Employer Healthcare Compliance
Employer-sponsored health plans operate under a dense and overlapping web of federal law — ERISA, ACA, COBRA, HIPAA, and the Consolidated Appropriations Act. The penalties for non-compliance are not theoretical. They are assessed per employee, per day, and per violation. This hub covers every major compliance obligation, with the depth employers and their advisors need to act.
Why employer health plan compliance is harder than it looks
Most employers understand that they have compliance obligations. Fewer understand how many distinct legal frameworks apply simultaneously — or how the obligations differ depending on whether the plan is fully insured or self-funded.
A self-funded employer health plan is simultaneously subject to ERISA (fiduciary duty, plan documents, SPD), the ACA (employer mandate, reporting, minimum value), COBRA (continuation coverage notices and administration), HIPAA (privacy and security rules for the plan itself), and the CAA (gag clause attestation, mental health parity analysis, RxDC reporting, surprise billing protections). Each framework has its own deadlines, its own penalties, and its own enforcement agency.
Fully insured plans have a lighter compliance burden — the carrier handles most HIPAA and some ERISA obligations — but ALEs with fully insured plans still face the full ACA employer mandate, COBRA administration, and CAA transparency requirements. The compliance gap between "we have a group health plan" and "we are fully compliant" is wider than most employers realize.
Key penalty exposure by law
| Law | Trigger | Penalty |
|---|---|---|
| ACA 4980H(a) | No MEC offered to 95%+ of FTEs | ~$3,340/FTE (minus first 30) |
| ACA 4980H(b) | Unaffordable or no minimum value | ~$5,010/affected FTE |
| COBRA | Late or missing notice | $110/day per qualified beneficiary |
| HIPAA | Privacy/security violation | $100–$50,000+ per violation |
| ERISA | Fiduciary breach | Personal liability; plan restoration |
| CAA gag clause | Missing annual attestation | $100/day per affected individual |
| PCORI fee | Late or missing filing | Failure-to-file penalties apply |
Compliance topics
ACA Employer Mandate
4980H requirements, minimum essential coverage, affordability, and penalty calculations for ALEs.
ERISA Fiduciary Duty
Prudent expert standard, duty of loyalty, prohibited transactions, and fiduciary liability for plan sponsors.
CAA 2021 Transparency
Gag clause attestation, mental health parity analysis, surprise billing, and RxDC reporting obligations.
HIPAA for Employers
Privacy and security rules for self-funded plans — what applies, what doesn't, and common violations.
COBRA Compliance
Qualifying events, notice deadlines, election periods, premium rules, and the most common COBRA mistakes.
State Mandates
State-level health insurance mandates, continuation coverage laws, and how they interact with ERISA.
Compliance Calendar
Annual compliance deadlines — ACA reporting, PCORI fees, gag clause attestation, and more.
Compliance FAQ
Answers to the most common employer healthcare compliance questions.
Self-funded vs. fully insured: the compliance difference
The single most important variable in employer health plan compliance is whether the plan is self-funded or fully insured. Self-funded plans are ERISA plans — the employer is the plan sponsor and a named fiduciary. Fully insured plans are also subject to ERISA, but the carrier absorbs most of the HIPAA and some of the plan document obligations. The table below shows where the obligations differ.
| Obligation | Self-funded | Fully insured |
|---|---|---|
| ERISA plan document + SPD | Employer responsible | Employer responsible |
| HIPAA privacy officer | Required | Carrier handles; employer has limited role |
| HIPAA security rule | Full compliance required | Carrier handles for plan; employer has limited role |
| ACA employer mandate | Full 4980H obligations | Full 4980H obligations |
| ACA 1094/1095 reporting | Employer files | Carrier files 1095-B; employer files 1095-C (ALEs) |
| COBRA administration | Employer responsible (often outsourced) | Employer responsible (often outsourced) |
| CAA gag clause attestation | Employer attests | Employer attests (carrier assists) |
| CAA MHPAEA analysis | Employer responsible | Carrier provides; employer must review |
| RxDC reporting | Employer responsible | Carrier files on employer's behalf |
| PCORI fee | Employer pays | Carrier pays |
Estimate your 4980H(a) and 4980H(b) employer shared responsibility exposure.
Score your plan's compliance posture across ACA, ERISA, COBRA, HIPAA, and CAA.
Evaluate your plan's CAA transparency obligations and identify gaps.
From the blog
CAA 2026: What Employers Must Do Now on PBM Transparency
The CAA 2026 mandates specific PBM transparency disclosures and contract terms. Here is exactly what self-funded employers must require from their PBMs — and the deadlines that apply.
Read article ERISA FiduciaryERISA Fiduciary Duty: What Every Plan Sponsor Must Understand
Courts are holding employers to a higher standard — and the CAA 2026 raises the bar further. A plain-language guide to what fiduciary duty means for your health plan decisions in 2026.
Read article ERISA LitigationERISA Litigation Is Expanding — and Plan Sponsors Should Pay Attention
Courts are holding employers to a higher fiduciary standard on health plan decisions. What the expanding ERISA litigation landscape means for self-funded plan sponsors.
Read article Fiduciary DutyFiduciary Duty and the Health Plan: What Every Employer Needs to Understand
Self-funded employers are ERISA fiduciaries — and that carries real legal obligations. A plain-language guide to what fiduciary duty means for your health plan decisions.
Read articleFree tool
Score your plan's compliance posture in 10 minutes
The Compliance Health Check evaluates your plan across ACA, ERISA, COBRA, HIPAA, and CAA — and shows you exactly where the gaps are before a regulator does.