You’ve done the fiduciary training. You’ve reviewed the investment menu. You’ve filed Form 5500 on time. You’re compliant, right?
Not so fast. There’s a hidden danger lurking in your self-insured plan, and it has nothing to do with stock funds or fee disclosures. It’s the claims adjudication system - the software that decides what gets paid and what gets denied, thousands of times a day. And most plan sponsors never once audit its logic.
Here’s the uncomfortable truth: that system is a fiduciary actor. ERISA holds you responsible for administering the plan “in accordance with the documents and instruments.” If your system’s code silently contradicts your plan document, every single claim processed that way is a potential breach. You own that risk - not your TPA, not the software vendor, and certainly not the algorithm.
The gap no one talks about
Most plan sponsors treat their third-party administrator like a utility. You pay them to process claims. They send reports. Everyone moves on. But here’s the kicker: your TPA’s contract explicitly disclaims fiduciary status. They provide a tool. You provide the plan document. The tool is supposed to follow the document… but what if it doesn’t?
I’ve seen cases where a plan document says “physical therapy covered at 80% after a $500 deductible,” but the system’s configuration applies 70% because of an old data mapping error. That mistake runs for months - or years - and costs the plan tens of thousands. And it’s the plan sponsor who gets sued, not the software company.
Three system risks that keep me up at night
1. The repricing engine that bleeds money
Your self-funded plan uses a PPO network to get discounts. But the repricing engine in most TPA systems applies a hierarchy: first contracted rate, then a percentage of billed charges, then a “usual and customary” fallback. If that fallback is set to the 50th percentile instead of the 80th, every out-of-network claim is overpaid by a few percentage points. It doesn’t sound like much, but over 10,000 claims, it adds up to real dollars. And it’s on you to validate the trigger hierarchy in that code.
2. The auto-admit logic that rewrote your plan
Some systems now automatically steer patients into narrow networks based on step-count data from the patient’s wearable. Your plan document never mentioned wearables. But the system created a new benefit pathway anyway. That’s an unauthorized plan amendment - and ERISA only allows amendments through formal plan documents. If a participant gets denied a claim because the system sent them to the wrong network, you’re on the hook.
3. The subrogation latency gap
Your plan has a subrogation clause. When a third party settles a liability claim, the plan should recoup the money it paid out. But how often does your system run that matching check? Quarterly? Annually? A 90-day gap between a settlement and a system recoupment means the plan is paying claims it could have recovered. That’s a failure to operate efficiently - and courts are starting to see it as a fiduciary lapse.
What you should audit right now
Stop auditing your TPA’s processes. Start auditing the system’s data. Here are three things you can ask for this week:
- The adjudication rule stack - a single-page document showing the order of claim payment operations: eligibility, coordination of benefits, network discount, medical necessity flag. If your TPA can’t provide it, that’s a red flag.
- The outlier threshold table - the dollar amount at which a claim is automatically flagged for manual review. Most systems default to $10,000. If your plan has high-cost claimants, that means no human sees a non-network claim until it hits five figures. You have a duty to set that threshold based on your plan’s actual risk profile.
- The reason code reconciliation - a report of the top five denial reason codes used by the system that are not explicitly described in your Summary Plan Description. If the system denies claims for “missing prior authorization” but your SPD only requires prior auth for inpatient procedures, the system is overwriting your plan language.
A radical but practical solution
I’ve seen a small number of sophisticated plan sponsors appoint a “systems fiduciary” - a named person under ERISA 3(16) who is explicitly responsible for the integrity of the claims adjudication algorithm. Not the investment advisor. Not the HR director. Someone who understands both ERISA law and database logic. That person ensures the system’s code matches the plan document exactly, and that any discrepancy is corrected within a defined window.
It sounds radical. But the law is moving in this direction. Courts are increasingly willing to hold plan sponsors accountable for the design and operation of their benefits systems, not just the words printed on paper.
Your next step
This week, ask your TPA this exact question: “Show me the last time a system logic error caused an incorrect claim payment or denial that took more than 90 days to correct.” If they can’t answer instantly, you have a fiduciary gap larger than any investment loss you will ever face.
Get ahead of this. Or get ready for a court ruling that applies fiduciary standards to your claims feed - and your wallet.
J.D. Vance has two decades of experience in health plan operations and ERISA litigation support. He has designed fiduciary audits for plans ranging from 50 lives to 500,000 lives.
