WellthCare

The Iceberg Beneath ERISA Reporting

For years, ERISA health plan reporting felt like a dusty annual ritual. Your TPA would drop a Form 5500 on your desk, maybe a Schedule A, and you’d check the boxes and move on. The questions were predictable: total contributions, total claims, a headcount here or there. Nobody lost sleep over it. That world, comfortable as it was, doesn’t exist anymore.

The Consolidated Appropriations Act of 2021 didn’t just add a new form. It introduced the Prescription Drug Data Collection - RxDC - and with it, carved a jagged new reality into an old, sleepy process. Suddenly, employers aren’t filing summary financials. They’re filing claims-level prescription drug spending data, member premium breakdowns, rebate disclosures, and service category spend - all stitched together from systems that were never designed to talk to each other. And somewhere deep in that stitching is a risk most plan sponsors haven’t seen yet.

The Old Reporting World Wasn’t Perfect, but It Was Simple

If you managed a self-insured health plan with over 100 participants, your ERISA reporting universe revolved around the Form 5500. Schedule A captured insured benefits. Schedule C disclosed service provider fees. Large plans added Schedule H. The data was broad, backward-looking, and relatively easy to batch-export from standard TPA or carrier systems. If something was slightly off, few people noticed and even fewer asked questions.

Plan administrators - and let’s be honest, that usually means the HR or finance team - could sign the filings after a quick review. The hard work happened upstream, buried in the vendor’s reporting queue. You trusted the output because the obligations were built for a paper-pushing era. That era lasted decades. It’s over.

RxDC Cracked the Glass

The RxDC requirement didn’t tweak the 5500. It created a parallel, data-hungry universe that most employers still aren’t equipped to navigate. Every year by June 1, group health plans must submit files that go far beyond high-level numbers. P2 breaks out average monthly premiums by market segment. D1 reports total drug spend split between the plan and members. D2 lists the 50 most frequently dispensed drugs, both brand and generic, plus the 50 costliest. D3 through D6 demand net spending details on the top 25 drugs, including every rebate, fee, and price concession. D8 pulls back the curtain on total health care spending, carved into hospital, professional, and other categories.

This isn’t just a new schedule to attach. It’s a deep, multidimensional look at how your plan spends money - and it forces information out of systems that have never had to agree on anything before. Medical TPAs, PBMs, stop-loss carriers, and specialty vendors all hold pieces of the puzzle. No one vendor holds the whole picture. Under ERISA, the plan administrator - the employer - owns the accuracy of the final submission. The Department of Labor, HHS, and Treasury are all looking. And most employers are pulling these filings together with spreadsheets and crossed fingers.

The Unseen Iceberg: Three Data Problems Nobody Prepared For

If you talk to benefits teams who’ve already been through a couple RxDC cycles, the polite version is “it’s complicated.” The honest version reveals a set of structural cracks that aren’t going to fix themselves.

First, nobody counts members the same way. Your PBM defines a covered life as anyone who filled a script. Your medical TPA counts based on enrollment files that might lag by a month. Your stop-loss carrier uses its own denominator for underwriting purposes. When it’s time to calculate the average monthly premium for the P2 file, which count becomes the source of truth? If you pick one, the math won’t match the others. If you blend them, you’re creating a methodology you may have to defend in an audit. Either way, the member-count mismatch trails through every aggregate field.

Second, data normalization is a quiet disaster. The RxDC template expects medical spending sorted into clean buckets: hospital, professional, pharmacy. But specialty drugs infused in a physician’s office often show up as medical claims, not pharmacy claims. The PBM may see zero dollars for those therapies while the medical TPA buries them in “outpatient hospital” or “clinic visit.” Without a data warehouse that cross-maps procedure codes and revenue codes, you risk double-reporting, underreporting, or simply mislabeling millions of dollars. One wrong category tag, and your D8 file becomes a work of fiction.

Third, and most dangerous, rebate and fee reporting exposes the fiduciary blind spot. Files D5 and D6 require full disclosure of drug rebates, service fees, and administrative costs retained by the PBM. Yet many PBM contracts still leave fee structures vague or buried in verbal agreements. The employer must file what the PBM delivers. But if a later audit shows underreported rebates, it’s not the PBM on the hook with the DOL - it’s the plan administrator who signed a filing they couldn’t verify. The DOL’s enforcement arm, EBSA, has been painfully clear: you can’t blindly delegate this duty. You have to actively monitor, and that requires systems that let you peek behind the curtain.

Why So Few Employers Feel Ready

The root cause isn’t laziness. It’s that every system in the benefits supply chain was built for periodic financial reconciliation, not continuous, multi-source data aggregation. Most mid-size and even large employers still manage RxDC reporting with emailed CSV files, manual merges, and last-minute calendar reminders. Each human touchpoint becomes an error multiplier. The process isn’t broken because anyone is incompetent - it’s broken because the systems gap has become the new compliance risk, and nobody trained for this.

And RxDC isn’t alone. It sits alongside the gag clause attestation, the Transparency in Coverage machine-readable files, and the looming Advanced Explanation of Benefits. Together, they draw a sharp line: health plan reporting is no longer about filling out forms. It’s about data governance at a fiduciary level.

Navigating Without Hitting the Iceberg

You don’t need to become a clinical analyst overnight. But you do need to build a few guardrails that didn’t exist before. Based on what’s working for organizations that are staying ahead of this, here’s where to start:

  1. Designate a single data governance owner for reporting. One person or committee needs clear authority over the RxDC submission. Document which vendor supplies each data element, how you reconcile conflicts, and who signs off. This paper trail is your first - and often most important - fiduciary layer.
  2. Demand data dictionaries and audit trail outputs from every vendor. During your next renewal or service review, require your PBM, TPA, and any carve-out vendors to provide version-controlled data layouts, reconciliation summaries, and plain-English documentation of how they map their internal codes to the CMS fields. You’re not auditing them yet; you’re gaining the ability to spot a mismatch before it gets filed.
  3. Bring in a middleware or aggregation platform. Even small-to-midsize employers are finding that benefits analytics platforms or third-party data warehouses - tools that ingest raw claims and enrollment feeds and normalize them - pay for themselves when measured against the cost of a DOL inquiry or a fiduciary breach claim. These tools can output RxDC-ready files without relying on a fragile patchwork of spreadsheets.
  4. Make RxDC a recurring fiduciary review agenda item. Add a standing slot in your benefits committee meetings to examine data validation reports, member-count reconciliation, and any red flags from vendor correspondences. Treat it with the same gravity you’d give a plan audit finding, because in the DOL’s eyes, it’s exactly that.

The quiet shift in ERISA reporting isn’t about government busywork. It’s about whether the people running health plans can see what’s happening inside them - and prove it when asked. If you’re still treating RxDC as a vendor upload you glance at before signing, you’re steering straight toward the part of the iceberg you can’t see. If you’re building the systems and habits to spot the risk before it mushrooms, you’re doing more than complying. You’re finally operating your plan with the kind of clarity that makes everything else - from cost management to employee trust - sharper too.

← Back to Blog