Skip to main content
Employer Benefits IQ
Employer Guide

Employer Healthcare Compliance Guide

Healthcare compliance is one of the highest-stakes areas of benefits management. ACA penalties, ERISA fiduciary liability, COBRA notice failures, and HIPAA violations can each result in significant financial exposure. This guide walks you through every compliance obligation — and how to build a system that keeps you current.

The most common compliance failures are not complex legal questions — they are missed deadlines and undocumented processes. A compliance calendar and documented vendor review process eliminate most risk.

01

ACA employer mandate compliance

The ACA employer mandate (IRC Section 4980H) requires Applicable Large Employers (ALEs) — those with 50 or more full-time equivalent employees — to offer minimum essential coverage (MEC) to at least 95% of full-time employees and their dependents. Failure to comply triggers penalties of $3,340–$5,010 per full-time employee (2026 indexed amounts). Self-funded employers have the same ACA obligations as fully insured employers.

The ACA affordability threshold is indexed annually. Using the prior year's threshold can result in unexpected penalties. Verify the current year's threshold before setting employee contribution rates.

Determine ALE status: count full-time employees + FTE equivalents for prior calendar year
Track full-time employee hours monthly (30+ hours/week = full-time)
Confirm your plan offers minimum essential coverage (MEC)
Verify affordability: employee premium for self-only coverage ≤ 9.96% of household income (2026)
File Forms 1094-C and 1095-C by March 31 (electronic) or February 28 (paper)
Distribute 1095-C to employees by March 1
02

ERISA fiduciary compliance

ERISA imposes fiduciary duties on anyone who exercises discretionary authority over a health plan — including the employer as plan sponsor. The core duty is prudent process: you must act in the sole interest of plan participants, follow a documented process for vendor selection and monitoring, and ensure plan documents are current. ERISA fiduciary liability is personal — it cannot be indemnified by the employer.

ERISA fiduciary duty extends to investment decisions for 401(k) plans AND health plan vendor selection. Recent litigation has targeted employers who failed to benchmark health plan costs or conduct competitive vendor reviews.

Document your vendor selection process for TPA, PBM, stop-loss, and other vendors
Conduct annual vendor performance reviews and document findings
Ensure your Summary Plan Description (SPD) is current and distributed to all participants
Review plan documents annually for compliance with current law
Establish a benefits committee with documented meeting minutes
Consider fiduciary liability insurance for plan administrators
03

COBRA administration

COBRA requires employers with 20+ employees to offer continuation coverage to qualified beneficiaries who lose coverage due to a qualifying event. The most common compliance failures: missing the 14-day notice deadline after a qualifying event, incorrect premium calculations (102% of plan cost), and inadequate election period tracking.

COBRA penalties are $110/day per qualified beneficiary for failure to provide timely notice. A single missed notice can result in significant liability. Consider outsourcing COBRA administration to a specialized vendor.

Establish a qualifying event tracking system (termination, reduction in hours, divorce, etc.)
Send COBRA election notice within 14 days of qualifying event notification
Confirm premium amounts: 102% of plan cost (150% for disability extension)
Track 60-day election period and 45-day first premium payment deadline
Establish procedures for COBRA premium payment and grace periods
Coordinate COBRA administration with your TPA if they handle it
04

HIPAA compliance for self-funded plans

Self-funded health plans are covered entities under HIPAA and must comply with privacy and security rules. Key obligations: limit access to protected health information (PHI), train employees who handle PHI, establish a breach notification procedure, and execute Business Associate Agreements (BAAs) with all vendors who handle PHI.

HIPAA penalties range from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. Willful neglect violations carry mandatory minimum penalties of $10,000 per violation.

Identify all employees and vendors who have access to PHI
Execute Business Associate Agreements (BAAs) with all PHI-handling vendors
Train all employees who handle PHI on HIPAA privacy rules annually
Establish a breach notification procedure (60-day notification requirement)
Conduct annual HIPAA security risk assessment
Implement minimum necessary standard for PHI access
Establish a process for participant PHI access requests
05

State mandate compliance

State healthcare mandates add complexity for multi-state employers. While ERISA generally preempts state insurance laws for self-funded plans, some state mandates apply regardless. Key areas: state continuation coverage (mini-COBRA for smaller employers), mental health parity requirements, and state-specific notice requirements.

Identify all states where you have employees
Review state continuation coverage requirements (mini-COBRA) for each state
Confirm mental health parity compliance under federal and state law
Review state-specific notice requirements (SBC, CHIP notices, etc.)
Assess whether any state mandates apply despite ERISA preemption
Consult ERISA counsel for multi-state compliance questions
06

Required notices and disclosures

ERISA and ACA require employers to distribute numerous notices to plan participants throughout the year. Missing a required notice can result in penalties and participant lawsuits. The most commonly missed: Summary of Benefits and Coverage (SBC), CHIP notice, Medicare Part D creditable coverage notice, and Women's Health and Cancer Rights Act notice.

Distribute Summary of Benefits and Coverage (SBC) at enrollment and upon request
Send annual CHIP notice to all employees (by first day of plan year)
Send Medicare Part D creditable coverage notice annually (before October 15)
Distribute Women's Health and Cancer Rights Act notice annually
Send Newborns' and Mothers' Health Protection Act notice
Provide Summary Annual Report (SAR) within 9 months of plan year end
Distribute Summary of Material Modifications (SMM) within 60 days of plan changes
07

Build a compliance calendar

Healthcare compliance is deadline-driven. A compliance calendar is the most practical tool for staying current. Map every annual deadline — ACA filings, required notices, plan document reviews, and vendor performance reviews — to specific dates and assign ownership. Review and update the calendar at the start of each plan year.

Map all annual compliance deadlines to a shared calendar
Assign ownership for each compliance task
Set reminders 30 and 60 days before each deadline
Schedule annual plan document review with ERISA counsel
Schedule annual vendor performance reviews
Review compliance calendar at start of each plan year for regulatory changes

Key penalty reference

Penalty amounts are indexed annually. Verify current amounts with ERISA counsel.

ACA 4980H(a) penalty (no offer)
$3,340/FTE (2026)
IRS Rev. Proc. 2025-19
ACA 4980H(b) penalty (unaffordable)
$5,010/FTE (2026)
IRS Rev. Proc. 2025-19
COBRA notice failure
$110/day per beneficiary
ERISA §502(c)(1)
HIPAA privacy violation
$100–$50,000 per violation
HHS OCR
ERISA SPD failure to provide
$110/day per participant
ERISA §502(c)(1)