ERISA & Plan Documents for Self-Funded Health Plans
When you self-fund your health plan, you become an ERISA plan sponsor — and that is a legal status with real obligations. Most employers understand the financial mechanics of self-funding. Far fewer understand what ERISA actually requires them to have in writing, what fiduciary duty means in practice, and what the CAA 2021 added to the compliance stack. Here is the full picture.
The four required documents
ERISA requires self-funded plan sponsors to maintain and distribute specific documents. Each has different content requirements, distribution rules, and penalty exposure. Most employers have some version of these — the question is whether they are current, accurate, and actually distributed.
Plan Document
What it is: The full legal governing instrument. Sets out all plan terms, eligibility rules, benefit structures, claims procedures, and amendment authority.
Distribution: Kept on file by the plan administrator. Not required to be distributed proactively.
Risk: If it doesn't exist or is outdated, the employer has no legal foundation for benefit decisions — and no defense in litigation.
Summary Plan Description (SPD)
What it is: Plain-language summary of the plan document. Must be written so the average participant can understand their rights and benefits.
Distribution: Must be distributed to every participant within 90 days of becoming covered. Updated every 5 years (or 10 years if no material changes).
Risk: Failure to distribute on request: up to $110/day per participant. Courts may interpret ambiguous terms against the employer.
Summary of Benefits and Coverage (SBC)
What it is: Standardized 4-page document using a federal template. Covers deductibles, out-of-pocket limits, covered services, and cost-sharing.
Distribution: Must be provided at open enrollment, upon request, and within 7 days of a special enrollment event.
Risk: Failure to provide: up to $1,362 per failure per participant (indexed annually).
Summary of Material Modification (SMM)
What it is: Notice of material changes to the plan. Required when the plan is amended in a way that materially affects participants' rights or benefits.
Distribution: Must be distributed within 210 days after the end of the plan year in which the change was adopted.
Risk: Participants who were not notified of a material change may be entitled to the prior, more favorable benefit.
The plan document vs. SPD conflict rule: If the plan document and SPD conflict, courts generally apply the interpretation most favorable to the participant — not the employer. An outdated SPD that describes benefits the plan no longer provides is a litigation liability, not just a paperwork gap.
Fiduciary duty: what it actually means
ERISA imposes fiduciary duties on anyone who exercises discretionary authority over the plan. For most self-funded employers, that means the HR director, the CFO, and the plan administrator are all fiduciaries — personally, not just as corporate officers. ERISA fiduciary breaches can result in personal liability for plan losses.
Duty of loyalty
Act solely in the interest of plan participants and beneficiaries — not in the interest of the employer as a company. This is the most frequently litigated fiduciary duty in health plan cases.
Example: Selecting a TPA or PBM based on the employer's existing vendor relationships rather than the plan's best interest is a potential breach.
Duty of prudence
Act with the care, skill, prudence, and diligence of a knowledgeable person familiar with such matters. Requires a documented, deliberate process — not just a good outcome.
Example: Renewing a PBM contract without benchmarking against alternatives or reviewing contract terms is a prudence risk.
Duty to follow the plan document
Administer the plan in accordance with the plan document and SPD. Benefit decisions must be consistent with written plan terms.
Example: Denying a claim based on an unwritten policy or approving a benefit not described in the plan document both create liability.
Duty to monitor service providers
Fiduciaries must periodically review the performance and fees of TPAs, PBMs, stop-loss carriers, and other service providers.
Example: Failing to review TPA administrative fees or PBM contract terms for multiple consecutive years is a monitoring failure.
Fiduciary liability insurance: Standard D&O policies typically exclude ERISA fiduciary claims. A separate ERISA fiduciary liability policy covers plan administrators and named fiduciaries for breach of duty claims. If your plan has significant assets or a large participant population, this coverage is worth evaluating.
CAA 2021: the compliance layer most employers are missing
The Consolidated Appropriations Act of 2021 added a significant new compliance layer on top of existing ERISA requirements. These obligations fall on the plan sponsor — not the TPA — even when the TPA handles day-to-day administration. Delegation does not eliminate liability.
Gag Clause Prohibition Attestation (GCPCA)
Responsible party: Plan sponsor files directly with CMS (or delegates to TPA)
Certifies that the plan's contracts with TPAs, providers, and networks do not contain gag clauses that restrict the plan's access to claims data, cost information, or quality metrics. Non-compliance: up to $100/day per participant.
Broker & Consultant Compensation Disclosure
Responsible party: Broker/consultant discloses to plan sponsor; plan sponsor must review and retain
Brokers and consultants receiving $1,000+ in direct or indirect compensation must disclose all compensation sources. The plan sponsor must request this disclosure and document receipt. Failure to request = fiduciary breach.
Mental Health Parity — NQTL Comparative Analysis
Responsible party: Plan sponsor (often with TPA or MHPAEA consultant)
Plans must document that non-quantitative treatment limitations (NQTLs) — prior authorization, step therapy, network standards — are no more restrictive for mental health/substance use benefits than for medical/surgical benefits. Regulators can request this analysis at any time.
Machine-Readable Files (MRFs)
Responsible party: TPA or carrier typically produces; plan sponsor is responsible
Plans must publish machine-readable files containing in-network negotiated rates and out-of-network allowed amounts. Most TPAs handle this, but the plan sponsor remains the responsible party. Confirm your TPA is compliant.
Prescription Drug Data Collection (RxDC)
Responsible party: Plan sponsor (typically delegated to TPA/PBM)
Annual report to CMS on prescription drug spending, top drugs by cost and utilization, and rebate data. Required for all group health plans. Most TPAs and PBMs handle submission, but the plan sponsor must confirm it was filed.
Common violations and penalty exposure
ERISA and CAA penalties are per-participant, not per-plan. For a 200-person employer, a single compliance gap can generate six-figure penalty exposure before any litigation costs.
| Violation | Penalty |
|---|---|
| No written plan document | No statutory cap — unlimited litigation exposure |
| SPD not distributed or outdated | Up to $110/day per participant on written request |
| SBC not provided | Up to $1,362 per failure per participant |
| Form 5500 not filed or late | $250/day, up to $150,000 per plan year |
| GCPCA not filed | Up to $100/day per participant |
| Broker compensation not requested/documented | Fiduciary breach — personal liability for plan losses |
Frequently asked questions
Can we use our TPA's standard plan document?
Yes — most TPAs provide a base plan document that can be customized. However, the plan sponsor (the employer) is responsible for ensuring the document accurately reflects the plan's actual terms and is kept current. A TPA's boilerplate document that hasn't been reviewed in years is a common source of compliance gaps.
What is a "wrap document" and do we need one?
A wrap document is a single ERISA plan document that wraps around multiple benefit programs (health, dental, vision, FSA, etc.) to satisfy the single-plan-document requirement under ERISA. It is not legally required, but it simplifies administration and reduces the risk of missing required plan document provisions across multiple benefit lines.
How often does the SPD need to be updated?
The SPD must be updated every 5 years if there have been material changes, or every 10 years if there have been no material changes. A Summary of Material Modification (SMM) must be distributed within 210 days after the end of the plan year in which a material change was adopted — you cannot wait for the next full SPD update.
Who is personally liable for ERISA fiduciary breaches?
Named fiduciaries and functional fiduciaries can be held personally liable for plan losses resulting from a breach. This means the HR director, CFO, or any individual who exercises discretionary authority over the plan can face personal liability — not just the company. ERISA fiduciary liability insurance (separate from D&O) is available and worth considering.
Upload your Summary Plan Description and get a structured analysis of missing required provisions, outdated language, and compliance gaps — with specific citations to ERISA and DOL guidance.
Includes a compliance readiness module — assess whether your plan document, SPD, and CAA obligations are in order before or after transitioning to self-funding.
Continue in this guide: