Skip to main content

The December 31 Filing Most Small Health Plans Forget: A Gag Clause Attestation Guide

Published 11 min readMike ThriftMike Thrift
The December 31 Filing Most Small Health Plans Forget: A Gag Clause Attestation Guide
On this page

If your business offers a group health plan, you owe the federal government a filing every December 31 that no tax software reminds you about, no calendar invite announces, and your broker may never have mentioned. It is called the Gag Clause Prohibition Compliance Attestation, and missing it can expose your plan to enforcement action — including, benefits attorneys warn, penalties of up to $100 per day per affected individual.

The good news: for many small employers the filing takes minutes, and if your plan is fully insured, your carrier may already be handling it. The bad news: "may" is doing a lot of work there. This guide walks through what the attestation is, who actually has to file, what your vendors will and will not do for you, and the checklist to get it done before the year-end deadline.

What the Gag Clause Prohibition Actually Requires

The rule comes from Section 201 of the transparency provisions in the Consolidated Appropriations Act, 2021. It is now codified in three parallel places — Internal Revenue Code Section 9824, ERISA Section 724, and Public Health Service Act Section 2799A-9 — which is the federal government's way of making sure the rule reaches nearly every group health plan regardless of how it is funded or regulated.

The prohibition itself is straightforward. A group health plan or health insurance issuer may not enter into an agreement with a health care provider, a network or association of providers, a third-party administrator (TPA), or any other service provider offering access to a network of providers if that agreement directly or indirectly restricts the plan from doing three things:

  1. Sharing provider-specific cost or quality-of-care information with referring providers, the plan sponsor, participants, beneficiaries, enrollees, or people eligible to enroll — through a consumer engagement tool or any other means.
  2. Electronically accessing de-identified claims and encounter data for each covered individual upon request, consistent with HIPAA, GINA, and ADA privacy rules — including, on a per-claim basis, financial information such as the allowed amount and other claim-related financial obligations in the provider contract.
  3. Sharing that data with a business associate, or directing that it be shared, again consistent with applicable privacy rules.

In plain terms: the contracts between your health plan and everyone who administers or provides care under it cannot hide what care costs, block you from seeing your own claims data, or stop you from handing that data to your auditor or consultant. Any contract term that does that is a "gag clause," and it has been prohibited since the law took effect.

The annual attestation is how you prove it. Plans and issuers must submit a Gag Clause Prohibition Compliance Attestation (GCPCA) to the Departments of Labor, Health and Human Services, and the Treasury every year, with the Centers for Medicare & Medicaid Services collecting the filings on behalf of all three. The first attestation was due December 31, 2023, and every December 31 since is its own deadline.

Who Has to File — and Who Is Off the Hook

The attestation requirement applies to group health plans broadly: ERISA-covered plans, church plans, and governmental plans alike, plus health insurance issuers. Plan size does not matter. A ten-person company with a group health plan has the same filing obligation as a ten-thousand-person one.

A few arrangements are outside the rule's scope. Excepted benefits (such as stand-alone dental or vision plans), health reimbursement arrangements (HRAs), and other account-based plans are not subject to the gag clause prohibition, so they do not attest. But if you offer a standard group medical plan — fully insured or self-funded — you are in scope, and you need a filing covering it.

The single most important distinction is how your plan is funded, because it decides whose hands do the filing:

Fully insured plans: your carrier files, but verify it. If a medical insurance carrier files an attestation covering all of the insured medical plans you sponsor, that filing relieves you of submitting a separate one for those plans. In practice, most carriers do file for their fully insured blocks. Your job is to get that in writing — a confirmation from the carrier that it filed (or will file) on your plan's behalf, kept with your benefit plan records. An assumption is not a compliance file.

Self-funded plans: you file unless a vendor covers every agreement. Self-funded employers — including level-funded arrangements, which are self-funded plans for compliance purposes — must confirm whether their TPA, pharmacy benefit manager (PBM), or other vendors will attest on the plan's behalf. If a vendor attests for all agreements under your plan, you do not need a separate filing. If it covers only some of them, you file for the rest; the HIOS webform lets you select exactly which programs and contracts you are attesting for. And critically, even when a vendor files for you, the legal obligation remains with the plan. A vendor's missed filing is your missed filing.

Mixed offerings need mixed answers. If you offer both an insured medical plan and a self-insured one — say, insured medical with a self-funded dental wrap — the carrier's attestation covers only the insured piece. The self-insured piece needs its own coverage, from you or from a vendor willing to file for it.

What Your TPA Will Not Do for You

This is where small employers get tripped up. Many assume the TPA handles "all the compliance." For the gag clause attestation, that assumption fails in several specific ways.

Many TPAs will not file on your behalf at all. Filing requires the vendor to stand behind the attestation in a federal system under its own reporting-entity account, and plenty of TPAs and PBMs simply decline. What they will usually provide instead is a statement confirming that their contract with your plan contains no gag clause. That letter is useful evidence for your files — it is not a filing. If no vendor files for a given agreement, the plan sponsor must.

Your TPA's subcontractors count too. Under tri-agency guidance, your plan violates the prohibition if your TPA subcontracts network or plan administration to a third party and that downstream agreement restricts your access to cost, quality, or claims data. You attested to your own contracts; the guidance extends the attestation to contracts you have never seen. Ask your TPA directly whether its downstream agreements preserve your data rights, and get the answer in writing.

"At our discretion" is a gag clause. The agencies have made clear that if your ability to share de-identified claims data with a business associate is left to the discretion of the provider, network, TPA, or vendor, the contract is deemed to contain a gag clause. Watch for discretionary language the same way you would watch for an outright ban.

Audit-access restrictions are gag clauses in disguise. Claims audits are how employers catch overpayments and verify that what the TPA paid matches the contract. The guidance lists several audit terms that cross the line: limiting access to a "statistically significant" or "minimum necessary" slice of claims, restricting access to narrow purposes such as audits only, capping review frequency (for example, no more than once a year), limiting the number or types of claims you may see, stripping data elements out of the claims you do see, or allowing access only on the vendor's physical premises. If your administrative services agreement contains any of these, it needs renegotiation — and meanwhile, you still have to file.

Yes, You File Even If Your Contracts Are Not Clean

One of the most misunderstood points: discovering a gag clause in your agreements does not excuse you from attesting. It changes what you attest to.

Plan sponsors whose service agreements contain prohibited terms must still complete the attestation through HIOS. In the Additional Information box in the Responsible Entity's Details section, you disclose the situation: which prohibited clauses a provider has refused to remove, the name of the TPA or vendor involved, conduct showing the vendor treats the agreement as restricting your data rights, evidence that you asked for the clause's removal, and any other steps you have taken toward compliance. The text box is limited to 1,000 words, so be succinct — and keep the full paper trail behind it in your own records.

The message to take from this is practical, not punitive: regulators would rather see a plan that files honestly about a vendor dispute than a plan that goes silent. Document every removal request in writing, save every response, and file on time regardless.

What a Missed Filing Can Cost

The CAA itself does not spell out a specific penalty for skipping the attestation. Instead, the tri-agency FAQs state that plans and issuers that miss the deadline "may be subject to enforcement action." Benefits attorneys read that as opening the door to the standard penalty schemes: an excise tax of up to $100 per day per affected individual under Internal Revenue Code Section 4980D, civil penalties under ERISA, or both.

Just as concerning for a small business is what a missing attestation signals. Federal audits rarely examine one requirement in isolation. A plan that skipped an annual filing it did not know about looks, to an auditor, like a plan whose compliance program has gaps — and auditors who find one gap tend to keep looking. The attestation is also cheap insurance in ERISA litigation touching plan administration: a filed GCPCA with a confirmation email is a one-page exhibit that your plan took its transparency duties seriously.

One more practical note: CMS now sends a confirmation email acknowledging successful submission, and the HIOS site lets you print or download a copy of the filing. Save both with your other benefit plan records. A filing you cannot prove is barely better than a filing you never made.

Your December 31 Checklist

Submissions are accepted through HIOS all year, so there is no reason to wait for December. Here is the sequence to work through this fall:

  1. Inventory every agreement. List your carrier, TPA, PBM, and any other vendor offering access to a provider network — plus any plan you sponsor that is self-funded in whole or in part. Mixed offerings need a filing (or vendor coverage) for each piece.
  2. Ask each vendor two questions in writing. Will you file the 2026 attestation on our plan's behalf, covering all of our agreements with you? And do our agreements — including your downstream agreements — contain any term restricting our access to cost, quality, or de-identified claims data? Save every answer.
  3. Review the contracts behind the answers. Skim your administrative services and network agreements for discretionary data-sharing language and the audit-access restrictions described above. Flag anything questionable for your benefits attorney or broker now, not in late December.
  4. File what is yours in HIOS. For 2026, the attestation covers the period since your last filing through the date of this one — for example, a plan that filed November 30, 2025 and files again November 15, 2026 attests to December 1, 2025 through November 15, 2026, with 2026 as the attestation year. CMS publishes instructions, a user manual, and a responsible-entity template on its GCPCA page; the Marketplace Service Desk answers questions by email and phone.
  5. Close the loop on paper. Download the submission, save the CMS confirmation email, and file both alongside the vendor confirmations from step 2. If a vendor refused to remove a gag clause, keep the request-and-response thread with the same records.

If you only take one action from this article, make it step 2. The employers who get hurt by this requirement are not the ones with imperfect contracts — they are the ones who assumed someone else was filing.

Keep Your Compliance Paperwork as Organized as Your Books

Benefits compliance runs on the same discipline as bookkeeping: every obligation needs an owner, a deadline, and a paper trail. Vendor confirmations, HIOS submissions, and contract-review notes deserve the same version-controlled, searchable home as your financial records — because the audit that asks for one will eventually ask for the other.

Beancount.io provides plain-text accounting that gives you complete transparency and control over your financial data — no black boxes, no vendor lock-in. Get started for free and see why developers and finance professionals are switching to plain-text accounting.

Share this article

Source: https://beancount.io/blog/2026/09/16/gag-clause-attestation-december-31-hios-filing-guide

Published: September 16, 2026