responsibilities to unexpected operational challenges, asking “what if?” helps plan sponsors anticipate risks before they become costly problems. By taking small, proactive steps now, fiduciaries can strengthen confidence, protect plan members and position the plan to respond more effectively when the unexpected occurs.
In a recent International Foundation webcast, “Planning for ‘What If?’ Scenarios With Your Health Plan,” Stephanie Patrick of Horizon Actuarial Services, LLC, and Jeff Lockwood of NYSUT discussed how health plans can prepare for a variety of scenarios, including disaster preparedness, vendor satisfaction and security breaches.
Hurricane Season Is Upon Us
Lockwood posed the question of “What if . . . a hurricane hits your fund office?”
He suggested several steps fund offices should take before a natural disaster, including:
- Developing a continuity of operations plan. This includes cross-training staff, developing standard operating procedures and creating an inclement weather policy.
- Identifying essential functions. Plans should determine which employees and operations are essential to keep the fund running.
- Succession planning. Funds should establish orders of succession and delegation of authority.
Lockwood also discussed roll-call procedures for worst-case scenarios when employees cannot get to the office. To create continuity in and out of the office, funds should consider the following:
- Develop a remote work infrastructure, engage contingency staffing firms and create a crisis team
- Select alternate facilities and ensure access to vital records and systems
- Establish communication protocols, including creating a phone tree for employee communication.
By following these suggestions, employers can be better prepared if the worst happens.
Vendor Satisfaction
Another question funds may face is, “What if . . . your vendors or plan professionals are not meeting your expectations?”
Lockwood said that plans succeed when treating plan professionals as partners while also managing fiduciary relationships proactively. When vendors fall short, it’s critical to have oversight and continuity plans in place. Vendor oversight includes:
- Defining service expectations early, including detailed service agreements with performance guarantees, penalties and audit rights
- Providing vendors with what they need to succeed
- Involving multiple stakeholders in benefit design review before systems go live, including testing systems after launch.
Lockwood talked about other best practices for monitoring vendors:
- Conducting regular performance reviews using key performance indicators (KPIs) and dashboards
- Establishing formal escalation procedures for service failures
- Issuing RFPs at set intervals to ensure competitiveness and accountability
- Creating transition plans or finding backup providers if a vendor collapses or is acquired.
To manage plan professionals, funds should:
- Define responsibilities clearly, including fiduciary vs nonfiduciary roles, so it is clear who manages each vendor
- Rotate auditors and periodically test reliance on key professionals
- Clarify relationships and fee arrangements
- Use independent review for actuarial assumptions, legal interpretations and investment strategies to confirm a professional’s results and performance.
According to Lockwood, clear roles and independent reviews help support strong plan performance and identify issues before they escalate. He advised funds to trust plan professionals, but also to verify that the plan is being properly administered. This can be accomplished by:
- Reviewing reporting regularly
- Holding regular check-ins
- Monitoring performance against service agreements
- Tracking complaints to catch red flags early. Do not dismiss one issue as a fluke; confirm that it is not systemic.
By following these best practices, plans can be better positioned to fulfill their obligations to participants.
Security Breaches
Another important question for funds today is, “What if . . . the fund has a security breach?” A breach can compromise member’s trust and compliance efforts.
Funds should prioritize security by creating clear, written policies for staff on passwords and access controls, artificial intelligence (AI), data storage and encryption, and device use.
Lockwood suggested additional steps funds can take to strengthen their defenses, including:
- Using multi-factor authentication (MFA)
- Keeping software and systems updated
- Limiting access based on employee role
- Performing security audits and penetration tests
- Contacting cyber insurance carriers, which may offer free tools to their members
- Using secure email gateway and anti-malware tools.
Training should be continuous, so security stays top of mind for staff. A variety of methods (e.g., in-house, self-paced, workshops, simulated events) should be used to keep staff engaged. Participation should be encouraged, and staff training completion and scores should be tracked.
For suggestions on how to handle other “what ifs,” including those related to fund office administration, legislative changes, employees on leave, overfunding the plan, new trustees, whistleblowers and staff protections, DOL audits and conflicts of interest, view the full “Planning for “What If?” Scenarios With Your Health Plan” webcast.
Developed by International Foundation Information Center staff. This does not constitute legal advice. Please consult your plan professionals for legal advice.


