Skip to main content
Employer Benefits IQ
Compliance

ERISA & Plan Documents for Self-Funded Health Plans

When you self-fund your health plan, you become an ERISA plan sponsor — and that is a legal status with real obligations. Most employers understand the financial mechanics of self-funding. Far fewer understand what ERISA actually requires them to have in writing, what fiduciary duty means in practice, and what the CAA 2021 added to the compliance stack. Here is the full picture.

The four required documents

ERISA requires self-funded plan sponsors to maintain and distribute specific documents. Each has different content requirements, distribution rules, and penalty exposure. Most employers have some version of these — the question is whether they are current, accurate, and actually distributed.

Plan Document

What it is: The full legal governing instrument. Sets out all plan terms, eligibility rules, benefit structures, claims procedures, and amendment authority.

Distribution: Kept on file by the plan administrator. Not required to be distributed proactively.

Risk: If it doesn't exist or is outdated, the employer has no legal foundation for benefit decisions — and no defense in litigation.

Summary Plan Description (SPD)

What it is: Plain-language summary of the plan document. Must be written so the average participant can understand their rights and benefits.

Distribution: Must be distributed to every participant within 90 days of becoming covered. Updated every 5 years (or 10 years if no material changes).

Risk: Failure to distribute on request: up to $110/day per participant. Courts may interpret ambiguous terms against the employer.

Summary of Benefits and Coverage (SBC)

What it is: Standardized 4-page document using a federal template. Covers deductibles, out-of-pocket limits, covered services, and cost-sharing.

Distribution: Must be provided at open enrollment, upon request, and within 7 days of a special enrollment event.

Risk: Failure to provide: up to $1,362 per failure per participant (indexed annually).

Summary of Material Modification (SMM)

What it is: Notice of material changes to the plan. Required when the plan is amended in a way that materially affects participants' rights or benefits.

Distribution: Must be distributed within 210 days after the end of the plan year in which the change was adopted.

Risk: Participants who were not notified of a material change may be entitled to the prior, more favorable benefit.

The plan document vs. SPD conflict rule: If the plan document and SPD conflict, courts generally apply the interpretation most favorable to the participant — not the employer. An outdated SPD that describes benefits the plan no longer provides is a litigation liability, not just a paperwork gap.

Fiduciary duty: what it actually means

ERISA imposes fiduciary duties on anyone who exercises discretionary authority over the plan. For most self-funded employers, that means the HR director, the CFO, and the plan administrator are all fiduciaries — personally, not just as corporate officers. ERISA fiduciary breaches can result in personal liability for plan losses.

Duty of loyalty

Act solely in the interest of plan participants and beneficiaries — not in the interest of the employer as a company. This is the most frequently litigated fiduciary duty in health plan cases.

Example: Selecting a TPA or PBM based on the employer's existing vendor relationships rather than the plan's best interest is a potential breach.

Duty of prudence

Act with the care, skill, prudence, and diligence of a knowledgeable person familiar with such matters. Requires a documented, deliberate process — not just a good outcome.

Example: Renewing a PBM contract without benchmarking against alternatives or reviewing contract terms is a prudence risk.

Duty to follow the plan document

Administer the plan in accordance with the plan document and SPD. Benefit decisions must be consistent with written plan terms.

Example: Denying a claim based on an unwritten policy or approving a benefit not described in the plan document both create liability.

Duty to monitor service providers

Fiduciaries must periodically review the performance and fees of TPAs, PBMs, stop-loss carriers, and other service providers.

Example: Failing to review TPA administrative fees or PBM contract terms for multiple consecutive years is a monitoring failure.

Fiduciary liability insurance: Standard D&O policies typically exclude ERISA fiduciary claims. A separate ERISA fiduciary liability policy covers plan administrators and named fiduciaries for breach of duty claims. If your plan has significant assets or a large participant population, this coverage is worth evaluating.

CAA 2021: the compliance layer most employers are missing

The Consolidated Appropriations Act of 2021 added a significant new compliance layer on top of existing ERISA requirements. These obligations fall on the plan sponsor — not the TPA — even when the TPA handles day-to-day administration. Delegation does not eliminate liability.

Gag Clause Prohibition Attestation (GCPCA)

Annual — December 31

Responsible party: Plan sponsor files directly with CMS (or delegates to TPA)

Certifies that the plan's contracts with TPAs, providers, and networks do not contain gag clauses that restrict the plan's access to claims data, cost information, or quality metrics. Non-compliance: up to $100/day per participant.

Broker & Consultant Compensation Disclosure

Before contract execution or renewal

Responsible party: Broker/consultant discloses to plan sponsor; plan sponsor must review and retain

Brokers and consultants receiving $1,000+ in direct or indirect compensation must disclose all compensation sources. The plan sponsor must request this disclosure and document receipt. Failure to request = fiduciary breach.

Mental Health Parity — NQTL Comparative Analysis

Available upon request; updated annually

Responsible party: Plan sponsor (often with TPA or MHPAEA consultant)

Plans must document that non-quantitative treatment limitations (NQTLs) — prior authorization, step therapy, network standards — are no more restrictive for mental health/substance use benefits than for medical/surgical benefits. Regulators can request this analysis at any time.

Machine-Readable Files (MRFs)

Ongoing — updated monthly

Responsible party: TPA or carrier typically produces; plan sponsor is responsible

Plans must publish machine-readable files containing in-network negotiated rates and out-of-network allowed amounts. Most TPAs handle this, but the plan sponsor remains the responsible party. Confirm your TPA is compliant.

Prescription Drug Data Collection (RxDC)

Annual — June 1

Responsible party: Plan sponsor (typically delegated to TPA/PBM)

Annual report to CMS on prescription drug spending, top drugs by cost and utilization, and rebate data. Required for all group health plans. Most TPAs and PBMs handle submission, but the plan sponsor must confirm it was filed.

Common violations and penalty exposure

ERISA and CAA penalties are per-participant, not per-plan. For a 200-person employer, a single compliance gap can generate six-figure penalty exposure before any litigation costs.

ViolationPenalty
No written plan documentNo statutory cap — unlimited litigation exposure
SPD not distributed or outdatedUp to $110/day per participant on written request
SBC not providedUp to $1,362 per failure per participant
Form 5500 not filed or late$250/day, up to $150,000 per plan year
GCPCA not filedUp to $100/day per participant
Broker compensation not requested/documentedFiduciary breach — personal liability for plan losses

Frequently asked questions

Can we use our TPA's standard plan document?

Yes — most TPAs provide a base plan document that can be customized. However, the plan sponsor (the employer) is responsible for ensuring the document accurately reflects the plan's actual terms and is kept current. A TPA's boilerplate document that hasn't been reviewed in years is a common source of compliance gaps.

What is a "wrap document" and do we need one?

A wrap document is a single ERISA plan document that wraps around multiple benefit programs (health, dental, vision, FSA, etc.) to satisfy the single-plan-document requirement under ERISA. It is not legally required, but it simplifies administration and reduces the risk of missing required plan document provisions across multiple benefit lines.

How often does the SPD need to be updated?

The SPD must be updated every 5 years if there have been material changes, or every 10 years if there have been no material changes. A Summary of Material Modification (SMM) must be distributed within 210 days after the end of the plan year in which a material change was adopted — you cannot wait for the next full SPD update.

Who is personally liable for ERISA fiduciary breaches?

Named fiduciaries and functional fiduciaries can be held personally liable for plan losses resulting from a breach. This means the HR director, CFO, or any individual who exercises discretionary authority over the plan can face personal liability — not just the company. ERISA fiduciary liability insurance (separate from D&O) is available and worth considering.

Related tools
SPD IQ™ — AI-Powered SPD Review

Upload your Summary Plan Description and get a structured analysis of missing required provisions, outdated language, and compliance gaps — with specific citations to ERISA and DOL guidance.

Self-Funding Readiness Assessment

Includes a compliance readiness module — assess whether your plan document, SPD, and CAA obligations are in order before or after transitioning to self-funding.