Skip to main content
Employer Benefits IQ

Compliance Health Check™ — ACA, ERISA & HIPAA Employer Assessment

All ToolsEmployer Benefits IQ
LinkedInX
Employer ToolFree · No login required

Identify compliance gaps across ACA, ERISA, HIPAA, COBRA, CAA, and plan documents before they become costly penalties.

Rules-Based™
Regulatory information verified: August 2026

About This Assessment

Not legal advice. This tool identifies potential gaps for educational purposes. Consult an ERISA attorney for legal guidance.

Employer health plan compliance failures can result in excise taxes, DOL audits, participant lawsuits, and IRS penalties. This assessment evaluates your plan across multiple compliance categories — ACA employer mandate, ERISA plan documents, HIPAA privacy and security, COBRA administration, CAA transparency requirements, and more.

ACA Compliance

Employer mandate, reporting, affordability

ERISA Duties

Plan documents, fiduciary, claims

HIPAA

Privacy, security, portability

CAA 2021

Gag clause, RxDC, transparency

8 minutes12 questionsFree · No login required
Question 1 of 128% complete
ACA ComplianceHigh impact

Does your organization track and report ACA employer mandate compliance (Forms 1094-C / 1095-C)?

Frequently Asked Questions

What compliance requirements apply to employer health plans?

Employer health plans are subject to a complex web of federal requirements including: ERISA (plan documents, fiduciary duties, claims and appeals); ACA (employer mandate, reporting, affordability, preventive care); HIPAA (privacy, security, portability, special enrollment); COBRA (continuation coverage); CAA 2021 (gag clause attestation, RxDC reporting, mental health parity, transparency in coverage); and PCORI fees. State law requirements may also apply to fully-insured plans.

What are the most common employer health plan compliance violations?

The most common violations found in DOL audits include: deficient or outdated SPDs and plan documents; failure to provide required notices (COBRA, HIPAA, SBC); inadequate claims and appeals procedures; mental health parity violations; failure to file Form 5500; HIPAA security rule deficiencies; and failure to comply with CAA 2021 gag clause attestation and RxDC reporting requirements.

What are the penalties for employer health plan compliance failures?

Penalties vary by violation: ACA 4980H penalties are $3,340–$5,010 per employee annually (2026, IRS Rev. Proc. 2025-26); ERISA violations can result in $110/day per participant penalties for notice failures; HIPAA civil penalties are tiered by culpability — from $141 per violation (unknowing) up to $2.1 million per violation category per calendar year (willful neglect, uncorrected), adjusted annually for inflation (45 CFR § 160.404); COBRA failures can result in $110/day per qualified beneficiary; and fiduciary breaches can result in personal liability for plan losses. DOL audits have increased significantly since 2020.

What is the CAA 2021 gag clause attestation requirement?

The Consolidated Appropriations Act of 2021 prohibits health plans from entering into contracts with providers, networks, or TPAs that restrict the plan's access to cost and quality data. Employers must annually attest to the DOL and HHS that their contracts do not contain prohibited gag clauses. The attestation is due by December 31 each year. Failure to attest can result in penalties and increased audit scrutiny.

How often should employers conduct a compliance audit?

Employers should conduct a comprehensive compliance audit annually — ideally 60–90 days before plan renewal to allow time to address findings. At minimum, employers should review: SPD and plan document currency; required notice distribution; Form 5500 filing status; COBRA administration procedures; HIPAA security risk assessment; and CAA 2021 attestation status. The Compliance Health Check™ provides a structured framework for this annual review.

Was this tool helpful?

Tool outputs are for informational and comparison purposes only. Results do not constitute a recommendation or endorsement of any vendor or approach. Verify all data independently and consult a qualified benefits advisor before making procurement or plan decisions. AI policy

Uploaded documents are deleted immediately after processing and are never used to train AI models. Document security policy