Benefits enrollment fraud covers schemes that exploit the enrollment process to steal data, divert money, or obtain coverage improperly. It concentrates in a predictable window — open enrollment — when employees expect unfamiliar messages about their benefits and are being asked to confirm personal details.
That expectation is the vulnerability. For most of the year an email asking an employee to verify their Social Security number and dependents would look suspicious. During enrollment it looks like Tuesday.
Fake enrollment portals. Employees receive a message directing them to a convincing replica of the benefits platform. They enter credentials and often a full set of personal data — identifiers, dates of birth, dependent information. Attackers time these to arrive alongside genuine enrollment communications, sometimes within days of the real announcement.
Impersonated HR. A message purporting to come from the benefits team asking employees to confirm details or complete an urgent step to avoid losing coverage. The threatened loss of health insurance is a powerful motivator and produces high response rates.
Account takeover. An attacker with an employee's credentials logs into the real benefits platform, changes banking details for reimbursement accounts, or redirects HSA funds.
Vendor impersonation. Messages appearing to come from the carrier or benefits administrator rather than the employer, which employees are less able to evaluate because they may never have interacted with that vendor directly.
Not all enrollment fraud comes from outside.
Ineligible dependents. Employees enrolling people who do not qualify — a former spouse after divorce, an adult child past the age limit, a relative who is not a dependent. This is often not malicious so much as a failure to report a change, but the cost to the plan is real and it can raise plan compliance questions.
Misrepresented eligibility. Claiming full-time status or a qualifying life event that did not occur in order to enroll outside the normal window.
Dependent eligibility audits are the standard response, and they consistently find ineligible enrollees. They need to be conducted uniformly rather than selectively, since auditing only some employees invites discrimination claims.
An enrollment form is one of the richest data sets an employer handles: employee identifiers, spouse and dependent names and Social Security numbers, dates of birth, and often health-related elections.
Dependent data is the part employers underweight. A successful phishing attack during enrollment can expose identifiers for children, whose identities are attractive to fraudsters precisely because nobody checks a child's credit for fifteen years. The harm surfaces long after the incident.
Exposure of this data triggers breach notification obligations, and where health information is involved the handling requirements are stricter still.
The no-links practice deserves emphasis. It is mildly inconvenient and it eliminates an entire attack class, because an employee trained never to expect a link cannot be routed to a fake portal by one.
Most enrollment runs through a third-party platform, and the employer still owns the consequences of a breach there. Before the season, confirm whether MFA is available and whether it can be required, how the vendor authenticates changes to banking details, what their breach notification commitment is, and whether their own communications to employees will contain links — because if they do, the employer cannot credibly tell employees to distrust links.
That last question surfaces a real inconsistency in many programs: the employer warns employees about links while the carrier sends them weekly.
Enrollment data should not sit indefinitely in inboxes and shared folders. Forms collected by email, spreadsheets built to track completion, and scanned documents all create copies outside the system of record. A short post-enrollment cleanup, applied as a routine step, meaningfully reduces standing exposure.
Employer's Guardian helps employers run enrollment communications, dependent verification, and platform controls through outsourced HR services.
This article provides general educational information, not legal, tax, or insurance advice. Benefits and plan requirements vary. Consult qualified counsel or your plan advisor regarding eligibility and audit practices.