Health Plan Fiduciary Governance: A Compliance Checkup for Health Care Employers
Health care employers are accustomed to operating in heavily regulated environments. Hospitals, health systems, clinics, long-term care providers, and other health care entities routinely manage complex compliance obligations involving patient care, privacy, reimbursement, staffing, licensing, and quality. But one area that often receives less executive-level attention is the employer’s own group health plan.
That oversight gap is becoming more important as recent litigation and regulatory developments have put a spotlight on an employer’s fiduciary obligations under the Employee Retirement Income Security Act of 1974 (“ERISA”). Specifically, that group health and welfare benefit plans are subject to the same fiduciary standards and governance obligations as employer-sponsored retirement plans.
Why This Matters Now
Employers have historically treated ERISA fiduciary governance as primarily a retirement plan issue. Retirement committees, investment reviews, fee benchmarking, and documented meeting minutes are commonplace. Health and welfare plans, by contrast, have often been handled more informally by human resources, consultants, brokers, third-party administrators, pharmacy benefit managers, and insurers. And while under ERISA, health and welfare plans have always been subject to the same formal fiduciary governance procedures, several developments have increased the importance of applying those procedures to health and welfare benefit plans on the same basis as retirement plans.
First, employer-sponsored health plans are increasingly expensive, complex, and scrutinized. Many health care entities sponsor self-funded or level-funded plans, carve out pharmacy benefits, use multiple vendors, or rely on detailed network, claims, rebate, stop-loss, and administrative arrangements, making administration multi-faceted.
At the same time, litigation theories that historically focused on retirement plan fees and investments are increasingly appearing in the health plan context. Plaintiffs and regulators are asking whether plan fiduciaries acted prudently, monitored service providers, reviewed vendor compensation, and understood pharmacy benefit arrangements. Congress has also acted: the Consolidated Appropriations Act of 2026 includes pharmacy benefit manager reforms that, once effective, will require PBMs to disclose all direct and indirect compensation, pass through 100% of rebates to health plans, and specifically grant plans audit rights. (For more information about PBM reform, view our article here.)
Federal transparency rules also place renewed focus on data access. For example, federal law prohibits “gag clauses” in service agreements and requires employers to attest that their group health plans and insurers are not directly or indirectly restricting access to provider-specific cost or quality information.
Key Governance Questions
ERISA does not require fiduciaries to guarantee the lowest possible cost or the best possible outcome in every instance. It does, however, require a prudent process. For health care employers, that process should begin with several basic questions:
- Who has authority to make decisions for the health plan?
- Are those individuals aware that they may be acting as fiduciaries?
- Are fiduciary decisions documented?
- Are vendors selected and monitored through a reasoned process?
- Are fees, compensation, rebates, and other financial arrangements understood and negotiated?
- Are plan documents, summary plan descriptions, contracts, and administrative practices aligned?
- Is the employer able to access the data needed to evaluate plan performance?
- Are participant communications accurate and timely?
- Are claims, appeals, and compliance obligations being handled according to the plan documents and applicable law?
The answers to these questions should be part of a formal and documented governance structure.
Special Considerations for Health Care Entities
Health care employers face unique health plan governance issues because of the size and complexity of their workforces and benefit programs. Prescription drug costs, specialty medications, behavioral health coverage, provider networks, employee on-site clinics, wellness programs, and claims administration may all raise fiduciary oversight questions.
Pharmacy benefit arrangements deserve particular attention in light of recent PBM laws and regulations. (For more information on PBM reform, view our article here.)
Vendor oversight is also critical. Health plans often depend on consultants, brokers, TPAs, PBMs, stop-loss carriers, wellness vendors, and data analytics vendors. Selecting a vendor is not the end of the fiduciary process: plan fiduciaries should periodically review service agreements, negotiate them; and regularly examine fees, performance standards, claim denial trends, and compliance responsibilities.
Finally, health plans are subject to a growing number of substantive compliance requirements, including mental health parity rules, claims and appeals rules under ERISA, COBRA, HIPAA, ACA mandates, and other federal requirements. (For more information about the mental health parity rules, view our article here.)
Practical Next Steps
Health care employers should consider a fiduciary governance checkup for their group health and welfare benefit plans. The following steps may be a useful starting point:
- Identify who has discretionary authority over plan decisions.
- Create or update a health and welfare benefits committee, complete with a committee charter and delegation structure.
- Review vendor contracts for compensation, data access, audit rights, and termination provisions.
- Confirm responsibility for recurring compliance obligations, including COBRA, HIPAA, ACA reporting, mental health parity, Form 5500 reporting, participant notices, claims procedures, and gag clause attestations.
- Provide fiduciary training to individuals involved in plan decisions.
- Review fiduciary liability insurance and indemnification provisions.
Health care employers already bring discipline and documentation to their patient-facing compliance obligations, and to the fiduciary responsibilities owed with respect to their retirement plans. The same approach should apply to the employer’s own group health plan. A well-run fiduciary process does not require perfection, but it does require structure, attention, and a well-documented process. As health plan costs rise and litigation theories evolve, now is a good time for health care employers to give their group health plan a compliance checkup.

