<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="https://www.effortlessadmin.com/articles/rss/xslt"?>
<rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Articles</title>
    <link>https://www.effortlessadmin.com/articles/</link>
    <description>Effortless Admin</description>
    <generator>Articulate, blogging built on Umbraco</generator>
    <item>
      <guid isPermaLink="false">1135</guid>
      <link>https://www.effortlessadmin.com/articles/post/soc-2-type-ii-floor-not-finish-line/</link>
      <category>Benefits Administration</category>
      <title>What it Actually Took to get SOC 2 Type II</title>
      <description>&lt;p&gt;Your benefits provider holds some of the most sensitive information your company has: your employees' health data. So how do you know they are protecting it?&lt;/p&gt;
&lt;p&gt;You cannot inspect their systems. You cannot interview their developers. However, you  can ask them for independent proof, and in our industry the most meaningful proof is a &lt;strong&gt;SOC 2 Type II report&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;In plain terms: an independent auditor examines how a company protects data, not just its technology but how it hires, how it trains people, how it handles departures and how it responds when something goes wrong, and then watches those practices operate over a period of months to confirm they are real rather than just written down. At the end the auditor issues a formal opinion. That opinion is the report.&lt;/p&gt;
&lt;p&gt;We went through that at Effortless Admin. It took longer than we expected, taught us more than we expected, and changed how we run the company. This is the story of why we did it, what it actually took, and how we maintain it today, ending with the three questions we now believe every employer should ask any provider holding their people's data. Including us.&lt;/p&gt;
&lt;h2&gt;Our clients raised the bar, and they were right&lt;/h2&gt;
&lt;p&gt;Employers and their advisors have grown less willing to accept &amp;quot;we take security seriously&amp;quot; without any independent evidence, and they have asked harder questions of every partner in their supply chain.&lt;/p&gt;
&lt;p&gt;Our clients were part of that shift. In 2022 we put our commitment in writing: we would obtain SOC 2 to meet the growing needs of our clients and advisors. That summer, on July 6, 2022, we signed the engagement letter with our auditor.&lt;/p&gt;
&lt;p&gt;To be honest, I assumed we were most of the way there already. We are a technology company after all and we build secure software for a living. How hard could this be?&lt;/p&gt;
&lt;p&gt;I was about to find out.&lt;/p&gt;
&lt;h2&gt;I had the wrong idea about what gets examined&lt;/h2&gt;
&lt;p&gt;My mental model of a security audit was someone technical poking at our servers and reviewing our code. The reality is much bigger, and understanding why is the key to understanding what SOC 2 really tells you.&lt;/p&gt;
&lt;p&gt;Our auditor's job was to draft the initial controls, the specific testable rules we would then be tested against, and to explain exactly how each one would be tested. When the list arrived it was not a list focusing on our servers and our code. It was a list about the company.&lt;/p&gt;
&lt;p&gt;Do we run background checks on new hires? Can we prove it, for every hire? When someone leaves, is their access revoked, every time, with a record? Does a second developer review every change before it ships? Does our board oversee any of this?&lt;/p&gt;
&lt;p&gt;That is the insight that changed how I think about security. &lt;strong&gt;Your data is not protected by technology. It is protected by an organization's habits.&lt;/strong&gt; A firewall doesn't help if a departed employee's account stays active. Encryption doesn't help if nobody reviews changes.&lt;/p&gt;
&lt;p&gt;At the project kick-off on August 22, 2022 our auditor grilled us on questions ranging from how we secured our systems, how our developers reviewed each other's code, how HR handled onboarding, offboarding and job descriptions, how our board of directors operated, and much much more. Sixteen days later they delivered the initial control set.&lt;/p&gt;
&lt;p&gt;There I learned that forty-nine of those controls carried an annual review obligation, to be re-performed every year rather than implemented once. That is when I understood we were not preparing for an event. We were opening ourselves up to this on an ongoing basis.&lt;/p&gt;
&lt;p&gt;So the work began. Fifteen security policies written from nothing, mapped to six internal audience groups so each employee acknowledged only the policies relevant to their role. A register of every out-of-date software component on our servers, forty-two items, each with an owner and a status, each to be upgraded or removed before the period opened. None of it was exotic. All of it was work.&lt;/p&gt;
&lt;p&gt;How much work? In September 2022, in those our early conversations with the auditor, I said our security policies were probably two to three weeks from approval. They were published on January 15, 2024, well over a year later. I no longer make estimates about compliance timelines.&lt;/p&gt;
&lt;h2&gt;The long middle, when the mountain is just that big&lt;/h2&gt;
&lt;p&gt;That gap between September 2022 and January 2024 wasn't because because we got distracted, but because the sheer volume of controls to design, implement, and document was simply enormous for a company our size, on top of running the platform our clients depend on every day. Anyone who tells you SOC 2 preparation is a quick project either has an army of consultants or hasn't done it.&lt;/p&gt;
&lt;p&gt;But that long middle produced the decision I'm most proud of.&lt;/p&gt;
&lt;h2&gt;We would not start the clock until we could pass&lt;/h2&gt;
&lt;p&gt;Here is something most people do not know about SOC 2 Type II. The company being examined chooses when its observation period begins, the window during which the auditor tests whether the controls are actually operating.&lt;/p&gt;
&lt;p&gt;We had a simple principle: &lt;strong&gt;we would not start that clock until every control was genuinely in place and working.&lt;/strong&gt; Not mostly in place. Not on track to be in place. Working.&lt;/p&gt;
&lt;p&gt;So in late December 2023, three weeks before our window was set to open, we pushed the start date back two weeks to finish the last of our infrastructure updates and give our staff proper time to review and formally accept the security policies. It would have been easy to start on schedule and tidy up along the way. We weren't willing to be examined on work we knew wasn't finished, because then the report wouldn't mean what our clients needed it to mean.&lt;/p&gt;
&lt;p&gt;That principle, more than any technology we deployed, is what I'd want a client to know about us.&lt;/p&gt;
&lt;h2&gt;What the reports say, and how to read one like a skeptic&lt;/h2&gt;
&lt;p&gt;Our first SOC 2 Type II report covered six months of operations in 2024. The auditor's opinion was unqualified (the strongest opinion available) meaning our controls were suitably designed and operating effectively throughout the period, with no exceptions noted on any control tested. Our second report picked up the day the first ended and covered a full year, with the same result: a clean, unqualified opinion. Together, the two reports cover eighteen continuous months of independently examined operations. Our third examination is underway right now.&lt;/p&gt;
&lt;p&gt;One habit worth borrowing from us: read even &lt;em&gt;good&lt;/em&gt; reports carefully. Every SOC 2 report defines its own scope... which criteria were examined, what period was covered, what was excluded. Ours cover security and privacy, the criteria that matter most for a company handling employee health data. A report that covers less is a smaller claim wearing the same name. When a vendor hands you a report, the scope section is where the truth lives.&lt;/p&gt;
&lt;p&gt;And here's a wrinkle that surprises almost everyone: a SOC 2 report doesn't necessarily tell you what was actually tested. Some reports don't list the specific controls at all, and others describe them so vaguely that you can't tell what practice sits behind the words. Two companies can each hand you a &amp;quot;clean SOC 2 Type II,&amp;quot; where one was examined against a rigorous, detailed set of controls and the other against a thin, generic list, and the cover pages look identical. If a vendor won't show you their controls, you're being asked to trust the label without the ingredients.&lt;/p&gt;
&lt;h2&gt;The report is a byproduct. The discipline is the product.&lt;/h2&gt;
&lt;p&gt;Here is what nobody told me at the start, and it is the most important thing I learned.&lt;/p&gt;
&lt;p&gt;I thought the report was the finish line. It's not. The moment one observation period ends, the next begins. Dozens of controls come due for re-performance every year. Security policies get formally re-reviewed annually. We now audit our &lt;em&gt;own&lt;/em&gt; suppliers the way our clients audit us, requesting and reviewing their reports on a recurring cycle. Compliance monitoring runs continuously in the background, every day.&lt;/p&gt;
&lt;p&gt;And some of it is gloriously unglamorous. Over the past year and a half, I have personally sent our staff three separate reminders to complete overdue security training. The Chief Technology Officer, chasing training completions. It doesn't sound impressive, and that's exactly why it matters. Security training is the single practice that touches every person in the company, and when it slips, everything else slips behind it.&lt;/p&gt;
&lt;p&gt;That's the real story of SOC 2. The report you can hand a client is just the visible artifact. What it actually certifies is that a company has built the &lt;em&gt;habits&lt;/em&gt;... the reviewing, the training, the record-keeping, the chasing... and kept them running when no one was watching. A vendor cramming for the exam and a vendor living the discipline can both wave a report at you. The questions below tell them apart.&lt;/p&gt;
&lt;h2&gt;What to ask any provider holding your people's data&lt;/h2&gt;
&lt;p&gt;A few facts most buyers do not know. SOC 2 is an attestation examination under AICPA standards, not a certification, and it produces a service auditor's report rather than a certificate. There is no certifying body and no central register. There is no pass or fail either: a report is issued regardless of what the examination finds, so an organization can hold one containing exceptions or a qualified opinion.&lt;/p&gt;
&lt;p&gt;And nothing expires, because AICPA imposes no validity period and no authority could revoke a report once issued. &amp;quot;We have SOC 2&amp;quot; can mean almost anything. These three questions make it mean something.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. What period does your report cover, and when did it end?&lt;/strong&gt; A SOC 2 report describes a window of time that has already closed. The industry convention is that a report goes stale about twelve months after its period ends. A vendor pointing to a report from two years ago is showing you history, not a current state. (And a vendor whose next examination is &amp;quot;in progress&amp;quot; has a plan, not a report. They should be upfront about which one they're offering you.)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. Which trust services criteria are in scope?&lt;/strong&gt; Security alone is the minimum. For anyone handling your employees' health information, ask whether privacy is covered too. The narrower the scope, the smaller the claim.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. Is it a Type I or a Type II?&lt;/strong&gt; A Type I says the controls were &lt;em&gt;designed&lt;/em&gt; properly on a single day. A Type II says they actually &lt;em&gt;operated&lt;/em&gt; effectively over months of real business. One letter, enormous difference.&lt;/p&gt;
&lt;h2&gt;We would rather you looked for yourself&lt;/h2&gt;
&lt;p&gt;Earlier I said a SOC 2 report might not tell you which controls were tested. We decided the fix for that is simple: show people.&lt;/p&gt;
&lt;p&gt;We publish our controls, openly and in plain language, at our Trust Centre: &lt;strong&gt;&lt;a href="https://trust.effortlessadmin.com/"&gt;trust.effortlessadmin.com&lt;/a&gt;&lt;/strong&gt;. There you will find the practices we are examined against, organized across five categories: infrastructure security, organizational security, product security, internal security procedures, and data and privacy. Everything from encryption key access and penetration testing to background checks, disaster recovery testing, and what happens to customer data when a client leaves.&lt;/p&gt;
&lt;p&gt;We built this because we are proud of these controls. Each one represents real, ongoing, unglamorous work, and we would rather you see them than take our word for it.&lt;/p&gt;
&lt;p&gt;So consider this an open invitation. Go read them. Bring your IT team. Ask us hard questions about any control on the list.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ask every provider holding your employees' data what period their last report covered, what was in scope, and whether it was a Type II.&lt;/strong&gt; Then ask for one more thing: to see the actual controls. Ours are waiting for you at &lt;a href="https://trust.effortlessadmin.com/"&gt;trust.effortlessadmin.com&lt;/a&gt;. The good ones will love that you asked.&lt;/p&gt;
</description>
      <pubDate>Mon, 17 Aug 2026 19:13:12 Z</pubDate>
      <a10:updated>2026-08-17T19:13:12Z</a10:updated>
    </item>
    <item>
      <guid isPermaLink="false">1097</guid>
      <link>https://www.effortlessadmin.com/articles/post/new-integration-partner-aperio/</link>
      <category>Effortless News</category>
      <category>Benefits Administration</category>
      <category>Human Resources</category>
      <title>Meet Effortless Admin’s Newest Partner: HRWARE</title>
      <description>&lt;p&gt;We are excited to announce that we have teamed up with &lt;a rel="noopener" href="https://www.hrware.com/" target="_blank" title="HRWARE"&gt;HRWARE&lt;/a&gt; to integrate their Aperio HR platform with Effortless Admin. We at Effortless Admin take pride in our focus to be the best at what we do: Benefits. We are ecstatic to have a Canadian HR product partner that takes the same pride in their focus on Human Capital Management.&lt;/p&gt;
&lt;p&gt;This integration will help take your HR product stack to the next level by pairing 2 of Canada’s most robust and complimentary HRIS platforms to reduce the workload and risks associated with duplicate data entry by automatically pulling data from HRWARE Aperio into Effortless Admin.&lt;/p&gt;
&lt;p&gt;&lt;img style="width: 350px; height: 46px;" src="/articles/media/1032/aperiohrlogo.png?width=350&amp;amp;height=46" alt="HRWARE" data-udi="umb://media/456f5f6f322f40ebb6855572297c61f0" /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;About HRWARE&lt;/h2&gt;
&lt;p&gt;&lt;a rel="noopener" href="https://www.hrware.com/" target="_blank" title="HRWARE"&gt;HRWARE&lt;/a&gt; delivers innovative cloud-based HR technology solutions to simplify day-to-day HR management. With over 25 years in the HR tech space, we understand the present and future needs of HR technology better than most.&lt;/p&gt;
&lt;p&gt;Aperio, a cloud-based Human Resource Management Solution is a giant step forward in HRWARE's pledge to deliver a truly disruptive HR Solution that makes managing people both easy and effective. We at HRWARE are committed to providing our clients with an exceptional "Position Based" Human Capital Management technology experience, backed by the certified HR professionals you can count on. In Q1 2019, HRWARE is adding a truly Canadian Payroll to its portfolio of solutions to help fellow Canadians businesses more easily manage their Payroll requirements, be they simple or complex.&lt;/p&gt;</description>
      <pubDate>Fri, 01 Feb 2019 22:02:48 Z</pubDate>
      <a10:updated>2019-02-01T22:02:48Z</a10:updated>
    </item>
    <item>
      <guid isPermaLink="false">1095</guid>
      <link>https://www.effortlessadmin.com/articles/post/we-love-our-azure-cloud/</link>
      <title>What we Love About our Azure Cloud</title>
      <description>&lt;p&gt;June 16, 2018 was a big day for the Effortless Admin platform. For the many advisors, plan administrators and employees that use the platform, this would have seemed liked any other day. But behind the scenes a significant change had occurred. This was the day that we retired our physical servers and embraced the robust and powerful cloud computing service created by Microsoft, and loved by countless tech giants… namely, &lt;a rel="noopener" href="https://azure.microsoft.com/" target="_blank" title="Microsoft Azure"&gt;Microsoft Azure&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Far before we decided to transition to Microsoft Azure we knew that cloud computing was the future of the Effortless Admin platform. Keeping up with the demands of our physical servers (hardware failures, upgrading hardware, adding servers, and so on) was challenging at best. Just ask any IT professional what it’s like to manage a physical server farm.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://media.giphy.com/media/Xjo8pbrphfVuw/giphy.gif" alt="IT management nightmare" /&gt;&lt;/p&gt;
&lt;p&gt;We knew that the right cloud computing environment would help us scale more efficiently and would free us from the nuisances that inherently come with physical servers. The big question was: Which cloud service is right for us? Given the importance of this decision, our engineers set aside countless hours to assess the various cloud computing services offered today, including Amazon AWS, Google Cloud, Microsoft Azure.&lt;/p&gt;
&lt;p&gt;Our primary considerations included:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Security&lt;/strong&gt; - This was the absolute number one priority!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Locality&lt;/strong&gt; of servers - The servers and all data had to be located in a Canadian datacenter.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Performance&lt;/strong&gt; - The new solution must deliver better performance than our current physical environment and there must be room to improve performance when needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scalability&lt;/strong&gt; - The time dedicated to expanding and maintaining our network was becoming a real problem. Whatever solution we went with had to make asset management a lot easier.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Subscription cost&lt;/strong&gt; - We weren't looking to break the bank. Ideally our new cloud solution would not cost any more than our current physical solution.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;After months of assessment and due diligence, we decided that Microsoft Azure was the best solution for our specific needs. The purpose of this article isn’t to put a stake in the ground and pontificate why our decision is “right” and why others are choosing the “wrong” service. Nope… you’ll have to do some more Googling if you are looking for an extensive pros-and-cons list. In our situation, however, Azure was the clear winner.&lt;/p&gt;
&lt;p&gt;That said, it’s been about six months since we made the transition and we wanted to share what we really appreciate about our new environment. Here are just a few highlights…&lt;/p&gt;
&lt;h2&gt;Azure is serious about security&lt;/h2&gt;
&lt;p&gt;Security is, without a doubt, the most important consideration when you’re choosing a cloud computing environment, or any technology solution for that matter. In my opinion, performance, cost, ease of use, and any other metric you are using to gauge a solution all need to take a back seat to security. After all, what’s the point of adopting a new technology if you are putting yourself and your clients at risk?&lt;/p&gt;
&lt;div class="post-content__emphasis-box"&gt;
&lt;p&gt;&lt;strong&gt;Answer&lt;/strong&gt;: there is none… it’s just a really bad idea.&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;Microsoft, Google and Amazon all have excellent security measures in place. However, Azure currently has the &lt;a rel="noopener" href="https://www.microsoft.com/en-us/trustcenter/compliance/complianceofferings?product=Azure" target="_blank" title="Microsoft Azure compliance offerings" data-anchor="?product=Azure"&gt;most security certifications&lt;/a&gt; out of all providers and they are constantly adding new certifications to maintain their title as the most secure cloud provider. They were the first major cloud provider to be compliant with ISO 27018, and they were the first (and remain the only) provider to be granted level 5 clearance by the Department of Defence for the purposes of national security.&lt;/p&gt;
&lt;p&gt;The attention that Microsoft places on keeping their security certifications up-to-date gives us a lot of confidence that our environment is well protected.&lt;/p&gt;
&lt;p&gt;Another major benefit with Azure is the many network protections that are included by default. One of the biggest current threats to platform stability are Distributed Denial of Service (DDoS) attacks. This is when a service is flooded with many more network requests than it can handle, which results in the service shutting down completely. We’ve all heard about DDoS attacks bringing down many major services in the recent news. Azure provides all of their customers with built in protection against DDoS attacks at the network level, often before any heavy traffic even gets to their servers.&lt;/p&gt;
&lt;p&gt;Azure also offers fine grained control of private networks with network partitioning and firewalls. This has enabled us to precisely define network access and monitoring to be sure things are secure. And, Azure provides numerous methods of encryption allowing us to ensure that data is always encrypted in-transit and at-rest.&lt;/p&gt;
&lt;h2&gt;Robust Canadian data centers&lt;/h2&gt;
&lt;p&gt;Out of all cloud service providers, Microsoft offers the most regions worldwide. At the time of this article, Microsoft has two, full-featured Canadian data centers. For a Canadian administrator of employee benefits, using exclusively Canadian data centers is an absolute must.&lt;/p&gt;
&lt;p&gt;What we really appreciate about the locality of Azure is that their Canadian data centers are not inferior to their American counterparts. We have never noticed important features being excluded from data centers north of the border.&lt;/p&gt;
&lt;h2&gt;Performance won’t be an issue&lt;/h2&gt;
&lt;p&gt;Azure has a reputation for being the backbone of many demanding, enterprise-level applications. This includes massive apps like Adobe’s Experience Cloud, Honeywell’s Lyric solution and Office 365, to name a few. There is no doubt that Azure will be able to keep up with our performance requirements.&lt;/p&gt;
&lt;h2&gt;Scaling is simple&lt;/h2&gt;
&lt;p&gt;One of the inherent features of cloud computing is the ability to dynamically change the resources in a deployed environment. This offers a major advantage over traditional (physical) server environments.&lt;/p&gt;
&lt;p&gt;As a point of context… a year ago, to add a server to our physical server farm we would manually requisition the new server, wait for days for the physical server to be added to our network and then spend another day configuring the server. Whereas in our cloud environment, a server can be deployed within minutes by simply clicking a few buttons in a web interface. Now we have the ability to double our even triple the size of our environment with relative ease.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://media.giphy.com/media/zcCGBRQshGdt6/giphy.gif" alt="Easy management" /&gt;&lt;/p&gt;
&lt;h2&gt;It’s salty&lt;/h2&gt;
&lt;p&gt;Along with the switch to Azure, we adopted &lt;a rel="noopener" href="https://www.saltstack.com/" target="_blank" title="SaltStack"&gt;SaltStack&lt;/a&gt; for automated machine configuration management. By using SaltStack’s intelligent IT automation toolset, deploying new assets is fully automated. For example, when we need to deploy a new front-end web server, we are able to use our Salt script in concert with the Azure API to (1) requisition the server, (2) encrypt hard drives, (3) update firewall rules, (4) deploy production code and (5) update the load balancer to include the server in the rotation. It’s beautiful, more agile, and it greatly reduces the risks involved with code deployment and configuration changes.&lt;/p&gt;
&lt;p&gt;And by adopting SaltStack we open ourselves up to a world of opportunities, including orchestrating the deployment of resources based on real-time demand.&lt;/p&gt;
&lt;h2&gt;We’re saving money&lt;/h2&gt;
&lt;p&gt;Microsoft Azure’s per minute, pay-as-you-go model allows us to only pay for what we need, when we need it. This means that we can scale our servers down (and save money) when demand is low, such as late at night and on weekends, and then scale the servers back up when demand increases. We are also able to create standalone test and staging environments and only pay for them when they are in use.&lt;/p&gt;
&lt;p&gt;Another major cost savings opportunity was the ability to track resource utilization by server and prevent waste by forecasting usage and scaling to match.&lt;/p&gt;
&lt;p&gt;Before we made the switch, we used Microsoft Azure’s &lt;a rel="noopener" href="https://azure.microsoft.com/en-ca/pricing/calculator/" target="_blank" title="Microsoft Azure pricing calculator"&gt;pricing calculator&lt;/a&gt; and estimated that we would save somewhere between 15% to 20% on our monthly hosting costs.&lt;/p&gt;
&lt;p&gt;&amp;gt; We are pleased to say that we are getting all of the added power of a robust, secure cloud environment and yet we are saving 16.7% each month. Freaking awesome!&lt;/p&gt;</description>
      <pubDate>Fri, 18 Jan 2019 21:13:54 Z</pubDate>
      <a10:updated>2019-01-18T21:13:54Z</a10:updated>
    </item>
    <item>
      <guid isPermaLink="false">1093</guid>
      <link>https://www.effortlessadmin.com/articles/post/leading-ben-admin-platform-improve-data-control/</link>
      <category>Benefits Administration</category>
      <category>Employee Benefits</category>
      <title>How Leading Benefits Administration Platforms can put You in Control of Your Data</title>
      <description>&lt;p&gt;Administering employee group benefits plans directly with insurance carriers, or through many ben-admin modules in HRIS platforms, comes at a cost. Some obvious, like a lack of robust data compliance built into these systems, which &lt;a href="/articles/post/hidden-liability-risks-in-your-employee-benefit-data/"&gt;results in liabilities in the way of plan member data errors&lt;/a&gt;. Some, less obvious but still significant, like: the lack of robust data retention.&lt;/p&gt;
&lt;p&gt;Consider the following example:&lt;/p&gt;
&lt;div class="post-content__emphasis-box"&gt;
&lt;p&gt;Once a year, a company and its benefits advisor receives a renewal report from the plan carrier. The report will provide some usage figures on the plan and will set out next year’s premium rates for the plan. The company and advisor will only be able to review the figures set out in the report, and then decide whether to: accept the new rate, ask for a rate break, or go to the carrier market for a better rate. If the company changes carriers for the better rate, what then?&lt;/p&gt;
&lt;/div&gt;
&lt;p&gt;Data collection occurs in the carrier’s system, as does claims processing. The company is not in control of its data. The spillover effects from this problem are twofold:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The company can’t verify that the information in the carrier report is accurate.&lt;/li&gt;
&lt;li&gt;The data history generated during the company’s plan will be lost if the company changes carriers.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src="https://media.giphy.com/media/xTiIzLmsjbQmmkRYrK/giphy.gif" alt="Data loss" /&gt;&lt;/p&gt;
&lt;p&gt;In our example, the fact that the company does not control its data reduces its bargaining position when deciding whether to accept the new rate or consider a carrier change. But a carrier change is not a solution to the problem in the long term, and it comes with short term consequences too.&lt;/p&gt;
&lt;p&gt;For example, following through on a carrier change requires the re-enrollment of the entire company with a new plan carrier, learning its admin system and technical guide, and working with a new customer service team. Also, and just as important, a carrier change means that the company will lose all of its eligibility and claims experience history from its current plan. What this means is that the company loses its ability to audit their data and mine it for trends and changes over time and across carrier changes. Taken together, the company’s options are to remain reliant on carrier data with the carrier that has its history, or to restart the cycle with a new carrier.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;A leading benefits administration software and service provider will solve this problem.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Whether your company is a small business or an enterprise, using a leading ben-admin platform will permit you to keep your company’s plan member eligibility data across insurance carrier and provider changes. And a truly leading technology can also permit you to retain your company’s claims experience data, so that you can leverage it to ensure your data is reflected correctly in your carrier’s renewal reports. This puts you in control of your data and allows your company and advisor to leverage long term insights into your employee benefits program.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Long story short: Make sure your company is in control of its data.&lt;/strong&gt;&lt;/p&gt;</description>
      <pubDate>Thu, 13 Dec 2018 23:05:42 Z</pubDate>
      <a10:updated>2018-12-13T23:05:42Z</a10:updated>
    </item>
    <item>
      <guid isPermaLink="false">1091</guid>
      <link>https://www.effortlessadmin.com/articles/post/new-integration-partner-bamboohr/</link>
      <category>Effortless News</category>
      <category>Benefits Administration</category>
      <category>Human Resources</category>
      <title>Meet Effortless Admin’s Newest Partner: BambooHR</title>
      <description>&lt;p&gt;We’re excited to announce that we’ve teamed up with BambooHR to help take your HR product stack to the next level. Integrating BambooHR with Effortless Admin reduces your workload and the risks associated with duplicate data entry by automatically pulling employee information from BambooHR into the Effortless Admin platform.&lt;/p&gt;
&lt;p&gt;Are you already benefiting from effortless administration? &lt;a href="/login/"&gt;Login&lt;/a&gt; and visit your integrations page for more information on how easy it is to setup the integration. Still on the fence? &lt;a href="/demo/"&gt;Talk to us&lt;/a&gt; about us about how we can streamline your benefits administration.&lt;/p&gt;
&lt;p&gt; &lt;/p&gt;
&lt;p&gt;&lt;img style="width: 350px; height: 52px;" src="/articles/media/1023/bamboohrlogo.png?width=350&amp;amp;height=52" alt="BambooHR" data-udi="umb://media/500a0974ef3b49c3b18b6f7b50cbe16e" /&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;h2&gt;About BambooHR&lt;/h2&gt;
&lt;p&gt;Serving more than 12,000 customers and supporting more than 1.1 million employees in over 100 countries, BambooHR is the leading provider of tools that power the strategic evolution of HR in small and medium businesses. BambooHR's cloud-based system is an intuitive, affordable way for growing companies to track and manage essential employee information in a personalized Human Resources Information System (HRIS). With BambooHR, HR managers have more time for meaningful work, executives get accurate, timely reports and employees can self-service their time off using a convenient mobile app. To find out more, visit &lt;a rel="noopener" href="https://www.bamboohr.com/lp/c-hr-saas-software/d/?utm_source=PT&amp;amp;utm_medium=MKP&amp;amp;utm_campaign=Effo-TR-FreeTrialR-20181009-01&amp;amp;utm_content=blank&amp;amp;utm_term=blank" target="_blank" title="bamboohr.com" data-anchor="?utm_source=Par-effadm-Ref"&gt;bamboohr.com&lt;/a&gt; or follow them on Twitter at &lt;a rel="noopener" href="https://twitter.com/bamboohr" target="_blank" title="@bamboohr"&gt;@bamboohr&lt;/a&gt;.&lt;/p&gt;</description>
      <pubDate>Fri, 30 Nov 2018 16:20:13 Z</pubDate>
      <a10:updated>2018-11-30T16:20:13Z</a10:updated>
    </item>
  </channel>
</rss>