---
title: October | Compliance Brief
description: Employers must prepare for the 2026 Gag Clause Prohibition Compliance Attestation, ensuring compliance with health plan information sharing regulations.
---

<https://vereopartners.com/vereo-partners-blog>

# [October | Compliance Brief](https://vereopartners.com/vereo-partners-blog/october-compliance-brief)

 Written by [Compliance Team](https://vereopartners.com/vereo-partners-blog/author/compliance-team) | Oct 9, 2026, 12:30:27 AM

## 2026 Gag Clause Attestation Deadline

Employers sponsoring group health plans should have the Dec. 31, 2026, Gag Clause Prohibition Compliance Attestation (GCPCA) on their year-end compliance calendars.

The requirement stems from the Consolidated Appropriations Act, 2021 (CAA), which prohibits group health plans and health insurance issuers from entering into certain agreements that restrict access to provider cost and quality information or certain claims data. Plans and issuers generally must attest to compliance with these requirements each year. The Centers for Medicare & Medicaid Services (CMS) collects the attestations on behalf of the Departments of Labor, Health and Human Services, and the Treasury (collectively, “The Departments”).

For employers, the key question is not simply whether an attestation is required. Employers also need to determine who will submit it, which contracts and service providers are implicated, and what documentation supports the plan's compliance.

 

##### Quick Facts

- Deadline: The 2026 GCPCA is due Dec. 31, 2026. Annual attestations are due by December 31 each year.
- Plans covered: The requirement generally applies to fully insured and self-insured group health plans, including ERISA plans, non-federal governmental plans, and church plans subject to the Internal Revenue Code.
- Important exclusions: Plans and issuers that offer only excepted benefits are not required to attest. A plan otherwise subject to the requirement generally does not attest as to its excepted-benefit coverage.
- Service providers may help: A TPA or other service provider may submit an attestation on behalf of a self-insured plan under a written agreement. However, the legal obligation to provide a timely attestation remains with the self-insured plan.
- Submission is electronic: Attestations are submitted through the [CMS GCPCA webform](https://hios.cms.gov/HIOS-GCPCA-UI).

 

##### Background

The gag clause prohibition became effective on Dec. 27, 2020, when the CAA was enacted. It is intended to prevent contractual restrictions that interfere with a health plan's ability to obtain, use, or share certain information needed to understand health care costs and quality.

In general, covered plans and issuers may not enter into agreements with health care providers, provider networks or associations, third-party administrators (TPAs), or other service providers offering access to a provider network if those agreements directly or indirectly restrict the plan's ability to:

- Make provider-specific cost or quality information available to participants, beneficiaries, eligible individuals, plan sponsors, or referring providers.
- Electronically access de-identified claims and encounter information, consistent with applicable privacy requirements.
- Share that information with a business associate, consistent with applicable privacy requirements.

The restriction does not have to expressly say that information cannot be disclosed to violate the rule. The Departments have explained that a contractual term may constitute a prohibited gag clause if, in practice, it directly or indirectly restricts the plan from accessing, providing, or sharing the protected information.

 

##### Which Employer Plans Are Subject to the Requirement?

The attestation requirement applies broadly to employer-sponsored group health plans, including both fully insured and self-insured plans. Grandfathered status does not remove a plan from the requirement.

There are important exceptions.

- Plans and issuers do not need to attest with respect to coverage that consists of excepted benefits. Examples can include certain stand-alone dental and vision coverage and health flexible spending accounts (FSAs).
- Retiree-only group health plans are not required to attest.
- HRAs and other account-based group health plans are not required to submit GCPCAs. The Departments are exercising enforcement discretion until those plans can be exempted through rulemaking.

 

##### Look Beyond the Medical Carrier or TPA

Employers should not automatically limit their compliance review to the primary medical carrier or TPA.

The federal prohibition can apply to agreements with providers, provider networks, TPAs, and others providing access to a network of providers. Federal GCPCA materials specifically recognize provider or service agreements and list medical networks, pharmacy benefit manager (PBM) networks, behavioral health manager networks, and “other arrangements.”

This issue became even more important following [additional guidance](https://www.dol.gov/agencies/ebsa/about-ebsa/our-activities/resource-center/faqs/aca-part-69) from the Departments concerning downstream agreements. A plan may contract with a TPA or another service provider which in turn enters into separate agreements with other entities involved in providing or administering the plan's network. The Departments have clarified that prohibited restrictions in these downstream arrangements can affect the plan's compliance.

 

##### Who Submits the Attestation?

Often, carriers or TPAs can submit the attestation, but employers should confirm the arrangement rather than assume it.

For a fully insured group health plan, both the plan and the issuer are subject to the annual attestation requirement. However, when the issuer submits the GCPCA on behalf of the plan, the Departments will consider the plan's submission requirement satisfied. Employers should obtain written confirmation when a carrier, TPA, or another service provider has agreed to attest for the plan and confirm the scope of that filing.

For a self-insured or partially self-insured plan, the plan may enter into a written agreement under which a service provider, such as its TPA, submits the attestation on the plan's behalf. However, federal guidance states that the legal requirement to provide a timely attestation remains with the self-insured plan even when a service provider has agreed to perform the filing.

An employer with multiple vendors should also determine whether one vendor's filing covers all of the relevant agreements associated with the plan.

 

##### What If a Vendor Will Not Attest?

If a service provider will not submit the attestation on the plan's behalf, the employer will need to satisfy the filing requirement and obtain the information necessary to support the attestation. That may involve reviewing relevant agreements and obtaining written confirmation from service providers regarding their compliance with the gag clause prohibition.

Employers should also be careful not to treat a vendor's refusal to attest as the end of the inquiry. The plan still needs to evaluate its compliance and, when required, ensure that an attestation is submitted.

 

##### What If the Employer Finds a Prohibited Gag Clause?

The Departments have clarified that a plan still must submit its annual GCPCA even when it knows an agreement contains a prohibited provision that it has been unable to remove, including a restriction arising through a downstream agreement.

In that situation, the plan should use the “Additional Information” field in the GCPCA webform to identify the noncompliant provision and provide relevant information about the issue. Federal guidance indicates that this information should include but is not limited to:

- Any prohibited gag clauses that a service provider has refused to remove.
- The name of the TPA or service provider with which the plan or issuer has the agreement containing the prohibited gag clause.
- Conduct by the service provider that shows the service provider interprets the agreement to contain a prohibited gag clause.
- Information on the plan's or issuer's requests that the prohibited gag clause be removed from the agreement.
- Any other steps the plan or issuer has taken to come into compliance with the provision.

Submitting this information does not make the prohibited provision compliant. The Departments may still take enforcement action regarding the underlying violation. However, the Departments have stated that a plan submitting an attestation with the required additional information will be considered to have satisfied the requirement to submit the GCPCA, and that good-faith efforts to self-report will be considered in an enforcement action.

This distinction is important; employers should not simply skip the filing because a compliance problem has been discovered.

 

##### How Is the Attestation Submitted?

CMS provides an electronic [Gag Clause Prohibition Compliance Attestation webform](https://hios.cms.gov/HIOS-GCPCA-UI). The process begins by entering an email address and obtaining an authentication code. CMS's user manual states that access codes are valid for 14 days.

The webform collects information concerning the submitter, attester, and responsible entity. CMS also provides instructions, a user manual, and an Excel template for situations involving multiple responsible entities.

Employers completing their own filing should allow enough time before December 31 to obtain access, gather plan information, resolve questions about vendor arrangements, and complete the submission.

 

##### Employer Action Items

- Identify plans subject to the requirement. Determine which employer-sponsored health plans must submit a GCPCA and whether any benefits qualify for an applicable exception or enforcement discretion.
- Inventory relevant service providers and arrangements. Consider the medical carrier or TPA as well as PBMs, behavioral health network arrangements, and other service providers offering access to provider networks.
- Determine who will file. Ask each applicable carrier, TPA, or other service provider whether it will submit the 2026 attestation on the plan's behalf.
- Get the arrangement in writing. For a self-insured plan relying on a service provider to submit the GCPCA, federal guidance specifies a written agreement. Retain documentation showing the provider's commitment and the plans or agreements covered by its filing.
- Address gaps in vendor filing. If a vendor is not filing for the plan, determine what additional contract review, compliance confirmation, or employer submission is necessary.
- Investigate potential prohibited restrictions. Do not overlook indirect restrictions or limitations contained in downstream agreements. If a prohibited provision cannot be removed, review the Departments' guidance regarding disclosure through the GCPCA's Additional Information field.
- Submit by Dec. 31, 2026. If the plan is responsible for its own filing, complete the GCPCA through the CMS webform by the annual deadline.

### DOL Clarifies MHPAEA Enforcement Priorities

The U.S. Department of Labor (DOL) has provided employers and group health plans with a clearer picture of how it intends to enforce the Mental Health Parity and Addiction Equity Act (MHPAEA).

The DOL issued [Field Assistance Bulletin 2026-03](https://beta.dol.gov/policy-regulations/reference-materials/guidance-searches/ebsa-field-assistance-bulletin-no-2026-03), outlining its current enforcement approach to the MHPAEA's requirements for non-quantitative treatment limitations (NQTLs). At the same time, the Employee Benefits Security Administration (EBSA) released a practical [enforcement guidance tool](https://beta.dol.gov/policy-regulations/pay-benefits/health-plans/mental-health-and-substance-use-disorder-parity/identifying-potential-problems-possible-mhpaea-compliance-problems) identifying common plan provisions and administrative practices that may signal potential parity problems.

This guidance is important because it follows a period of uncertainty surrounding the 2024 MHPAEA Final Rule. Although the Departments are not currently enforcing portions of that rule, the underlying MHPAEA requirements remain in effect, including the statutory requirement to perform and document comparative analyses of NQTLs.

For employers, the message is straightforward: MHPAEA compliance remains an active enforcement issue, but the EBSA has identified specific areas where it intends to concentrate its resources.

 

##### Background

In September 2024, the Departments of Labor, Health and Human Services, and the Treasury issued a final rule that made significant changes to the regulations implementing the MHPAEA. Among other provisions, the rule addressed how plans evaluate NQTLs and expanded requirements associated with NQTL comparative analyses.

The rule subsequently became the subject of litigation. In May 2025, while reconsidering the rule, the Departments announced that they would not enforce the 2024 Final Rule—or pursue enforcement actions based on failures to comply with it occurring before a final decision in the litigation plus an additional 18 months—with respect to provisions that were new compared with the 2013 Final Rule.

The Departments specifically stated that MHPAEA's statutory requirements, including requirements added by the Consolidated Appropriations Act, 2021 (CAA), remain in effect. Among those requirements is the obligation for plans and issuers to perform and document comparative analyses regarding the design and application of NQTLs imposed on mental health and substance use disorder (MH/SUD) benefits.

 

##### EBSA Enforcement Priorities

Field Assistance Bulletin 2026-03 states that the EBSA will focus its NQTL comparative analysis enforcement resources on three categories where the agency believes there is the highest potential for significant harm to participants and beneficiaries.

 

##### 1. Separate Treatment Limitations and Exclusions

The EBSA will focus on treatment limitations that apply separately to MH/SUD benefits, particularly blanket treatment exclusions.

The fact that a plan covers a particular mental health condition does not necessarily mean its treatment limitations comply with the MHPAEA. EBSA guidance identifies several examples of provisions that may raise concerns when comparable restrictions do not apply to medical/surgical benefits. These include exclusions involving:

- Applied behavioral analysis (ABA), speech therapy, or occupational therapy for autism spectrum disorder
- Medications used to treat opioid or other substance use disorders
- Nutritional counseling or medical nutrition therapy for eating disorders
- Residential treatment, intensive outpatient treatment, or partial hospitalization for MH/SUD conditions

These examples are not automatic findings of a violation. Rather, the EBSA identifies them as potential red flags warranting further review.

 

##### 2. Medical Necessity Standards and Review Processes

The EBSA will examine how plans determine whether MH/SUD treatment is medically necessary and how utilization management procedures are administered. This includes prior authorization, concurrent review, and retrospective review.

For example, a potential concern may arise when prior authorization or concurrent review applies to all or nearly all MH/SUD benefits but applies to few or no medical/surgical benefits within the same benefit classification.

The agency also identifies potentially problematic differences in the way review procedures operate. For example, a plan could warrant additional scrutiny if its prior authorization system for medical/surgical benefits is largely automated while the process for MH/SUD benefits involves a more burdensome manual exchange of documents and information.

This highlights an important point for employers: compliance is not determined solely by what the plan document says.

 

##### 3. Network Adequacy

The EBSA's third priority is network adequacy, with particular attention to network admission standards and provider reimbursement methodologies.

Potential issues can arise when the processes for recruiting, admitting, or reimbursing MH/SUD providers differ from those applied to medical/surgical providers. EBSA enforcement guidance identifies potential concerns when:

- MH/SUD providers face more burdensome network admission processes.
- Participants have greater difficulty obtaining network gap exceptions for MH/SUD care.
- Provider reimbursement methodologies differ between MH/SUD and medical/surgical providers,
- Plans take steps to recruit medical/surgical providers where network shortages exist but do not make comparable efforts to address MH/SUD network gaps.
- Participants use out-of-network MH/SUD providers at substantially higher rates, potentially signaling problems with network access.

Where the EBSA identifies network adequacy parity issues, it will seek to ensure that plans and issuers consider available options to help participants obtain covered MH/SUD treatment without exposing them to out-of-network costs because the covered service is unavailable in-network.

Employers should not interpret the three priorities as a safe harbor for other NQTLs. Field Assistance Bulletin 2026-03 states that the EBSA may investigate other categories of NQTLs as issues arise, particularly in response to participant complaints. That makes participant experience an important part of an employer's compliance review.

For example, the EBSA's new guidance identifies disproportionate complaints about access to in-network MH/SUD providers as a potential operational red flag. Differences between written plan terms and actual claims administration can also draw scrutiny.

 

##### Recent Enforcement Shows What Is At Stake

The DOL's [2025 MHPAEA Report to Congress](https://beta.dol.gov/research-data/surveys-reports-publications/2025-mhpaea-report-congress), released in February 2026, provides additional context for the EBSA's new enforcement priorities.

During the report's enforcement period, the EBSA's NQTL work resulted in corrections affecting more than 18 million participants across more than 39,000 group health plans. According to the report, those corrections included more than:

- 130,000 participants receiving new or expanded access to treatment for opioid use disorder
- 800,000 participants facing fewer barriers to autism spectrum disorder treatment
- 2 million participants whose plans reduced prior authorization or concurrent review requirements for MH/SUD services
- 1.8 million participants receiving easier access to nutritional counseling for eating disorders

During the reporting period, the agency issued 25 initial determination letters finding MHPAEA violations involving 43 limitations. Prior authorization and provider network admission standards were the two most frequently represented categories, with other findings involving out-of-network reimbursement, exclusions, concurrent review, fail-first policies, telehealth exclusions, and other limitations.

The report also illustrates that corrective action may extend beyond changing plan terms prospectively. Depending on the circumstances, enforcement resolutions have involved removing exclusions, changing utilization management requirements, notifying affected participants, and reprocessing previously denied claims.

 

##### A Comparative Analysis Still Matters

One of the most important takeaways from recent developments is what has not changed.

The CAA amended the MHPAEA to require group health plans and issuers that impose NQTLs on MH/SUD benefits to perform and document comparative analyses examining the design and application of those NQTLs. Those statutory requirements remain in effect despite the current nonenforcement policy concerning the new portions of the 2024 Final Rule.

The EBSA's new guidance specifically tells plans selected for an NQTL compliance review to have their documentation ready, including coverage documents, comparative analyses, supporting documentation, and records showing monitoring activities. The agency also advises plans to be prepared to explain apparent disparities and demonstrate how an NQTL operates in practice.

In other words, obtaining a generic comparative analysis from a carrier or TPA may not end the employer's inquiry—particularly for a self-funded plan with customized benefits or multiple vendors.

 

##### What Should Employers Ask Their Carriers and TPAs?

The EBSA's new enforcement tool includes practical questions that plans can ask their service providers. For employers, these questions can help turn MHPAEA compliance from a document-gathering exercise into an ongoing oversight process.

Among other things, employers may want to ask their carrier, TPA, behavioral health vendor, or other applicable service provider if it:

- Has prepared comparative analyses applicable to the employer's specific plan.
- Will provide the underlying information necessary to evaluate MHPAEA compliance.
- Monitors MH/SUD and medical/surgical claims and out-of-network utilization.
- Identifies and addresses gaps in the MH/SUD provider network.
- Uses different prior authorization or utilization review processes for MH/SUD benefits.
- Tracks participant complaints involving access to MH/SUD care.
- Will assist the plan if it becomes the subject of a federal or state parity investigation.

These questions can be particularly important for self-funded employers, where the plan sponsor may rely heavily on TPAs, network administrators, PBMs, and behavioral health vendors to administer benefits and provide the data needed to evaluate compliance.

 

##### Employer Action Items

The September 2026 guidance provides employers with a useful opportunity to reassess their MHPAEA compliance process.

- Do not treat the 2024 Final Rule's nonenforcement policy as a suspension of the MHPAEA. The relief applies to portions of the 2024 Final Rule that are new compared with the 2013 regulations. The MHPAEA's statutory obligations, including the CAA's NQTL comparative analysis requirement, remain in effect.
- Confirm that required NQTL comparative analyses exist. Employers should work with their carrier, TPA, behavioral health vendor, and other applicable service providers to determine which NQTLs apply and whether appropriate comparative analyses have been prepared.
- Prioritize the same areas the EBSA is prioritizing. Review treatment exclusions, medical necessity and utilization management procedures, and network admission, adequacy, and reimbursement practices.
- Review operations, not only plan documents. A provision that appears neutral on paper can still raise a parity concern if it is administered more stringently for MH/SUD benefits. Claims practices, authorization turnaround times, denial information, out-of-network utilization, network access, and participant complaints may provide important information.
- Ask vendors for plan-specific information. Employers, particularly sponsors of self-funded plans, should understand what their service providers will supply if the EBSA requests a comparative analysis or supporting documentation.
- Document monitoring and corrective action. The EBSA's guidance specifically points to monitoring activities and recommends that plans take and document action when reviews identify disparities or other red flags.
- Address identified problems promptly. EBSA examples show that voluntary corrections can include modifying plan provisions and administrative practices and, where appropriate, addressing prior participant harm.

### Medicare Part D Creditable Coverage Notices Due Before Oct. 15

Employers sponsoring group health plans that include prescription drug coverage should remember the upcoming [Medicare Part D creditable coverage](https://www.cms.gov/medicare/employers-plan-sponsors/creditable-coverage) notice deadline. The required notice must be provided to Medicare Part D-eligible individuals before October 15 each year, which coincides with the start of Medicare's annual enrollment period.

The notice tells individuals whether the employer's prescription drug coverage is creditable, meaning it is expected to pay, on average, at least as much as Medicare's standard prescription drug coverage, or non-creditable. This information is important because individuals who go without Medicare Part D or other creditable prescription drug coverage for a continuous period of 63 days or more after their initial enrollment period may be subject to a Part D late enrollment penalty. The Centers for Medicare & Medicaid Services (CMS) introduced important [changes](https://www.ubabenefits.com/compliance-brief-may-2026.html) affecting Medicare Part D creditable coverage determinations beginning with plan years starting on or after Jan. 1, 2027. The updates will affect the way employer-sponsored health plans evaluate prescription drug coverage and comply with Medicare Part D disclosure requirements.

The disclosure requirement applies to Medicare-eligible individuals covered under the employer's prescription drug plan, including Medicare-eligible active employees and dependents, COBRA participants and dependents, individuals with disabilities, and retirees and their dependents, as applicable.

CMS provides [model coverage notices](https://www.cms.gov/medicare/employers-plan-sponsors/creditable-coverage/model-notice-letters) for creditable and non-creditable that employers may use and modify for this purpose.

 

##### Employer Action Items

Employers should confirm whether each prescription drug option is creditable or non-creditable and ensure the appropriate notice is distributed to Medicare-eligible individuals before October 15. Because employers may not always know which employees or dependents are Medicare-eligible, employers should review their distribution procedures to make sure all potentially eligible individuals receive the notice.

### Form 5500 Extended Filing Deadline Approaching

Plan sponsors and plan administrators of calendar-year employee benefit plans that timely filed Form 5558 to extend their 2025 Form 5500 filing deadline should keep October 15, 2026, on their compliance calendars.

Generally, Form 5500 is due by the last day of the seventh month after the close of the plan year. For plans with a Dec. 31, 2025, plan-year end, the normal filing deadline was July 31, 2026. A plan that timely filed a properly completed Form 5558 may obtain a one-time extension of up to 2½ months. For a calendar-year plan, the extended filing deadline is generally Oct. 15, 2026.

Form 5500 filings must be submitted electronically through the Department of Labor’s [EFAST2 system](https://www.efast.dol.gov/). The plan administrator must provide the required electronic signature for a Form 5500 or Form 5500-SF filed through EFAST2, although a preparer or other authorized service provider may assist with preparation and transmission of the filing.

An extension gives the filer more time to submit the annual return or report; it does not remove the filing obligation. Plan sponsors and administrators should avoid waiting until the final days before October 15 to resolve missing information, required schedules, or electronic-signature issues.

### Compliance Question of the Month | COBRA for Small Employer

**Q.** An employer has 25 total employees; however, 20 of those employees fall under a union plan and not the group coverage plan, so technically only 5 employees are signed up for coverage under the group plan. Should all 25 employees be counted for COBRA purposes, or only the 5 employees in the group plan, making this subject to a state continuation plan?

**A.** Yes, for COBRA purposes, you look at all employees of the employer. This includes union employees who may have coverage elsewhere. Based on the numbers below, the employer is subject to COBRA.

 

This information is general information and provided for educational purposes only. It is not intended to provide legal advice. You should not act on this information without consulting legal counsel or other knowledgeable advisors.

[View full post](https://vereopartners.com/vereo-partners-blog/october-compliance-brief)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Compliance Team"
  },
  "dateModified" : "2026-10-09T00:30:27.855Z",
  "datePublished" : "2026-10-09T00:30:27Z",
  "headline" : "October | Compliance Brief",
  "image" : {
    "@type" : "ImageObject",
    "height" : 4480,
    "url" : "https://242731751.fs1.hubspotusercontent-na2.net/hubfs/242731751/romain-dancre-doplSDELX7E-unsplash.jpg",
    "width" : 5973
  },
  "mainEntityOfPage" : "https://vereopartners.com/vereo-partners-blog/october-compliance-brief",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Vereo Partners blog"
  }
}
```