.png)
Self-funded employers are responsible for compliance with transparency in coverage rules even when a TPA handles the actual work. Enforcement is ramping up and Congress is moving toward mandatory audits. Penalties could reach $300 per member per day.
This guide covers what the TiC rules require and how TPAs fit into the compliance picture. It also addresses recent regulatory and legislative developments for employers in 2026.
The Transparency in Coverage (TiC) rules require group health plans to publicly disclose negotiated rates and cost-sharing information. The goal is simple: enable consumers and employers to compare healthcare prices before care.
These rules come from the Affordable Care Act and Consolidated Appropriations Act. They apply to most non-grandfathered group health plans, including self-funded arrangements.
For self-funded employers, TiC compliance typically falls to the third-party administrator (TPA) handling plan operations. A TPA processes claims, manages member services, and handles regulatory tasks for the employer's health plan.
However, the employer remains the plan sponsor and retains ultimate legal responsibility under ERISA, the federal law governing employee benefit plans. Delegating tasks to a TPA is permitted, but delegation doesn't eliminate employer liability if something goes wrong.
Self-funded employers occupy a unique position. Unlike fully insured plans where the insurance carrier handles compliance automatically, self-funded plans place the compliance burden on the employer. The employer is the plan fiduciary, and that carries weight when regulators come knocking.
The scale here matters. According to the KFF 2025 Employer Health Benefits Survey, 67% of covered workers are in self-funded plans. That number jumps to 80% at large firms.
Over 165 million Americans under 65 are on employer-sponsored coverage. Well over 100 million are in plans where the employer is directly responsible for TiC compliance.
The TiC final rule establishes four main disclosure categories. Understanding each clarifies what your TPA must deliver.
Plans must post negotiated rates for all covered items and services with in-network providers. Machine-readable files (MRFs) are large data files formatted in JSON that computers can process automatically. These files contain the dollar amounts your plan contracted to pay for office visits, surgeries, and more.
This requirement covers historical allowed amounts paid to out-of-network providers. The allowed amount is the maximum a plan will pay for a covered service. Publishing this data shows members what the plan paid for out-of-network care.
This requirement has had a complicated journey. Enforcement was deferred in 2021, then rescinded in 2023. As of the June 2025 Request for Information, enforcement is happening on a case-by-case basis while technical requirements and an implementation timeline are developed.
Employers would benefit from asking their TPA or pharmacy benefit manager (PBM) where they stand on Rx MRF readiness now, before the timeline lands.
The member-facing online tool lets plan participants request personalized cost estimates for shoppable services. The tool provides several key data points:
The TiC landscape has shifted dramatically since 2022. Three developments are changing the compliance calculus for self-funded employers.
The executive order directed HHS, DOL, and Treasury to enforce transparency rules and require actual prices rather than estimates. It also called for standardized data formats and increased enforcement activity.
According to CHIR's analysis, the era of light-touch TiC enforcement is ending. TPA performance gaps now carry more risk than a year ago.
The December 2025 proposed rule would reorganize files by provider network instead of by plan. It would also allow aggregation across self-insured plans and shift updates from monthly to quarterly. It would add four new contextual files including change logs and utilization data.
If finalized, administrative services agreement language on TiC duties will likely require updating. Change logs will make TPA errors visible and auditable in new ways.
This bipartisan bill passed the Senate HELP Committee on July 22, 2026. According to CHIR's analysis, it would codify TiC in statute and mandate MRF submission to regulators. It would also require annual audits of at least 200 group health plans and authorize penalties up to $300 per member per day.
One notable provision: the committee language would let a self-insured plan ask the carrier or TPA controlling pricing data to attest to its accuracy. The plan could then rely on that attestation for compliance.
However, there's currently no protection for the plan when an attestation is wrong. That gap applies when the carrier or TPA fails to fix errors after DOL notification.
State legislatures and courts aren't waiting for federal action. Indiana SB3 makes TPAs fiduciaries with transparency duties.
Employer data-access suits like Bricklayers v. Elevance and Aramark v. Aetna show sponsors enforcing their rights directly through litigation.
As Leader's Edge reported, the TPA transparency campaign is just beginning.
When contracted by a self-funded employer, TPAs assume the operational duties that make TiC compliance happen.
The TPA hosts files on a publicly accessible URL and ensures proper JSON schema formatting. This sounds straightforward, but technical requirements are exacting and formatting errors can render files unusable.
The TPA builds or licenses the self-service tool and integrates it with the member portal. Members interact with this tool directly, so functionality and accuracy matter for compliance and experience.
Files currently require monthly refresh to reflect current negotiated rates. The TPA manages data pipelines and publishing cadence. The December 2025 proposed rule would move updates to quarterly if finalized, though monthly remains the current requirement.
Delegation works, but only when documented properly. The administrative services agreement (ASA) or compliance addendum typically addresses several key elements:
Employers negotiating ASAs should build in attestation-style certifications and cure periods. This positions contracts to align with the Price Tags Act framework if it becomes law.
Under ERISA, the employer remains the plan fiduciary regardless of what the TPA contract says. Regulators may pursue the employer even when the TPA caused the failure. This makes ongoing oversight and documentation of TPA performance essential.
The financial exposure is substantial. Current law provides an excise tax of $100 per affected individual per day of noncompliance under IRC 4980D. DOL and HHS can also pursue enforcement actions and civil monetary penalties.
The Price Tags Act would raise the stakes considerably. According to CHIR's analysis, the bill authorizes civil penalties up to $300 per member per day, capped at $10 million per violation.
It also mandates annual audits of at least 200 group health plans. Beyond financial penalties, there's reputational risk and employee trust to consider.
Employers can take concrete steps now while Congress works through the legislative process.
Review ASA language to verify the TPA is explicitly responsible for each disclosure requirement. Consider adding attestation-style certifications and cure periods to align with federal requirements.
Manually check that files are live, downloadable, and formatted correctly. Confirm provider NPIs and TINs aren't being masked, which undermines transparency.
Spot-check sample rates against actual contract terms. Confirm monthly update timestamps. Benchmark against what the same carrier publishes for other plans in your market to identify discrepancies.
Maintain written records of compliance reviews, TPA certifications, correction requests, and remediation steps. This paper trail maps to the safe-harbor structure in the Price Tags attestation language.
TiC is one piece of a broader federal transparency framework. Understanding how the requirements relate helps avoid confusion:
Raw MRF data is massive and complex. A single carrier's files can contain billions of rate records, making manual analysis impractical for most employers. Yet this data represents an unprecedented opportunity for benchmarking, contract negotiation leverage, and network optimization.
Platforms like Gigasheet transform TiC data into actionable insights by processing billions of rates and surfacing outliers, contract issues, and market trends. Every rate traces back to its original source file, which becomes increasingly important as attestation requirements take shape. Independent verification is how sponsors will validate carrier and TPA attestations rather than taking them on faith.
Book a demo to see how Gigasheet helps self-funded employers act on TiC data.
Yes, ERISA governs most private-sector self-funded health plans and establishes the fiduciary framework for employer responsibility for plan compliance, including TiC disclosures.
A third-party administrator (TPA) is an independent company that handles claims processing and member services. It also manages regulatory compliance tasks on behalf of a self-funded employer's health plan.
Yes. The employer is the plan sponsor and fiduciary. Regulators may hold the employer liable for TiC violations even when a TPA was contractually responsible.
Machine-readable files currently require monthly updates. The December 2025 proposed rule would shift updates to quarterly if finalized.
Yes. Grandfathered group health plans that maintained their status since the ACA's enactment are exempt from TiC disclosure requirements.
The bill would codify TiC in statute and mandate audits of group health plans. It would raise penalties and let plan sponsors rely on formal accuracy attestations from carriers or TPAs. It passed the Senate HELP Committee on July 22, 2026 but is not yet law.