Explore Our Blog Library!

Your Library of Employee Wellbeing Resources.

Payment integrity is a technical process that checks whether individual claims were coded and priced correctly. Fiduciary intelligence is a governance framework that documents whether the plan sponsor prudently monitored its vendors, as ERISA Section 404 requires. Payment integrity catches claim errors. Fiduciary intelligence protects the people legally responsible for the plan.

Most self-funded plans confuse a claims tool with a legal defense, and the gap between them is where lawsuits start.

A mid-size manufacturer with 1,400 employees paid $340,000 in claims for a coordination of benefits failure that ran undetected for eighteen months (Willis Towers Watson). The plan's payment integrity vendor never flagged it because the claims were coded correctly.

The problem wasn't accuracy. It was that nobody on the plan sponsor's side could show they had monitored the TPA's handling of COB determinations at all. That gap, between a clean claim and a documented oversight process, is the entire subject of this article.

Why Payment Integrity Is Not the Same as Fiduciary Responsibility

Sixty-seven percent of covered workers in the United States are enrolled in self-funded health plans, and that share climbs to 80 percent among firms with 200 or more employees (Kaiser Family Foundation, 2025).

Every one of those employers carries fiduciary duties under the Employee Retirement Income Security Act (ERISA) regardless of whether they know it. Payment integrity is one useful tool for managing plan spend.

It is not the same thing as meeting that legal duty, and treating the two as interchangeable leaves plan sponsors exposed.

Key Takeaways
Payment integrity focuses on whether individual claims were priced, coded and paid correctly. It is primarily a claims accuracy function.
Fiduciary intelligence goes beyond claims accuracy by documenting that the plan sponsor prudently monitored service providers and fulfilled its oversight responsibilities under ERISA Section 404.
A plan can achieve excellent payment integrity results and still fail a fiduciary review if it cannot demonstrate a documented, prudent oversight process.
TPA-reported error rates are often lower than independent audit findings because most TPA self-audits review less than 1% of total claims rather than the full claims population.
Even when a TPA processes every claim, ERISA places fiduciary responsibility for claims oversight and payment accuracy on the plan sponsor.
Payment integrity helps ensure claims are paid correctly. Fiduciary intelligence demonstrates that the plan sponsor exercised prudent oversight. Self-funded plans need both to reduce financial leakage, strengthen governance and satisfy ERISA fiduciary expectations.

What Payment Integrity Actually Does

Payment integrity is the set of technical processes and software that verify whether a submitted claim was billed, coded, and priced correctly before or after payment. It answers a narrow question: did the plan pay the right dollar amount for this specific service.

Most people assume payment integrity is a comprehensive safeguard for the plan. It is not designed to be one. It is a claims-accuracy layer, built to catch duplicate billing, upcoding, and pricing errors against contracted rates. The global payment integrity market has grown to roughly $9 billion, expanding at about 7 percent annually as payers invest more heavily in automated claims review (McKinsey).

The tools are genuinely useful. They catch a meaningful share of overpayments that would otherwise slip through automated adjudication. What they do not do is document whether the plan sponsor exercised the kind of ongoing, independent oversight that ERISA requires of a fiduciary.

A payment integrity report can show a clean claims file and still leave a plan sponsor unable to answer basic questions about vendor monitoring, fee reasonableness, or conflict of interest review.

Why the Gap Exists

The gap between payment integrity and fiduciary protection exists because most self-funded plans were designed for administrative efficiency, not employer oversight. Standard administrative services agreements typically treat a small sampling audit as the complete review, and plan sponsors accept it because it has been considered the industry standard for decades.

TPAs may have limited incentives to identify their own payment errors. Industry studies report claims processing error rates of 2% to 6%, depending on the source and plan complexity (Baker Tilly). At the same time, many TPAs report self-audit accuracy rates close to 99% (ClaimInformatics). This does not necessarily mean either number is wrong. They measure different things. Self-audits often focus on processing accuracy and system rules, not whether the correct amount was ultimately paid.

There is also a structural asymmetry in who has access to the data. Many TPAs release detailed claims files only upon request, often in formats that require technical expertise to analyze (Benosphere). Under ERISA Section 404(a)(1)(B), the fiduciary must act "with the care, skill, prudence, and diligence" of a prudent expert (U.S. Department of Labor). It is difficult to meet that standard when the party being monitored controls the data used to monitor it.

The Real Cost of Treating Payment Integrity as Sufficient

Self-funded employers spending between $10 million and $100 million annually in healthcare claims face $200,000 to $2 million in unrecovered leakage under even a conservative 2 percent error rate (ClaimInformatics). Payment integrity tools recover some of that. Independent claims audits with full review typically recover an additional 1 percent to 3 percent of annual claims spend on top of whatever the TPA's own systems caught (Benosphere).

The financial cost is real but it is not the largest exposure. The fiduciary cost is. ERISA fiduciaries who breach their duties can be held personally liable to restore plan losses, and courts have referred to fiduciary obligations under the statute as among "the highest known to law" (ASPPA). A plan sponsor that relied entirely on a TPA's self-reported payment integrity metrics, with no independent verification, has a documentation problem the moment a participant or the Department of Labor asks how oversight was performed.

Consider the analogy of a building inspector who only checks whether individual bricks meet code. That inspector can sign off on every brick and still miss that the foundation was never surveyed. Payment integrity checks bricks. Fiduciary intelligence checks whether anyone verified the foundation.

What's Actually Happening Behind the Scenes

Sampling Gaps

A standard TPA audit reviews a stratified sample, commonly 200 to 400 claims, against plan documents (Baker Tilly). For a plan processing 80,000 claims annually, that represents roughly 0.3 percent to 0.5 percent of total claims volume (Benosphere). The remaining 99.5 percent goes unreviewed by anyone independent of the TPA.

Coordination of Benefits Failures

COB errors occur when a plan pays as primary when another payer, such as Medicare or a spouse's plan, should have paid first. A COB failure can produce a 60 percent to 80 percent overpayment on the affected claim (Benosphere), and these errors are difficult for automated payment integrity tools to catch because the claim itself may be coded correctly.

Vendor Fee Structures on Recovered Dollars

When TPAs or carrier-affiliated vendors do identify and recover overpayments, they frequently retain a substantial share. Post-pay recovery programs commonly take 40 percent to 50 percent of recovered dollars (ClaimInformatics), which means even a functioning payment integrity process may return less value to the plan than the raw recovery number suggests.

Governance Documentation

DOL guidance emphasizes that fiduciaries must document their decision-making process, not simply achieve a good outcome (DOL elaws Fiduciary Advisor). A payment integrity dashboard, no matter how sophisticated, is not itself governance documentation unless the plan sponsor can show it was reviewed, questioned, and acted upon.

Why Current Approaches Aren't Enough

Dimension Payment Integrity Alone Fiduciary Intelligence Framework
Primary Question Answered Was this claim priced correctly? Did the plan sponsor prudently monitor its vendors?
Data Source Often TPA self-reported Independent, plan sponsor-controlled
Coverage Sampled or automated claims review Full documentation of oversight activities, decisions and rationale
Legal Standard Addressed None directly ERISA Section 404(a) prudent expert standard
Primary Output Error reports and recovery opportunities Governance record including committee minutes, vendor reviews and documented oversight
Who It Protects The plan's financial assets The plan sponsor and named fiduciaries

How to fix it

1
Separate Payment Integrity from Fiduciary Oversight
Ask your payment integrity vendor what claim errors it identifies, then separately determine who is responsible for documenting your fiduciary oversight process. These are different responsibilities and are rarely delivered by the same provider.
2
Request Full Claims Data Access
Obtain detailed claims data instead of relying on summary reports. The Consolidated Appropriations Act strengthened plan sponsors' ability to access detailed claims information from TPAs and PBMs, making independent review more practical.
3
Establish a Regular Review Cadence
Hold monthly or quarterly committee meetings to review vendor performance and document decisions. Meeting minutes create the governance record regulators and courts expect to see.
4
Use an Independent Claims Auditor
Select an audit firm with no ownership or financial relationship to your TPA. Independence strengthens both the credibility of audit findings and the fiduciary value of the review.
5
Benchmark Vendor Fees
Understand how your audit vendor is compensated, including any share of recovered overpayments, before signing the agreement. Transparent pricing supports better vendor governance.
6
Build a Fiduciary File Every Year
Maintain a complete record of audit reports, committee minutes, vendor scorecards and correspondence related to identified issues. This documentation demonstrates a consistent, prudent oversight process under ERISA.
Effective fiduciary oversight combines independent verification, documented governance and regular vendor accountability. Together, these practices improve claims accuracy, strengthen ERISA compliance and create a defensible record of prudent decision-making.

Red Flags That Signal the Gap Applies to Your Plan

You receive a payment integrity or TPA audit summary but cannot describe the sample size or methodology behind it.
Your administrative services agreement restricts which firms can audit your claims or limits when audits can be performed.
You have not obtained detailed claims data independently within the last 12 months.
Pharmacy and specialty drug claims are not reviewed separately against contract pricing terms.
Your plan changed TPAs within the last three years, and claims from the previous administrator were never independently reviewed.
You cannot produce committee minutes or documentation showing vendor performance was actively reviewed rather than simply received.
No one on your team can answer "What was our overpayment rate last year?" with a specific number.
If three or more of these statements describe your plan, there is a strong possibility that payment errors, hidden overpayments and fiduciary risks are going undetected. Independent claims oversight, documented governance and regular vendor reviews help close these gaps before they become costly.

The ROI of Doing It Right

Independent claims audits with full review typically find discrepancies in 3 percent to 5 percent of paid claims costs, with actual recoveries in the 1 percent to 2 percent range (MedInsight). On a $30 million annual claims spend, that is $300,000 to $600,000 in identified overpayments, with $300,000 to $600,000 recoverable even under conservative assumptions.

The larger return is harder to put a number on but matters more in a dispute. A documented fiduciary process, maintained consistently across plan years, is described by the DOL as the strongest defense against audits and litigation (Ascensus). Plans that can produce that record are simply in a different legal position than plans that cannot, regardless of how their payment integrity metrics look in isolation.

Dependent eligibility reviews, treated as a distinct workstream from claims audits, frequently pay for themselves within months (Benosphere) and are one of the fastest ways to demonstrate near-term ROI while the broader fiduciary documentation process is being built out.

Conclusion and Next Steps

Payment integrity and fiduciary intelligence solve different problems, and a self-funded plan needs both. Payment integrity keeps individual claims accurate. Fiduciary intelligence protects the plan sponsor and named fiduciaries by documenting that oversight actually happened, in the way ERISA requires.

The gap between the two is exactly where fiduciary breach claims originate. Closing it does not require replacing your payment integrity vendor. It requires building a separate, deliberate governance record alongside it. [internal link: TPA performance guarantees guide] can help you evaluate whether your current vendor contract measures the right things, and [internal link: claims audit vs payment integrity comparison] walks through how to structure both functions without duplicating cost.

Frequently Asked Questions

Is payment integrity the same as fiduciary compliance?

No. Payment integrity checks individual claims accuracy. Fiduciary compliance requires documented, independent oversight of vendors under ERISA Section 404.

Who is legally responsible for claims errors, the TPA or the plan sponsor?

The plan sponsor. ERISA places fiduciary responsibility on the sponsor, not the TPA, even though the TPA processes the claims.

What does ERISA Section 404 actually require?

It requires fiduciaries to act with the care, skill, prudence, and diligence of a prudent expert familiar with plan administration.

How often should a self-funded plan run an independent claims audit?

Industry guidance generally recommends every two to three years, with more frequent monitoring for larger or higher-risk plans.

Can a plan sponsor rely on a TPA's self-reported accuracy numbers?

Relying solely on self-reported data, without independent verification, does not demonstrate the prudent oversight ERISA requires.

What percentage of claims does a typical TPA audit actually review?

Often well under 1 percent of total claims volume, since standard TPA audits use small stratified samples.

Does the Consolidated Appropriations Act change plan sponsor audit rights?

Yes. It strengthened plan sponsors' rights to full claims data access from TPAs and PBMs upon request.

What is the single most common dollar-weighted claims error?

Duplicate billing, followed closely by coordination of benefits failures on claims that should have paid secondary.

Fiduciary Intelligence

Fiduciary Intelligence: The TPA Oversight Gap Explained

Abhishek Ghosh
July 10, 2026

Fiduciary intelligence is the independent claims oversight layer that sits between a third-party administrator (TPA) and a self-funded employer. It combines ongoing claims monitoring, audit documentation and vendor accountability data so plan sponsors can meet ERISA Section 404 duties instead of relying solely on the TPA's self-reported performance numbers.

A regional manufacturer with 1,400 employees ran an independent claims audit in 2024 and found $812,000 in overpayments across 18 months. The errors included a $47,000 inpatient claim paid twice, 63 ineligible dependents still active on the plan, and a specialty drug billed at 240% of the contracted rate. None of it showed up in the TPA's internal reporting, because none of it was ever reviewed.

That is not a rare story. It is the default outcome for a self-funded plan that treats its TPA's word as the audit. Most employer plans have no independent layer checking whether claims were paid correctly, and by the time anyone notices, the money is gone and the fiduciary exposure has already accrued.

Key Takeaways
Approximately 67% of covered workers are enrolled in self-funded health plans, rising to nearly 80% among employees at large organizations, making claims oversight a widespread employer responsibility.
Most self-funded plans independently review fewer than 5% of claims each year, relying primarily on TPA-run sampling that examines only a few hundred claims from a much larger population.
Industry research places typical TPA payment error rates between 1% and 6%, while comprehensive independent audits often identify error rates of 5% to 12% when every claim is reviewed.
ERISA Section 404 assigns fiduciary responsibility for claims accuracy to the plan sponsor, even when claims administration is delegated to a third-party administrator.
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend. For a plan spending $20 million each year, that can translate into approximately $200,000 to $600,000 in recoverable overpayments.
As self-funded plans continue to grow, relying solely on TPA sampling leaves significant financial and fiduciary risk unchecked. Independent claims oversight provides the visibility needed to recover overpayments, validate payment accuracy and demonstrate a prudent governance process under ERISA.

What Fiduciary Intelligence Actually Means

Fiduciary intelligence is the independent oversight layer that verifies TPA claims performance instead of trusting it. Most employers assume their TPA relationship already includes this. It does not.

A TPA's job is to process claims according to plan documents and network contracts. A TPA's incentive is speed and member satisfaction, not necessarily financial accuracy on every dollar. Those two things frequently pull in different directions, and nothing in a standard administrative services agreement forces alignment.

The common assumption is that performance guarantees in the ASO contract already cover this ground. In reality, most guarantees measure turnaround time and claims-processing speed, not whether the dollar amount paid was correct. A TPA can hit every service level target in its contract while still overpaying claims at a rate the plan sponsor never sees.

Why the Oversight Gap Exists

The gap exists because plan sponsors delegate claims processing but rarely build independent verification into the relationship. Self-funded plans took off because employers wanted to bend the cost curve and gain flexibility insurance carriers do not offer. What did not scale at the same pace was internal expertise to monitor what a TPA actually does with that authority.

TPAs are not financially responsible for the plan. Their costs are covered by administrative fees, not by how accurately claims are paid, so they lack the same financial incentive an insurer carrying its own risk would have. That is not a matter of bad faith. It is simply a structural incentive problem plan sponsors need to correct with independent checks, not TPA good intentions.

Carrier and TPA post-pay sampling reviews typically cover only 3% to 5% of claims, and many ASO agreements specify an annual sample of just 300 to 350 claims regardless of plan size. A plan processing 200,000 claims a year can have 99.8% of its payments never independently reviewed by anyone outside the TPA that made the payment.

The Real Cost of an Unreviewed Plan

Unreviewed claims translate directly into unrecovered dollars, and the scale is larger than most benefits committees assume. Independent, full-population claims analysis consistently identifies error rates between 5% and 12% once every claim is checked instead of a sample, according to third-party claims analytics data covering more than $16 billion in reviewed claims. Industry benchmarks that rely on standard TPA sampling report a narrower 1% to 3% error range, largely because sampling catches fewer error types than a comprehensive review.

The dollar impact compounds quickly. A plan spending $20 million a year that carries even a 2% unrecovered error rate is looking at $400,000 walking out the door annually, before accounting for coordination of benefits failures or dependent eligibility errors that carry their own separate cost.

Consider the manufacturer's numbers again. Sixty-three ineligible dependents sitting on a plan for even one plan year can add tens of thousands of dollars in claims paid for people who should never have been covered. A single misapplied coordination of benefits rule, where the plan should have paid secondary but paid as primary instead, often produces a 60% to 80% overpayment on that specific claim.

What's Actually Happening Behind the Scenes

Coordination of Benefits Failures

Coordination of benefits, or COB, determines which plan pays first when a member has more than one source of coverage. When a TPA's system fails to catch a spouse's other employer coverage or a dependent's eligibility for a separate plan, the self-funded plan can end up paying as primary when it should be secondary. That single misconfiguration routinely produces overpayments in the 60% to 80% range on the affected claims.

Upcoding and Unbundling

Upcoding happens when a provider bills a higher-acuity procedure code than the service actually supports. Unbundling separates a single comprehensive procedure into multiple line items billed individually, inflating the total. Both require clinical and coding expertise to catch, which is exactly why standard TPA sampling rarely flags them.

Dependent Eligibility Drift

Employees change marital status, dependents age out, and COBRA windows close, but eligibility files do not always update on schedule. A plan that has not run a dependent eligibility verification in several years is very likely still paying claims for people who are no longer eligible for coverage.

Out-of-Network and Surprise Billing Gaps

Even after the No Surprises Act took effect, out-of-network claims can still slip through with billed charges well above usual and customary rates when a plan is not actively reviewing them. Without active oversight, the plan simply pays whatever the TPA's repricing engine calculates, correct or not.

Specialty Pharmacy Spend

Specialty drugs now account for more than half of pharmacy spend on many self-funded plans, and pricing errors in this category carry outsized dollar impact per incident compared to medical claims. A single misapplied contract rate on a specialty drug claim can run into tens of thousands of dollars.

Why Current Approaches Aren't Enough

Standard TPA performance guarantees were built to measure operational speed, not financial accuracy, and that mismatch is the core problem plan sponsors need to solve.

Status Quo (TPA Self-Reporting) Fiduciary Intelligence Approach
Reviews only 3% to 5% of claims through internal sampling. Reviews close to 100% of claims through ongoing independent monitoring.
Measures turnaround time and procedural accuracy. Measures financial accuracy and actual overpayment rates.
Findings are reported by the same organization being evaluated. Findings are reported by an independent party with no claims processing conflict.
Periodic audit every two to three years, if conducted at all. Continuous monthly or quarterly monitoring supported by a documented audit trail.
Little or no fiduciary documentation between audits. Board-ready documentation demonstrating a prudent, ongoing oversight process.
Recovery fees are often deducted from the plan's own recovered assets. Transparent fee structure negotiated independently of the TPA.

How to Fix It

1
Confirm Your Audit Rights
Review your ASO agreement to ensure the plan can audit any claim, at any time, using any qualified independent firm. Renegotiate restrictive clauses at the next renewal if they limit these rights.
2
Audit Dependent Eligibility Separately
Treat dependent eligibility verification as its own workstream rather than part of the claims audit. These reviews often recover enough unnecessary costs to pay for themselves within months.
3
Replace Periodic Audits with Ongoing Monitoring
A claims audit performed every few years identifies problems after they have accumulated. Monthly or quarterly independent reviews catch payment errors while they are still small and easier to recover.
4
Choose an Independent Auditor
Select an audit firm with no ownership or financial relationship to your TPA. Look for organizations that combine clinical review, coding expertise and contingency or hybrid pricing models.
5
Strengthen TPA Performance Guarantees
Expand TPA performance guarantees beyond procedural metrics by including measurable financial accuracy standards and overpayment rate targets tied to contractual remedies.
6
Document the Oversight Process
Keep board minutes, committee charters, audit reports and corrective actions on file. This documentation demonstrates that a prudent fiduciary process was followed if your plan is ever reviewed by the Department of Labor or challenged in litigation.
Effective claims oversight depends on strong audit rights, independent verification and continuous monitoring. Together, these practices improve payment accuracy, strengthen fiduciary governance and reduce long-term financial leakage.

Red Flags That Signal the Problem Applies to Your Plan

You cannot state your plan's overpayment rate for the last plan year with an actual number.
Your TPA's performance guarantees measure processing speed and procedural compliance rather than financial accuracy.
Independent claims audit reporting is not a standing agenda item for your benefits committee.
Your last independent claims audit was conducted more than three years ago, or your plan has never had one.
Your audit rights clause restricts which firms can review claims or limits how often audits can be performed.
Dependent eligibility has not been independently verified since your last major open enrollment update.
If three or more of these statements describe your plan, it is likely carrying recoverable overpayments along with meaningful fiduciary exposure. Independent claims oversight can help uncover hidden payment errors, strengthen governance and create a documented process that supports ERISA compliance.

The ROI of Doing It Right

A full independent claims audit typically recovers 1% to 3% of annual claims spending on its first pass. For a plan spending $20 million a year, that translates to $200,000 to $600,000 recovered, often within the first audit cycle. Ongoing monthly or quarterly monitoring tends to catch errors closer to the point of payment, which both prevents future leakage and creates a documented accountability trail with the TPA.

Audit costs are typically far lower than the amount recovered, particularly for mid-sized and large plans. Beyond the direct dollar recovery, the process strengthens vendor negotiating position at renewal and produces the kind of documentation that demonstrates a prudent fiduciary process, which matters enormously if the Department of Labor's Employee Benefits Security Administration ever opens an inquiry.

EBSA recovered more than $1.4 billion for retirement, health and welfare plans in fiscal year 2025 alone, closing 878 civil investigations with 556 producing monetary or corrective results.

Conclusion and Next Steps

Self-funded plans now cover the majority of American workers with employer health benefits, and that share keeps growing. Every one of those plans carries fiduciary duties that do not pause just because a TPA is handling the paperwork. Fiduciary intelligence, in the form of independent claims oversight, is what actually closes that gap between delegation and accountability.

The next step is straightforward. Pull your ASO agreement and check the audit rights clause, then ask your benefits committee when the plan's claims were last independently reviewed. If nobody has a confident answer, that is the signal to schedule a claims audit and dependent eligibility review before the next renewal cycle.

Frequently Asked Questions

What is fiduciary intelligence in the context of self-funded health plans?

It is the independent oversight layer, combining claims monitoring and audit documentation, that verifies TPA performance rather than relying on the TPA's own reporting.

Who holds fiduciary responsibility for claims accuracy under ERISA?

The plan sponsor, under ERISA Section 404, regardless of which vendor actually processes and pays the claims. [external link: DOL/EBSA fiduciary responsibilities guide]

How often should a self-funded plan audit its TPA?

At minimum every one to two years for larger plans, with ongoing monthly or quarterly monitoring recommended between formal audits.

What percentage of claims does a typical TPA sampling audit review?

Roughly 3% to 5%, often limited to a fixed sample of 300 to 350 claims per year regardless of total plan size.

How much can an independent claims audit typically recover?

Most first-time audits recover 1% to 3% of annual claims spend, which can total hundreds of thousands of dollars on mid-sized plans.

What is the difference between a TPA performance guarantee and a fiduciary audit?

Performance guarantees measure speed and procedural accuracy; a fiduciary audit measures whether the dollar amount paid was actually correct.

Can a plan sponsor be held personally liable for TPA errors it never discovered?

Yes. ERISA fiduciary duty requires a prudent ongoing process, and failing to monitor a TPA can itself constitute a breach regardless of who made the underlying error.

What is coordination of benefits and why does it matter for claims accuracy?

COB determines which plan pays first when a member has multiple coverage sources; failures here commonly cause 60% to 80% overpayments on affected claims.

The claims that shape a self-funded plan's renewal are rarely the flagged, high-dollar outliers a TPA reviews closely. They are the routine mid-range claims, often between $500 and $15,000, that pass through standard adjudication unchecked. Left unaudited, this volume of small errors accumulates into the claims trend data insurers use to set renewal pricing.

A self-funded employer with a $30 million annual claims spend trusts its TPA's reported 99% payment accuracy rate at face value. An independent audit later shows the real financial accuracy sits closer to 96.8%, with payment accuracy at 96.1% (Baker Tilly, 2026).

That two to three point gap on a plan this size can mean hundreds of thousands of dollars in overpayments the plan never saw coming. None of those errors showed up as outliers. They were ordinary, mid-range claims that simply moved through the system.

Key Takeaways
Industry benchmarks estimate that TPA payment errors affect approximately 1% to 3% of total claims processed, with some studies reporting rates as high as 2% to 6% depending on plan complexity.
Most routine TPA audits examine only a small sample of claims, often 300 to 350 claims per year, leaving the vast majority of payments unverified.
Research comparing 100% claims audits with random sampling found that sampling alone missed payment errors totaling $200,000 to $750,000 per plan.
Approximately 67% of covered workers are enrolled in self-funded health plans, making claims oversight a critical issue across the employer-sponsored insurance market.
ERISA places fiduciary responsibility for claims accuracy on the plan sponsor, requiring a documented and prudent process to verify that claims are paid correctly.
Sampling alone cannot provide complete assurance that a self-funded plan is paying claims accurately. Independent, comprehensive claims oversight helps identify hidden payment errors, recover unnecessary spending and demonstrate the prudent fiduciary process expected under ERISA.

What "The Claims Nobody Flags" Actually Means

The claims that damage a self-funded plan financially are not the ones anyone is watching. Most plan sponsors assume risk lives in the big, obvious claims: the $400,000 transplant, the six-figure NICU stay, the catastrophic case that triggers stop-loss reimbursement. Those claims get scrutiny by default because the dollar amount forces it.

The claims nobody flags are different. They sit in the $500 to $15,000 range, look ordinary on their face, and process through standard adjudication rules without triggering any manual review. A duplicate physical therapy session, a specialty drug billed slightly above the contracted rate, a coordination-of-benefits error where the plan paid as primary instead of secondary: none of these look alarming individually.

The reality is that volume beats size. A single $400,000 claim gets audited. Ten thousand $1,200 claims with a 3% error rate do not, and that 3% adds up to real money moving out the door every single month.

Why This Problem Exists in the First Place

TPAs are not financially incentivized to catch every small error, because the cost of the error falls on the plan, not on them. This is the structural root of the issue. A TPA's contract typically ties performance guarantees to speed and procedural accuracy, not to overpayment rates.

Claims adjudication systems are built for throughput. Prompt payment requirements common in TPA contracts, often 21 to 30 days from receipt, push claims through fast rather than carefully. The faster a claim moves, the less time anyone spends confirming eligibility, coordination of benefits, or contracted pricing before payment goes out.

Add to this a sampling problem. Most routine post-payment audits built into Administrative Services Only agreements review a small, fixed sample, commonly 300 to 350 claims per year regardless of total plan volume. On a plan processing 40,000 claims annually, that sample size touches well under 1% of total activity, which means the other 99% simply goes unchecked.

The Real Cost and Impact on Plan Spending

Unflagged mid-range claims errors are not rounding errors. They are a measurable percentage of total plan spend, year after year. Industry benchmarks place typical TPA claims error rates between 1% and 3% of total claims processed, with some sources citing a wider 2% to 6% range depending on plan complexity and TPA maturity (WTW, 2025; Baker Tilly, 2026).

A peer-reviewed comparison of audit methodologies analyzed claim data from two Fortune 100 corporations and found that random-sample audits failed to catch a meaningful share of errors that, in aggregate, ranged from $200,000 to $750,000 per plan.

The same research concluded that reviewing 100% of claims rather than a small sample surfaced significantly more of these errors. That is not a marginal difference. That is the gap between a plan that thinks it is clean and a plan that is quietly bleeding.

Think of it like a slow leak in a tire rather than a blowout. A blowout, the catastrophic claim, gets immediate attention because it is impossible to ignore. A slow leak, the routine claims error repeated thousands of times, goes unnoticed until the plan sponsor is standing at the renewal table wondering why the trend line moved.

What's Actually Happening Behind the Scenes

Duplicate and Resubmitted Claims

Duplicate billing remains one of the most common dollar-weighted error types found in claims audits. It typically happens when a provider resubmits a claim, when a plan migrates administrative systems, or when a secondary insurer's payment is not properly coordinated with the plan's own payment.

Coordination of Benefits Failures

When a plan pays as primary on a claim where another carrier should have paid first, a common scenario for dependents with other coverage or spouses on a second plan, the overpayment on that single claim can run significantly higher than it should. These errors require cross-referencing eligibility data that standard adjudication rarely checks in real time.

Upcoding and Unbundling

Upcoding bills a higher-acuity procedure code than the service actually supports. Unbundling charges separately for components of care that should be billed under one comprehensive code. Both inflate provider revenue at the plan's expense, and both require clinical and coding expertise to catch, which is exactly why a standard TPA sample audit rarely flags them.

Why Current Audit Approaches Aren't Enough

A once-a-year sample audit checks whether the TPA followed procedure. It does not tell a plan sponsor whether the plan actually lost money. These are two different questions, and most benefits committees only ever get an answer to the first one.

Status Quo Approach Recommended Approach
Reviews a small random sample, typically 300–350 claims annually. Reviews claims continuously or audits 100% of claims during a defined period.
Measures procedural performance and claims processing speed. Measures actual financial accuracy and total overpayment rates.
Conducted once every one to three years. Ongoing monitoring supported by scheduled comprehensive audits.
Performed or influenced by the TPA being evaluated. Performed by an independent third-party firm with no ownership or financial ties to the TPA.
Findings rarely reach the benefits committee in meaningful financial terms. Findings support fiduciary documentation, governance decisions and renewal negotiations.

How to Fix It: A Practical Action Plan

1
Separate Audit Rights from TPA Influence
Review your TPA agreement to ensure it allows any qualified independent firm to audit any claim at any time. Remove restrictive provisions that limit audit scope, timing or auditor selection.
2
Replace Annual Sampling with Ongoing Monitoring
Shift from infrequent sample audits to continuous claims monitoring. Even monthly reviews of a defined portion of claims can identify errors while they are still recoverable.
3
Audit Dependent Eligibility Separately
Make dependent eligibility its own audit workstream. Removing ineligible dependents is often one of the fastest ways to recover unnecessary plan spending.
4
Measure Financial Accuracy, Not Just Speed
Renegotiate TPA performance guarantees so they include measurable overpayment rates and financial accuracy standards, rather than focusing solely on turnaround time and procedural metrics.
5
Document Your Oversight Process
Maintain committee minutes, audit reports and a formal claims oversight charter. A documented review process helps demonstrate prudent fiduciary oversight under ERISA.
6
Bring Independent Claims Data to Renewal Negotiations
Arrive at renewal discussions with independent audit findings rather than relying solely on TPA trend reports. Verified claims data strengthens negotiations and supports better purchasing decisions.
Independent claims oversight is most effective when it combines unrestricted audit rights, continuous monitoring, measurable financial accountability and documented governance. Together, these practices reduce payment errors, strengthen fiduciary compliance and improve long-term plan performance.

Red Flags That Signal Your Plan Has This Problem

You cannot answer "What was our claims overpayment rate last year?" with an actual number.
Your TPA's performance guarantees measure turnaround time and procedural accuracy rather than actual payment accuracy.
Claims audit reporting is not a standing agenda item for your benefits committee.
Your last independent claims audit, if one was conducted, took place more than two years ago.
Your most recent renewal increase had no clear explanation supported by your own claims data.
Dependent eligibility has not been reverified during the current plan year.
If three or more of these statements describe your plan, there is a strong chance that payment errors, unnecessary costs and fiduciary risks are going undetected. Independent claims oversight provides the visibility needed to improve financial accuracy and strengthen ERISA compliance.

The ROI of Getting Claims Oversight Right

A full independent claims audit typically recovers between 1% and 3% of annual claims spending in its first year. For a plan spending $20 million annually, that translates to $200,000 to $600,000 in direct recoveries, often exceeding the entire cost of the audit itself many times over.

Beyond direct recovery, the ongoing value compounds. Ongoing monitoring catches new errors before they repeat across thousands of claims, and it builds a documented, defensible fiduciary process that protects plan sponsors named personally in ERISA litigation.

There is also a renewal-specific benefit. A plan sponsor walking into a stop-loss or TPA renewal conversation with independently verified claims data negotiates from evidence, not assumption, which shifts leverage back toward the employer.

Conclusion and Next Steps

The claims that quietly reshape a self-funded plan's renewal are not the ones anyone was watching. They are the ordinary, mid-range claims moving through standard adjudication every day, unflagged and unaudited. A self-funded health plan claims audit is the single most direct way to find out what is actually happening inside that volume before the renewal conversation forces the question.

Plan sponsors carry fiduciary responsibility for this outcome whether or not they have the visibility to act on it. The next step is straightforward: confirm your audit rights, move from annual sampling toward ongoing monitoring, and bring independently verified claims data to your next renewal instead of relying solely on your TPA's own reporting.

Frequently Asked Questions

What is a self-funded health plan claims audit?

An independent review of paid claims to verify accuracy, eligibility, and contract compliance beyond what the TPA reports internally.

How often should a self-funded plan audit its claims?

Most large plans benefit from an annual independent audit paired with ongoing monthly or quarterly monitoring between full reviews.

What is a typical TPA claims error rate?

Industry benchmarks generally place TPA error rates between 1% and 3% of total claims, with some sources citing up to 6%.

Why does the plan sponsor bear fiduciary risk instead of the TPA?

ERISA assigns fiduciary responsibility to whoever exercises discretionary control over the plan, and sponsors typically retain that role even when a TPA administers claims.

Can a claims audit really pay for itself?

Yes. Recoveries of 1% to 3% of annual claims spend routinely exceed audit costs, especially for mid-sized and large plans.

What is the most common type of claims error?

Duplicate billing is consistently cited as the most common dollar-weighted error category in independent audits.

Does a small sample audit satisfy ERISA's fiduciary standard?

A sample audit alone may not demonstrate a fully prudent process, since it leaves the large majority of claims unreviewed.

What should a plan sponsor look for in an independent audit firm?

Look for coding and clinical expertise, no ownership ties to the TPA, and a fee model tied to actual findings rather than flat retainer billing.

Fiduciary Intelligence

Healthcare Pricing Is Negotiated. Why Claims Oversight Matters.

Abhishek Ghosh
July 3, 2026

Claims oversight for a self-funded health plan means independently verifying that claims were paid correctly under the negotiated contract, not just that a rate was negotiated. Most TPAs self-report accuracy above 96%, but independent audits routinely find 1% to 10% of claims dollars paid in error.

A 1,400-employee manufacturer ran its first independent claims audit in 2024, eighteen months into a new TPA relationship. The audit found $812,000 in overpayments, including a $47,000 inpatient claim paid twice and a specialty drug billed at 240% of the contracted rate. None of it had surfaced in the TPA's own reporting.

This is the blind spot inside most self-funded employer health plans. Benefits committees spend months negotiating stop-loss terms, network discounts, and PBM rebates, then hand claims payment entirely to a TPA and stop watching.

Sixty-seven percent of covered workers, including 80% at large firms, are now enrolled in self-funded plans, according to KFF's 2025 Employer Health Benefits Survey. That is a lot of employer money moving through systems almost nobody independently checks.

Key Takeaways
Most self-funded health plans independently review fewer than 5% of paid claims, typically through TPA-run sampling audits.
Independent claims audits routinely identify payment errors equal to 1% to 10% of total claims dollars, well above the 96% to 98% accuracy rates commonly reported through TPA self-audits.
ERISA places fiduciary responsibility for claims accuracy on the plan sponsor, regardless of whether claims administration has been delegated to a TPA.
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend during its first year, often exceeding the cost of the audit itself.
EBSA recovered $1.4 billion in FY 2025 and has identified health and welfare plan oversight as a major enforcement priority for FY 2026.
Independent claims oversight has become an essential part of prudent fiduciary governance. Regular auditing helps recover overpayments, validates TPA performance and creates the documented oversight process that regulators increasingly expect from self-funded plan sponsors.

Negotiated Pricing Is Not the Same as Paid Correctly

A negotiated rate protects a plan only if each claim is processed using the correct contract, and most plans have no independent way to verify that. Many plan sponsors assume that once a discount or fee schedule is negotiated, every claim is automatically paid at that rate. It is not. Negotiating the price determines what the plan should pay. Claims adjudication determines what the plan actually pays.

Pricing is a static number in a contract. Payment is a live process running through claims adjudication software, manual review queues, coordination of benefits logic, and provider billing codes, any one of which can override the contracted rate without anyone noticing.

A negotiated 40% network discount means nothing on a claim that was coded wrong, paid to the wrong coordination order, or processed against an expired fee schedule.

Why the Gap Exists

The gap exists because TPAs are not financially exposed when claims payments go wrong, so accuracy checking rarely gets the same rigor as claims processing speed. Under most administrative services agreements, the TPA processes claims and gets paid a fee regardless of whether the plan overpaid. The plan bears the financial risk. The TPA does not.

That misalignment shows up in what gets measured. TPA performance guarantees typically track turnaround time and procedural compliance rather than dollar accuracy. A TPA can hit every service level target in its contract while still paying claims incorrectly, because the contract was never written to test for that.

Reporting compounds the problem. TPA accuracy figures are usually self-reported, while independent claims audits often identify payment errors that internal reviews miss. Because self-reported accuracy measures vary by methodology, an independent review is frequently the only way to verify whether claims were processed according to plan documents, provider contracts and payment rules. Studies of claims accuracy show that audit methodology can materially affect reported results.

The Real Cost of Unreviewed Claims

Unreviewed claims create measurable financial losses for self-funded plans, and those losses grow as plan spending increases. Industry benchmarks estimate that claims payment errors typically affect 1% to 3% of total claims dollars, while some comprehensive independent audits have identified substantially higher error rates when 100% of claims are reviewed instead of a small sample.

Even a modest error rate can translate into hundreds of thousands of dollars in unnecessary spending each year for larger self-funded plans.

Coordination of benefits (COB) failures are among the most expensive claims payment errors. When a self-funded plan pays as the primary insurer on a claim that should have been paid second, it may cover costs that another health plan was responsible for first.

The resulting overpayment on a single claim can equal 60% to 80% of the amount your plan paid. Across a workforce with employees and dependents covered by multiple health plans, even a small number of COB errors can create substantial unnecessary costs over the course of a plan year.

What's Actually Happening Behind the Scenes

Duplicate Payments

Duplicate billing is consistently the highest dollar-weighted error category found in claims audits. It happens when a provider resubmits a claim, when a TPA migrates claims systems, or when a secondary payer's response is not reconciled against the primary payment. The same procedure code, same date of service, and same patient can get paid twice without triggering an internal flag.

Eligibility Drift

Plans routinely keep paying claims for people who are no longer eligible, and nobody catches it until an audit runs a full eligibility reconciliation. Terminated employees, dependents who aged out, and spouses who gained other primary coverage all continue generating paid claims until someone cross-checks eligibility files against claims data, which most TPAs are not contractually required to do proactively.

Coordination of Benefits Errors

When a plan should pay secondary but pays as primary instead, the overpayment on that claim is disproportionately large. This failure mode is common where employees have working spouses with their own coverage, and it is one of the few error categories where a single claim can carry a five- or six-figure correction.

Contract Misapplication

Even a well-negotiated rate schedule can be misapplied if the adjudication system was never updated to reflect it. Specialty drug pricing, out-of-network reimbursement caps, and site-of-service differentials are common places where the contracted rate and the paid rate quietly diverge, sometimes for months before anyone notices.

Why Current Approaches Aren't Enough

Most plans rely on the TPA's own performance guarantees and periodic sample audits to confirm accuracy. Both approaches were built to measure process, not dollars, and both leave the plan sponsor with an incomplete picture of what was actually paid.

Dimension Status Quo (TPA Self-Reporting + Sample Audit) Independent Claims Oversight
Scope of Review Small random sample, often under 5% of claims Comprehensive or statistically robust review of paid claims
Source of Findings Self-reported by the party being measured Independently verified by a party with no stake in the result
What Is Measured Processing speed and procedural compliance Dollar accuracy against contract terms and plan documents
Frequency Often once every two to three years, if at all Annual or continuous monitoring
Fiduciary Documentation Minimal, rarely tied to a defensible process Creates a documented, prudent process record
Financial Outcome Errors persist and compound across plan years Typically recovers 1% to 3% of annual claims spend

How to fix it

1
Establish an Independent Audit Relationship
Engage a claims audit firm that is completely independent of your TPA. Firms owned by or affiliated with the administrator being reviewed cannot provide the level of objectivity needed for meaningful oversight.
2
Strengthen Audit Rights in TPA Contracts
During every contract renewal, ensure your plan can audit any claim, at any time, using any qualified independent firm. Remove provisions that limit reviews to small claim samples.
3
Audit Every TPA Transition
Whenever your plan changes TPAs, perform a comprehensive audit of the outgoing administrator's final claims period before records and institutional knowledge are lost.
4
Review Eligibility Separately
Conduct dependent and terminated-employee eligibility audits as a dedicated workstream. These reviews are typically inexpensive and often recover significant plan dollars.
5
Measure Financial Accuracy
Expand TPA performance guarantees beyond turnaround times and procedural metrics by including measurable standards for payment accuracy and overpayment rates.
6
Maintain a Fiduciary Record
Preserve committee minutes, audit scopes, findings and corrective actions to demonstrate a documented, ongoing oversight process under ERISA.
7
Move to Continuous Monitoring
When resources allow, replace periodic reviews with monthly or quarterly monitoring so payment errors are identified while they remain small and easier to correct.
Effective claims oversight depends on independent verification, strong contractual audit rights and continuous monitoring. Together, these practices reduce financial leakage, improve TPA accountability and create the documented fiduciary process expected under ERISA.

Red Flags That Signal the Problem Applies to Your Plan

You changed TPAs within the last three years and the prior administrator's claims were never independently audited.
No one on your benefits committee can state your plan's actual overpayment rate for the last plan year.
Your TPA contract's performance guarantees measure only processing speed and procedural compliance, not payment accuracy.
Claims audit reporting has never been a standing agenda item for your benefits or finance committee.
Your plan reviews fewer than 5% of claims, and the sample is selected or conducted by the TPA itself.
You have never separately audited dependent and employee eligibility against active claims.
If three or more of these statements describe your plan, it is likely carrying recoverable overpayments along with meaningful fiduciary exposure. Independent claims oversight can help identify payment errors, strengthen governance and reduce future financial risk.

The ROI of Doing It Right

Independent claims oversight typically pays for itself well beyond its cost, both in direct recovery and in reduced fiduciary risk. A first-year comprehensive audit commonly recovers 1% to 3% of annual claims spend, and audit fees are generally far smaller than the amounts identified, particularly for plans in the mid-size to large range.

There is also a fiduciary dimension that does not show up on a savings spreadsheet. A documented, defensible oversight process is exactly what ERISA's duty of prudence requires, and it is the kind of record that matters if a plan is ever the subject of a DOL inquiry or a participant lawsuit.

There is also a fiduciary dimension that does not show up on a savings spreadsheet. A documented, defensible Independent claims oversight process is exactly what ERISA fiduciary responsibilities require, and it is the kind of record that matters if a plan is ever the subject of a DOL inquiry or a participant lawsuit. Courts evaluating an ERISA duty of prudence place significant weight on the fiduciary's decision-making process and documentation.

Conclusion and Next Steps

Negotiating strong contract terms is necessary but not sufficient. A self-funded health plan's real financial exposure lives in the gap between what was negotiated and what was actually paid, and that gap only closes with independent claims oversight. The plans absorbing $812,000 overpayment findings are not unusual. They are simply the ones who finally looked.

Start with a scoping conversation about your plan's current audit rights, your TPA's self-reported accuracy figures, and when your claims data was last independently reviewed. If the honest answer is "we're not sure," that uncertainty is itself the finding your benefits committee needs to document and address.

Frequently Asked Questions

Is a self-funded employer legally required to audit its health plan claims?

ERISA does not mandate a specific audit schedule, but it does require fiduciaries to prudently monitor service providers, including TPAs. Without some form of independent verification, a plan sponsor has no reliable way to demonstrate that monitoring duty was fulfilled.

How often should a self-funded plan conduct a claims audit?

Most claims audit specialists recommend an annual review for larger plans and at least a biennial review for smaller ones. Plans that change TPAs, PBMs, or plan designs should also audit at the transition point before historical claims become harder to access.

What is a normal TPA claims error rate?

Industry benchmarks generally place administrator error rates between 1% and 3% of total claims dollars in routine operations, with some independent full-scope audits finding rates as high as 10% once every claim is reviewed rather than a small sample.

Who is liable if a TPA pays a claim incorrectly?

The plan sponsor generally carries fiduciary and financial responsibility, even though the TPA processed the claim. A contract with the TPA does not transfer ERISA fiduciary liability away from the plan sponsor.

How much does an independent claims audit typically cost?

Costs vary by plan size and audit scope, but many claims audit firms work on a contingency or hybrid fee tied to recovered dollars. Fees are typically well below the amount recovered, especially for mid-sized and large plans.

Can a TPA restrict how much of the claims data a plan is allowed to audit?

Some TPA contracts include language limiting audits to a random sample. Plan sponsors can and should negotiate broader audit rights, including the ability to review any claim at any time using an auditor of their choosing.

What is the difference between a TPA performance guarantee and a claims audit?

A performance guarantee measures whether the TPA hit contractual service metrics, typically speed and procedural compliance. A claims audit independently verifies whether the dollar amount paid on each claim matches what the plan document and contract actually require.

Does the Department of Labor actually investigate self-funded health plans over claims issues?

Yes. EBSA closed 878 civil investigations in FY 2025 and recovered $1.4 billion across enforcement and informal resolution, and has named health and welfare plan oversight a national enforcement priority for FY 2026.

The healthcare claims oversight gap refers to medical claims, usually between $5,000 and $25,000, that often receive little or no review. They are too small to trigger a stop-loss review and too large to be treated as routine low-cost claims.

Together, these claims make up a large share of plan spending, and payment errors in this range are estimated to cost self-funded plans 2% to 5% of their annual claims spend.

A self-funded employer spendizng $15 million on healthcare claims each year could be losing $150,000 to $450,000 annually to payment errors without ever receiving a report that identifies those mistakes.

Key Takeaways
Most self-funded health plans independently review fewer than 5% of claims, typically through a TPA sample of only 300 to 400 claims.
Mid-range claims, generally between $5,000 and $25,000, are the least likely to receive independent scrutiny despite representing a significant share of total plan spending.
Industry estimates place TPA payment error rates between 2% and 5% of annual claims spend, creating the potential for substantial financial losses on large self-funded plans.
ERISA places fiduciary responsibility for claims accuracy on the plan sponsor, even when claims administration has been delegated to a TPA.
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend, often producing savings that exceed the cost of the audit itself.
The greatest claims oversight gap often exists in the middle of the payment distribution, where routine claims are too large to ignore but too small to trigger enhanced review. Closing that gap helps reduce financial leakage while strengthening fiduciary oversight.

The Oversight Gap Most Plans Don't Know They Have

Mid-range claims are the most common and least-reviewed category in most self-funded health plans. Most plan sponsors believe their TPA handles auditing. That assumption is expensive. A standard TPA audit reviews a random sample of 250 to 400 claims and uses the results to generate an overall accuracy score. That score becomes the plan's reported error rate.

The claims oversight gap exists because no one routinely reviews a large portion of healthcare claims. Stop-loss carriers focus on very high-cost claims, while low-cost claims are often processed automatically. The claims in between receive the least attention, even though they make up a significant share of healthcare spending.

This middle band, typically claims between $5,000 and $25,000, accounts for a significant share of a typical plan's annual healthcare spending. It includes orthopedic surgeries, outpatient procedures, emergency room visits with facility fees, and specialty infusion claims that quietly add up across hundreds of members. For most self-funded plans, these claims are processed and paid without independent review.

Why the Problem Exists

This oversight gap exists for three main reasons. First, TPAs are paid to process claims, not to find mistakes in their own work. Second, many audits review only a sample of claims instead of every claim. Third, employers often have limited access to detailed claims data. Many plan sponsors also don't realize that the "audit" included in their TPA contract is usually an internal review by the TPA, not an independent claims audit.

Most claims audits review only a small sample of claims. For example, if a health plan processes 40,000 claims in a year and the audit reviews only 350, more than 39,000 claims are never checked. If the same billing mistake appears on hundreds of claims that aren't part of the sample, the audit may never find it.

Data access has historically made the situation worse. Many TPA contracts included gag clauses that restricted employers from accessing detailed claims data or from hiring independent auditors outside the TPA's approved list. Section 201 of the Consolidated Appropriations Act of 2021 (CAA 2021) explicitly prohibited these clauses and required plan sponsors to attest annually to the DOL that their contracts do not contain them. Despite the law, some plan sponsors still face delays and partial disclosures when requesting their own data.

The Real Cost

The financial impact of unreviewed claims is significant. Industry estimates put claims payment error rates at 2% to 5% of annual healthcare spending, even among well-performing TPAs. According to Withum, overpayment recoveries typically represent 1% to 1.5% of paid claims.

For a health plan spending $20 million a year, that could mean $200,000 to $300,000 in recoverable overpayments that go unnoticed.

The risk is not only financial. ERISA Section 404 requires plan fiduciaries to manage plan assets with care and prudence. Regular claims oversight helps demonstrate that the plan sponsor is actively monitoring healthcare spending.

Without documented oversight, employers may face greater legal and fiduciary risk if their claims administration is questioned. Recent litigation has also placed increased attention on whether plan sponsors are adequately monitoring healthcare plan expenses and service providers.

What's Actually Happening Behind the Scenes

Four specific error categories drive the majority of recoverable overpayments in mid-range claims, and none of them require fraud to occur.

Duplicate Payments

Duplicate claims occur when the same medical service is billed more than once. Although TPAs have duplicate detection systems, small differences in billing details can prevent the claims from being flagged, allowing the same service to be paid twice.

Coordination of Benefits Failures

When a member has more than one health plan, one plan should pay first and the other should pay only the remaining balance. COB errors occur when the wrong plan pays first or the TPA doesn't recognize other coverage, causing the employer's plan to overpay.

Medical Coding Errors and Upcoding

Procedure codes determine how much a health plan pays for a service. Upcoding happens when a provider bills for a more complex service than was performed, resulting in a higher payment. These errors are often caused by coding or documentation issues and can go unnoticed without an independent review.

Eligibility Errors

Eligibility errors occur when a health plan pays claims for people who are no longer covered, such as former employees or dependents who have lost eligibility. If these records are not updated on time, the plan can pay claims that should never have been covered.

Why Current Approaches Are Not Enough

The typical audit model was designed for compliance documentation, not financial recovery. The table below illustrates the structural difference between what most plans do and what an independent claims oversight program actually requires.

Dimension Standard TPA Sample Audit Independent 100% Claims Review
Who Conducts It TPA internal team or an approved vendor Fully independent third-party firm
Claims Reviewed 250–400 claims (typically under 1% of total volume) 100% of claims paid during the review period
Primary Purpose Accuracy score for contract compliance Financial recovery and error prevention
Error Categories Covered Basic adjudication accuracy Duplicates, coordination of benefits, coding, eligibility and repricing errors
Reporting to Plan Sponsor Aggregate accuracy percentage Detailed findings with dollar amounts and recovery guidance
Frequency Annual or biennial Quarterly or continuous
Independence TPA-controlled Fiduciary-grade, no TPA affiliation
Audit Rights Documented Rarely negotiated Contractually secured

How to Fix It

Fixing the oversight gap requires six specific actions, not a single vendor change.

1
Conduct a 100% Independent Claims Audit
Engage an audit firm with no financial relationship to your TPA or carrier to review every claim paid during the previous 12 to 24 months. Prioritize claims between $5,000 and $50,000 to establish a baseline error rate and identify recoverable overpayments.
2
Assert Your CAA 2021 Data Rights
Submit a formal written request for complete machine-readable claims data, including adjudication details and remittance records. Keep documentation of requests, responses and timelines as part of your fiduciary records.
3
Strengthen Audit Rights in Your ASO Agreement
Remove or renegotiate provisions that restrict audit scope, limit auditor selection, require excessive advance notice or otherwise reduce your ability to independently verify claims accuracy.
4
Implement Continuous Claims Monitoring
Move beyond one-time retrospective reviews by monitoring claims monthly or quarterly. Earlier detection improves recovery rates and reduces the likelihood that recovery windows expire.
5
Tie TPA Performance to Financial Accuracy
Add contractual guarantees covering overpayment rates, coordination-of-benefits accuracy and eligibility verification, with financial consequences when agreed standards are not achieved.
6
Maintain a Written Fiduciary Record
Document audit findings, corrective actions, committee reviews and follow-up activities. A well-maintained oversight record demonstrates a prudent fiduciary process if your plan is ever reviewed by regulators or challenged by participants.
Effective claims oversight is built on three principles: independent verification, continuous monitoring and documented governance. Together, these practices help recover overpayments, improve payment accuracy and strengthen your fiduciary position under ERISA.

Red Flags That Signal This Problem Applies to Your Plan

1
Conduct a 100% Independent Claims Audit
Engage an audit firm with no financial relationship to your TPA or carrier to review every claim paid during the previous 12 to 24 months. Prioritize claims between $5,000 and $50,000 to establish a baseline error rate and identify recoverable overpayments.
2
Assert Your CAA 2021 Data Rights
Submit a formal written request for complete machine-readable claims data, including adjudication details and remittance records. Keep documentation of requests, responses and timelines as part of your fiduciary records.
3
Strengthen Audit Rights in Your ASO Agreement
Remove or renegotiate provisions that restrict audit scope, limit auditor selection, require excessive advance notice or otherwise reduce your ability to independently verify claims accuracy.
4
Implement Continuous Claims Monitoring
Move beyond one-time retrospective reviews by monitoring claims monthly or quarterly. Earlier detection improves recovery rates and reduces the likelihood that recovery windows expire.
5
Tie TPA Performance to Financial Accuracy
Add contractual guarantees covering overpayment rates, coordination-of-benefits accuracy and eligibility verification, with financial consequences when agreed standards are not achieved.
6
Maintain a Written Fiduciary Record
Document audit findings, corrective actions, committee reviews and follow-up activities. A well-maintained oversight record demonstrates a prudent fiduciary process if your plan is ever reviewed by regulators or challenged by participants.
Effective claims oversight is built on three principles: independent verification, continuous monitoring and documented governance. Together, these practices help recover overpayments, improve payment accuracy and strengthen your fiduciary position under ERISA.

The ROI of Doing It Right

An independent claims oversight program can pay for itself. First-time audits often recover 1% to 3% of annual claims spend. For a $10 million health plan, that could mean $100,000 to $300,000 in recoveries, while audit fees are typically much lower.

The benefits continue beyond the first audit. Regular claims monitoring helps reduce recurring errors because TPAs know their work is being reviewed. Over time, this can improve claims accuracy and reduce unnecessary spending.

There is also a fiduciary benefit. A documented claims oversight program shows that the plan sponsor is actively monitoring healthcare spending. If the plan is ever reviewed by regulators or challenged by participants, those records can help demonstrate prudent oversight.

Conclusion and Next Steps

Many mid-range healthcare claims are paid without an independent review, leaving plans exposed to unnecessary costs and risk. The good news is that employers now have better access to claims data, making independent oversight easier than before.

Start by requesting complete claims data from your TPA under your CAA 2021 rights. Then conduct an independent 100% claims audit to identify errors and establish a baseline. Use the results to strengthen your TPA agreement and implement regular claims monitoring to prevent future overpayments.

Frequently Asked Questions

What is the healthcare claims oversight gap?

The claims oversight gap is the portion of claims that are paid without an independent review. Most self-funded plans audit only a small sample of claims, leaving many payment errors undetected.

What percentage of health plan claims contain errors?

Industry estimates suggest that 2% to 5% of annual claims costs contain payment errors, including duplicate payments, coding mistakes, COB failures, and eligibility errors.

Who is responsible for claims accuracy under ERISA?

The plan sponsor is responsible for overseeing claims payments. While a TPA processes claims, the employer remains responsible for monitoring the plan.

What does the CAA 2021 require regarding claims data access?

The CAA 2021 prohibits contract clauses that prevent employers from accessing claims data or using independent auditors. Plans must annually attest that their contracts comply.

How much can an independent claims audit recover?

A first-time independent audit typically recovers 1% to 3% of annual claims spend. On a $20 million plan, that could equal $200,000 to $600,000 in recoverable overpayments.

How is a 100% claims review different from a sample audit?

A sample audit reviews only a small number of claims. A 100% review examines every claim, helping identify specific overpayments and recurring billing errors.

How often should a self-funded plan conduct an independent claims audit?

Most plans should perform an independent audit at least once a year and monitor claims regularly throughout the year.

What should I look for in an independent claims audit firm?

Choose a firm that is independent of your TPA, reviews 100% of claims, has medical coding expertise, and offers a transparent fee structure.

Fiduciary Intelligence

Healthcare Claims Oversight Is Still Stuck in 2005

Abhishek Ghosh
June 26, 2026

Healthcare claims oversight refers to a plan sponsor's process of systematically reviewing medical and pharmacy claims paid on a self-funded health plan for errors, fraud and overbilling. Most employers rely on their TPA to catch errors, but independent audits routinely find that 3 to 7 percent of paid claims contain recoverable overpayments.

A mid-sized manufacturer in Ohio discovered last year that its TPA had been paying a local hospital system at billed charges for nearly three years. The contract clearly called for network rates. The error cost the plan over $1.1 million before anyone noticed. The plan sponsor was the employer. No one at the company had reviewed a single Explanation of Benefits.

Key Takeaways
Most self-funded employers delegate claims oversight entirely to their TPA and never independently verify payment accuracy.
Independent claims audits routinely uncover overpayments equal to 3% to 7% of total claims spend, revealing costs that often remain hidden for years.
ERISA requires plan fiduciaries to monitor plan operations, including claims payment activities, with the care, skill and diligence of a prudent expert.
The technology needed to identify claims errors in near-real time has existed for years, yet many plans continue to rely on delayed reviews and periodic reporting.
Maintaining the status quo is becoming increasingly risky as Department of Labor scrutiny and participant litigation continue to increase.
Claims oversight is no longer just an operational concern. Independent verification, documented monitoring and timely review processes have become essential components of prudent fiduciary governance for self-funded health plans.

Plan Sponsors Are Flying Blind on Claims

Most employers have no systematic process to verify that the claims paid on their health plan are accurate, appropriate or even contractually permitted.

The assumption is that the TPA handles it. The TPA assumes it is processing claims per the plan document and network contracts. In practice, neither party is actively looking for errors on a sustained basis. That gap between assumption and reality is where overpayments live.

Self-funded plans cover roughly 65 percent of all privately insured workers in the United States, according to the Kaiser Family Foundation. Collectively, employer-sponsored plans pay trillions in claims each year.

The typical process remains largely unchanged: a TPA processes claims, issues EOBs, and coordinates payments, while employers often rely on summary reports rather than reviewing claim-level activity.

Why the Problem Exists

The current self-funded model can make it challenging to maintain continuous, detailed claims oversight.

TPAs are generally compensated for claims administration rather than claims accuracy. As a result, independent claims reviews can provide an additional layer of oversight and help identify issues that may not be apparent through routine claims processing alone.

As a result, many employers rely primarily on vendor reporting and may have limited ability to independently validate claim accuracy.

The Real Cost of Inadequate Claims Oversight

Claims leakage, the portion of plan spend lost to errors, fraud, waste and overbilling, typically runs between 3 and 7 percent of total paid claims, based on industry auditing benchmarks published by auditing firms and benefits consultants.

For a self-funded employer spending $10 million annually on health claims, a 3% to 7% payment error rate could represent $300,000 to $700,000 in potential payment errors or avoidable claims costs, depending on the nature of the errors and whether they can be recovered.

Self-funded employers are facing greater scrutiny over how they oversee health plan spending. Benefits attorneys, including the Groom Law Group, have noted that ERISA investigations increasingly focus on whether plan sponsors have prudent oversight processes.

In Lewandowski v. Johnson & Johnson, participants alleged the employer failed to manage pharmacy spending prudently. Although the court dismissed the fiduciary claims on standing grounds without ruling on the merits, the case highlighted growing expectations for stronger health plan oversight and governance.

What's Actually Happening Behind the Scenes

Claims adjudication is a high-volume, rules-based automated process and automated rules can be misconfigured, outdated or simply absent.

Duplicate Claims

A provider submits a claim. A clearinghouse resubmits it. The TPA pays it twice. Duplicate logic in adjudication systems is supposed to catch this, but logic exceptions exist. Retrospective audits by independent firms routinely recover duplicate payments as one of the most common error categories.

Upcoding and Unbundling

A facility bills a complex evaluation and management visit when the documentation supports a lower-level code. Or a surgical procedure is billed as multiple component codes when a single bundled code should apply. These errors inflate reimbursement and are rarely flagged by TPA automated edits without specific clinical logic overlays.

Coordination of Benefits Failures

When a participant has coverage under two plans, the primary carrier is supposed to pay first. COB errors occur when the TPA lacks current information about secondary coverage or fails to recover from the other carrier. These can result in the self-funded plan overpaying as both primary and secondary payer simultaneously.

Contract Pricing Errors

Network contracts specify allowed amounts, discount thresholds, carve-outs and fee schedules. When a TPA's pricing file is not updated to reflect contract renegotiations, or when a claim routes to an out-of-network provider incorrectly classified as in-network, the plan overpays. This category of error can be large per-claim and is difficult to detect without comparing paid amounts against the actual contract.

Billing Fraud and Abuse

This is distinct from honest errors. Some providers systematically bill for services not rendered, upcode routinely or fabricate diagnoses. FBI and OIG enforcement data show healthcare fraud costs the U.S. system tens of billions annually. Self-funded plans are targets because they often lack the robust fraud analytics that large commercial carriers deploy.

Why Current Approaches Are Not Enough

Most TPAs have internal audit functions and claim editing software. These catch a portion of errors before payment (pre-payment editing) or flag obvious duplicates. But they are not independent, they are not comprehensive, and they are not designed to surface systemic problems in the TPA's own adjudication.

Think of it this way. Asking your TPA to audit its own claims accuracy is like asking a restaurant to grade its own health inspection. The restaurant may have good intentions and internal protocols. But the incentive structure makes objective self-assessment structurally difficult.

Capability TPA Internal Audit Independent Claims Audit
Independence from the Payer No Yes
Reviews 100% of Claims Rarely Yes, when retrospective
Compares Claims to Actual Contract Sometimes Standard practice
Clinical Code Review Limited Included
Fraud Pattern Detection Basic Advanced analytics
Results Shared with Plan Sponsor Summary only Full findings with recovery recommendations
Ongoing Monitoring One-time spot checks Can be continuous
Fiduciary Documentation for DOL Not provided Provided

How to Fix It: A Practical Oversight Framework

Plan sponsors can establish meaningful claims oversight without replacing their TPA, using a layered approach that combines contractual rights, independent review and ongoing monitoring.

1
Secure Independent Audit Rights
Ensure your TPA agreement explicitly grants the right to conduct independent claims audits, including access to claims data, pricing files and adjudication logic. If these rights are missing, negotiate them during your next renewal.
2
Conduct a Baseline Retrospective Audit
Review 100% of claims paid during the previous 12 to 36 months against contracts, plan documents and clinical coding standards to establish an error baseline and identify improvement opportunities.
3
Review High-Dollar Claims Before Payment
Implement concurrent or prospective review for large claims, typically above $25,000 to $50,000, to identify billing or clinical issues before funds leave the plan.
4
Audit Complex Hospital Claims
Apply reference-based pricing validation or detailed hospital bill auditing to large inpatient claims, where line-item billing errors frequently occur.
5
Review Coordination of Benefits Annually
Update coordination-of-benefits records for all participants and dependents, then perform a formal COB review to identify claims that should have been paid by another health plan.
6
Evaluate TPA Performance Guarantees
Understand exactly how your TPA measures claims accuracy, what standards apply and what contractual remedies are available if those guarantees are not achieved.
7
Document the Oversight Process
Maintain records of audit activities, findings, corrective actions and governance decisions. A documented oversight framework provides strong evidence of prudent fiduciary process under ERISA.
Effective claims oversight does not require replacing your TPA. It requires independent verification, stronger contractual protections and a documented governance process that continuously safeguards plan assets.

Red Flags That Signal Your Plan Has a Claims Oversight Problem

Your TPA agreement does not include an explicit audit right or limits audits to a narrow review window of less than 24 months of claims data.
You have never received a claims accuracy report from your TPA that breaks errors down by category or root cause.
Your plan has never undergone an independent retrospective claims audit performed by a firm with no financial relationship to your TPA.
Stop-loss claims are submitted and paid without itemized bill review or formal case management.
Your pharmacy benefits manager has never been audited separately from your medical claims program.
You cannot identify the contracted reimbursement rates being applied to your top 20 providers by annual spend.
Your broker or consultant cannot provide documentation showing claims accuracy was independently reviewed within the past 12 months.
Coordination-of-benefits processes have not been reviewed or tested since the plan was originally implemented.
If three or more of these conditions apply to your plan, your claims oversight framework likely has significant gaps. Strengthening audit rights, increasing data transparency and implementing independent claims reviews can substantially improve both financial performance and fiduciary protection.

The ROI of Getting Claims Oversight Right

Independent claims audits return between $3 and $12 for every $1 spent on the audit, based on published recovery ranges from auditing firms and benefits consulting organizations.

A one-time retrospective audit on a plan with $15 million in annual claims typically identifies $300,000 to $900,000 in recoverable overpayments. Recovery depends on contractual provisions with the TPA and the age of the errors found, but most TPA agreements allow recovery of documented overpayments.

The Milliman actuarial consulting firm has documented that plans with active oversight programs spend 2 to 5 percent less on claims over time compared to unmonitored plans, controlling for demographics and benefit design.

Regular claims audits don't just help find billing errors and save money. They also create a record showing that the employer was actively monitoring the health plan. If questions ever arise about how the plan was managed, that documentation can be valuable. In many cases, the cost of dealing with legal disputes or regulatory investigations can be far greater than the cost of maintaining a proactive claims oversight program.

Conclusion and Next Steps

Healthcare claims oversight is not a luxury or a compliance checkbox. It is one of the most financially consequential activities a self-funded plan sponsor can undertake.

The technology to monitor claims accurately in near-real time has existed for years. The legal obligation to do so under ERISA has existed for decades. What has changed is the enforcement environment. DOL investigations are broader. Participant lawsuits are more specific about fiduciary process failures. Stop-loss carriers are paying closer attention to what was reviewed before a large claim was paid.

Start with a baseline retrospective audit. Review your TPA agreement for audit rights. Assign someone in finance or legal to own the oversight process. Those three steps will put your plan ahead of a large majority of self-funded employers in the country.

Frequently Asked Questions

What is healthcare claims oversight for a self-funded plan?

Healthcare claims oversight is the process of checking that medical and pharmacy claims are paid accurately and according to plan rules. It includes claims audits, eligibility checks, coordination of benefits (COB), and monitoring TPA performance.

Is a plan sponsor legally required to audit claims under ERISA?

ERISA does not require a specific audit schedule, but it requires plan fiduciaries to monitor plan operations and service providers. Regular claims reviews help demonstrate prudent oversight.

How much does an independent claims audit cost?

Costs vary by plan size and scope. Retrospective audits often range from $15,000 to $50,000, while some firms work on a contingency basis and only charge if they recover overpayments.

What percentage of claims typically contain errors?

Industry benchmarks suggest that 3% to 7% of paid claims contain recoverable errors, including duplicate payments, pricing mistakes, eligibility issues, and billing errors.

Can the plan recover overpayments from the TPA?

It depends on the TPA agreement and the type of error. Many contracts allow recovery of overpayments, but recovery deadlines and conditions vary.

What is the difference between a retrospective audit and concurrent review?

A retrospective audit reviews claims after they are paid to identify recoverable overpayments. Concurrent review examines claims before or shortly after payment to prevent errors from occurring.

Does the CAA 2021 change claims oversight obligations for employers?

The CAA 2021 increased transparency requirements but did not require routine claims audits. It reinforced that plan sponsors are responsible for understanding and monitoring healthcare spending.

How do I know if my TPA agreement allows an independent audit?

Review your ASO or ASA agreement for audit rights, data access, and recovery provisions. If these rights are unclear, consider negotiating stronger audit language at your next contract renewal.

The Fiduciary Cost of Delayed Claims Audit

Abhishek Ghosh
June 22, 2026

Waiting 90 days to review claims increases both financial and operational risk. As recovery windows narrow, providers become less likely to return overpayments. Meanwhile, recurring billing and adjudication errors can continue across thousands of claims before they are detected.

The delay not only increases potential losses but also leaves plan sponsors with less documentation demonstrating ongoing oversight of plan expenditures and vendor performance.

A distribution company with 600 employees did not review its healthcare claims until its annual audit. By then, a provider had been overcharging for infusion therapy for five months, and the health plan paid the higher amount on every claim during that period.

Because no one was monitoring claims regularly, the problem continued unnoticed and the losses kept growing. Plan sponsors are expected to take reasonable steps to protect plan funds. Waiting months to review claims can allow small errors to turn into significant costs.

Key Takeaways
A 90-day audit delay allows claims errors to accumulate for three months before they are reviewed, increasing both financial losses and recovery challenges.
ERISA Section 404 requires ongoing prudent oversight of plan assets, not a once-a-year compliance exercise.
Recovering overpayments becomes increasingly difficult as contractual lookback periods expire and state prompt-pay protections narrow available recovery options.
Department of Labor enforcement efforts are increasingly focused on the timing and frequency of claims oversight, not merely whether an audit program exists.
Reducing the audit cycle to 30 days or less can significantly decrease claims leakage while strengthening fiduciary protection.
The effectiveness of a claims audit program is determined not only by what it finds, but also by how quickly it finds it. Shorter review cycles improve recovery outcomes, reduce ongoing leakage and create a stronger record of prudent fiduciary oversight.

What "Waiting 90 Days" Actually Means for a Self-Funded Plan

A 90-day audit cycle means that for every dollar paid in error, the plan sponsor has no visibility into the mistake for up to three months. Most plan sponsors think of a quarterly or annual audit as standard practice, even responsible practice. The assumption is that claims get checked eventually, so the system works.

The reality is that "eventually" is doing a lot of work in that sentence. A TPA processing claims for a 600-life plan might process 2,000 to 4,000 claims per month. Over 90 days, that is 6,000 to 12,000 claims that go entirely unreviewed by anyone outside the TPA's own internal quality process. Errors do not wait politely for the audit calendar. They compound.

The Government Accountability Office has documented that improper payments in health benefit programs are persistent precisely because detection systems are not built to catch errors close to the point of payment. A self-funded plan operating on a 90-day or annual review cycle is replicating that same structural weakness inside its own claims oversight.

Why the 90-Day Gap Exists in the First Place

The 90-day audit lag exists because it was built around TPA reporting cycles, not around fiduciary risk. Several structural habits keep this delay in place across the industry.

Legacy Contract Design

Many administrative services only (ASO) agreements were written years ago when quarterly reporting was the technical norm. TPAs batch claims data into quarterly files because that matched their internal reporting infrastructure, not because it served the plan sponsor's oversight needs.

Data Access Friction

Some TPAs charge additional fees for more frequent claims data extracts, or simply do not offer a faster cadence as a standard service tier. Plan sponsors who never ask for a 30-day data feed never learn that one is possible.

Underestimating compounding risk

A single duplicate payment or repricing error rarely alarms anyone. The risk is not the individual error. It is the same error repeating across every claim that matches the same billing pattern for as long as nobody is looking.

The Real Cost of a 90-Day Blind Spot

The financial cost of a 90-day audit delay scales with claims volume in a way that catches most plan sponsors off guard. Consider a self-funded plan with $9 million in annual claims spend, which is roughly $750,000 per month. A billing error affecting just 2% of claims volume that goes undetected for a full quarter represents $45,000 in overpayments before anyone even opens an audit file.

Now extend the timeline. If the same plan operates on an annual cycle instead of quarterly, that same 2% error rate compounds to $180,000 before review. The The Healthcare Financial Management Association has reported that hospitals lose an average of 4.8% of net revenue to claim denials, and other industry estimates for self-funded claims processing errors range higher still.

The fiduciary cost runs alongside the financial cost. ERISA Section 404(a)(1) requires fiduciaries to act with the care, skill, prudence, and diligence that a prudent person familiar with such matters would use under similar circumstances. A plan sponsor who can produce evidence of monthly claims monitoring has a materially stronger position in a DOL inquiry than one who can only show an annual review. Documented frequency matters because intent and diligence are judged by process, not by outcome alone.

What's Actually Happening Behind the Scenes During the Gap

Error Patterns Repeat Before Anyone Notices

A single coding error from a provider's billing system rarely appears once. If a provider's software misapplies a modifier code or a TPA's adjudication engine mishandles a specific procedure code, that same error recurs on every matching claim until someone catches it. Ninety days gives that pattern three full months to multiply.

Provider Dispute Windows Start Closing

Most state prompt-pay statutes and provider contracts establish specific windows during which a payer can dispute or recoup a payment without escalated friction. As days pass, providers gain stronger legal footing to resist repayment demands, citing reliance on the original payment and administrative finality. A claim flagged at day 15 is a different negotiation than the same claim flagged at day 95.

Dependent Eligibility Drift Goes Unchecked

Life events such as divorce, a dependent aging out, or a spouse gaining other coverage do not pause for the audit calendar. A 90-day gap means a plan can pay three additional months of claims for someone who became ineligible on day one of the quarter, with no mechanism catching it until the cycle closes.

Stop-Loss Reporting Misalignment

Self-funded plans with stop-loss coverage typically need to report large claims promptly to remain compliant with notice provisions in the stop-loss contract. A 90-day internal audit cycle can mean large claims are not flagged for stop-loss notification within the carrier's required timeframe, risking a denied or reduced reimbursement on a catastrophic claim.

Fiduciary Documentation Gaps Widen

Every quarter without a documented review is a quarter without evidence that the plan exercised the procedural prudence ERISA requires. DOL investigators reviewing a plan's fiduciary process look for a paper trail. A 90-day gap, repeated across multiple plan years, creates a pattern of sparse documentation that is difficult to explain after the fact.

Why an Annual or Quarterly Cadence Isn't Enough

A quarterly or annual audit cycle was adequate when claims data was difficult to access. It is not adequate now that near real-time data feeds exist. The table below compares the standard cadence against a tighter monitoring model.

Factor 90-Day / Annual Cadence 30-Day or Continuous Cadence
Time Before Error Detection Up to 90 days (or 365 days for annual audits) 30 days or less
Claims Exposed Before Review 6,000 to 12,000+ claims per cycle (mid-size plan) 2,000 to 4,000 claims per cycle
Provider Dispute Friction High (lookback windows narrowing) Lower (claims still fresh)
Dependent Eligibility Exposure Up to one full quarter of ineligible claims One month maximum
Stop-Loss Notification Risk Elevated for large claims missed mid-quarter Minimal, large claims flagged immediately
Fiduciary Documentation Strength Sparse, quarterly snapshots Continuous, monthly evidence trail
DOL Audit Defensibility Moderate Strong

How to Fix It: Shortening the Audit Cycle

1
Request Monthly Claims Data
Obtain an 837 or 835 transaction file from your TPA on a 30-day cadence rather than quarterly. More frequent access reduces the time between payment and review.
2
Create a Written Monitoring Policy
Define how often claims are reviewed, what data is examined and who is responsible. A documented policy provides evidence of prudent fiduciary oversight.
3
Review High-Dollar Claims Faster
Establish accelerated review for claims above a defined threshold, commonly $25,000 to $50,000, to improve accuracy and support stop-loss reporting requirements.
4
Integrate Eligibility Verification
Incorporate dependent eligibility checks into monthly payroll and enrollment workflows rather than relying solely on periodic audits.
5
Strengthen Contract Language
Clearly define data formats, delivery schedules, audit rights and fees within your TPA agreement rather than relying on broad cooperation language.
6
Assign Clear Ownership
Designate a responsible individual and establish a recurring review meeting. Audit programs are most effective when accountability is clearly assigned.
Shortening the audit cycle is not simply an operational improvement. It reduces financial leakage, improves recovery rates and creates a stronger record of ongoing fiduciary oversight.

Red Flags That Signal Your Plan Is Exposed

Your current TPA contract specifies quarterly or annual data delivery with no faster option available.
Your most recent claims audit findings cover a period that ended more than 60 days ago.
No one on your internal team can immediately identify when the last claims review was completed.
Your plan documents contain no written claims monitoring policy or defined audit cadence.
Large claims have been reported to your stop-loss carrier after the contractual notification deadline at least once.
Your broker's stewardship report is the only claims review your organization receives throughout the year.
Dependent eligibility verification occurs on an ad hoc basis rather than through a recurring review schedule.
If three or more of these statements describe your plan, your claims oversight process is likely operating with significant delays. Shortening the review cycle, formalizing monitoring procedures and increasing data visibility can substantially reduce both financial leakage and fiduciary exposure.

The ROI of Moving to a Shorter Audit Cycle

Shortening the audit cycle from 90 days to 30 days or less produces a measurable reduction in both recoverable loss and ongoing exposure. Independent claims integrity data suggests that catching an error within 30 days of payment results in recovery rates roughly two to three times higher than catching the same error after 90 days, largely because provider dispute friction and statutory lookback limits have not yet hardened.

On a plan with $9 million in annual claims spend and a conservative 3% error rate, that is $270,000 in identifiable overpayments per year. Shifting from annual to monthly review does not eliminate errors, but it shrinks the average exposure window from 180 days (the midpoint of an annual cycle) to roughly 15 days (the midpoint of a monthly cycle). That alone can convert a six-figure annual loss into a five-figure one.

The fiduciary protection value compounds over time. A documented monthly review process, sustained over multiple plan years, builds a defensible record of prudent process under ERISA Section 404. The Department of Labor's Meeting Your Fiduciary Responsibilities guidance emphasizes that fiduciaries are judged on the process they followed, not simply the financial outcome. A consistent, frequent, well-documented audit cadence is one of the clearest ways to demonstrate that process.

Conclusion: The Calendar Is Not a Fiduciary Strategy

Waiting 90 days to audit claims is a scheduling habit, not a deliberate risk decision, and that distinction matters under ERISA. Plan sponsors who have never questioned their audit cadence are not negligent by intent. They are simply operating on a calendar inherited from TPA reporting defaults and broker stewardship cycles that were never designed with fiduciary exposure in mind.

The fix does not require new technology budgets or a TPA switch. It requires a written policy, a faster data feed, and a named owner who reviews claims monthly instead of quarterly. The dollar savings are real and the fiduciary protection compounds every plan year the new cadence holds.

Start by asking your TPA one question this week: how quickly can we get claims data, and how often are we currently reviewing it. The gap between those two answers is your fiduciary exposure.

Frequently Asked Questions

What does ERISA require regarding claims audit frequency?

ERISA does not specify an exact audit frequency. Section 404(a)(1) requires fiduciaries to act with the care, skill, prudence, and diligence of a prudent person managing similar matters, which courts and the Department of Labor interpret as an ongoing obligation rather than a once-a-year exercise. The absence of a specific number does not mean infrequent review satisfies the standard.

How much does a 90-day audit delay typically cost a self-funded plan?

The cost scales with claims volume and the underlying error rate. A plan with $9 million in annual claims spend and a 3% error rate can accumulate roughly $67,500 in unreviewed overpayments over a single 90-day quarter before any audit begins, based on standard industry error-rate benchmarks from claims integrity sources.

Is a quarterly claims audit considered sufficient under ERISA?

There is no bright-line rule stating that quarterly review satisfies fiduciary duty. The Department of Labor evaluates the totality of a plan's prudent process, including frequency, documentation, and follow-through on identified errors. A quarterly cadence with strong documentation may be defensible, but a monthly or near-continuous cadence offers a stronger position.

What is the difference between a claims audit and ongoing claims monitoring?

A claims audit is typically a discrete, periodic review of a defined claims population, often tied to an annual or quarterly cycle. Claims monitoring refers to a continuous or near-continuous process that reviews claims data on a rolling basis, closer to the point of payment, which reduces the window during which errors go undetected.

Can a plan sponsor be held personally liable for failing to audit claims promptly?

Named fiduciaries, including HR leaders or finance executives who exercise discretionary authority over plan administration, can face personal liability under ERISA Section 409 for breaches of fiduciary duty. Failing to establish a reasonable claims monitoring process is a factor courts and the DOL consider when evaluating whether a breach occurred.

How do stop-loss notification requirements relate to audit timing?

Stop-loss contracts typically require prompt notification of large or catastrophic claims, often within a specified number of days from the claim reaching a certain dollar threshold. A 90-day internal audit cycle can cause large claims to be flagged for stop-loss reporting later than the contract requires, risking reduced or denied reimbursement on the claim.

What is a reasonable target audit cadence for a self-funded plan with 100 or more employees?

Most claims integrity consultants and TPA performance benchmarks recommend monthly review of claims data at minimum, with concurrent or near-real-time review for claims above a defined high-dollar threshold. Plans below 500 employees may reasonably start with monthly review and layer in more frequent high-dollar claim flags as the program matures.

Does shortening the audit cycle require switching TPAs?

No. Most plan sponsors can shorten their audit cycle by renegotiating data delivery terms within their existing TPA contract or by adding an independent claims monitoring vendor that integrates with the current TPA's claims feed. Switching TPAs is rarely necessary and introduces its own transition risk.

Fiduciary Intelligence

Why Post-Pay Audits Fail Self-Funded Employers

Abhishek Ghosh
June 18, 2026

A manufacturing company with 400 employees received its annual post-pay audit results and learned it had overpaid $340,000 in medical claims over the prior plan year. The TPA recovered $47,000. The rest was gone.

One reason was simple. The TPA's claims system lacked the sophisticated pre-payment detection capabilities needed to identify certain billing errors before funds were released.

Key Takeaways
Post-pay audits review claims after payment, which often limits how much of an overpayment can ultimately be recovered.
Common sources of claims leakage include duplicate payments, network repricing errors, unbundled procedure codes and ineligible dependents.
ERISA Section 404 requires plan sponsors to act as prudent fiduciaries when managing plan assets, including the oversight of claims payments.
Concurrent and pre-pay audit models identify errors before funds leave the plan, resulting in significantly higher recovery and prevention rates than post-pay audits alone.
Most self-funded employers cannot quantify the financial impact of claims errors because they lack independent measurement of TPA performance and accuracy.
The most effective claims oversight programs focus on preventing payment errors before money leaves the plan, rather than relying solely on recovery efforts after the fact. Earlier detection improves financial outcomes and strengthens fiduciary protection.

What a Post-Pay Audit Actually Does (and Doesn't Do)

A post-pay audit reviews claims after the TPA has already processed and paid them, which means every dollar of error it finds has already been spent. Most employers understand post-pay audits as a quality-control tool.

TPAs process millions of transactions per year. A post-pay audit typically samples 100% of claims above a dollar threshold or a statistical sample of all claims, then flags anomalies for potential recovery. The auditor sends a demand letter to the provider, the provider disputes it, negotiations begin, and the employer eventually recovers a fraction of the original error amount.

Industry data from the Healthcare Financial Management Association suggests that self-funded plans overpay between 3% and 10% of total medical claims spend annually due to processing errors, billing fraud, and repricing failures. On a $5 million annual claims spend, that is $150,000 to $500,000 in potential overpayments. The post-pay audit catches some of it. It permanently loses most of it.

Why Post-Pay Audits Are Structured to Underperform

The fundamental flaw is not execution. It is timing. Post-pay audits were designed for a world where employers primarily wanted to satisfy an annual compliance checkbox. They were never engineered to maximize claims integrity or fiduciary protection.

Several structural problems compound the timing issue:

1
Contractual Lookback Limits
Most TPA contracts limit recovery opportunities to a defined window, often 12 to 18 months. Provider repayment rights may narrow even faster under prompt-pay rules, making late recovery efforts difficult or impossible.
2
Statistical Sampling Gaps
Sampling-based audits review only a fraction of claims. Large portions of the claims population remain untouched, allowing recurring billing and payment errors to persist undetected.
3
Provider Dispute Rates
Once payment has been made, recovering funds becomes substantially harder. Providers frequently challenge repayment requests, reducing recovery success and extending resolution timelines.
4
TPA Incentive Misalignment
Many TPA contracts reward administrative activity rather than payment accuracy. Performance guarantees may focus on audit volume or processing speed instead of actual error recovery.
Together, these structural barriers make post-pay recovery increasingly difficult as time passes. The longer an error remains undetected, the lower the likelihood of recovering the full amount.

The Real Cost to Plan Sponsors

The financial exposure from inadequate claims oversight is larger than most HR leaders and CFOs realize, and it compounds year over year. A single plan year of 5% overpayments on a $10 million claims spend equals $500,000. Over five years, with no corrective action, that is $2.5 million in preventable losses.

The cost extends beyond the dollar amount recovered or not recovered. ERISA Section 404(a)(1) requires plan fiduciaries to discharge their duties with the care, skill, prudence, and diligence that a prudent person acting in a like capacity would use.

The Department of Labor has made clear through its audit and enforcement activity that reliance on a TPA does not absolve plan sponsors of fiduciary responsibility. A plan that conducts only an annual post-pay audit and recovers 15 cents on the dollar is not meeting that standard.

The Kaiser Family Foundation's 2023 Employer Health Benefits Survey found that the average annual family premium for employer-sponsored coverage exceeded $23,000. Self-funded plans bear 100% of claims cost directly. Every dollar of claims error flows straight to the plan's bottom line, and ultimately to employee cost-sharing and benefit design decisions.

What's Actually Happening Behind the Scenes

Duplicate Payment Errors
Providers and billing clearinghouses routinely resubmit denied or rejected claims. Without a pre-payment duplicate detection process, the same claim can be paid more than once before the error is identified.
Network Repricing Failures
Claims processed using the wrong fee schedule can result in substantial overpayments. Detecting these errors often requires matching claims against network contracts that are not always readily available or easy to audit.
Unbundling and Upcoding
Billing practices can increase reimbursement by separating procedures that should be billed together or assigning higher-complexity codes than warranted. These errors frequently require clinical review to identify.
Ineligible Dependent Coverage
Changes in eligibility status are not always captured promptly. Plans may continue paying claims for dependents who no longer qualify for coverage, creating avoidable costs over time.
Coordination of Benefits Failures
When members are covered by multiple health plans, payment responsibilities must be coordinated correctly. Failures in this process are a frequent source of overpayments and are often difficult to detect after payment occurs.
These errors rarely occur in isolation. Most plans experience multiple leakage sources simultaneously, making independent claims oversight essential for identifying patterns that routine post-pay reviews often miss.

Why Current Approaches Aren't Enough

Annual post-pay auditing has become an industry default, not an industry best practice. The comparison below shows the practical difference between a post-pay approach and a concurrent or pre-pay model.

Factor Post-Pay Audit Concurrent / Pre-Pay Audit
When Errors Are Detected After payment, often 30 to 180 days later Before or at the moment of payment
Recovery Rate Typically 10% to 30% of identified errors 80% to 100% of identified errors
Provider Dispute Friction High (money already paid) Low (claim pended for correction)
Claims Reviewed Statistical sample or threshold-based 100% of claims in real time
Dependent Eligibility Verification Periodic, not continuous Continuous, integrated with enrollment data
Fiduciary Documentation Minimal Comprehensive audit trail per claim
Cost to Employer Lower upfront, higher net loss potential Higher upfront, positive ROI in most plans over 200 lives

How to Fix It: A Practical Path for Plan Sponsors

1
Review Your TPA Contract First
Examine your ASO agreement for audit rights, data access provisions and recovery limitations. Many contracts restrict access to claims data or impose fees that weaken oversight efforts.
2
Demand Complete Claims Data
Obtain full claims files in a standardized format such as HIPAA 835 or 837. Independent auditors need raw transaction data, not summarized reporting, to perform a comprehensive review.
3
Implement a Pre-Pay Audit Layer
Integrate an independent payment integrity vendor into the claims workflow to identify errors before payment is released rather than attempting recovery after the fact.
4
Conduct a Dependent Eligibility Audit
Verify dependent eligibility and establish an ongoing re-verification process. Ineligible dependents can represent a significant source of avoidable plan expense.
5
Add Clinical Review for High-Cost Claims
Establish nurse or clinical review for claims above a defined threshold to evaluate medical necessity, level of care and billing accuracy before payment.
6
Maintain Fiduciary Documentation
Keep records of policies, audits, findings, vendor agreements and corrective actions. A documented process is often as important as the audit itself from a fiduciary perspective.
The strongest payment integrity programs prevent errors before money leaves the plan. Combining contractual protections, independent auditing and documented oversight creates a more defensible and financially efficient health plan.

Red Flags That Signal This Problem Applies to Your Plan

Your TPA's annual audit report shows a recovery rate below 50% of identified errors.
You have not reviewed your TPA's performance guarantees in the past 24 months.
Your plan has not conducted a dependent eligibility audit in the past three years.
Your stop-loss carrier has never asked to review your claims data or audit processes.
Your benefits broker cannot tell you what your TPA's aggregate claims error rate is.
You are relying solely on your TPA's internal quality control team to catch its own errors.
Your plan documents do not include a written claims audit policy or schedule.
You have changed TPAs in the past three years without auditing claims processed during the transition period.
If three or more of these statements apply to your plan, there is a strong possibility that payment errors are going undetected or unrecovered. Independent auditing, stronger governance and ongoing claims oversight can help close those gaps before they become larger financial and fiduciary issues.

The ROI of Getting Claims Oversight Right

The return on investment from upgrading claims audit infrastructure is measurable and consistent across employer sizes. Independent studies and vendor case data suggest the following benchmarks:

Pre-pay and concurrent audit programs typically generate $3 to $8 in recovered or avoided overpayments for every $1 spent on the program. On a plan spending $8 million annually in medical claims, capturing even half of a conservative 3% error rate produces $120,000 in savings. A concurrent audit program for a plan that size typically costs $30,000 to $60,000 annually. The math is straightforward.

Dependent eligibility audits cost $15 to $40 per employee audited and routinely return 10 to 20 times that amount in annual premium savings from removing ineligible dependents. For a plan with 500 employees, the audit cost might be $20,000. If 4% of 900 covered dependents are removed and each carried an average monthly cost of $400, the annual savings exceeds $86,000.

The fiduciary protection value is harder to quantify but significant. DOL investigations of self-funded plans that result in findings of inadequate claims oversight can require the plan to reimburse participants for losses plus interest. Documented, proactive audit programs are a primary defense against that exposure.

Conclusion: Stop Auditing Yesterday's Mistakes

Post-pay audits have a place in a comprehensive claims oversight program, but they cannot be the entire program. Self-funded employers who rely on an annual post-pay review as their primary quality control tool are systematically overpaying their claims, underperforming on their ERISA fiduciary obligations, and leaving recoverable money on the table every month.

The good news is that better tools exist and are accessible to plans well below the Fortune 500 threshold. Concurrent audit programs, dependent eligibility verification, and clinical review of high-cost claims can be layered into most TPA relationships with modest contract adjustments and reasonable vendor investment. The ROI is well-documented. The fiduciary argument is clear.

Start by requesting your full claims data file from your TPA and scheduling an independent review. If your TPA resists providing the data, that resistance is itself a finding.

Frequently Asked Questions

What is a post-pay claims audit?

A post-pay claims audit is a review of health plan claims that have already been processed and paid by the third-party administrator. The auditor identifies errors such as duplicate payments, incorrect repricing, or unbundled procedure codes after the funds have transferred to providers.

How much do self-funded employers typically overpay on medical claims?

Industry estimates from the Healthcare Financial Management Association and independent payment integrity consultants place the overpayment rate for self-funded plans at 3% to 10% of total annual claims spend.

What is the difference between a post-pay audit and a concurrent audit?

A post-pay audit reviews claims after payment has been made. A concurrent audit integrates with the claims payment process in real time and flags suspected errors before the TPA releases payment to the provider. Concurrent audits prevent overpayment rather than attempting to recover it, which produces materially higher net savings for the plan.

Does ERISA require self-funded employers to audit their claims?

ERISA does not mandate a specific audit frequency or methodology, but Section 404 requires plan fiduciaries to act with the care, prudence, and diligence of a knowledgeable person managing plan assets.

Can a TPA conduct its own claims audit?

A TPA can conduct internal quality reviews, and most do. However, relying solely on the TPA to audit its own claims processing creates a conflict of interest. An independent third-party auditor with access to raw claims data provides a more objective assessment and typically identifies a different, often larger, set of errors than the TPA's internal team.

What should a self-funded employer look for in a claims audit vendor?

Look for a vendor that reviews 100% of claims rather than a statistical sample, has direct integration with your TPA's claims system, provides itemized error reporting with CPT code-level detail, covers dependent eligibility as part of the audit scope, and offers a clear fee structure that is not contingency-only (which can create incentives to flag borderline items). Ask for client references from plans of similar size and industry.

How long should self-funded employers retain claims audit records?

ERISA Section 107 requires plan records to be retained for at least six years from the filing date of the annual Form 5500 to which they relate. Claims audit documentation, including methodology, findings, and corrective actions, should be treated as plan records subject to this retention requirement.

What percentage of identified overpayments does a post-pay audit typically recover?

Recovery rates vary widely, but most independent claims auditors and benefits consultants report effective post-pay recovery of 15% to 35% of identified overpayments. Provider disputes, expired lookback windows, and practical collection limitations account for the gap. Pre-pay and concurrent models avoid this problem because the money never leaves the plan's account.

Fiduciary Intelligence

Claims Leakage Is Not Fraud. It's Operational Drift

Abhishek Ghosh
June 15, 2026

Claims leakage is the chronic, undetected loss of health plan dollars caused by billing errors, pricing failures, and processing gaps rather than intentional fraud. It typically costs self-funded employers 3 to 5 percent of total annual claims spend. It is addressable through independent claims audits and stronger TPA oversight contracts.

A mid-size manufacturing company with 800 employees discovers, two years into its self-funded health plan, that its TPA paid the same surgical claim three times. The total overcharge: $47,000. No one committed fraud.

The TPA's system missed a duplicate claim after the facility changed a single digit in the billing code, a reminder that many TPAs lack the advanced technology needed to identify complex claims leakage.

According to the Healthcare Financial Management Association, improper payments and billing errors account for an estimated 3 to 5 percent of total health plan spend annually. For a plan spending $8 million a year, that's up to $400,000 leaving through the back door quietly, year after year.

Key Takeaways
Claims leakage is a form of systemic payment error caused by operational breakdowns, not fraud or intentional misconduct.
Most leakage goes undetected because plan sponsors often rely entirely on their TPA for claims oversight and verification.
Common sources include duplicate payments, repricing failures, coordination-of-benefits errors and unbundled surgical coding.
ERISA requires plan fiduciaries to act with the care and diligence of a prudent expert. Passive reliance on a TPA does not satisfy that obligation.
Independent claims audits routinely recover 1% to 3% of audited spend while helping reduce future leakage through improved oversight.
Claims leakage is rarely the result of a single large mistake. More often, it stems from small errors repeated across thousands of transactions. Independent auditing helps identify those errors, recover overpayments and strengthen fiduciary governance.

What Claims Leakage Actually Is (And What It Is Not)

Claims leakage is not fraud. It is the slow, compounding erosion of health plan assets caused by errors, process failures, and gaps in oversight that no one catches.

Most HR leaders and CFOs associate financial loss with intentional misconduct. That framing is understandable but costly. It means they do not look for a problem that is almost certainly present in their plan right now.

The term "claims leakage" describes payments that leave the plan incorrectly. They may be duplicates. They may be priced against the wrong contract. They may reflect services that were billed but not rendered. They may include charges for a dependent who aged off the plan six months ago. None of these require bad intent. All of them represent real money paid out that should not have been.

The analogy that makes this stick: claims leakage is like a slow water leak behind your walls. Nothing looks wrong from the outside. There's no burst pipe, no flood. But by the time you notice the damage, the loss has been accumulating for years.

Why Claims Leakage Is Structural, Not Accidental

The root cause is a fundamental misalignment between who processes claims, who audits them, and who bears the financial risk.

Your TPA adjudicates and pays claims on your behalf. Their incentive is speed and throughput. Volume is how they demonstrate value. Catching every nuanced billing error requires the kind of meticulous review that slows throughput.

Most TPA performance guarantees focus on turnaround time and error rates tied to a narrow sample of total claims, often 1 to 3 percent reviewed post-payment.

The employer. the party that actually funds every claim. typically has no internal claims expertise. Benefits staff manage enrollment and vendor relationships. They are not trained to interrogate 835 transaction files or identify miscoded facility charges.

This is not a conspiracy. It is a structural gap that allows billing errors to pass through the system unchallenged. According to the Government Accountability Office, the lack of independent oversight in self-funded plan management is a documented and recurring concern in federal reporting on healthcare payment integrity.

The Real Cost: What the Numbers Show

Employers with self-funded health plans lose an estimated 3 to 5 percent of total annual claims spend to leakage, a figure documented across multiple industry analyses.

The dollar impact scales fast. A plan spending $5 million per year loses $150,000 to $250,000. A plan at $20 million loses $600,000 to $1 million. These figures represent what independent claims auditors routinely find when they examine a full plan year of adjudicated data.

Duplicate claims alone account for a meaningful share of that loss. The Medical Billing Advocates of America estimates that up to 80 percent of medical bills contain at least one error. Not all errors favor the payer, but a significant portion result in overpayments.

Coordination of benefits failures create additional exposure. When a dependent is covered under two health plans, the plan that should pay secondary sometimes pays primary because the eligibility data was never updated. The overpayment is often never recovered unless someone specifically looks for it.

Stop-loss reimbursement accuracy is another underappreciated risk. If your TPA misclassifies claims or applies the wrong deductible accumulator logic, your stop-loss carrier may pay less than your plan is owed. A claim repriced at $180,000 instead of the actual $210,000 allowed amount could cause the plan to miss its specific attachment point entirely.

What Is Actually Happening Inside Claim Adjudication

Repricing Errors

Repricing failures occur when a claim is paid against the wrong network contract, wrong fee schedule, or outdated rate.

This is more common than most plan sponsors realize. Provider contracts update. Network configurations change when TPAs renegotiate. If system tables are not updated promptly, claims process at old rates. In some cases, out-of-network claims are incorrectly routed as in-network. The difference per claim can be tens of thousands of dollars on high-cost procedures.

Duplicate Claim Payments

A duplicate payment occurs when the same service is paid more than once due to minor variations in the claim submission.

Facilities often refile claims after a denial or delay. If the original claim was eventually paid and the refiled version is also paid, the plan has double-funded the same service. Variations in billing code, date of service formatting, or provider NPI can defeat basic duplicate detection logic.

Coordination of Benefits Failures

COB failures result in the plan paying primary when it should pay secondary or not paying at all.

Dependents covered under a spouse's plan, working retirees with Medicare, and children of divorced parents with dual coverage all create COB complexity. When eligibility data is stale or the TPA's COB workflow breaks down, the employer plan overpays. Recovery requires proactive subrogation and COB recovery programs most plans do not have in place.

Unbundling and Upcoding

Unbundling occurs when a provider bills separately for services that should be billed as a single bundled procedure code.

CPT code bundling rules exist precisely to prevent this. But automated claim systems do not always catch every improper unbundling pattern, particularly for surgical assists, anesthesia, and facility fees. Upcoding is the related practice of billing for a more complex service than the one delivered. Both inflate plan costs without triggering fraud detection.

Ineligible Dependent Coverage

Claims paid for dependents who no longer qualify under the plan document represent direct leakage with a recoverable element.

Dependents who age out, ex-spouses who remain on the plan after divorce, and adult children past the plan's cutoff date all generate improper payments. Dependent eligibility audits conducted by independent vendors typically find ineligible dependents on 3 to 8 percent of enrolled employee files.

Why Current Oversight Approaches Are Not Enough

Relying on your TPA to self-report payment errors is structurally equivalent to asking a contractor to audit their own invoices.

Most plan sponsors accept their TPA's claims reports as authoritative. They review aggregate spend by category and surface-level utilization metrics. They do not examine claim-level data for patterns that indicate systematic errors. This is not negligence. It is a knowledge gap reinforced by a lack of independent access to the data.

Approach What It Covers What It Misses
TPA Internal QA Sample of claims, self-defined error categories Systemic repricing failures, coordination-of-benefits gaps and pattern-based errors
Broker Annual Review Plan-level cost trends, network performance Claim-level accuracy and individual overpayments
Stop-Loss Audit (Carrier-Initiated) High-dollar claims above the attachment point Claims below the specific deductible
Independent Claims Audit Full claim-level review across all categories Nothing, by design
Reactive Recovery Only Errors flagged after a complaint or issue is reported Errors that never surface, duplicate payments and silent leakage

The Consolidated Appropriations Act of 2021 (CAA 2021) now requires TPAs and brokers to disclose conflicts of interest and compensation to plan fiduciaries. This is a significant development. But disclosure does not equal oversight.

A plan sponsor who receives a compensation disclosure and takes no further action has not fulfilled their fiduciary duty under ERISA Section 404. The DOL's Employee Benefits Security Administration has been explicit on this point.

How to Fix Claims Leakage in Your Plan

Addressing claims leakage requires a shift from passive monitoring to structured, independent verification at the claim level.

1
Commission an Independent Claims Audit
Engage a firm with no financial relationship to your TPA, broker or PBM. A comprehensive audit should review every claim, not just a sample.
2
Require Contractual Data Access
Ensure your plan documents and TPA agreement provide unrestricted access to complete claims data in a machine-readable format.
3
Strengthen TPA Accountability
Establish performance guarantees with meaningful financial consequences tied to payment accuracy and overpayment recovery.
4
Conduct a Dependent Eligibility Audit
Review eligibility records to identify ineligible dependents and reduce avoidable plan costs.
5
Audit Pharmacy Benefits Separately
PBM contracts require specialized review. Examine spread pricing, rebate arrangements, DIR fees and formulary management practices independently from medical claims.
6
Review Your Fiduciary Posture
Work with ERISA counsel to evaluate whether current oversight practices meet the prudent expert standard and withstand regulatory scrutiny.
Claims leakage rarely disappears on its own. Independent auditing, stronger contract controls and documented fiduciary oversight are the most effective ways to reduce recurring payment errors and protect plan assets.

Red Flags That Claims Leakage Is Present in Your Plan

1
Commission an Independent Claims Audit
Engage a firm with no financial relationship to your TPA, broker or PBM. A comprehensive audit should review every claim, not just a sample.
2
Require Contractual Data Access
Ensure your plan documents and TPA agreement provide unrestricted access to complete claims data in a machine-readable format.
3
Strengthen TPA Accountability
Establish performance guarantees with meaningful financial consequences tied to payment accuracy and overpayment recovery.
4
Conduct a Dependent Eligibility Audit
Review eligibility records to identify ineligible dependents and reduce avoidable plan costs.
5
Audit Pharmacy Benefits Separately
PBM contracts require specialized review. Examine spread pricing, rebate arrangements, DIR fees and formulary management practices independently from medical claims.
6
Review Your Fiduciary Posture
Work with ERISA counsel to evaluate whether current oversight practices meet the prudent expert standard and withstand regulatory scrutiny.

The ROI of Getting Claims Oversight Right

Independent claims audits consistently return more than they cost, often by a factor of three to ten.

Recovery rates vary by plan size, audit scope, and how long since the last audit. For plans that have never been independently audited, first-year recovery of 1 to 3 percent of total audited spend is typical. On a $10 million plan, that is $100,000 to $300,000 recovered in year one.

The ongoing benefit is larger than the one-time recovery. Once errors are identified and the TPA corrects underlying system or process failures, forward-looking savings compound annually. A repricing error corrected in year one does not recur in years two through five.

ERISA litigation against plan sponsors has increased significantly in the past five years. Cases like Lewandowski v. Johnson and Johnson and parallel suits against Wells Fargo and JPMorgan Chase demonstrate that courts and plaintiffs will examine whether plan fiduciaries took active steps to control costs and verify claims accuracy.

Conclusion and Next Steps

Claims leakage is not a fringe problem. It is the predictable outcome of a system in which the party that processes payments is also the party responsible for validating them. For self-funded employers, the financial exposure is real, the fiduciary risk is documented, and the fix is actionable.

The first step is accepting that your claims data probably contains errors you have not seen. The second step is gaining independent access to that data. The third is engaging an auditor who owes their loyalty to the plan and its participants, not to your vendor relationships.

ERISA does not require perfection. It requires diligence. An independent claims audit is one of the most concrete demonstrations of that diligence available to a plan sponsor today.

Frequently Asked Questions

What is claims leakage in a self-funded health plan?

Claims leakage is the loss of health plan assets through payment errors, processing failures, and oversight gaps rather than fraud. It includes duplicate payments, repricing mistakes, coordination of benefits failures, and payments for ineligible dependents. It is endemic to self-funded plans and typically goes undetected without an independent claims audit.

How much does claims leakage cost employers?

Industry estimates consistently place claims leakage at 3 to 5 percent of total annual claims spend. For a plan with $8 million in annual claims, that represents $240,000 to $400,000 in annual loss. First-time independent audits frequently recover 1 to 3 percent of total audited spend in identifiable overpayments.

Is my TPA responsible for catching claims leakage?

Your TPA has contractual obligations to process claims accurately, but their internal QA programs typically audit only a small sample of total claims. They are not positioned as independent auditors and have no financial incentive to surface systemic errors. Under ERISA, the plan fiduciary, which is the employer, bears responsibility for oversight.

What does ERISA require of plan sponsors regarding claims accuracy?

ERISA Section 404 requires plan fiduciaries to act with the care, skill, prudence, and diligence that a knowledgeable person familiar with such matters would use. This prudent expert standard means plan sponsors cannot simply defer to their TPA. They must take active steps to verify that the plan is being administered correctly and in the interest of participants.

What is an independent claims audit and how does it work?

An independent claims audit is a systematic review of adjudicated claims data conducted by a firm with no financial relationship to the TPA, broker, or PBM. The auditor receives full claims data in electronic format (typically 835 transaction files), applies rule-based and analytical review logic, and produces a report identifying overpayments, error patterns, and recovery opportunities.

How is claims leakage different from healthcare fraud?

Fraud involves intentional misrepresentation. Claims leakage involves errors, system failures, and process gaps. Both result in improper payments, but fraud requires criminal intent and legal enforcement. Leakage is correctable through operational fixes, contract renegotiation, and process improvement. Most dollar losses in self-funded plans fall into the leakage category, not fraud.

Does CAA 2021 help plan sponsors address claims leakage?

The Consolidated Appropriations Act of 2021 strengthened plan sponsors' data access rights and required TPAs and brokers to disclose compensation and conflicts of interest. These provisions create a foundation for better oversight. But the law gives plan sponsors tools, not guarantees. Sponsors still need to exercise their data rights and act on what the data shows.

How often should a self-funded plan conduct a claims audit?

Annual audits are the standard recommended by benefits attorneys and claims integrity consultants for plans above $5 million in annual spend. Plans that have never been audited should treat the first audit as a priority regardless of size. Plans undergoing TPA transitions should audit the prior TPA's full claims history before the transition closes.

Fiduciary Intelligence

The Hidden Fiduciary Risk Sitting Inside Every TPA Relationship

Abhishek Ghosh
June 9, 2026

A TPA fiduciary risk is the legal and financial exposure a self-funded employer faces when its third-party administrator processes claims incorrectly and the employer, as ERISA plan fiduciary, is held responsible for the losses. Because TPAs are typically not ERISA fiduciaries themselves, the liability stays with the plan sponsor.

A mid-sized manufacturer in Ohio recently discovered that its TPA had been paying a terminated employee's medical claims for 14 months after the employee left the company.

The total exposure: $340,000. Under ERISA, the employer, not the TPA, bore responsibility for recovering those funds. The Department of Labor does not grade plan sponsors on how trusting they were of their vendor.

Key Takeaways
Self-funded employers are ERISA fiduciaries, while their TPAs typically are not.
When a TPA makes a claims error, the plan sponsor is usually the party responsible for addressing the financial and fiduciary consequences.
Industry research suggests that 3% to 10% of health plan claims contain some form of error.
Most employers lack an independent process to identify claims errors before or after payment.
A structured claims audit program is the most direct way to strengthen oversight, improve accountability and reduce exposure to avoidable claims errors.
Delegating claims administration does not transfer fiduciary responsibility. Independent auditing helps plan sponsors verify accuracy, recover overpayments and demonstrate prudent oversight under ERISA.

What the TPA Relationship Actually Means for Fiduciary Liability

Most employers believe their TPA carries the legal risk when something goes wrong with claims. That belief is incorrect, and it is expensive.

Under ERISA Section 404, the plan sponsor (the employer) is a named fiduciary obligated to act solely in the interest of plan participants, follow the plan document and exercise the skill of a prudent expert.

TPAs are hired as service providers. Unless a TPA contractually accepts discretionary authority over plan assets and explicitly agrees to ERISA fiduciary status, which almost none do, it operates as a vendor, not a co-fiduciary.

Think of it like hiring a contractor to wire your building. If the work is faulty and someone gets hurt, the building owner faces liability. The contractor may owe indemnification under the service contract, but that is a separate civil dispute that takes time and money to resolve. Meanwhile, the DOL or an aggrieved participant is looking at you.

Why the Problem Exists

The TPA model was built for efficiency, not for employer oversight.

When an employer moves from fully insured to self-funded, it gains cost transparency and control. It also inherits accountability.

The administrative services only (ASO) agreement that governs the TPA relationship is typically written by the TPA's legal team. These contracts often include liability caps, indemnification carve-outs and language that limits the TPA's responsibility for errors to a narrow definition of "gross negligence."

1
Volume and Velocity
A TPA serving a 500-life group may process more than 10,000 claims annually. At that scale, both manual review and automated adjudication systems inevitably produce errors.
2
Asymmetric Information
Employers typically receive summary reports while TPAs retain the detailed claim-level data. Most organizations cannot evaluate what they cannot see.
3
No Independent Verification Loop
Fully insured plans have carriers reviewing their own financial risk. Self-funded plans lack a comparable backstop unless the employer intentionally creates one.
4
Misaligned Incentives
TPAs earn administrative fees, not a share of claims savings. Identifying and recovering overpayments often creates additional work without generating additional revenue.
Together, these structural factors make claims errors difficult for employers to detect without independent oversight, detailed data access and a formal audit process.

The Real Cost of Unchecked Claims

The financial exposure from TPA claims errors is not theoretical. It is documented, recurring and significant.

The Government Accountability Office has reported that improper payments in employer health plans are a persistent problem across both public and private sectors.

Industry benchmarks from claims audit firms consistently show that between 3 and 10 percent of processed claims contain some form of error, ranging from duplicate payments to incorrect member eligibility to miscoded procedures.

For a self-funded employer spending $5 million annually on medical claims, a 5 percent error rate represents $250,000 in potential misprocessed payments. A 2022 analysis by the Healthcare Financial Management Association found that coordination of benefits (COB) errors alone cost employers an average of $350 per affected employee per year.

Beyond the direct dollar loss, there are secondary costs:

DOL Audit Exposure
Plans that lack documented fiduciary controls may face greater scrutiny during a Department of Labor review or investigation.
Legal Defense Costs
Participant complaints, fiduciary breach allegations and regulatory inquiries can result in significant legal expenses regardless of the outcome.
Reputational Damage
Benefit errors that directly affect employees can reduce trust in leadership and create unnecessary employee relations challenges.
Lost Recovery Opportunities
Delays in subrogation and third-party liability recovery can permanently reduce the amount returned to the health plan.
The financial impact of claims errors extends beyond overpayments. Regulatory exposure, legal costs, reputational harm and missed recovery opportunities can significantly increase the total cost of inadequate oversight.

What Is Actually Happening Behind the Scenes

Most claims errors are not fraud. They are systemic, predictable and preventable through routine auditing.

Duplicate Claims

A provider submits the same claim twice with minor coding variations. Auto-adjudication systems miss the duplication. Both claims pay. This is among the most common and most recoverable error types.

Eligibility Errors

Dependents age off coverage but are not removed from the system. Former employees remain active in the TPA's eligibility file. Claims pay for individuals who are no longer entitled to benefits. These errors are often months old before anyone notices.

Coordination of Benefits Failures

When a member has coverage under two plans, the primary payer should pay first and the secondary payer should pay only the remaining balance. When COB logic is applied incorrectly or not applied at all, both plans pay in full. The employer's plan absorbs a cost it should never have incurred.

Incorrect Repricing and Network Discounts

A claim is processed at billed charges rather than the contracted network rate. The provider is overpaid. Recovery from a provider after the fact is possible but administratively burdensome and often partial.

Unbundling and Upcoding

Providers submit separate line items for services that should be billed as a single bundled procedure code, inflating the allowed amount. Upcoding, billing for a higher-acuity service than was documented, is an ongoing issue that claims review software sometimes catches and sometimes does not.

Terminated Provider Contracts

A provider's network contract expires or is terminated, but the TPA continues to process claims as if the contract is in force. The employer pays network rates on claims that should have been processed as out-of-network, which may create additional downstream liability.

Why Current Approaches Are Not Enough

Relying solely on TPA internal controls to protect your plan is the equivalent of asking the contractor to inspect their own work.

Most employers receive monthly or quarterly claims reports. Those reports show aggregated spend by category, provider type or member. They are useful for budgeting. They do not reveal individual claim errors.

Some TPAs offer internal audit functions. These are not independent by definition. The TPA auditing its own claims adjudication has an inherent conflict of interest, regardless of how diligent the staff may be.

Approach What It Covers What It Misses Independence
TPA Internal Review High-dollar outliers, fraud flags Routine errors, eligibility gaps, COB failures None
Employer Claims Reports Aggregate spend trends Individual claim accuracy None
Annual TPA Scorecard SLA metrics, call center performance Claims-level accuracy Partial
Independent Prospective Audit Pre-payment review of claims logic Claims already paid Full
Independent Retrospective Audit Paid claims errors, recoveries Future claims Full
Continuous Audit Program Both pre- and post-payment review None (by design) Full

How to Fix It: A Practical Action Plan

Closing the fiduciary gap requires structure, contract language and independent verification. None of these steps requires replacing your TPA.

1
Review Your ASO Agreement
Confirm the contract clearly addresses TPA liability for claims errors and grants unrestricted access to claim-level data.
2
Demand Full Claims Data Access
Establish a regular data feed so claims information can be independently reviewed and analyzed.
3
Engage an Independent Claims Auditor
Use an independent firm to identify payment errors, recover overpayments and validate claims accuracy.
4
Strengthen Audit Rights
Ensure every vendor agreement explicitly permits independent claims audits without unnecessary restrictions.
5
Review High-Dollar Claims Before Payment
Implement a secondary review process for large claims that carry disproportionate financial risk.
6
Document the Oversight Process
Maintain records of audits, findings, reviews and corrective actions to demonstrate prudent fiduciary oversight.
7
Review Performance Guarantees Annually
Measure TPA performance against contractual guarantees and pursue available remedies when standards are not met.
Closing the fiduciary gap does not require replacing your TPA. It requires stronger governance, independent verification and documented oversight.

Red Flags That Signal This Problem Applies to Your Plan

You have never conducted an independent claims audit.
Your TPA contract does not grant unrestricted access to claim-level data.
You cannot identify all active plan participants and dependents in real time.
Your stop-loss carrier has never asked to review your audit results.
Your ASO agreement has not been reviewed by ERISA counsel in more than two years.
You rely entirely on TPA-generated reports for plan performance data.
You have no documented process for reviewing TPA claims accuracy.
Your plan has grown or changed significantly since you last reviewed TPA eligibility files.
If several of these conditions apply to your plan, there is a strong likelihood that oversight gaps exist. Independent auditing, stronger contract controls and regular governance reviews can significantly reduce fiduciary and financial risk.

The ROI of Doing It Right

Independent claims auditing consistently returns more than it costs, often by a multiple of three to five.

Retrospective audits of self-funded plans regularly recover between 1 and 3 percent of total paid claims. On a $5 million claims spend, that is $50,000 to $150,000 in recoveries per audit cycle. Contingency-fee audit arrangements mean the employer pays nothing unless recoveries are made.

The less quantifiable but equally real returns include:

  • Documented fiduciary process that withstands a DOL inquiry
  • Corrected eligibility files that reduce future claim errors
  • Data that reveals patterns requiring TPA system corrections
  • Leverage in TPA contract renegotiation backed by actual performance data
  • Stop-loss carrier confidence that reduces friction at claim time

One regional health system with approximately 1,200 covered lives conducted its first independent claims audit after a compliance review flagged the absence of any oversight process. The audit recovered $218,000 in overpayments and identified a COB configuration error in the TPA system that had been generating duplicate payments for 22 months.

Conclusion and Next Steps

The fiduciary risk inside your TPA relationship is not a hypothetical. It is a documented, measurable and addressable problem that most plan sponsors have simply not prioritized.

ERISA does not expect perfection. It expects process. The plan sponsors who fare best in DOL audits, stop-loss disputes and participant complaints are those who can show a documented, repeatable approach to monitoring their TPA and correcting errors when they occur. An independent claims audit is the most direct tool available to accomplish that.

If you have never conducted an independent claims audit, that is the place to start. If you have not reviewed your ASO agreement with ERISA counsel, that is the second step. Neither task requires replacing your TPA. Both tasks are within reach for any plan sponsor, regardless of plan size.

Frequently Asked Questions

Is my TPA an ERISA fiduciary?

Almost certainly not. Most TPAs operate under administrative services only (ASO) agreements and explicitly disclaim ERISA fiduciary status in those contracts. Unless your TPA has signed a written agreement accepting discretionary fiduciary authority over plan assets, ERISA fiduciary responsibility stays with the employer as plan sponsor. Always verify this with ERISA counsel by reviewing your ASO agreement directly.

What does ERISA actually require me to do to oversee my TPA?

ERISA Section 404(a) requires plan fiduciaries to act with the care, skill, prudence and diligence of a knowledgeable professional. Applied to TPA oversight, this means having a documented process for selecting, monitoring and, when warranted, replacing your TPA. Courts and the DOL have held that "monitoring" requires more than receiving summary reports. It requires meaningful review of the TPA's actual claims performance.

How often should we conduct a claims audit?

Most benefits consultants recommend a full retrospective audit every one to two years, with continuous or quarterly monitoring in between. High-volume plans or plans that have recently changed TPAs, plan designs or eligibility rules benefit from more frequent review. The first audit typically yields the highest recoveries because it establishes a baseline and catches errors that have accumulated over time.

What types of errors does a claims audit typically find?

The most common categories are duplicate payments, eligibility errors (covering ineligible members or dependents), coordination of benefits failures, incorrect network repricing, unbundled or upcoded procedure codes and terminated provider contract issues. Eligibility errors and COB failures tend to generate the largest individual recoveries because they often persist for months before detection.

Can we require our TPA to conduct audits on our behalf?

You can require it contractually, and many ASO agreements include provisions for TPA self-reporting and internal quality reviews. However, a TPA auditing its own claims adjudication is not independent oversight. It does not satisfy the prudent expert standard under ERISA and will not carry the same weight with the DOL or in litigation as an audit conducted by a firm with no financial relationship to the TPA.

What should we look for in an ASO agreement before signing?

Prioritize four provisions: (1) unrestricted access to claim-level data, (2) explicit audit rights allowing independent review at any time, (3) defined liability for claims errors with no cap that effectively eliminates recovery, and (4) performance guarantees with financial penalties tied to measurable claims accuracy metrics. Most standard TPA contracts require negotiation to include all four.

Does our stop-loss carrier care whether we conduct claims audits?

Increasingly, yes. Stop-loss carriers are paying closer attention to plan sponsor fiduciary practices because their own exposure depends on the accuracy of underlying claims data. Some carriers now include audit requirements as a condition of coverage or give premium credit to employers with documented audit programs. If your stop-loss carrier has never asked about your audit practices, raise the topic proactively.

What is the difference between a prospective and a retrospective claims audit?

A prospective audit reviews claims before payment, typically for high-dollar or complex claims, to catch errors before money leaves the plan. A retrospective audit reviews claims already paid to identify recoverable overpayments and systemic errors. Most employers start with a retrospective audit because it yields immediate recoveries and reveals patterns for the TPA to correct going forward.

Fiduciary Intelligence

What Happens When No One Owns Claims Accuracy?

Abhishek Ghosh
June 11, 2026

A 1,000-employee company spends ~$15 million each year on healthcare claims. The TPA processes payments on time. Employees receive care without disruption. Renewal discussions focus on trend projections and stop-loss premiums.

Three years later, an independent review uncovers hundreds of thousands of dollars in claims errors that nobody noticed.

The surprising part is not that errors occurred. The surprising part is that nobody was explicitly responsible for finding them.

In many self-funded health plans, claims accuracy falls into an accountability gap. Everyone assumes someone else is watching. Few organizations verify whether that assumption is true.

Key Takeaways
Most self-funded plans do not independently verify claims accuracy.
TPAs process claims but are not always audited against every claim they pay.
Even small error rates can translate into significant financial losses over time.
Lack of oversight can create ERISA fiduciary concerns in addition to financial leakage.
Clear ownership combined with independent auditing improves accountability, strengthens oversight and supports better plan performance.
Organizations that treat claims oversight as an ongoing fiduciary responsibility rather than a periodic administrative task are better positioned to reduce financial leakage, improve vendor accountability and protect plan assets.

What Is the Core Problem?

The core problem is that claims accuracy often lacks a clearly designated owner within self-funded health plans.

Most employers assume their TPA is fully responsible for ensuring every claim is paid correctly. That assumption sounds reasonable but overlooks an important reality.

TPAs administer claims according to plan documents, contracts, system configurations, provider agreements, and eligibility data. Each component introduces opportunities for mistakes.

Meanwhile, HR teams focus on employee experience. Finance leaders focus on budgets. Brokers focus on strategy and market positioning. Stop-loss carriers focus on large claim exposure.

As a result, no single stakeholder consistently validates whether claims are being paid accurately.

Claims accuracy becomes like a building with multiple security cameras but no one monitoring the screens.

Why the Problem Exists

Claims accuracy gaps exist because responsibility is distributed while accountability remains undefined.

Several structural factors contribute to the issue.

Complexity Continues to Increase

Modern healthcare claims involve network discounts, coding rules, plan provisions, coordination of benefits, eligibility feeds, pharmacy integrations, and provider contracts.

Each transaction depends on multiple systems working correctly.

The complexity of healthcare payment systems continues to grow as reimbursement methodologies and payment integrity requirements evolve across the industry. See resources from Healthcare Financial Management Association (HFMA) for additional guidance on healthcare finance and payment integrity.

Employers Trust Administrative Expertise

Most plan sponsors hire experienced TPAs and reasonably expect professional administration.

That trust often reduces demand for independent verification.

Audits Are Frequently Limited

Many organizations review only small samples of claims.

Sampling can identify patterns but cannot guarantee visibility into every payment.

Performance Metrics Focus Elsewhere

Service metrics often emphasize call center performance, turnaround times, and participant satisfaction.

Accuracy receives less attention than operational speed.

Data Is Difficult to Access

Claims data is often fragmented across vendors, making comprehensive oversight challenging without specialized tools.

The Real Cost and Impact

Even modest claims error rates can create substantial financial exposure.

Healthcare payment integrity studies consistently find that payment errors occur across public and private healthcare programs.

Multiple reviews by the U.S. Government Accountability Office (GAO) have highlighted the ongoing challenge of improper payments across healthcare systems.

A self-funded employer spending $15 million annually may view a 1% error rate as insignificant.

That seemingly small percentage equals $150,000 per year.

Over five years, the cumulative impact exceeds $750,000 before considering trend growth.

The consequences extend beyond direct overpayments.

Financial Leakage

Incorrect payments increase healthcare costs without improving outcomes.

Budget Distortion

Leadership teams make future decisions using inaccurate spending data.

Contract Compliance Risks

Undetected processing errors can indicate deviations from plan terms or administrative agreements.

Fiduciary Exposure

Under ERISA, plan fiduciaries must act prudently and solely in the interest of participants and beneficiaries.

The U.S. Department of Labor's Fiduciary Responsibilities Guidance outlines the standards fiduciaries are expected to follow when overseeing employee benefit plans.Failure to monitor service providers can create governance concerns.

According to the Employee Benefits Security Administration (EBSA), plan fiduciaries have a responsibility to prudently select and monitor service providers acting on behalf of the plan.

Lost Recovery Opportunities

Many overpayments become harder to recover as time passes and contractual recovery windows expire.

What's Actually Happening Behind the Scenes?

Most claims inaccuracies result from ordinary operational breakdowns rather than intentional misconduct.

Eligibility Errors

Employees or dependents may remain active in administrative systems after coverage should have ended.

Claims continue to be paid despite ineligible status.

Duplicate Payments

The same service can occasionally be paid more than once due to billing variations or processing workflows.

Incorrect Plan Provisions

System configurations may apply outdated deductibles, copays, or benefit limits.

Provider Contract Issues

Network discounts may not match contracted reimbursement terms.

Even small deviations can accumulate across thousands of transactions.

Coordination of Benefits Problems

Claims involving multiple coverage sources often create payment discrepancies.

Coding and Pricing Errors

Incorrect coding logic can affect reimbursement calculations.

Automation improves efficiency but can also scale mistakes rapidly.

Stop-Loss Reimbursement Gaps

Large claims may contain payment errors that affect reimbursement calculations and downstream reporting.

Vendor Integration Failures

Eligibility platforms, pharmacy systems, and claims platforms exchange data continuously.

Minor integration issues can create significant downstream effects.

Why Current Approaches Aren't Enough

Relying on TPA system edits and annual vendor reviews is not a claims accuracy program. It is claims processing with a thin layer of fraud detection.

Factor Status Quo Approach Independent Claims Audit Approach
Who reviews claims TPA automated edits only Independent auditor with clinical and billing expertise
What triggers review System-flagged anomalies Statistical sampling plus targeted high-dollar review
Data access TPA controls reporting Plan sponsor receives full line-level data
Error recovery Rarely pursued proactively Overpayments identified and recovery initiated
Fiduciary documentation None generated Audit report provides documented due diligence
Frequency Continuous but shallow Periodic deep review (quarterly or annual)
COB review Dependent on eligibility file accuracy Cross-referenced against external data sources
Clinical coding review Not standard Included in comprehensive audit scope
Cost to plan sponsor Included in TPA admin fee Contingency or fixed-fee audit engagement
Conflict of interest TPA auditing its own work Independent third party with no payment relationship to TPA

How to Fix It: A Practical Action Plan

The solution is not to distrust your TPA. It is to implement independent oversight as a standard plan governance practice. Here are the steps that work.

1
Secure Full Claims Data Access
Require your TPA contract to include access to complete line-level claims data in a machine-readable format at least quarterly. Resistance to providing plan-owned data should be treated as a warning sign.
2
Conduct a Baseline Claims Audit
Complete a retrospective review of the prior 12 to 24 months of claims within the first 90 days of the plan year. The audit establishes an error baseline and identifies recoverable overpayments.
3
Assign Clear Ownership
Designate a specific individual responsible for reviewing audit findings, tracking recovery activity and reporting results to leadership. Effective oversight requires clear accountability.
4
Strengthen Audit Rights in Vendor Contracts
Ensure TPA, PBM and specialty vendor agreements explicitly permit independent audits of paid claims. Contracts that restrict audit rights should be renegotiated or competitively rebid.
5
Set Measurable Performance Standards
Establish financial and procedural accuracy targets and tie performance guarantees to independent audit findings rather than self-reported vendor metrics.
6
Build a Rolling Audit Calendar
Move beyond one-time audits by establishing an ongoing review schedule. Annual, semi-annual or prospective audits create continuous accountability and stronger fiduciary protection.
7
Report Findings to Leadership
Provide formal audit reports to the plan committee or ERISA fiduciary at least annually. A documented reporting process strengthens governance and demonstrates prudent oversight.
Independent oversight does not replace your TPA. It complements the TPA's role by adding accountability, transparency and fiduciary protection to the claims payment process.

Red Flags That Signal This Problem Applies to Your Plan

You have never received a line-level claims data file from your TPA.
Your TPA contract does not include an audit rights clause.
You have not conducted an independent claims audit in the past 24 months.
Your annual TPA report shows a claims payment accuracy rate above 99.5 percent. Self-reported metrics this clean are rarely validated externally.
You do not know your plan's coordination-of-benefits recovery rate.
Your stop-loss carrier reviews claims only at the specific attachment point, with no broader oversight program.
Your broker or consultant cannot identify the person at your TPA responsible for financial accuracy.
Your plan document has not been reviewed against current TPA system configuration within the past three years.
If several of these statements apply to your plan, there is a strong likelihood that claims oversight gaps exist. Independent auditing, stronger contract language and formal governance processes can help reduce both financial leakage and fiduciary risk.

The ROI of Doing It Right

Strong claims oversight can generate measurable financial and governance value.

Independent claims audits commonly identify recoverable overpayments and process improvements.

Financial benefits often come from multiple sources.

Direct Recoveries

Previously undetected payment errors can be recovered when identified within applicable recovery periods.

Future Savings

Correcting root causes prevents repeated mistakes.

Improved Vendor Performance

Measurement drives accountability.

Vendors generally perform better when accuracy receives consistent attention.

Better Decision-Making

Cleaner data improves forecasting, budgeting, and plan design decisions.

Stronger Fiduciary Position

Documented oversight demonstrates prudent governance practices.

The most valuable outcome may not be the recovered dollars.

It may be the confidence that healthcare spending reflects intended plan design rather than avoidable administrative errors.

Frequently Asked Questions

Who is responsible for claims accuracy in a self-funded health plan?

The TPA processes claims, but plan sponsors retain ultimate responsibility for monitoring plan operations. Effective oversight typically involves HR, finance, consultants, and independent auditors working within a defined governance structure.

How common are healthcare claims errors?

Claims errors occur across all healthcare payment environments. Error frequency varies by plan structure, administration quality, and audit methodology. Even low error rates can create meaningful financial impact when applied to millions of dollars in annual claims spending.

Why isn't the TPA enough to ensure claims accuracy?

TPAs maintain internal controls and quality assurance processes. However, independent verification provides an additional layer of accountability. Organizations routinely audit financial statements despite having accounting teams. Claims oversight follows a similar principle.

What types of claims errors occur most often?

Common issues include eligibility mistakes, duplicate payments, coordination of benefits errors, pricing discrepancies, provider reimbursement issues, and incorrect application of plan provisions.

How often should self-funded plans conduct claims audits?

Many experts recommend periodic independent audits supported by ongoing monitoring. The appropriate frequency depends on plan size, complexity, annual spend, and organizational risk tolerance.

Can claims errors create ERISA fiduciary concerns?

Yes. ERISA requires fiduciaries to act prudently and monitor service providers. Consistent oversight helps demonstrate responsible governance and protection of plan assets.

What is the difference between a claims audit and a financial audit?

A financial audit evaluates financial reporting accuracy. A claims audit examines whether healthcare claims were processed and paid according to plan rules, contracts, and administrative requirements.

What is the business case for investing in claims oversight?

The value comes from recoveries, future savings, improved vendor accountability, better data quality, and stronger governance practices. Many employers view claims oversight as both a financial control and a fiduciary safeguard.

Fiduciary Intelligence

Healthcare Claims Are the Largest Unmonitored Corporate Expense

Abhishek Ghosh
June 2, 2026

A hospital in Texas billed a self-funded employer plan $187,000 for a single inpatient stay. The third-party administrator paid it within 15 days. A post-payment audit later found the bill contained a duplicate room charge, an unbundled surgical code, and a coordination-of-benefits error that a secondary insurer should have covered. Total recoverable overpayment: $41,000. No one had flagged it. No one had looked.

That scenario is not unusual. For most self-funded employers, health plan claims represent the second-largest line item on the income statement. They are also the line item with the least structured oversight.

Key Takeaways
Self-funded health plans often represent one of an employer's largest expenses, yet claims payments typically receive far less oversight than other major corporate expenditures.
Industry research suggests claims errors and overpayments can range from 3% to 10% of annual spend, creating meaningful financial leakage when left unchecked.
Delegating claims administration to a TPA does not eliminate a plan sponsor's fiduciary responsibility under ERISA.
Common error categories include duplicate claims, coordination-of-benefits failures, coding issues, eligibility errors and network repricing mistakes.
Internal TPA quality assurance is not the same as an independent claims audit and may not identify all payment errors.
A structured claims oversight program combines independent audits, claims data analysis, performance guarantees and documented fiduciary review.
Retrospective and concurrent claims audits can recover overpayments, improve future payment accuracy and strengthen fiduciary compliance.
Plans that lack access to claims data, independent auditing or defined oversight processes may be carrying avoidable financial and fiduciary risk.

The Problem: Your Biggest Bill Has No Auditor

Self-funded employers write blank checks to pay health claims, then assume the TPA cashed them correctly.

Consider what happens with every other major corporate expense. Accounts payable audits vendor invoices. Finance reconciles software licenses. Procurement validates purchase orders against contracts. For many companies, a $500 expense report requires two approvals and a receipt scan.

Now consider health claims. A plan with 500 employees might process $6 million in claims annually. The TPA adjudicates those claims using its own system, its own pricing network, and its own quality controls. The employer receives a summary report, pays the funding account, and moves on. The individual claim adjudications are rarely reviewed by anyone outside the TPA.

This is not a flaw in one company's process. It is the industry default.

Why the Problem Exists

The architecture of self-funded plans creates a structural accountability gap between who pays the claims and who processes them.
1
Delegation Without Verification
Self-funding became popular because employers gained greater control over plan design. Many delegate claims adjudication entirely to a TPA but never build the verification layer that control requires. Hiring a TPA is the right move. Assuming claims are error-free is not.
2
Misaligned TPA Incentives
Many TPAs earn administrative fees through PEPM pricing or claims-based fee arrangements. These models reward processing volume and speed, not necessarily payment accuracy. Claims can be paid incorrectly without creating meaningful contractual consequences.
3
Claims Data Complexity
A mid-size employer plan can generate thousands of claim lines each month. Reviewing that volume requires software tools, coding expertise and a defined audit methodology, resources many HR and finance teams do not possess.
4
False Protection From Stop-Loss
Stop-loss insurance protects against catastrophic claims exposure but does not recover overpayments that fall below the attachment point. Those errors accumulate quietly within the plan's normal operating costs.
5
No Regulatory Audit Mandate
ERISA requires prudent fiduciary management of plan assets, but no federal rule specifies how frequently claims must be audited. Many organizations interpret that absence of a mandate as a reason to skip auditing altogether.

The Real Cost of Unmonitored Claims

Claims overpayments cost self-funded plans an estimated 3% to 10% of total annual spend.

HFMA has documented billing errors as pervasive across the provider ecosystem. Milliman's actuarial analyses show inappropriate payments in commercial plans routinely exceed 5% of expenditures when audited.

Apply that to real numbers. A 300-employee plan spending $4.5 million annually could be overpaying $135,000 to $450,000 per year. These are not one-time mistakes. They compound silently until someone looks.

The fiduciary exposure is separate and growing. EBSA increased enforcement actions in 2023 and 2024 targeting plan sponsors who failed to monitor their TPAs. ERISA Section 404(a)(1) requires the care and diligence of a prudent expert. Delegating administration does not delegate liability.

Hiring an accountant does not relieve a CFO of the duty to review the books. The same logic applies here.

What's Actually Happening Behind the Scenes

Claims processing errors fall into predictable categories, and most go undetected because no one is specifically looking for them.

Billing Code Manipulation

Upcoding occurs when a provider bills a higher-complexity service code than the service actually delivered. Unbundling occurs when a provider bills component procedures separately that should be billed as a single bundled code at a lower rate.

Both are common, both are often unintentional, and both result in systematic overpayment. The Office of Inspector General (OIG) has documented upcoding and unbundling as among the most frequent sources of improper payments in federal programs. Commercial plans face the same vulnerabilities.

Duplicate and Resubmitted Claims

A claim is submitted, appears to fail or delay, and is resubmitted. Both versions pay. This category is among the most straightforward to detect and also among the most consistently missed without automated duplicate-detection logic applied at the claim-line level rather than the claim-header level.

Coordination of Benefits Failures

When a member has coverage under two plans, the primary plan pays first and the secondary plan covers remaining eligible expenses. COB failures occur when the primary-payer determination is wrong, when the secondary plan pays as if it were primary, or when the member's coverage under a second plan is unknown to the TPA.

According to the Kaiser Family Foundation, approximately 10% of covered workers have coverage from a source other than their employer. COB errors on that population can be substantial.

Network Repricing Errors

Self-funded plans contract with a carrier or network to reprice claims at negotiated rates. The repricing calculation should reduce the billed amount to the contracted rate.

When the repricing logic is applied to the wrong fee schedule, applied inconsistently, or bypassed for out-of-network claims, the employer pays more than the contracted rate. These errors are nearly invisible on a standard remittance report.

Medical Necessity and Eligibility Errors

Claims are sometimes paid for services that required pre-authorization and did not receive it. Claims are paid for terminated employees or dependents who have aged out of eligibility.

Both categories are preventable with proper eligibility file management and pre-authorization tracking, neither of which employers verify systematically once a TPA is in place.

Why Current Approaches Are Not Enough

Relying on TPA self-reporting and annual plan renewals is not a substitute for independent claims oversight.
The table below contrasts typical practice with a structured oversight model.
Dimension Status Quo Structured Oversight Model
Audit frequency Ad hoc or never Ongoing concurrent + annual retrospective
Who audits TPA internal QA only Independent third-party auditor
Claims reviewed Summary-level reports Line-item claim data with clinical review
Error detection Reactive (complaints only) Proactive (rule-based and statistical)
TPA accountability Verbal assurances Contractual performance guarantees with penalties
Fiduciary documentation Minimal Audit trail showing prudent oversight
Recovery process None Formal overpayment recovery and prevention
Benchmarking Internal year-over-year Against external peer plans

The status quo is not a neutral position. Every year without an audit is a year in which recoverable overpayments expire under applicable recovery windows, fiduciary risk accumulates undocumented, and plan costs trend upward without a root-cause explanation.

Red Flags That Signal This Problem Applies to Your Plan

You have never received a line-item claims data extract from your TPA.
Your TPA contract contains no financial accuracy performance guarantee.
Your plan has not undergone an independent claims audit within the past 24 months.
Your claims trend is running above regional benchmarks and no one has explained why.
You do not know your plan's coordination-of-benefits recovery rate.
Stop-loss renewals are increasing significantly year over year without a large individual claimant explanation.
Your broker or consultant has never raised the subject of claims auditing.
Your TPA's internal audit reports show near-perfect accuracy. A realistic audit process should identify and report errors.
If any of the following are true, your plan is exposed to undetected claims errors today.

The ROI of Doing It Right

Independent claims auditing consistently returns $3 to $8 for every $1 invested.

Recovery from a retrospective audit typically represents 1% to 3% of audited claim spend. On a $10 million plan, that is $100,000 to $300,000 from a single audit cycle.

TPAs that know their claims will be audited independently process them more carefully. That deterrence effect reduces future errors before they are paid.

The fiduciary protection matters too. The Supreme Court's 2015 decision in Tibble v. Edison International affirmed that fiduciary duties are ongoing. A documented audit program is your evidence of compliance.

Frequently Asked Questions

How common are errors in employer health plan claims?

Industry analyses and actuarial research consistently estimate that 3% to 10% of commercial health plan claims contain a billing or processing error. Not all errors favor the payer. But overpayments to providers and TPAs are documented as the more prevalent direction. Plans that audit systematically almost always find recoverable amounts in excess of audit costs.

Does my TPA already audit claims internally?

Most TPAs perform some internal quality assurance, but internal QA is not the same as an independent audit. The TPA's QA process is designed to measure its own performance against its own standards. An independent audit measures performance against your plan's interests, your contract terms, and external benchmarks. The difference matters financially and legally.

Are we required by law to audit our claims?

ERISA does not specify a mandatory audit frequency. However, ERISA Section 404 requires fiduciaries to manage plan assets with the care of a prudent expert and to monitor service providers on an ongoing basis. Courts and the DOL have found that plan sponsors who never audited their TPA failed to fulfill this duty. An audit program is the clearest evidence of compliance with the monitoring obligation.

What is a realistic claims audit recovery amount?

Recovery rates vary by plan size, audit depth, TPA quality, and how long it has been since the last audit. First-time audits of plans that have never been reviewed independently tend to return more. A reasonable baseline expectation is 1% to 3% of audited claim spend in identified overpayments. A 300-employee plan with $4 million in audited claims might recover $40,000 to $120,000.

How do I get access to my claims data for an audit?

You own your plan's claims data as the plan sponsor. Your TPA is obligated under ERISA and typically under your administrative services agreement to provide it. Request a complete claim-line data extract covering the period you intend to audit. If your TPA charges excessive fees for this extraction or limits the data fields provided, consult your ERISA counsel. The data is yours.

What types of errors does a claims audit typically find?

The most common categories are duplicate payments, unbundled or upcoded procedure codes, coordination-of-benefits failures, network repricing errors, payments for ineligible members or dependents, and claims paid without required pre-authorization. Each category has a distinct detection methodology, which is why auditors use both automated rule-based tools and clinical coding reviewers.

How long does a claims audit take?

A retrospective audit of 12 months of claims data typically takes 60 to 90 days from the time clean data is delivered to the auditor through final reporting. Concurrent review programs, which flag claims in near-real time, can be implemented within 30 to 45 days of contract execution. Timeline depends heavily on data quality and TPA responsiveness.

Can a claims audit damage our relationship with our TPA?

A professional, contractually-grounded audit should not damage a good-faith TPA relationship. TPAs that perform well welcome independent validation because it demonstrates their value. Resistance to auditing is worth noting. Your obligation as plan sponsor runs to plan participants, not to the TPA's comfort. If a TPA treats oversight as adversarial, that response itself warrants a service-provider review.

Fiduciary Intelligence

Most Self-Funded Plans Review Less Than 5% of Claims. Here's the Problem

Abhishek Ghosh
May 29, 2026

A regional manufacturer with 1,400 employees ran an independent claims audit in 2024 and found $812,000 in overpayments across 18 months. The errors included a $47,000 inpatient claim paid twice, 63 ineligible dependents still on the plan, and a specialty drug billed at 240% of the contracted rate.

None of these issues had been identified during the TPA's internal reviews, leading the plan sponsor to realize that many routine claims audits examine only a small portion of total payments.

Key Takeaways
Most self-funded employer health plans review fewer than 5% of claims, typically through TPA-conducted sampling audits.
Industry-documented TPA error rates run between 3% and 10%, meaning meaningful overpayments often remain hidden within the unreviewed 95%.
ERISA places fiduciary responsibility on the plan sponsor, not the TPA, for ensuring claims are paid correctly.
A full self-funded claims audit with a 100% review typically recovers between 1% and 3% of annual claims spend.
Plan sponsors who rely solely on TPA self-audits face both financial leakage and fiduciary exposure.

The 5% Problem: What Self-Funded Plans Actually Review

The gap is straightforward. Most self-funded employers think their claims are audited, but only a small slice is actually examined. A standard TPA audit usually reviews a stratified sample of 250 to 400 claims against plan documents and then reports an overall accuracy rate.

For a plan handling 80,000 claims annually, that works out to roughly 0.3% to 0.5% of total claims activity.

Even when internal TPA quality checks are included, scrutiny rarely reaches 5% of total claims volume. The remaining 95% moves through the system untouched. Employers see a reported accuracy score, often 97% or higher, and assume the payments were correct. That assumption is not always warranted.

There is a real difference between a TPA validating its own workflow and an independent reviewer determining whether the plan actually paid the right amount.

Why So Few Claims Get Reviewed

Why Most Self-Funded Plans Review Under 5% of Claims
Self-funded plans review so few claims because the system was built around TPA convenience rather than plan sponsor oversight. These structural issues keep audit activity limited across much of the market.
1
TPA Sampling Became the Default
Standard administrative services agreements typically define sampling audits as the deliverable. Most plan sponsors accept the process because it has historically been treated as standard practice.
2
Limited Access to Claims Data
Many TPAs release detailed claims files only upon request and often in formats requiring technical expertise to analyze. Without direct access to usable data, independent audits become difficult.
3
Audit Restrictions in ASO Agreements
Some contracts limit audit scope, timing or methodology. Others restrict which firms may conduct reviews or require advance notice that gives TPAs time to prepare.
4
Misconceptions About Audit Costs
Many employers assume a full claims audit will cost six figures. In practice, technology-driven audit firms often work on contingency or modest flat-fee arrangements, with recoveries frequently exceeding the audit cost.
5
Manual Review Does Not Scale
A human reviewer may process around 50 claims per day. Reviewing 80,000 claims manually would take years, which explains why sampling became common before automation matured.
6
Overreliance on TPA Controls
Many plan sponsors assume large national TPAs catch payment errors internally. However, most TPA guarantees focus on processing speed and procedural accuracy rather than confirming the correct dollar amount was paid.

What's Hiding in the Other 95%

The unreviewed claims are not random. Specific error categories cluster, and a full claims audit looks for each one.

Duplicate and Double-Billed Claims

Same procedure code, same date of service, same patient, paid twice. This happens when providers resubmit claims, when claims are processed across system migrations or when secondary insurer payments are not coordinated. Duplicate billing is the single most common dollar-weighted error type in most audits.

Eligibility and Coordination of Benefits Errors

Claims paid for terminated employees, dependents who aged out, spouses with other coverage that should be primary. A coordination of benefits failure can mean a plan pays as primary when it should pay as secondary, often a 60% to 80% overpayment on that claim.

Upcoding and Unbundling

Upcoding bills a higher-acuity code than the service supports. Unbundling charges separately for components that should be billed under a single comprehensive code. Both inflate provider revenue at the plan's expense. These errors require clinical and coding expertise to identify, which is why TPA sampling rarely catches them.

Out-of-Network Surprise Charges

Even after the No Surprises Act, out-of-network claims slip through with billed charges far above usual and customary rates. Without active review, plans pay whatever the TPA's repricing engine produces.

Pharmacy and Specialty Drug Overcharges

Specialty drugs now account for over 50% of pharmacy spend on many self-funded plans. PBM contracts contain dozens of pricing terms (AWP discount, dispensing fees, rebate guarantees, MAC lists, specialty carve-outs) and errors against any of them rarely surface in a TPA audit. A single misclassified specialty claim can cost the plan $10,000 to $40,000.

Ineligible Dependents Still on the Plan

Dependent eligibility audits routinely find 4% to 8% of enrolled dependents do not qualify under plan terms. Ex-spouses, adult children past age limits, dependents with disqualifying other coverage. Each ineligible dependent costs the plan an average of $3,000 to $5,000 per year in unwarranted claims.

Why Traditional TPA Audits Aren't Enough

A TPA auditing its own claims is structurally different from an independent party reviewing 100% of claims. The distinctions matter both for what gets identified and for fiduciary defensibility.
Dimension TPA Self-Audit Independent 100% Claims Review
Scope 250 to 400 sampled claims Every claim paid in the period
Reviewer TPA staff or affiliated auditor Third-party firm with no payment role
Method Statistical sampling, manual review Automated rules engines plus targeted human review
Error types caught Procedural and basic financial Duplicates, eligibility, COB, coding, contract pricing
Output Accuracy percentage Itemized overpayment list with recovery path
Recovery action Often limited to forward-looking corrections Active pursuit of overpaid claims
Fiduciary value Limited (auditor not independent) Strong (independent verification of plan payments)
Typical cost Bundled into ASO fee Contingency or flat fee, usually net-positive
Conflict of interest TPA grading its own work None
The TPA self-audit is not worthless. It can identify process drift and provide a baseline view of operational accuracy. However, it is not a substitute for an independent review confirming that the plan paid only what it actually owed.

How to Move From 5% to 100% Claims Review

Steps to Strengthen Claims Oversight
1
Pull Historical Claims Data
Request the last 12 to 24 months of detail-level claims files in standard formats. If your ASO agreement does not guarantee access, address it during the next renewal cycle.
2
Hire an Independent Audit Firm
Work with a firm that has healthcare claims expertise, coding review capability and a contingency or hybrid fee model. Avoid firms owned by or connected to TPAs.
3
Run a Dependent Eligibility Audit
Treat dependent eligibility as a separate audit workstream. These reviews frequently recover costs quickly and often pay for themselves within months.
4
Review ASO Audit Rights
Confirm your organization can audit any claim, at any time, using any qualified firm. Remove or renegotiate restrictive audit clauses where possible.
5
Move to Ongoing Reviews
Retrospective audits uncover historical leakage, while ongoing monthly or quarterly reviews help prevent future leakage and create accountability with the TPA.
6
Document the Fiduciary Process
Maintain board minutes, committee charters and audit reports to demonstrate the plan sponsor followed a prudent review process.
7
Tie Guarantees to Financial Accuracy
Most TPA guarantees focus on procedural performance. Add guarantees tied directly to overpayment rates and financial accountability.

Red Flags That Your Plan Has a Claims Oversight Gap

Signs Your Plan May Have Hidden Claims Leakage
You receive a TPA audit summary but cannot describe the methodology or sample size.
Your ASO agreement restricts which firms can audit or limits audit timing.
You have not pulled detail-level claims data in the last 12 months.
Your dependent eligibility was last verified at initial enrollment, years ago.
Pharmacy and specialty drug claims are not reviewed against contract pricing terms.
Your plan changed TPAs within the last three years and prior-period claims were never audited.
You cannot answer the question “what was our overpayment rate last year” with a number.
TPA performance guarantees in your contract measure speed and procedural accuracy only.
No member of your benefits committee has formal claims audit reporting on the agenda.
If three or more apply, the plan is likely carrying recoverable overpayments and meaningful fiduciary exposure.

The ROI of Full Claims Review

A full self-funded claims audit often recovers 1% to 3% of annual claims spending during the first review. For a plan spending $20 million each year, that can mean $200,000 to $600,000 in recovered costs.

Audit costs are usually much lower than the amount recovered, especially for mid-sized and large plans.

Claims audits can also improve documentation, strengthen vendor negotiations, identify eligibility issues, and help reduce repeated payment errors over time.

Frequently Asked Questions

What percentage of claims do self-funded plans usually review?

Most self-funded plans review only a small sample of claims during routine audits. Independent claims audits can review every claim using automated tools and targeted reviews.

What is a claims audit in a self-funded health plan?

A claims audit reviews medical and pharmacy claims to check whether they were paid correctly under the plan rules and provider contracts. It can identify issues such as duplicate payments, billing errors, and ineligible dependents.

What is the typical TPA error rate?

Industry studies have found that TPA payment error rates often range between 3% and 10%, depending on the plan and audit method used.

How much can claims errors cost a self-funded plan?

Even small error rates can create large costs. For example, a plan spending $20 million each year could lose hundreds of thousands of dollars annually through payment errors.

Who is responsible for catching claims errors?

Under ERISA, the plan sponsor is responsible for making sure plan assets are spent correctly. TPAs help manage claims, but fiduciary responsibility still remains with the employer.

How often should claims audits be performed?

Many employers begin with a full retrospective audit and then move to regular quarterly or ongoing reviews to catch errors earlier.

What is the difference between a sample audit and a 100% claims review?

A sample audit reviews a small group of claims to estimate error rates. A 100% claims review examines every claim to identify specific overpayments and errors.

Does an independent audit hurt the relationship with the TPA?

Usually not. Most large TPAs expect independent audits as part of normal plan oversight. In many cases, audits improve accountability and accuracy over time.

Fiduciary Intelligence

Fiduciary Intelligence for Self-Funded Plans: What It Actually Means

Abhishek Ghosh
May 30, 2026

In February 2024, a Johnson & Johnson employee filed a class action alleging the company paid its PBM more than $10,000 for a 90-pill prescription that retailed for under $80 cash. The case named not just J&J, but the individual members of its benefits committee.

Whether or not the suit ultimately prevails (a district court dismissed it on standing grounds in January 2025 and similar claims have followed against JPMorgan Chase and others), the message to every self-funded plan sponsor is unmistakable. The era of passive health plan oversight is over.

Fiduciary intelligence is how plan sponsors respond.

Key Takeaways
Fiduciary intelligence is a continuous, data-driven approach to ERISA duties for self-funded health plans and not a once-a-year compliance exercise.
Recent litigation involving J&J, JPMorgan Chase and Wells Fargo targets plan sponsors and committee members over excessive PBM costs.
The CAA of 2021 removed the “we didn’t know” defense by requiring compensation disclosure from brokers, consultants and service providers.
Five pillars include data transparency, vendor accountability, fee benchmarking, performance monitoring and documented decisions.
Getting this right helps reduce litigation exposure and strengthens fiduciary governance.

What Is Fiduciary Intelligence?

Fiduciary intelligence is the operational discipline of running a self-funded health plan with the data, processes and documentation needed to satisfy ERISA's prudent-person standard on a continuous basis.

Traditional fiduciary compliance asks, "Did we sign the right documents this year?" Fiduciary intelligence asks, "Can we prove today, with evidence, that every material decision about this plan was made in the sole interest of participants and at reasonable cost?"

Think of it as the difference between owning a smoke detector and running a fire-safety program. Both involve fire. Only one will help you when the inspector arrives.

The concept emerged from two converging pressures: a sharp expansion in what regulators and courts expect of group health plan fiduciaries and a new generation of analytics tools that finally make those expectations achievable.

Why Self-Funded Plans Face Heightened Fiduciary Risk

ERISA Section 404(a) requires plan fiduciaries to act solely in the interest of participants, with the care, skill, prudence and diligence of a person familiar with such matters. For decades, this standard was litigated mostly against 401(k) sponsors. Group health plans got comparatively little attention.

That has changed. Three forces converged.

1. The Consolidated Appropriations Act of 2021.

CAA Section 202 requires brokers and consultants expecting $1,000 or more in compensation to disclose all direct and indirect compensation to plan fiduciaries in writing. Plan fiduciaries are explicitly required to review those disclosures for reasonableness.

The CAA also removed gag clauses that historically prevented plan sponsors from accessing their own claims data. This eliminated a common excuse for not knowing what the plan was paying.

2. A new wave of class actions.

Lewandowski v. Johnson & Johnson (D.N.J., 2024) alleged the plan paid $10,239.69 for a 90-pill teriflunomide prescription available elsewhere for $28 to $77.

Similar suits have been filed against JPMorgan Chase and Wells Fargo. Even where defendants prevail, defense costs run into the millions and benefits committee members are named personally.

3. DOL enforcement priorities.

The Employee Benefits Security Administration (EBSA) has signaled that health plan compensation disclosures and prudent vendor selection are active enforcement areas, not paperwork.

The result: self-funded plan sponsors now sit roughly where 401(k) sponsors sat in 2010. On the leading edge of a litigation curve that is not going to flatten.

The 5 Pillars of Fiduciary Intelligence

Data Transparency and Claims-Level Visibility

You cannot prudently manage what you cannot see. Fiduciary intelligence starts with the contractual right and technical ability to access detailed claims data by member, provider, drug and procedure. Post-CAA, any vendor refusing this access is a red flag, not a normal counterparty.

Vendor and PBM Accountability

PBM contracts are the single most common source of fiduciary risk in self-funded plans. Spread pricing, rebate retention, formulary steering toward affiliated specialty pharmacies and "specialty generic" reclassification can each cost a mid-sized plan seven figures annually. Fiduciary intelligence means contracts with clear definitions, audit rights and performance guarantees. And the willingness to enforce them.

Fee Benchmarking and Reasonableness Documentation

Reasonableness under ERISA is not an opinion. It's a comparison. Fiduciaries need documented benchmarks for TPA fees, PBM economics, broker compensation, stop-loss premiums and point-solution vendor pricing. Benchmarks should be refreshed regularly and tested through RFPs at appropriate intervals.

Continuous Plan Performance Monitoring

A prudent committee reviews the plan more than once a year. Quarterly dashboards covering cost trend, high-cost claimants (de-identified), network performance, Rx mix, prior authorization patterns and member experience turn fiduciary oversight from anecdote into evidence.

Documented Decision-Making and Audit Trails

If a decision isn't documented, it didn't happen. At least not in front of a judge. Fiduciary intelligence means board-style minutes for every committee meeting: what was discussed, what alternatives were considered, what was decided and why.

How Fiduciary Intelligence Differs From Traditional Plan Management

Dimension Traditional Plan Management Fiduciary Intelligence
Cadence Annual renewal cycle Continuous monitoring
Data access Carrier-summarized reports Claims-level, plan-owned data
Vendor oversight Trust the broker's recommendation Independent benchmarking and RFPs
Decision record Renewal email thread Documented committee minutes
Fee review Asked once at renewal Tested against market benchmarks
Risk posture "We've always done it this way" Prudent process, documented
Primary question "Is the rate okay?" "Can we prove this was prudent?"

What Plan Sponsors Should Actually Do: An Action Framework

1
Charter a Benefits Fiduciary Committee
Written charter, named members, defined authority and regular meeting cadence.
2
Review CAA Section 202 Disclosures
Document reasonableness analysis in writing. Vendor refusal to disclose should be treated as a finding.
3
Audit PBM Contracts
Review generic definitions, rebate pass-through, spread pricing, specialty pharmacy steerage and audit rights.
4
Quarterly Plan Performance Reviews
Review cost, utilization, Rx, network and member experience. Record meeting minutes.
5
Benchmark Vendors on Schedule
TPA every 3–5 years, PBM every 3 years, stop-loss annually and broker compensation annually.
6
Train Committee Members
Conduct annual ERISA fiduciary training and document attendance.
7
Buy Fiduciary Liability Insurance
Separate from EPLI or D&O coverage and verify health plan coverage specifically.

Red Flags That Signal a Fiduciary Intelligence Gap

You do not have direct access to your own plan's claims data.
Your broker's compensation is bundled, opaque or described as "paid by the carrier."
Your PBM contract is more than three years old and has never been benchmarked.
Your committee has no written minutes or meets only during renewal season.
No one on staff can answer: "When did we last document the reasonableness of our TPA fees?"
You rely on a single advisor's recommendation without independent validation.
Stop-loss, PBM and TPA services all flow through the same vendor with little or no independent oversight.
If three or more of these describe your plan, you likely have exposure that is straightforward to remediate. The challenge is recognizing it and taking action before it becomes a larger fiduciary issue.

The ROI of Getting This Right

Fiduciary intelligence is not a cost center. Self-funded plans that adopt the disciplines above typically capture 8 to 15% reductions in total plan spend within 18 to 24 months. Most of it comes from PBM renegotiation, network steerage corrections and elimination of duplicate or low-utilization point solutions.

Add the avoided cost of litigation defense (commonly $2M to $10M even in dismissed cases), reduced personal liability exposure for committee members and measurably better participant outcomes from cleaner formularies and steerage. The math is straightforward.

The plans that struggle with fiduciary intelligence are not the ones that can't afford it. They're the ones that haven't yet realized they can't afford to skip it.

Frequently Asked Questions

What is fiduciary intelligence in simple terms?

Fiduciary intelligence is the practice of running a health plan with the data, process and documentation needed to prove at any moment that decisions were made prudently and in participants' interest. It replaces annual compliance checkboxes with continuous, evidence-based oversight.

Who is a fiduciary under ERISA for a self-funded plan?

Anyone with discretionary authority over plan administration or plan assets is a fiduciary, regardless of title. This typically includes the plan sponsor, named fiduciaries, benefits committee members and sometimes officers who appoint them. Fiduciary status flows from function, not job description.

What is the difference between fiduciary intelligence and fiduciary compliance?

Compliance asks whether required documents and filings exist. Fiduciary intelligence asks whether the underlying decisions were prudent, documented and defensible. You can be compliant on paper while still breaching your duty in substance.

Can a TPA, broker or PBM be a fiduciary?

Sometimes. If they exercise discretionary authority over plan administration or assets such as deciding claims appeals or unilaterally setting fees, they can be functional fiduciaries. Many contracts try to disclaim this, but courts look at actual conduct, not contract language.

What are the penalties for breach of fiduciary duty?

Fiduciaries can be held personally liable to restore plan losses, disgorge profits, pay civil penalties under ERISA Section 502(l) and cover plaintiffs' attorneys' fees. The Department of Labor can also pursue removal and prohibition from future fiduciary roles.

Fiduciary Intelligence

How Fiduciary Risks Arise in Self-Funded Health Plans

Abhishek Ghosh
May 27, 2026

Self-funded health plans give companies more control over healthcare costs, but they also create fiduciary responsibilities under ERISA. Instead of paying a traditional insurer, the company pays employee medical claims directly and takes a more active role in managing the plan.

Fiduciary risk usually does not come from one major mistake. It often develops through vendor relationships, claims handling, prescription drug costs, and other plan decisions.

This article explains how fiduciary risks arise in self-funded health plans and the areas companies should pay attention to.

What Is a Self-Funded Health Plan?

Most of us get health insurance through our job. Usually, the company pays a health insurance company (like Blue Cross or Aetna), and that insurance company pays the doctor bills.

But some companies, especially big ones, do something different. Instead of paying an insurance company, they pay doctor bills directly from their own money. This is called a self-funded health plan.

When a company self-funds its health plan, it gets more control over how the money is spent. But it also takes on a big responsibility of making sure the plan is run fairly and follows the rules. 

What Does Fiduciary Mean?

A fiduciary is someone who is trusted to take care of something that belongs to other people. Their job is to always act in the best interest of those people. 

In a self-funded health plan, the company or individuals responsible for managing the plan may act as fiduciaries. 

There is a law called ERISA  that requires fiduciaries to follow strict standards. If those responsibilities are not met, fiduciaries may face legal and financial consequences, including personal liability in some cases.

What Are the Main Fiduciary Risks in Self-Funded Health Plans? 

Fiduciary risk in self-funded health plans rarely arises from a single issue. Instead, it often develops across several areas that may receive greater attention once disputes or litigation arise.

Excessive or Unreasonable Fees

Failing to benchmark TPA, PBM, and stop-loss fees against the market invites claims that the fiduciary paid more than was reasonable for plan services.

Conflicts of Interest with Vendors

Undisclosed compensation arrangements between brokers, TPAs, and pharmacy benefit managers can constitute a prohibited transaction under ERISA Section 406.

Not Monitoring Claims Administration

If an employee claim is denied incorrectly, the company needs oversight into how claims are processed and resolved. Delegating claim administration to a service provider does not eliminate fiduciary obligations.

Prescription Drug Cost Failures

The CAA 2021 requires plans to demonstrate that prescription drug spending is reasonable. Failure to negotiate or benchmark drug costs is now a named liability.

Why Is This Receiving More Attention Now?

In 2021, the U.S. government passed the Consolidated Appropriations Act (CAA), which introduced new transparency requirements for employers and organizations that sponsor health plans.

The law extended disclosure requirements to health plan fiduciaries, similar to the fee disclosure rules that affected retirement plans.

One important requirement is compensation disclosure. Brokers and service providers that receive $1,000 or more in direct or indirect compensation must disclose that information to the plan sponsor.

According to KFF's health policy research, employer plan fiduciaries who do not obtain these disclosures may face ERISA compliance concerns. Companies are expected to review and understand this information rather than simply collecting it.

How Can Companies Reduce Fiduciary Risk?

The courts have been consistent on one point: a fiduciary who can demonstrate a prudent, documented process is far more likely to prevail than one who cannot, even when the underlying decision was imperfect.

Courts mostly look at whether the company followed a smart, thoughtful process. Here is what that looks like:

  • Create a benefits committee with clear responsibilities, defined members, and regular meetings, ideally at least once every quarter.
  • Review TPA, PBM, and stop-loss providers every year by comparing costs, services, and options. Keep records showing why each vendor was selected.
  • Collect and review compensation disclosures required under the CAA from brokers and consultants before renewing contracts.
  • Review health plan data every quarter, including claim denials, appeals, and high-cost claims, instead of relying completely on the TPA.
  • Consider fiduciary liability insurance that matches the size and spending level of the health plan.

Why PBMs Need Extra Attention

PBMs (Pharmacy Benefit Managers) manage prescription drug benefits in self-funded health plans. Because prescription drugs are often one of the largest plan expenses, PBM decisions can have a major effect on costs and employee access to medications.

PBMs may earn money in different ways, and those arrangements are not always easy to understand. This can make it harder for companies to know whether they are getting fair pricing and value.

For this reason, PBM relationships have become an important area of focus in self-funded health plans and fiduciary oversight.

Hiring Vendors Does Not Transfer Responsibility

Many companies believe that hiring a TPA, PBM, or benefits broker transfers responsibility for the health plan. In reality, companies still have fiduciary responsibilities.

Even when outside vendors handle daily tasks, the company is still expected to oversee the plan and monitor how those services are being provided.

The Bottom Line

Self-funding a health plan means more control but also more responsibility. ERISA holds plan managers to a high standard, and the rules around fees, vendors, and transparency are only getting stricter.

The companies that stay out of trouble are not necessarily the ones that get every decision right. They are the ones that pay attention, ask questions, and write it all down. SHRM's health care cost management toolkit is a practical starting point for employers who want to build that process.

Fiduciary risk is real, and it grows when it is ignored. The best time to take it seriously is before a problem appears.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Stay informed about employee wellness

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.