Your privacy choices

We use cookies and similar technologies to analyze traffic, improve site performance, and personalize content. You can accept all cookies or manage your preferences at any time. View our Privacy Policy for details.

Skip to Main Content

Press "Enter" to search

Employee Benefits

5 Ways HR Pros Thwart Cybercriminals During Open Enrollment

Protecting employee data requires vigilance, education, and layered security throughout enrollment season.

August 19, 2026

Open enrollment is one of the busiest times of year for HR teams. It is also a prime opportunity for cybercriminals.

Benefits enrollment requires employees to share sensitive personal, financial, and healthcare information, making HR departments and their vendors attractive targets for phishing scams, identity theft, and data breaches.

While cybersecurity is everyone's responsibility, HR professionals play a critical role in protecting employee data during open enrollment and throughout the year. Here are five practical ways to help keep sensitive information secure.

1. Strengthen Account Security with Modern Authentication Practices

Employee data is only as secure as the systems used to access it. Traditional passwords alone are no longer enough to protect against today's cyber threats.

To improve account security:

  • Create strong, unique passwords or passphrases for every account.
  • Avoid reusing passwords across multiple systems or websites.
  • Use a password manager to generate and store credentials securely.
  • Enable multifactor authentication (MFA) wherever possible. MFA adds an extra layer of protection by requiring users to verify their identity through a second factor, such as a mobile device or authentication app.
  • Take advantage of single sign-on (SSO) solutions when available to reduce password fatigue and improve security management.

Organizations should also regularly review user access rights and ensure only authorized personnel can access sensitive employee information.

2. Stay Alert to Phishing and Social Engineering Scams

Open enrollment season creates an ideal environment for cybercriminals because employees expect to receive emails, forms, and communications related to benefits.

Attackers may impersonate:

  • HR representatives
  • Benefits providers
  • Insurance carriers
  • Payroll administrators
  • Company leaders requesting urgent action

These fraudulent emails and text messages often encourage recipients to click links, open attachments, provide login credentials, or submit personal information. Common examples include emails claiming benefits elections must be updated immediately, requests to verify dependent or beneficiary information, notices directing employees to a fake enrollment portal, or text messages purportedly from HR or a benefits provider asking employees to confirm personal information before a deadline.

To reduce risk:

  • Verify the sender before responding to benefits-related emails or text messages.
  • Examine links carefully before clicking.
  • Be cautious of urgent requests, unexpected attachments, or messages containing spelling and grammatical errors.
  • Use official company communication channels for enrollment activities.
  • Confirm suspicious requests directly with HR, the benefits administrator, or the vendor through known contact information.

Remember: a convincing phishing email, text message, or fraudulent website can lead to credential theft, identity theft, financial fraud, or unauthorized access to employee records.

3. Protect Sensitive Information in the Office and at Home

Physical security remains an important part of cybersecurity, especially when working with employee records.

In addition to using privacy screens when necessary, HR professionals should:

  • Follow clean desk practices by removing or securing sensitive documents when not in use.
  • Lock computer screens whenever stepping away from a workstation.
  • Secure laptops, tablets, and mobile devices with passwords, biometrics, and automatic screen locks.
  • Store printed enrollment materials and employee records in locked cabinets or secure locations.
  • Be mindful of sensitive information displayed during virtual meetings, screen sharing sessions, or video calls.

Whether working in the office, at home, or while traveling, protecting employee information from unauthorized viewing is essential.

4. Use Secure Networks and Trusted Vendors

Many employees and HR professionals work remotely at least part of the time, making network security increasingly important.

When accessing benefits systems:

  • Avoid using public Wi-Fi networks for enrollment-related activities.
  • Use a secure company network, virtual private network (VPN), or trusted mobile hotspot whenever possible.
  • Ensure devices receive regular security updates and patches.
  • Report lost or stolen devices immediately.

It's also important to evaluate the security practices of benefits providers, payroll partners, and other third-party vendors that handle employee information. Because these partners often manage highly sensitive employee data, cybersecurity should be a key factor when selecting and managing benefits vendors.

Consider the following:

  • Review vendor cybersecurity policies and security certifications.
  • Ask vendors whether they encrypt employee data, conduct regular security assessments, and require multifactor authentication (MFA) for access to benefits administration systems.
  • Understand how vendors store, transmit, and protect sensitive employee information, including personal, financial, and health-related data.
  • Confirm vendors have procedures for incident response and breach notification.
  • Limit data sharing to only the information necessary to perform business functions.

A strong cybersecurity strategy extends beyond your organization to the partners that support your benefits program, helping protect employees from data breaches, fraud, and identity theft.

5. Educate Employees About Cybersecurity Best Practices

Employees are often the first line of defense against cyber threats. Providing simple, ongoing cybersecurity education can help reduce risk during open enrollment and throughout the year.

Help and encourage employees to:

  • Recognize common benefits-related scams and phishing attempts.
  • Access enrollment platforms only through approved company channels.
  • Protect personal and financial information from unsolicited requests.
  • Use MFA and strong passwords on personal and work-related accounts.
  • Report suspicious emails, phone calls, text messages, or enrollment activity immediately.
  • Contact HR directly when they are unsure whether a communication is legitimate.

Regular reminders and awareness campaigns can help employees make safer decisions and reduce opportunities for cybercriminals.

Cybersecurity Is a Year-Round Responsibility

Open enrollment may increase cybersecurity risks, but protecting employee information should not be limited to a single season. By strengthening authentication practices, educating employees, securing devices and networks, evaluating vendors' security, and staying alert to phishing scams, organizations can better safeguard sensitive data year-round. Just as important, these efforts help build employee trust by demonstrating a commitment to protecting the personal and financial information employees share when making important benefits decisions.

Related Reading: Getting the Most Out of Your Open Enrollment Communications

The above information does not constitute advice. Always contact your employee benefits broker or trusted advisor for insurance-related questions.

Don’t Miss Out on the Latest HR News & Tools

Get trusted updates on industry trends, compliance changes, webinars and tools designed to make benefits management easier. Subscribe to Benefits Insider and receive expert insights every month.

By entering your contact information and submitting the form, you understand that Hylant may send similar information in the future. You can unsubscribe anytime by using the link at the bottom of any Hylant email.

Related Insights