On July 22, 2026, the Department of Labor's Employee Benefits Security Administration (EBSA) issued a proposed rule that would establish a new safe harbor for the electronic…


On July 22, 2026, the Department of Labor's Employee Benefits Security Administration (EBSA) issued a proposed rule that would establish a new safe harbor for the electronic delivery of participant disclosures required under the Employee Retirement Income Security Act (ERISA). If finalized, the rule would give administrators of ERISA-covered group health plans a streamlined, cost-effective alternative to paper delivery, aligning group health plan practices more closely with the digital communication methods already common among participants and their families.

Under the proposal, plan administrators could satisfy their disclosure obligations by posting covered documents to a secure website and notifying participants of the availability of those documents through email or text message. This approach is designed to reduce administrative burden and printing costs while improving the timeliness and accessibility of important plan information, including summary plan descriptions, summaries of material modifications, and other participant notices that ERISA requires plans to furnish.

Notably, the proposal departs from the 2020 retirement plan electronic disclosure safe harbor in one significant respect. Because group health plan communications frequently contain or relate to protected health information (PHI), the proposed rule does not permit direct email delivery of the covered documents themselves. Instead, the actual disclosures must be housed on a secure website, and the email or text message serves only as a notification that new information is available. This structure reflects the DOL's effort to reconcile the efficiencies of electronic delivery with the privacy and security obligations that arise under the Health Insurance Portability and Accountability Act (HIPAA).

The public comment period is open until September 21, 2026. Plan sponsors, administrators, third-party service providers, and other stakeholders have a meaningful opportunity to weigh in on the proposal's scope, technical requirements, and interaction with HIPAA before the rule is finalized. Plan fiduciaries should also begin evaluating whether their current websites, notification systems, and vendor arrangements could support the safe harbor's requirements, and whether existing HIPAA safeguards would need to be enhanced to accommodate expanded electronic delivery.

This update is provided for general informational purposes only and does not constitute legal advice. Clients should consult qualified counsel regarding how the proposed safe harbor may apply to their specific plans and compliance obligations.

Authors