Employers face steady pressure to control rising healthcare costs. Aggressive cost management strategies can also expose an organization to legal liability under federal laws such as ERISA, HIPAA, the ACA, and the ADA. Saving money is a legitimate goal, but mishandling these requirements can lead to lawsuits, penalties, and employee discrimination claims. These are the most common legal risks and how to mitigate them.
1. Violating ERISA's Fiduciary Duties
The Employee Retirement Income Security Act (ERISA) requires employers to act solely in the interest of plan participants. Cost management tactics that prioritize employer savings over participant benefits can breach fiduciary duty.
- Risk: Selecting high-deductible plans or narrow networks solely to cut costs, without ensuring adequate coverage for essential services.
- Risk: Failing to disclose plan design changes that limit access to care (e.g., removing a major hospital from a network) in a timely, clear manner.
Mitigation: Document a prudent process for cost decisions, including comparison of multiple plan options and evidence-based benefit designs. Regularly review plan documents for consistency with communicated benefits.
2. Transparency and Coverage Rule Compliance
The Affordable Care Act sets minimum coverage standards for some plans, including essential health benefits in the small group market. Price transparency duties come mainly from the Transparency in Coverage final rule and the Consolidated Appropriations Act of 2021. Most non-grandfathered plans must post machine-readable files of in-network negotiated rates and out-of-network allowed amounts and maintain an online price comparison tool. Cost management moves that hide costs or trim coverage can violate these rules.
- Risk: Implementing reference-based pricing without properly disclosing the methodology to employees.
- Risk: Reducing essential health benefits (EHBs) below ACA minimums, especially in small group plans.
Mitigation: Confirm the plan posts the required machine-readable files and price comparison tool on time. Provide employees with clear, accessible cost and coverage summaries.
3. HIPAA Privacy and Security Breaches
Using employee health data to design cost management initiatives (like wellness programs or disease management) can inadvertently violate HIPAA's Privacy Rule. Employers that are plan sponsors must de-identify data or secure valid authorizations before using protected health information (PHI).
- Risk: Sharing aggregated claims data with a wellness vendor without a HIPAA business associate agreement (BAA).
- Risk: Offering incentives for completing a health risk assessment that discriminates based on a health factor, triggering HIPAA nondiscrimination provisions.
Mitigation: Always use a BAA with third-party administrators. Limit data sharing to de-identified or aggregate data whenever possible. Review wellness program incentives against the five HIPAA requirements for health-contingent programs, including the 30% reward cap and the reasonable alternative standard.
4. Disability and Genetic Discrimination Under ADA and GINA
Cost management strategies that involve biometric screening, genetic testing, or fitness tracking can violate the Americans with Disabilities Act (ADA) and the Genetic Information Nondiscrimination Act (GINA) if not executed carefully.
- Risk: Requiring employees to complete a biometric screening as a condition of plan enrollment without offering reasonable accommodations.
- Risk: Asking about family medical history in a health risk assessment (HRA) and using that data to adjust premiums or contributions.
Mitigation: Keep health risk assessments voluntary and anonymous. Avoid collecting genetic information (including family history) in connection with employment decisions or plan tier assignments. Work with legal counsel on wellness incentives: a federal court vacated the EEOC's 2016 incentive rules under the ADA and GINA effective January 1, 2019, and no replacement has been finalized.
5. Benefit Mandates and Surprise Billing
State-level healthcare mandates (minimum coverage for specific treatments) and the federal No Surprises Act can complicate cost-cutting efforts.
- Risk: Excluding mental health or substance use disorder benefits to save costs, which may violate state parity laws or the Mental Health Parity and Addiction Equity Act (MHPAEA).
- Risk: Using a limited network that forces employees out-of-network, triggering surprise billing protections and potential penalties.
Mitigation: Maintain ongoing compliance monitoring for state benefit mandates. Design networks to include adequate in-network options for all key specialties. Implement clear out-of-network cost disclosure policies.
6. Contractual and Vendor Management Risks
Outsourcing cost management to third-party vendors (e.g., pharmacy benefit managers, telemedicine platforms) does not relieve the employer of legal responsibility. Vendor errors can create liability for the plan. Class actions filed since 2024 have pressed this point, including Lewandowski v. Johnson & Johnson, which alleged breaches of fiduciary duty over PBM drug pricing and fees. Courts have dismissed several of those suits on standing, leaving the pricing claims unresolved.
- Risk: A PBM's formulary design that breaches fiduciary duties by overpricing generics or steering patients to high-cost drugs.
- Risk: A wellness vendor failing to safeguard employee data, leading to a HIPAA breach.
Mitigation: Perform quarterly fiduciary reviews of vendor performance. Include audit rights, data security clauses, and indemnification in all vendor contracts. Use independent auditors to validate vendor cost assumptions.
7. Gag Clause Attestation and Parity Analyses
The Consolidated Appropriations Act of 2021 added compliance duties that many cost-management reviews miss. It bars group health plans from signing agreements that keep the plan from accessing or sharing provider price and quality data, and it requires each plan to attest annually that no such gag clauses exist. Plans must file the attestation by December 31 every year; the first was due December 31, 2023. The same law requires plans that impose nonquantitative treatment limitations on mental health and substance use benefits, such as prior authorization or step therapy, to document a comparative analysis showing those limits are no more restrictive than limits on medical and surgical benefits.
Mitigation: Review vendor and TPA contracts for gag clause language before each attestation. Keep the NQTL comparative analysis current and ready to produce if federal regulators request it.
Conclusion: Balancing Cost and Compliance
Employer healthcare cost management is not just a financial exercise; it is a legal and ethical one. By understanding these seven risk areas, organizations can design cost-saving programs that comply with federal and state laws, protect employee rights, and avoid costly litigation. Partnering with benefits law experts and running annual compliance audits are baseline practices for any employer serious about sustainable healthcare cost management.
Contact