Skip to main content
Employer Benefits IQ
Compliance hub

Employer Healthcare Compliance

Employer-sponsored health plans operate under a dense and overlapping web of federal law — ERISA, ACA, COBRA, HIPAA, and the Consolidated Appropriations Act. The penalties for non-compliance are not theoretical. They are assessed per employee, per day, and per violation. This hub covers every major compliance obligation, with the depth employers and their advisors need to act.

Why employer health plan compliance is harder than it looks

Most employers understand that they have compliance obligations. Fewer understand how many distinct legal frameworks apply simultaneously — or how the obligations differ depending on whether the plan is fully insured or self-funded.

A self-funded employer health plan is simultaneously subject to ERISA (fiduciary duty, plan documents, SPD), the ACA (employer mandate, reporting, minimum value), COBRA (continuation coverage notices and administration), HIPAA (privacy and security rules for the plan itself), and the CAA (gag clause attestation, mental health parity analysis, RxDC reporting, surprise billing protections). Each framework has its own deadlines, its own penalties, and its own enforcement agency.

Fully insured plans have a lighter compliance burden — the carrier handles most HIPAA and some ERISA obligations — but ALEs with fully insured plans still face the full ACA employer mandate, COBRA administration, and CAA transparency requirements. The compliance gap between "we have a group health plan" and "we are fully compliant" is wider than most employers realize.

Key penalty exposure by law

LawTriggerPenalty
ACA 4980H(a)No MEC offered to 95%+ of FTEs~$3,340/FTE (minus first 30)
ACA 4980H(b)Unaffordable or no minimum value~$5,010/affected FTE
COBRALate or missing notice$110/day per qualified beneficiary
HIPAAPrivacy/security violation$100–$50,000+ per violation
ERISAFiduciary breachPersonal liability; plan restoration
CAA gag clauseMissing annual attestation$100/day per affected individual
PCORI feeLate or missing filingFailure-to-file penalties apply

Self-funded vs. fully insured: the compliance difference

The single most important variable in employer health plan compliance is whether the plan is self-funded or fully insured. Self-funded plans are ERISA plans — the employer is the plan sponsor and a named fiduciary. Fully insured plans are also subject to ERISA, but the carrier absorbs most of the HIPAA and some of the plan document obligations. The table below shows where the obligations differ.

ObligationSelf-fundedFully insured
ERISA plan document + SPDEmployer responsibleEmployer responsible
HIPAA privacy officerRequiredCarrier handles; employer has limited role
HIPAA security ruleFull compliance requiredCarrier handles for plan; employer has limited role
ACA employer mandateFull 4980H obligationsFull 4980H obligations
ACA 1094/1095 reportingEmployer filesCarrier files 1095-B; employer files 1095-C (ALEs)
COBRA administrationEmployer responsible (often outsourced)Employer responsible (often outsourced)
CAA gag clause attestationEmployer attestsEmployer attests (carrier assists)
CAA MHPAEA analysisEmployer responsibleCarrier provides; employer must review
RxDC reportingEmployer responsibleCarrier files on employer's behalf
PCORI feeEmployer paysCarrier pays
Related tools
ACA Penalty Calculator

Estimate your 4980H(a) and 4980H(b) employer shared responsibility exposure.

Compliance Health Check

Score your plan's compliance posture across ACA, ERISA, COBRA, HIPAA, and CAA.

CAA 2026 Compliance Assessment

Evaluate your plan's CAA transparency obligations and identify gaps.

Free tool

Score your plan's compliance posture in 10 minutes

The Compliance Health Check evaluates your plan across ACA, ERISA, COBRA, HIPAA, and CAA — and shows you exactly where the gaps are before a regulator does.