Employee Benefits
COMPLIANCE RESOURCE CENTER
Bookmark this page for timely compliance alerts and updates on evolving employee benefits regulations, along with practical insights to help interpret changes for your workforce.
As part of Foundation Risk Partners, our employee benefits compliance team, including experienced ERISA attorneys, monitors complex state and federal requirements and delivers clear, actionable guidance you can trust, helping you mitigate risk, avoid penalties and navigate compliance with confidence.
Download our 2026 Employee Benefits Compliance Calendar for a clear, practical view of what lies ahead.
Home → Compliance Resource Center
On June 18, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with a group health plan (the Plan) to resolve an OCR investigation that commenced in 2022 after the Plan discovered that an unauthorized actor accessed the company’s network, deployed ransomware, and compromised its systems. This incident potentially affected the private health information (PHI) of 10,023 individuals, including health plan members’ names, addresses, zip codes, phone numbers, email addresses and social security numbers. OCR determined that the Plan had potentially violated provisions of the HIPAA Privacy and Security Rules, including failing to conduct an accurate and thorough risk analysis to determine potential risks and vulnerabilities to ePHI prior to the breach. In addition, the Plan failed to implement reasonable and appropriate policies and procedures to comply with HIPAA prior to the breach. Under the settlement terms, the Plan paid $450,000 and agreed to a two-year corrective action plan monitored by OCR. To mitigate or prevent HIPAA liability from cyber-threats, employers should ensure that their group health plans have comprehensive HIPAA policies and procedures in place, including a risk analysis.
- 08.11.2026
- 07.15.2026
On June 18, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with a group health plan (the Plan) to resolve an OCR investigation that commenced in 2022 after the Plan discovered that an unauthorized actor accessed the company’s network, deployed ransomware, and compromised its systems. This incident potentially affected the private health information (PHI) of 10,023 individuals, including health plan members’ names, addresses, zip codes, phone numbers, email addresses and social security numbers. OCR determined that the Plan had potentially violated provisions of the HIPAA Privacy and Security Rules, including failing to conduct an accurate and thorough risk analysis to determine potential risks and vulnerabilities to ePHI prior to the breach. In addition, the Plan failed to implement reasonable and appropriate policies and procedures to comply with HIPAA prior to the breach. Under the settlement terms, the Plan paid $450,000 and agreed to a two-year corrective action plan monitored by OCR. To mitigate or prevent HIPAA liability from cyber-threats, employers should ensure that their group health plans have comprehensive HIPAA policies and procedures in place, including a risk analysis.
- 07.15.2026
On April 14, 2026, the U.S. Department of Labor Employee Benefits Security Administration (EBSA) announced a shift in their enforcement philosophy. EBSA announced in their Field Assistance Bulletin (FAB) that they will place a greater emphasis on compliance assistance, formal rulemaking, and amicus participation, rather than “regulation by enforcement.” According to the FAB, EBSA will focus its investigations on cybersecurity, benefit distributions, mental health parity and substance use disorder coverage, retirement asset management, No Suprises Act enforcement and fiduciary prudence. Further, greater emphasis will be placed on systemic risks as opposed to smaller plan-level issues.
- 07.15.2026
Effective June 1, 2026, the City of Chicago adopted amended paid leave, paid sick leave, and safe leave ordinance (“New Rules”) which clarify previous paid leave and paid sick leave policies. Among other issues, the New Rules clarify that non-exempt employees will accrue leave on all hours worked including overtime, whereas exempt employees accrue hours based on a maximum of 40 hours worked per week. The New Rules also provide additional guidance on permitted leave for childcare, which includes taking leave when a child’s place of care unexpectedly closes. The New Rules also clarify that the aforementioned “place of care” can include informal babysitting arrangements, and care by family members or friends in addition to formal arrangements such as schools or daycare. The New Rules further clarify that if an employer has a formal PTO policy in place that includes the ability to accrue time off, allows for the carrying over of hours, and permits use of the PTO hours for all permitted uses under the Chicago Ordinances, the employer does not need to maintain the separate policies. Last, the New Rules allow employers to take disciplinary action, which can include termination of employment, against employees who abuse paid sick leave.
- 07.15.2026
On June 2, 2026, The U.S. Department of Health and Human Services (“HHS”) published a notice (“Notice”) in the Federal Register informing covered entities that a federal court vacated certain provisions of the 2024 final regulation under Section 1557 of the Affordable Care Act (“2024 Final Rule”). As background, in May of 2024, HHS published the 2024 Final Rule, clarifying that the definition of discrimination based on sex includes discrimination based on gender identity. Shortly after the 2024 Final Rule took effect, a federal district court enjoined the gender identity provisions of the Final Rule, preventing them from taking effect. Later, the same federal district court formally vacated the provisions of the 2024 Final Rule that expanded Title IX’s definition of sex discrimination to include gender-identity discrimination. The Notice confirms that HHS and CMS will not enforce the vacated provisions that expanded Title IX’s definition of sex discrimination to include gender identity discrimination. All other provisions of the 2024 Final Rule remain in effect.
- 07.15.2026
On June 4, 2026, the U.S. Office of Personnel Management, Treasury, Department of Labor, and the Department of Health and Human Services (“Agencies”) issued a final regulation (45 CFR Part 149) (“Final Rule”) updating certain parts of the Federal Independent Dispute Resolution (“IDR”) Operations of the No Surprises Act. Effective June 11, this Final Rule updates the fee required to engage the IDR process from $115 to $15 per party per dispute. In order to utilize the IDR process, all health plans and issuers must register with the new IDR Registry to ensure that medical providers can identify payers. The Final Rule also ensures that the IDR negotiation process is handled through the IDR portal, using standardized forms with responses due within 15 business days. IDR entities must determine whether their dispute is IDR eligible within five business days, and payment determinations must be made within 30 business days. While the reduced fee already went into effect on June 11, 2026, most of the other provisions will go into effect August 3, 2026.
- 07.15.2026
On June 17, 2026, the U.S. Department of Labor (“DOL”) issued Technical Release 2026-02 (the “Guidance”) addressing whether Trump Accounts and related employer contribution programs are subject to ERISA. Trump Accounts, created by the One Big Beautiful Bill Act, are special savings accounts for eligible children under age 18. The DOL concluded that Trump Accounts and most employer-sponsored Trump Account Contribution Programs generally are not ERISA pension plans. The guidance further explains circumstances under which ERISA could apply to such programs, and outlines conditions under which employers may facilitate contributions without creating an ERISA-covered arrangement
- 07.15.2026
Effective July 20, 2026, the U.S. Centers for Medicare & Medicaid Services (CMS) finalized rules allowing certain plans without traditional provider networks (“non-network plans”) to qualify as ACA qualified health plans (QHPs) if they satisfy applicable provider access and certification requirements. Additionally, the final rules implement reporting requirements that apply from the 2028 plan year onward. Employers utilizing Individual Coverage HRAs (ICHRAs) should monitor whether these new Exchange offerings affect plan availability, pricing, or enrollment patterns.
- 07.15.2026
Effective January 1, 2027, the American Medical Association (AMA) will replace the traditional global maternity billing codes with a more detailed coding structure that separately reports antepartum care, labor management, delivery services, and postpartum care. The changes are intended to better reflect modern obstetrical care, including telehealth, remote monitoring and team-based care arrangements. While employers do not need to make plan design changes, the transition could create claims administration challenges and increase employee questions regarding maternity claim processing.
- 07.15.2026
Beginning July 1, 2027, Virginia will begin implementing a statewide paid sick leave law. Employees will accrue one hour of paid sick leave for every 30 hours worked, up to 40 hours annually. The law applies to employers with 50 or more employees beginning July 1, 2027; employers with 25 or more employees beginning January 1, 2028; and employers with one or more employees beginning January 1, 2029. Leave may be used for an employee’s or family member’s health needs and for certain domestic violence, sexual assault, or stalking-related purposes. Employers need not pay out unused leave on termination, but previously accrued leave generally must be reinstated if the employee is rehired within 12 months. Employers that violate the law may face administrative penalties and civil actions.
For questions on earlier news/guidance, please contact your Corporate Synergies Account Manager or call 877.426.7779.