Featured Post
Fiduciary Intelligence Is the Next Broker Advantage
Featured Post
Fiduciary Intelligence Is the Next Broker Advantage


Fiduciary Intelligence Is the Next Broker Advantage
Fiduciary intelligence is the ongoing practice of auditing claims data, TPA performance, and plan spend to prove healthcare dollars are managed prudently under ERISA. For brokers and captives, offering it as a standing service, rather than a renewal-season extra, is becoming the clearest way to differentiate and retain self-funded clients.
A mid-market manufacturer with 340 employees spent three years assuming its TPA had claims accuracy handled. Nobody had looked at a claim file directly since the plan moved self-funded. When a broker finally pulled an independent sample, the review found six figures in duplicate payments and dependents who should have been dropped two open enrollments ago.
Family health premiums hit $26,993 on average in 2025, up 6% for the third year running, and 67% of covered workers are now in self-funded plans. Every dollar of that spend sits on the plan sponsor's books, and under ERISA, the sponsor is on the hook for how it's managed, not the TPA. Brokers who can prove that oversight is happening, continuously and independently, are starting to win business that pure renewal negotiation can't touch.
What Fiduciary Intelligence Actually Means
Fiduciary intelligence is the continuous review of claims data, TPA performance, and plan spend to demonstrate that a self-funded plan is being run prudently under ERISA. Most people in this industry hear "claims audit" and picture a one-time project: a consultant pulls a sample, writes a report, and everyone moves on until the next renewal cycle.
That's not what fiduciary intelligence is. It's closer to a standing discipline, similar to how a CFO doesn't audit the books once every three years and call it done. The plan's claims data gets reviewed on a rolling basis, TPA performance gets benchmarked against contract terms, and the plan committee has a documented trail showing they actually looked.
Here's the part most sponsors get wrong: they assume their TPA's self-reported accuracy numbers are the audit. TPAs often report 98% to 100% payment accuracy on their own claims. Third-party reviews of the same claims routinely find something different, because TPAs are grading against their own processing rules, not against the plan document itself.
Why the Problem Exists
TPAs process claims fast because speed is what they're measured on internally. Accuracy against the specific plan document, the one with your custom exclusions, your dependent eligibility rules, your coordination of benefits language, isn't usually the metric that gets watched day to day.
Most TPA contracts include a self-reported accuracy guarantee, and most plan sponsors never verify it independently. That's not negligence exactly. It's a resourcing gap. HR teams running benefits alongside a dozen other responsibilities don't have the bandwidth to pull claim files and check them against plan language line by line.
Brokers, historically, haven't filled that gap either. Renewal negotiation and open enrollment support have been the job. Ongoing claims oversight sat outside the traditional scope, and nobody was pricing it as its own service line.
The Real Cost or Impact
Numbers make this concrete. Independent studies of self-funded plans put TPA payment error rates in the 2% to 6% range, with some reviews finding rates as high as 10% depending on plan complexity and audit method, according to Baker Tilly. Willis Towers Watson pegs the industry standard for financial accuracy, the share of total claim dollars paid incorrectly, at roughly 1%, which still translates into millions of dollars for a large plan, as WTW notes.
Run the math on a $20 million annual claims spend. Even a conservative 1% to 2% error rate represents $200,000 to $400,000 a year, money that may be recoverable but can easily go unnoticed without independent review. One Baker Tilly review of tribal self-funded plans found that independent testing identified accuracy gaps in 60% of cases, highlighting why claims oversight should extend beyond TPA reporting.
Beyond the dollars, there's regulatory exposure. DOL's Employee Benefits Security Administration recovered more than $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, and over half of that, $714.4 million, came directly from enforcement actions rather than voluntary corrections, per DOL's own fact sheet. Nearly 300 of those investigations started because participants complained repeatedly about the same plan or service provider, a pattern that's entirely avoidable with proactive oversight.
What's Actually Happening Behind the Scenes
Claims Leakage Nobody's Tracking
Duplicate payments, coding errors, and out-of-network claims processed at in-network rates rarely show up on a TPA's own dashboard, because the dashboard is measuring what the TPA chose to measure. An independent review checks against the actual plan document instead.
Dependent Eligibility Drift
Divorced spouses, aged-out dependents, and employees who left the company months ago quietly stay on plan rosters. Nobody catches it until an audit specifically checks eligibility files against HR records, and by then it's often been years.
Pharmacy and Specialty Drug Spend
Specialty pharmacy claims are complex enough that errors hide easily inside them. Coordination of benefits failures, meaning the plan pays first when another payer should have, are especially common on pharmacy claims involving Medicare-eligible dependents.
Vague or Missing Documentation
When the DOL or a plan participant asks how a claims decision was made, plans without a documented review process often can't produce one. That absence of a paper trail is itself a fiduciary problem, separate from whatever the underlying claim showed.
Why Current Approaches Aren't Enough
Most plans rely on whatever the TPA offers as standard, and that's rarely built for the sponsor's protection. The comparison below shows where the gap sits.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Comprehensive claims audits with full population review typically recover 1% to 3% of annual claims spend in the first cycle, according to industry-documented ranges. For a $15 million plan, that's $150,000 to $450,000 recovered in year one alone, before counting the savings from fixing the process going forward.
The ongoing value compounds. Once dependent eligibility is cleaned up and the TPA knows it's being watched, error rates tend to drop on their own. Several audit firms report that plans moving from periodic to continuous oversight see meaningfully lower error rates within a year or two of implementation.
Then there's the fiduciary protection, which is harder to put a dollar figure on but matters just as much. A documented, defensible process is the single best protection a plan committee has if a participant or the DOL ever challenges how the plan was run.
Conclusion and Next Steps
The self-funded market isn't getting simpler, and the fiduciary exposure that comes with it isn't going away either. Brokers and captives that treat fiduciary intelligence as a real, priced service, not a favor thrown in at renewal, are the ones building relationships that survive past the next RFP cycle.
If your current broker relationship stops at renewal negotiation, that's worth a direct conversation. Ask what independent claims oversight looks like for your plan and what it would take to build a documented, defensible fiduciary process starting now.
Frequently Asked Questions
What is fiduciary intelligence in employee benefits?
It's the ongoing practice of auditing claims data and TPA performance to prove a self-funded plan is managed prudently under ERISA, not a one-time audit.
Who is legally responsible for claims accuracy on a self-funded plan?
The plan sponsor holds fiduciary responsibility under ERISA, even though the TPA processes the claims day to day.
How often should a self-funded plan be audited?
Best practice is continuous or quarterly review, not the once-every-two-to-three-years cadence most plans still use.
What's a typical TPA claims error rate?
Industry studies put it between 2% and 10% of paid claims, depending on plan complexity and how the review is conducted.
Can a broker offer fiduciary intelligence as a paid service?
Yes. Leading agencies now scope it as a standalone PEPM service rather than bundling it free into renewal work.
Does fiduciary intelligence apply to group captives too?
Yes. Claims oversight data feeds directly into loss experience, which affects captive renewal terms and member pricing.
What triggers a DOL/EBSA investigation into a self-funded plan?
Repeated participant complaints about the same plan or service provider are a common trigger, along with informal inquiry patterns.
What's the difference between a TPA self-audit and an independent claims audit?
A TPA self-audit measures against its own internal rules. An independent audit measures against the actual plan document and contract terms.
.jpg)
How to Make Fiduciary Oversight a Core Service
Fiduciary oversight becomes a core service, not an add-on, when brokers provide it as an ongoing service with clear deliverables, such as regular claims reviews, documented TPA performance checks and reports prepared for fiduciary committees. This turns a responsibility plan sponsors already have under ERISA Section 404 into a defined, recurring and billable service.
A mid-size manufacturer with 340 covered employees discovered that its TPA had been using the wrong payment rate for out-of-network claims for 18 months. The error was found only after a new CFO ordered an independent claims audit before renewal. The audit helped the plan recover nearly $210,000. The broker had never provided ongoing oversight beyond mentioning it in the annual stewardship presentation.
This happens every year across the self-funded health plan market. It shows why fiduciary oversight is often treated as a free courtesy instead of a separate service that can provide real financial value.
Willis Towers Watson research shows that administrator errors typically affect 1% to 3% of total claims, while financial accuracy errors can be around 1% of paid claims, even when administrators meet industry standards.
For a plan spending $20 million a year, even a 1% error rate could mean $200,000 in potential overpayments or errors that go unnoticed.
What "Positioning Fiduciary Oversight as a Core Service" Actually Means
Positioning fiduciary oversight as a core service means clearly defining it, explaining what it includes and charging for it separately instead of burying it in a renewal presentation. Most brokers already do parts of this work: they review claims trends, flag stop-loss issues or mention TPA performance guarantees. But these actions alone do not create documented, ongoing oversight or give the plan sponsor evidence of a prudent process if the DOL asks for it.
The common assumption is that TPAs handle accuracy internally and that a broker's job ends at plan design and carrier negotiation. The reality is that ERISA places the fiduciary burden on the plan sponsor, not the administrator, for every dollar the plan pays out. A TPA's self-reported accuracy rate is not oversight. It is the vendor grading its own homework.
Why Fiduciary Oversight Keeps Getting Treated as an Add-On
The root cause is structural, not a lack of awareness. Broker compensation has historically been tied to placement and renewal, so revenue flows from the sale, not from ongoing monitoring, and monitoring gets deprioritized by default.
A second root cause is capability. Genuine claims oversight requires access to raw claims data, analytics tools and clinical or coding expertise that a generalist broker team was never built around, so the work gets waved off as "the TPA's job" rather than built out as a service.
A third factor is inertia inside plan sponsor organizations. HR and finance leaders assume that because a TPA is contractually obligated to pay claims correctly, someone is already checking that they do. Baker Tilly notes it is common for organizations to perform a claim audit only once every three years, which leaves long windows where nothing is being verified at all.
The Real Cost of Leaving Oversight Unpriced
Unreviewed claims dollars do not disappear. They compound, and the compounding is the real cost most plan sponsors never see on a single line item.
An independent claims analytics firm's client data across a large self-funded book found 5% to 15% error detection rates once claims were fully reviewed, with average findings landing between $500 and $1,200 per employee per year.
A peer-reviewed study found that sample-based claims audits can miss significant errors. In two Fortune 100 companies, random sampling failed to detect errors worth $200,000 to $750,000 because only a portion of claims were reviewed. The takeaway is simple: a small sample can leave significant dollars undetected.
What's Actually Happening Behind the Scenes
TPA Sampling Covers a Sliver of the Plan
Standard TPA-conducted audits typically review a stratified sample of a few hundred claims out of tens of thousands processed annually, then extrapolate an accuracy score from that sample. The extrapolation looks clean on a stewardship slide, but it was never designed to catch every category of error, only the categories most likely to show up in a small, structured sample.
Financial Accuracy Is Not the Same as Payment Accuracy
A plan can hit its financial accuracy target, meaning the dollar amount paid was close to correct, while still failing payment accuracy, meaning the claim was processed against the wrong plan rule, provider contract or coordination of benefits determination entirely. Baker Tilly's audit example showed exactly this split, with financial and payment accuracy landing at different rates against the same set of claims.
Broker Compensation Structures Rarely Reward Vigilance
The CAA 2021 rules require brokers and consultants to disclose how they are compensated, giving plan sponsors more visibility into broker fees. But compensation tied to placing or renewing coverage does not necessarily reflect the time spent on ongoing claims and TPA oversight. This gives brokers an opportunity to clearly define fiduciary oversight as a separate service and charge for the work they perform.
Why Current Approaches Aren't Enough
Most plans default to whatever oversight the TPA offers as part of the base contract, and that default carries structural conflicts that a standalone, independently priced oversight engagement does not.
How to Fix It: A Framework for Positioning Oversight as a Core Service
Red Flags That Signal Your Plan Needs This Now
The ROI of Doing It Right
Independent claims reviews can uncover far more money than they cost. ClaimInformatics client data shows 5% to 15% error detection rates in full-population reviews, with average findings of $500 to $1,200 per employee per year. For a 500-employee plan, even the low end could mean $250,000 in findings that a sample-based audit might have missed.
The value goes beyond recovering money. A documented, ongoing oversight process gives plan sponsors evidence that they are actively monitoring their plan if the DOL asks questions. EBSA's FY 2025 enforcement activity shows why this matters. The agency closed 878 civil investigations, with 556 resulting in repayments or corrective action, and recovered more than $1.4 billion for benefit plans overall.
Making fiduciary oversight a defined, paid service helps brokers deliver measurable value while giving plan sponsors a stronger record of prudent oversight.
Conclusion and Next Steps
Fiduciary oversight was never meant to be a courtesy add-on to a broker renewal. It is a standing legal obligation under ERISA Section 404, and the plans that treat it as core, priced and documented are the ones building a real defense against both financial leakage and regulatory exposure. Positioning it that way is also the clearest path for brokers and consultants to build a recurring, defensible revenue line instead of competing on placement alone.
Start with one step: pull your plan's last claims audit and ask who performed it, what percentage of claims it actually reviewed and what happened to the findings. If you cannot answer all three, fiduciary oversight is still an add-on in your organization, not a core service. [internal link: TPA performance guarantees guide] can help you evaluate whether your current administrator's contract even supports the level of oversight your plan needs.
Frequently Asked Questions
What does "fiduciary oversight as a core service" mean?
It means naming, scoping and pricing claims and TPA oversight as its own engagement rather than bundling it free into a broker or consulting contract.
Is fiduciary oversight legally required under ERISA?
Yes. ERISA Section 404 requires plan fiduciaries to act as a prudent expert would in monitoring how plan assets, including claims payments, are handled.
How is fiduciary oversight different from a standard TPA claims audit?
A TPA audit reviews the TPA's own work using a small claims sample. Independent oversight reviews the TPA using outside tools and a much larger claims population.
How often should a self-funded plan review its TPA's claims accuracy?
Quarterly reviews aligned to benefits committee meetings build a stronger, more defensible record than the once-every-few-years cadence many plans currently use.
What is a typical TPA claims error rate?
Industry sources place standard error rates around 1% to 3% of total claims, with some independent full-population reviews finding 5% to 15% error detection rates.
Can brokers charge separately for fiduciary oversight services?
Yes, and the CAA 2021 compensation disclosure rule makes that separate pricing more transparent, not less viable, since compensation must already be disclosed.
What documentation proves a plan sponsor met its fiduciary duty?
Committee meeting minutes, written TPA performance reviews, claims audit findings and corrective action logs together form the paper trail regulators expect to see.
What happens if a self-funded plan skips independent oversight entirely?
The plan sponsor carries undocumented fiduciary exposure, and EBSA's FY 2025 enforcement data shows regulators are actively pursuing exactly these gaps in health and welfare plans.

Why Brokers Are Becoming Fiduciary Advisors
A fiduciary intelligence advisor is a broker who goes beyond annual renewal negotiation to monitor TPA claims accuracy, flag ERISA compliance gaps, and help plan sponsors document prudent oversight. The shift responds to rising DOL enforcement of health plans and growing recognition that a good renewal doesn't satisfy a sponsor's fiduciary duty.
In 2024, a 1,400-employee manufacturer switched TPAs after eighteen months of unremarkable renewal cycles. Its broker had negotiated a competitive rate every year without incident. Nobody had checked whether the claims underneath that rate were being paid correctly.
An independent audit, run separately from the broker relationship, found $812,000 in overpayments across eighteen months, including a $47,000 inpatient claim paid twice and 63 ineligible dependents still active on the plan.
What "Fiduciary Intelligence Advisor" Actually Means
A broker's traditional renewal cycle was never designed to catch claims payment errors. Most employers assume that once a broker negotiates favorable rates and a strong network, the plan is being watched. In reality, renewal work happens once a year and focuses on price, plan design, and carrier or TPA selection.
Claims payment accuracy is a separate discipline entirely. It requires reviewing how individual claims were adjudicated against plan documents, contracted rates, and coordination of benefits rules, month after month, not once a year.
A fiduciary intelligence advisor is a broker who has added that discipline to the relationship. They monitor claims data on a recurring basis, flag patterns that suggest overpayment or compliance risk, and help the plan sponsor build the documentation record ERISA Section 404 requires of a prudent fiduciary.
Why the Renewal-Only Model Persists
Broker compensation has historically been tied to placement and renewal, not ongoing claims monitoring. Commission structures reward closing a deal, and claims oversight work sits outside that transaction entirely.
The Consolidated Appropriations Act of 2021 requires brokers and consultants who receive $1,000 or more from a group health plan to disclose their direct and indirect compensation in writing to the plan fiduciary. This makes potential conflicts more visible and is pushing some brokers to provide broader fiduciary support.
Historically, few brokers had claims-level expertise on staff. Reviewing adjudication logic, contracted rate tables, and coordination of benefits data requires a different skill set than plan design or carrier negotiation, and many brokerages simply never built it.
That capability gap, more than a lack of will, has kept most broker relationships confined to the renewal calendar.
The Real Cost of Watching Only at Renewal
Claims errors are not rare edge cases. Across one national analytics platform's client base, claims analysis identified error detection rates of 5% to 15%, with average findings of $500 to $1,200 per employee per year. On a 1,000-employee plan, that range alone represents hundreds of thousands of dollars in annual leakage.
Industry-standard estimates put administrator error rates at 1% to 3% of total claims processed, and other audit firms report a wider band of 2% to 6%. The manufacturer's $812,000 finding sits comfortably inside that range once you apply it to real claims volume.
The regulatory cost is rising alongside the financial one. EBSA recovered more than $1.4 billion for retirement, health and welfare plans in fiscal year 2025, and announced a shift of FY 2026 enforcement resources toward health and welfare plans, service providers, and plan sponsors after decades of retirement-plan focus.
What's Actually Happening Behind the Scenes
Compensation structures limit scope
A broker paid on commission has little financial incentive to add unpaid claims oversight work. Fee-based and hybrid arrangements are changing that calculus, but the shift is uneven across the industry.
TPA reporting is not independent verification
A TPA's internal quality assurance measures its own process against its own standards. It is not the same as an outside party checking claims against the plan document and the contracted rates.
Annual cycles miss continuous risk
Claims errors accumulate every pay period, not once a year. A broker who reviews the plan only at renewal is, by definition, looking backward at a year of unmonitored payment activity.
Dependent eligibility rarely gets its own review
Ineligible dependents, ex-spouses, adult children who aged out, individuals added without documentation, tend to stay on a plan for years once enrolled. Most renewal reviews never ask the eligibility question at all, because it falls outside price negotiation entirely.
Why Renewal-Only Advisory Isn't Enough
How Plan Sponsors Can Move Toward Fiduciary Intelligence
Red Flags That Your Plan Is Still Renewal-Only
he ROI of Fiduciary Intelligence
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend in its first year, often covering the cost of the audit itself. For a plan spending $20 million annually on claims, that range translates to $200,000 to $600,000 in first-year recoveries alone.
The less visible return is fiduciary protection. A documented, ongoing oversight process is the evidence a plan sponsor needs if EBSA opens an inquiry, and it is the same evidence that has shielded 401(k) plan fiduciaries from personal liability in excessive-fee litigation.
Ongoing monitoring also compounds. Catching a coding error or an ineligible dependent in month three, rather than at next year's renewal, stops that leakage before it repeats twelve more times. There's a talent retention angle too. A benefits committee that can point to a documented, ongoing oversight process has a stronger answer for skeptical CFOs asking why healthcare spend keeps climbing, and a stronger defense if a participant or regulator ever asks the same question in less friendly terms.
Conclusion and Next Steps
A strong renewal has never been proof that a self-funded plan is being watched. The plans avoiding six and seven-figure claims leakage are the ones whose brokers have expanded into ongoing fiduciary intelligence: independent claims review, dependent audits, and documented oversight, not just annual price negotiation.
Ask your broker where their scope actually ends. If claims accuracy monitoring, compliance documentation, and audit rights aren't part of the relationship, that gap belongs to your plan, not theirs.
Frequently Asked Questions
Is my broker legally a fiduciary?
Usually not automatically. Brokers generally aren't ERISA fiduciaries unless they exercise discretionary control, though CAA disclosure rules now increase transparency into their role.
Who holds fiduciary liability for claims accuracy?
The plan sponsor, typically through its benefits committee or board, regardless of whether claims administration is delegated to a TPA.
How often should claims be reviewed?
Ongoing monthly or quarterly review catches errors faster than annual audits and creates a stronger documentation trail for regulators.
What's the difference between a claims audit and TPA quality assurance?
A claims audit is performed by an independent party against plan documents and contracts. TPA quality assurance is internal and self-reported.
Does adding claims oversight cost more than it recovers?
Typically not. First-year recoveries of 1% to 3% of claims spend usually exceed the cost of an independent audit.
What does CAA 2021 require of brokers?
Brokers earning $1,000 or more must disclose direct and indirect compensation to the plan fiduciary in writing before the contract is finalized.
Can a broker perform the claims audit themselves?
Some can, but plan sponsors should confirm the reviewer has healthcare claims expertise and no ownership ties to the TPA being reviewed.
How does this connect to 401(k) fiduciary litigation?
Courts and regulators increasingly expect health plan fiduciaries to document prudent process, the same standard already tested in retirement plan excessive-fee cases.

How to Document Fiduciary Prudence and Protect Your Plan
A fiduciary paper trail is simply a record of how a benefits committee makes and reviews decisions about a self-funded health plan. It can include meeting notes, vendor reviews, and claims audit results. Under ERISA, this documentation helps show that the committee took a careful, reasonable approach to its decisions, even if one of those decisions later turned out to be wrong.
In fiscal year 2025, the Department of Labor’s Employee Benefits Security Administration recovered more than $1.4 billion for retirement, health and welfare plans. More than half came from enforcement actions, not voluntary corrections. Plaintiff firms filed 155 ERISA fiduciary class actions in 2025, including 39 involving health plans.
That is a major shift from the retirement-plan lawsuits that dominated a decade ago. Most benefits committees can explain what their plan did. Far fewer can show why they made those decisions, and that gap is often where investigators and plaintiffs’ attorneys start.
What a Fiduciary Paper Trail Actually Is
A fiduciary paper trail is the documented evidence that a benefits committee followed a prudent, repeatable process when making decisions about the plan. Most plan sponsors assume that if the plan works reasonably well and the TPA has a good reputation, the fiduciary duty is satisfied. That assumption is wrong under ERISA Section 404, which requires fiduciaries to act with the care, skill and diligence of a prudent expert, not merely to reach an acceptable result.
Courts and the DOL do not ask whether a claim got paid correctly in hindsight. They ask whether the committee had a process for finding out, and whether that process left a record. A plan that overpaid on a handful of claims but can show quarterly TPA reviews, documented vendor comparisons and audit engagement letters is in a fundamentally different legal position than a plan with the same errors and no record at all.
The key difference is between substantive and procedural prudence. Substantive prudence asks whether the decision was reasonable. Procedural prudence asks whether the committee used a careful, reasonable process to make it. Under ERISA, that process matters, which is why documentation, not perfection, is a committee’s strongest fiduciary protection.
Why Most Plans Have a Documentation Gap
The gap exists because benefits committees are staffed by HR and finance professionals whose core job is running the business, not building a compliance record. Claims administration gets outsourced to a TPA, and plan sponsors quietly extend that outsourcing to include oversight itself, even though ERISA does not allow fiduciary responsibility to be delegated away.
TPAs can make things look better than they really are by reporting their own performance numbers. They often report payment and financial accuracy rates above 96%, which may meet their contract requirements. But independent audits of the same claims can find very different results.
The problem is that a benefits committee cannot rely only on a TPA’s own scorecard to prove it provided proper oversight. Reviewing the vendor’s numbers shows that the committee checked the report. It does not necessarily show that the committee independently tested whether those numbers were accurate.
Turnover makes this problem worse. Committee members leave, brokers change, and people forget why certain plan decisions were made years ago. Without clear meeting notes and supporting documents, a plan sponsor facing a DOL investigation or lawsuit may have to piece together what happened from memory instead of showing a clear record.
The Real Cost of an Undocumented Process
When a fiduciary process is not documented, a simple vendor mistake can become a much bigger legal problem. Under ERISA, fiduciaries who fail to meet their duties may have to repay losses suffered by the plan. This liability can apply to the individual committee members involved, not just the employer.
The scale of enforcement shows why this matters. In FY 2025, EBSA’s civil investigations recovered $714.4 million. The agency also closed 253 criminal investigations, leading to 62 indictments and 45 convictions involving the way plan assets were handled and controlled.
Health plan lawsuits are now following a similar path to the 600+ excessive-fee lawsuits filed against 401(k) plans over the past decade. Plaintiff firms are increasingly using the same arguments about excessive fees and poor oversight against health and welfare plans, especially as the Consolidated Appropriations Act, 2021 increased disclosure requirements.
What's Actually Happening Behind the Scenes
Committees That Meet Without Minutes
Many benefits committees hold regular meetings but treat them as informal check-ins rather than fiduciary proceedings. Decisions about plan design, stop-loss renewal or TPA retention get discussed and agreed upon verbally, with no minutes capturing what alternatives were considered or why the chosen option was selected.
Vendor Oversight That Stops at the Contract
Signing a services agreement with a TPA is treated as the end of the oversight process instead of the beginning. ERISA places fiduciary responsibility for claims accuracy on the plan sponsor regardless of delegation, yet many committees have no calendar for reviewing TPA performance against that contract after signature.
Audit Activity That Is Self-Reported, Not Independent
A claims audit conducted by the TPA on its own claims is not independent evidence of prudent oversight. Objectivity is inherently limited when the party being reviewed also produces the review, and reviews conducted this way are typically performed only once every three years, if at all.
Dependent Eligibility and Data Hygiene Left Unchecked
Ineligible dependents remaining on a plan after a divorce, a dependent aging out or a change in employment status is one of the most common and most avoidable sources of claims leakage, yet dependent eligibility is rarely treated as its own documented review workstream separate from broader claims auditing.
Why Current Approaches Aren't Enough
How to Fix It
Think of fiduciary documentation like a flight data recorder. Nobody expects a plan year to run without any turbulence, and regulators do not expect one either. What they want to know after something goes wrong is whether the committee followed procedure the whole way through.
The paper trail does not prove the plan never made a mistake. It proves the committee was flying the plane on purpose.
Red Flags That Signal Your Plan Is Exposed
The ROI of Doing It Right
A defensible fiduciary process pays for itself twice, once in claims recoveries and once in avoided liability. A comprehensive independent claims audit typically recovers between 1% and 3% of annual claims spend in its first year, an amount that regularly exceeds the full cost of the audit engagement itself. On a $15 million claims book, that range translates to $150,000 to $450,000 in first-year recoveries alone.
The liability side of the equation is harder to quantify but larger in scale. EBSA's FY 2025 enforcement activity alone moved $1.4 billion, and individual ERISA breach settlements in the 401(k) space have run into the tens of millions of dollars per case over the past decade. A documented process is inexpensive insurance against exposure of that magnitude, and unlike claims recoveries, its value is realized only when it is needed most.
Good documentation can also make a DOL investigation faster and less expensive. If a plan has its records organized and ready, investigators can quickly see what happened and why. Without those records, the plan may have to spend extra time searching for documents and piecing together what happened, which can lead to more questions and requests.
Conclusion and Next Steps
Fiduciary prudence is not measured by whether a self-funded plan avoided every error. It is measured by whether the committee overseeing that plan can produce a record showing it looked, asked the right questions and acted on what it found. That record, built consistently over time, is what separates an ordinary vendor mistake from a documented fiduciary breach.
Start with what is fastest to fix. Put a committee charter and minutes template in place this quarter [internal link: benefits committee charter template], schedule your next TPA performance review [internal link: TPA performance guarantees guide], and confirm your ASO agreement actually allows independent claims auditing [internal link: independent claims oversight guide]. If it has been more than a year since your plan's last independent claims audit, that is the single highest-leverage next step available.
Frequently Asked Questions
What does ERISA Section 404 actually require of a plan fiduciary?
It requires fiduciaries to act with the care, skill and diligence of a prudent expert, solely in the interest of participants.
Is a self-funded plan sponsor personally liable for TPA errors?
Yes. Fiduciary responsibility for claims accuracy stays with the plan sponsor even when claims processing is delegated to a TPA.
How often should a benefits committee meet to stay fiduciary-compliant?
Quarterly meetings with retained minutes are the common baseline used by fiduciary-grade committees.
Can a TPA's self-reported audit satisfy fiduciary oversight requirements?
No. Independent review is needed because a TPA auditing its own claims lacks the objectivity courts and regulators expect.
How long should fiduciary committee records be retained?
Retain minutes, audit reports and vendor contracts beyond ERISA's statute of limitations for breach claims, typically six years or longer.
What triggers a DOL investigation of a self-funded health plan?
Common triggers include participant complaints, Form 5500 irregularities, and EBSA's targeted enforcement priorities for a given year.
Does a documented process protect against every fiduciary breach claim?
No single record eliminates risk, but a consistent, documented process is the strongest evidence of prudence available in litigation or investigation.
What is the difference between substantive and procedural prudence?
Substantive prudence judges the decision itself; procedural prudence judges the process used to reach it, and ERISA case law favors the latter.

Every Healthcare Dollar Should Be Reviewed and Justified
A self-funded health plan claims audit is an independent review of paid medical claims that verifies payment accuracy, confirms contract compliance and recovers overpayments. ERISA Section 404 places this oversight duty on the plan sponsor, not the TPA. Most plans review fewer than 5% of claims, leaving the rest unchecked.
A 1,400-employee manufacturer ran its first independent claims audit eighteen months into a new TPA relationship. The review found more than $800,000 in overpayments, including one inpatient claim paid twice and a specialty drug billed well above the contracted rate. None of it had appeared in the TPA's own accuracy reporting.
That gap is not unusual. Industry benchmarks put administrator error rates at 1% to 3% of total claims processed, and most self-funded plans independently review only a small slice of what gets paid. Sixty-seven percent of covered workers, including 80% at large employers, are now enrolled in self-funded plans according to KFF's 2025 Employer Health Benefits Survey, which means the unreviewed portion represents real money moving through systems almost nobody independently checks.
What a Claims Audit Actually Verifies
A claims audit is an independent, line-by-line review of paid medical claims against plan documents, contracted rates and coding rules. Most employers assume this already happens because their TPA reports a high accuracy score every quarter. That figure is usually self-reported and calculated against the TPA's own sample, not an outside standard.
The reality looks different once someone outside the TPA checks the work. Most self-funded employer health plans review fewer than 5% of claims, typically through a stratified sample the TPA selects and grades itself. Grading your own homework produces a different number than an outside reviewer checking the same file.
An audit is not an accusation. It is closer to a financial reconciliation: matching what the plan document promises, what the contract with the provider specifies and what actually got paid.
Audit frequency compounds the problem. It is common for employers to run a full claims audit or provider billing review only once every three years, according to Baker Tilly's analysis of self-funded plan billing reviews. Between those audits, errors accumulate quietly and rarely show up in a quarterly dashboard.
Why the Oversight Gap Exists
The gap exists because TPAs are not the ones bearing financial risk when a claim gets paid wrong. The plan sponsor pays the claim either way, so the administrator has limited financial incentive to catch every error before it goes out the door. That is a structural fact of the outsourcing arrangement, not a statement about any single TPA's intent.
Audit frequency compounds the problem. It is common for employers to run a full claims audit or provider billing review only once every three years, according to Baker Tilly's analysis of self-funded plan billing reviews. Between those audits, errors accumulate quietly and rarely show up in a quarterly dashboard.
Contract language plays a role too. Some administrative services agreements historically limited how many claims a sponsor could audit, who could perform the audit or what data the auditor could access, which narrowed what oversight was even possible.
The Real Cost of an Unreviewed Plan
Unreviewed claims translate directly into dollars the plan never should have paid. Industry benchmarks estimate payment errors typically affect 1% to 3% of total claims dollars, and some comprehensive independent audits identify a wider range depending on plan complexity and TPA type. On a plan paying $20 million a year in claims, even the low end of that range is $200,000 sitting unrecovered.
Think of it like a bank account that is never properly checked. A small error might not seem like much on one transaction, but when thousands of transactions have small errors, the total can become huge.
That is what happens with many healthcare audit findings. It is usually not one big fraud. It is thousands of small errors that nobody was checking for.
The average family health insurance premium is now $26,993. Employers and employees share this cost. When an audit finds and recovers money that was paid incorrectly, that money can help reduce future healthcare costs instead of forcing employers to raise premiums or cut benefits.
What's Actually Happening Behind the Scenes
Coding and Billing Errors
Upcoding, unbundling and duplicate billing are the most common findings in independent audits. A procedure billed at a higher-complexity code than performed, or a bundled service billed as separate line items, both inflate the paid amount without an obvious red flag in a summary report.
Coordination of Benefits Gaps
When a member has coverage under more than one plan, claims should be split according to coordination of benefits rules. Gaps here mean the self-funded plan sometimes pays a share that another payer should have covered.
Why Current Approaches Aren't Enough
Relying solely on the TPA's own reporting leaves the plan sponsor with an incomplete picture, because the reviewer and the reviewed party are the same entity. The table below lays out the practical difference between the status quo and an independent oversight model.
How to Fix It
Red Flags That Signal Your Plan Needs This Now
The ROI of Doing It Right
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend in its first year, often more than covering the cost of the audit itself. On a plan spending $30 million annually, that is a recovery range of $300,000 to $900,000 before counting the value of catching future errors sooner.
The fiduciary protection matters as much as the dollar recovery. DOL/EBSA recovered $1.4 billion in FY 2025 and closed 878 civil investigations, with 63% producing monetary or corrective results, and the agency has signaled health plan oversight is a growing FY 2026 focus. A documented, independent audit process is the evidence a plan sponsor needs if that scrutiny ever reaches their plan.
Litigation risk reinforces the same point. Plaintiff firms that spent two decades pursuing excessive-fee claims against 401(k) plans have expanded into health plan cases, including Lewandowski v. Johnson & Johnson and Navarro v. Wells Fargo, both alleging fiduciaries failed to prudently monitor PBM and administrative costs. An audit trail is the difference between a defensible process and an unmonitored one.
Conclusion and Next Steps
Every dollar a self-funded plan pays out should be able to withstand a question: was this claim reviewed, is the payment justified, and can the plan sponsor defend it if asked. Right now, most plans cannot answer that question for the majority of what they pay, because the only review happening is the one the TPA runs on itself.
The fix does not require replacing your TPA relationship. It requires adding an independent layer of oversight, documenting the process, and treating claims accuracy as a fiduciary obligation rather than an assumption. Schedule a claims audit scoping call to see what an independent review would find on your plan.
Frequently Asked Questions
What is a self-funded health plan claims audit?
An independent review of paid claims that checks payment accuracy against plan terms, contracted rates and coding rules.
Who is legally responsible for claims accuracy under ERISA?
The plan sponsor, under the fiduciary duty in ERISA Section 404, not the TPA that processes the claims.
How often should a self-funded plan be audited?
Every twelve to eighteen months, with ongoing quarterly or monthly spot reviews between full audits.
What percentage of claims does a typical TPA review internally?
A stratified sample, usually 250 to 400 claims, far short of the full claims population.
How much money does an independent audit typically recover?
About 1% to 3% of annual claims spend in the first year, based on industry benchmarks.
Can a TPA restrict how a plan sponsor audits its own claims?
Some contracts historically limited audit scope or auditor choice; sponsors should negotiate these restrictions out.
Does an audit create legal protection for plan fiduciaries?
Yes. Documented, independent review is core evidence of the prudent process ERISA requires.
What is the difference between a claims audit and dependent eligibility review?
A claims audit checks payment accuracy; a dependent eligibility review confirms covered dependents still qualify for the plan.

When Fiduciaries Fail: ERISA Litigation Cases and Key Lessons
An ERISA fiduciary breach occurs when a plan sponsor fails to act prudently and solely in participants' interest when managing a health plan, such as failing to monitor a PBM's pricing or negotiate reasonable fees. Recent lawsuits against Johnson & Johnson and Wells Fargo show courts scrutinizing these failures closely, even when claims get dismissed on legal technicalities.
In February 2024, a Johnson & Johnson employee filed a 75-page class action alleging the company let its prescription drug benefit program bleed money through an unmonitored pharmacy benefit manager contract.
Five months later, four Wells Fargo plan participants filed a nearly identical suit, claiming the bank squandered its bargaining power and let Express Scripts overcharge the plan.
In 2025, Illinois recovered $45 million from CVS Caremark after alleging the PBM withheld manufacturer rebates it owed the state's employee health plan. These are not isolated incidents. They are the opening chapters of a litigation wave that mirrors the excessive-fee lawsuits that reshaped 401(k) plan governance a decade ago, and self-funded employer health plans are now the target.
What ERISA Fiduciary Breach Actually Means for a Health Plan
A fiduciary breach happens when the people responsible for running a health plan fail to act with the care, skill and diligence ERISA requires, regardless of whether a lawsuit ever gets filed. Most HR leaders assume fiduciary duty is a retirement plan concept that only applies to 401(k) committees. That assumption is increasingly wrong.
ERISA Section 404 imposes the same prudent expert standard on anyone who exercises discretion over a group health plan's assets or administration. If your organization signs a PBM contract, approves plan design or reviews claims data even occasionally, you likely function as a fiduciary. The exclusive benefit rule adds a second layer, requiring that plan assets be used only to provide benefits and pay reasonable expenses, not to preserve a convenient vendor relationship.
The common misconception is that hiring a reputable TPA or PBM satisfies the duty. It does not. Delegating administration does not delegate the fiduciary's obligation to monitor that vendor's performance on an ongoing basis.
Why the Problem Exists
Health plan fiduciary duty gets overlooked because most plan sponsors treat benefits as an HR function rather than a financial oversight function. The committee structure, meeting cadence and documentation habits that retirement plan fiduciaries built over 20 years of ERISA litigation simply do not exist yet on the health plan side.
PBM and TPA contracts also compound the problem through complexity. Rebate formulas, spread pricing and administrative fee structures are often opaque by design, and few internal teams have the claims data expertise to audit them without outside help.
Finally, self-funded plans grew faster than fiduciary governance kept pace. KFF's 2025 Employer Health Benefits Survey found 67 percent of covered workers are now in self-funded plans, rising to 80 percent at large firms. Many of those plans still run on the oversight habits of a fully insured plan, where the carrier absorbed the risk and the scrutiny.
The Real Cost or Impact
Prescription drug spending is where fiduciary failures show up fastest. KFF found that 36 percent of large firms say drug prices contributed "a great deal" to premium increases in 2025, and the average family premium reached $26,993 that year.
Litigation creates a second layer of cost on top of the original overpayment. The Johnson & Johnson complaint alone was 75 pages and named individual committee members, not just the company. That should concern HR leaders who assume the company will always fully protect them from personal liability.
The Illinois settlement shows that vendor-related payment problems can involve millions of dollars. If similar problems exist across many self-funded employer plans, the total financial impact could be huge.
What's Actually Happening Behind the Scenes
PBM Contracts Nobody Re-Negotiates
Most self-funded plans sign a PBM contract and revisit it only when it expires. The Wells Fargo complaint alleged the company paid Express Scripts administrative fees that "greatly exceeded" what comparable plans paid, a gap that persisted because nobody benchmarked it mid-contract.
Rebates That Never Reach the Plan
Rebate pass-through language sounds protective on paper but is rarely audited in practice. Illinois only uncovered CVS Caremark's shortfall through a formal state investigation into an affiliated rebate aggregator, not through routine contract review.
Formulary and Mail-Order Steering
Both the J&J and Wells Fargo complaints alleged fiduciaries steered participants toward higher-cost mail-order channels and branded drugs without evaluating whether cheaper, clinically equivalent options existed. That is a design choice a committee approved once and never revisited.
No Independent Claims Data Review
In every one of these cases, the plaintiffs' core allegation is not that fiduciaries acted maliciously. It is that nobody with independent authority was checking the PBM's own numbers against outside benchmarks on a recurring basis.
Why Current Approaches Aren't Enough
Most plan sponsors believe their existing TPA or broker relationship already covers this ground. It usually does not, because the entity administering the plan has limited incentive to flag its own pricing.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Independent claims audits typically recover a meaningful share of total plan spend in overpayments and billing errors that routine TPA review misses. On a plan spending $20 million annually, even a modest recovery rate represents a substantial six-figure return.
Beyond recovery, documented fiduciary governance is itself protective. Courts in the Lewandowski and Navarro cases dismissed claims on standing grounds partly because plaintiffs could not tie specific harm to specific fiduciary failures. A plan sponsor with clean documentation is in a materially stronger position if that standing bar shifts in future litigation.
The ongoing savings compound. Fee benchmarking and rebate audits performed annually, rather than once at contract signing, tend to catch cost creep before it accumulates into a multi-year shortfall like the one Illinois uncovered.
Conclusion and Next Steps
Every case examined here traces back to the same gap: nobody independent was checking the numbers. Courts have so far dismissed the highest-profile suits on procedural grounds, but that offers plan sponsors a narrowing window, not a permanent shield. The prudent expert standard doesn't pause while standing law develops.
Start by asking whether your plan could produce, today, a written record of when your PBM contract was last benchmarked and by whom. If the honest answer is "not recently" or "never," that's the gap to close first.
An independent claims audit is the fastest way to establish both the documentation and the cost recovery this article describes.
Frequently Asked Questions
Is an HR director personally liable for ERISA fiduciary breaches?
Yes, if they exercise discretion over plan administration. The J&J case named individual committee members, not just the company.
Does hiring a PBM or TPA transfer fiduciary liability to them?
No. Delegating administration does not delegate the ongoing duty to monitor that vendor's performance.
Why were the Johnson & Johnson and Wells Fargo lawsuits dismissed?
Courts found plaintiffs lacked Article III standing, meaning they hadn't shown concrete, traceable financial injury, not that the conduct was proper.
How often should a self-funded plan audit its PBM?
At minimum annually, with rebate pass-through and administrative fees benchmarked independently of the PBM's own reporting.
What is the prudent expert standard under ERISA?
It requires fiduciaries to act with the care and skill a knowledgeable person familiar with plan administration would use under similar circumstances.
Can a plan sponsor be sued even if premiums didn't rise?
Yes, though recent rulings suggest plaintiffs must show a clearer causal link between fiduciary conduct and specific financial harm.
What triggered the CVS Caremark settlement with Illinois?
A state investigation found Caremark's affiliate withheld manufacturer rebates owed to the state's employee health plan over a four-year contract period.
Is a written fiduciary policy legally required?
ERISA doesn't mandate a specific document, but documented process is the primary evidence fiduciaries have if their conduct is challenged.

Fiduciary vs. Non-Fiduciary Advisors: What It Costs You
A fiduciary advisor is legally bound under ERISA Section 404 to act solely in a health plan's best interest and disclose every source of compensation. A non-fiduciary advisor only has to recommend suitable options, often while earning commissions that reward higher-cost vendors. That gap can cost self-funded plans millions in unmanaged claims spend.
In 2024, an employee of Johnson & Johnson sued the company's own benefits committee, alleging that mismanaged pharmacy benefit contracts cost the health plan and its participants millions of dollars in inflated drug prices.
The Lewandowski v. Johnson & Johnson case has since been dismissed twice on standing grounds, but it opened a door that had stayed shut for years: ERISA fiduciary breach claims aimed squarely at health plan sponsors, not just retirement plan committees.
Average family premiums for employer-sponsored coverage hit $26,993 in 2025, according to the KFF Employer Health Benefits Survey, a 6 percent jump in a single year. Most plan sponsors have no idea whether the person advising them on that spending is legally required to act in their interest, or simply required to avoid recommending something unsuitable.
What Actually Separates a Fiduciary From a Non-Fiduciary Advisor
A fiduciary advisor owes your plan an undivided duty of loyalty. A non-fiduciary advisor only owes you a suitable recommendation. That single distinction determines who is legally exposed when a decision goes wrong, and it is where most plan sponsors get confused.
Under ERISA Section 404, a fiduciary must act with the care, skill, and diligence of a prudent expert, and must place the plan's interests ahead of their own. A non-fiduciary broker, operating under a suitability standard, can recommend a product that pays a higher commission as long as it technically fits the client's needs. Most employers assume their broker already carries fiduciary obligations. In practice, unless a broker or consultant has signed a written fiduciary acknowledgment for the health plan specifically, they almost certainly have not.
The confusion runs deeper because retirement plan fiduciary roles are well defined under ERISA 3(21) and 3(38), while health and welfare plan fiduciary roles were left comparatively vague for decades.
Why the Confusion Exists
The fiduciary rules that apply to 401(k) plans took shape starting in 2012, when the Department of Labor required retirement plan service providers to disclose their compensation. Group health plans went without an equivalent rule for nearly a decade. Brokers built entire compensation models around that gap, often earning commissions, override bonuses, and contingent payments from carriers without ever disclosing them to the employer.
The CAA closed part of that gap. Under ERISA Section 408(b)(2) as amended by the CAA, any broker or consultant who reasonably expects $1,000 or more in direct or indirect compensation must disclose it in writing to the plan's responsible fiduciary before the arrangement begins. The rule took effect December 27, 2021. Disclosure alone does not create a fiduciary relationship, and most plan sponsors still are not reviewing what lands in their inbox.
The Real Cost of Non-Fiduciary Advice
Family premiums have grown 26 percent over the past five years, according to KFF, while employer contributions absorbed most of that increase. A plan paying $27,000 per family per year has almost no room for advisor conflicts of interest or unreviewed claims spend. Every dollar steered toward a higher-commission vendor instead of the best available option compounds across thousands of employees.
Independent claims audits show why this matters beyond premiums. TPA self-reported error rates typically run 1 to 3 percent, according to Willis Towers Watson, but independent third-party reviews that examine claims the TPA never flagged routinely find error rates between 5 and 15 percent. On a plan processing tens of millions in annual claims, that gap alone can represent six figures in unrecovered overpayments every year.
EBSA's enforcement record adds another layer of cost. The agency recovered $1.4 billion for benefit plans, participants, and beneficiaries in fiscal year 2025, with 63 percent of closed civil investigations producing monetary or corrective results. Plan sponsors who cannot demonstrate a prudent process for selecting and monitoring advisors are the ones investigators focus on first.
What's Actually Happening Behind the Scenes
Commission Structures and Spread Pricing
Many non-fiduciary brokers are paid through carrier commissions tied to premium volume, which means their income rises when the plan's costs rise. Some arrangements also involve spread pricing, where a vendor bills the plan more than it actually pays a provider and keeps the difference. Neither practice is illegal on its own, but neither one is disclosed by default.
Undisclosed or Buried Compensation
CAA disclosures technically satisfy the law even when compensation is described in vague, bundled categories rather than itemized dollar figures. A plan sponsor who receives a disclosure but never asks a follow-up question has, in effect, accepted whatever arrangement the broker chose to describe.
Undisclosed or Buried Compensation
CAA disclosures technically satisfy the law even when compensation is described in vague, bundled categories rather than itemized dollar figures. A plan sponsor who receives a disclosure but never asks a follow-up question has, in effect, accepted whatever arrangement the broker chose to describe.
Claims Oversight That Never Happens
Most self-funded plans review a small sample of claims once a year through the TPA's own reporting, rather than an independent party examining the full claims file. That self-reported review structure is precisely why error rates identified by outside auditors run several times higher than what TPAs report internally.
Claims Oversight That Never Happens
Most self-funded plans review a small sample of claims once a year through the TPA's own reporting, rather than an independent party examining the full claims file. That self-reported review structure is precisely why error rates identified by outside auditors run several times higher than what TPAs report internally.
Why Current Broker Relationships Aren't Enough
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Plans that move from TPA self-reporting to independent, full-file claims review typically recover findings in the range of $500 to $1,200 per employee per year, based on independent audit firm data. A 1,500-employee plan sitting in the middle of that range recovers well over $1 million annually in previously invisible overpayments. Fiduciary-grade compensation review adds a second layer of savings by exposing commission structures that inflate premium costs without improving service.
Beyond the dollar recovery, a documented fiduciary process is itself protection. When EBSA investigates or a participant files a claim, the plans that fare best are the ones that can show a prudent, ongoing process rather than a single annual conversation with a broker.
Conclusion and Next Steps
The gap between fiduciary and non-fiduciary advice is not a technicality. It determines who is legally required to put your plan first, and it shapes every dollar your organization spends on premiums, claims, and vendor fees. Plan sponsors who treat this as a compliance checkbox rather than an ongoing process are the ones facing DOL inquiries and participant lawsuits.
Start with a written fiduciary acknowledgment, an itemized compensation review, and an independent claims audit. These three steps alone move a plan from reactive to prudent.
Frequently Asked Questions
Is my benefits broker automatically a fiduciary?
No. Most brokers operate under a suitability standard unless they sign a written fiduciary acknowledgment for the health plan.
What does ERISA Section 404 require of a fiduciary?
Acting solely in the plan's interest with the care and skill of a prudent expert, avoiding conflicts of interest.
Does the CAA make brokers fiduciaries?
No. It only requires compensation disclosure for brokers earning $1,000 or more; it does not change their legal standard.
How often should a self-funded plan audit its claims?
At minimum annually, using an independent auditor reviewing the full claims file rather than a small sample.
What is spread pricing?
When a vendor bills the plan more than it pays a provider and retains the difference, often undisclosed.
Can a plan sponsor be personally liable for fiduciary breaches?
Yes. ERISA allows personal liability for fiduciaries who fail to act prudently or loyally.
What triggered the recent wave of health plan fiduciary lawsuits?
The 2024 Lewandowski v. Johnson & Johnson case, alleging mismanaged PBM contracts inflated drug costs plan-wide.
What's the fastest first step toward fiduciary protection?
Request itemized CAA compensation disclosures and an independent claims audit within the next renewal cycle.

Top DOL Audit Triggers Every Self-Funded Employer Should Know
The Department of Labor (DOL) often starts investigating a self-funded health plan when employees complain about their benefits, required compliance documents are missing, fee disclosures are incomplete, or the employer cannot prove it is monitoring its third-party administrator (TPA). In FY 2025, the DOL completed 878 civil investigations and recovered $714.4 million. If several employees raise similar complaints about the same plan, it may prompt the DOL to take a closer look.
A mid-size employer gets a letter from the Department of Labor. Not a lawsuit. A request for documents. The plan sponsor has never seen the claims data behind their own health plan, has no comparative analysis on file, and has no record of ever asking the TPA a hard question.
That letter is not random. EBSA closed 878 civil investigations in FY 2025 and recovered $714.4 million in the process, and most of those cases started with a pattern someone could have caught first.
What "DOL Audit Triggers" Actually Means
A DOL audit trigger is any pattern, complaint, or documentation gap that gives EBSA a reason to open a formal investigation into a self-funded health plan. Most plan sponsors assume audits are random, similar to a tax audit lottery. That assumption is wrong.
EBSA investigations are largely pattern-driven. Complaint volume, missing required disclosures, and known compliance gaps like NQTL comparative analyses generate referrals long before any letter arrives.
The gap between assumption and reality matters because plan sponsors who believe audits are random tend to under-invest in the documentation that would protect them. Prudent process, not luck, is what EBSA looks for once an investigation opens.
Why This Problem Exists
Self-funded plans hand claims processing, network access, and much of the compliance workload to a TPA. That arrangement creates a documentation and accountability gap that most sponsors never notice until it's tested.
ERISA places fiduciary responsibility for the plan on the sponsor, not the TPA. Selecting a service provider is itself a fiduciary act, and DOL guidance is explicit that hiring a TPA does not end the sponsor's duty to monitor performance and fees on an ongoing basis.
Most HR and finance teams were never trained to monitor a TPA the way they'd monitor a retirement plan recordkeeper. The retirement side of ERISA has decades of litigation and case law teaching sponsors to document process. The health side is catching up fast, and sponsors who haven't adjusted are exposed.
The Real Cost and Impact
EBSA's FY 2025 numbers show the scale of federal enforcement. The agency closed 878 civil investigations, and 556 of those, or 63 percent, produced monetary results or required corrective action, totaling $714.4 million in recoveries from enforcement alone.
Complaint-driven referrals are a meaningful share of that activity. EBSA opened 291 investigations from Benefits Advisor referrals in FY 2025, cases that typically start with repeated complaints about the same plan, employer, or service provider rather than a scheduled review.
DOL audits aren't the only concern. Many claim payment errors can remain hidden because most TPAs use sampling to review claims rather than examining every paid claim. Independent audits that review 100% of claims often identify overpayments that sampling-based reviews did not detect.
What's Actually Happening Behind the Scenes
MHPAEA Comparative Analysis Gaps
Mental health parity compliance is one of the clearest current audit triggers. A joint DOL and CMS review examined 56 plans for MHPAEA compliance and found 33 violations, and nearly every noncompliant plan was self-funded or included a self-funded option.
For plan years beginning on or after January 1, 2025, a named ERISA fiduciary must certify that the plan followed a prudent process to select and monitor whoever performs the NQTL comparative analysis. A comparative analysis that was written once and filed away does not meet that bar.
Participants can request a copy of the comparative analysis at any time under ERISA Section 104, which starts a 30-day disclosure clock. A plan that cannot produce a current, complete analysis on short notice has already created its own audit trigger.
Missing CAA 2021 Disclosures
The Consolidated Appropriations Act, 2021 requires brokers and consultants earning more than $1,000 annually in direct or indirect compensation to disclose those fees to the plan sponsor. Sponsors are responsible for confirming those disclosures exist and reviewing them, not just receiving them.
Gag clause attestations, another CAA 2021 requirement, must be submitted annually confirming the plan hasn't agreed to contract terms that restrict access to cost and quality data. A missed attestation is a simple, easily documented compliance failure, which makes it an easy first data point for an investigator.
Why Current Compliance Approaches Aren't Enough
How to Fix It
Red Flags That Signal Your Plan Is Exposed
The ROI of Doing It Right
Independent oversight isn't just a compliance cost. Claims-auditing benchmarks across the industry typically show recoverable overpayments in the low single digits as a percentage of annual claims spend, and for many self-funded plans that translates into six or seven figures a year in identified errors alone.
Beyond dollars recovered, a documented oversight process is the single strongest piece of evidence a fiduciary can produce during an EBSA inquiry. Prudent process, not a clean outcome, is what ERISA actually requires.
The plans least likely to face a lengthy, costly investigation are the ones that can hand over a complete file the day a request arrives.
Conclusion and Next Steps
DOL audit triggers aren't a mystery, and they aren't random. They come from documentable gaps: complaints that pile up, a comparative analysis that's gone stale, fee disclosures nobody tracked, and a TPA relationship nobody independently checked. Self-funded employers who close those gaps before a letter arrives put themselves in a fundamentally different position than plans that wait.
Start with an honest inventory. If your plan can't produce a current comparative analysis, a full CAA 2021 disclosure file, and a recent independent claims audit today, that's the starting point for next quarter's fiduciary calendar.
Frequently Asked Questions
What triggers a DOL audit of a self-funded health plan?
Common triggers include repeated participant complaints, incomplete MHPAEA comparative analyses, missing CAA 2021 fee disclosures, and no documented TPA oversight process.
How many investigations did EBSA close in FY 2025?
EBSA closed 878 civil investigations in FY 2025, with 556 producing monetary results or corrective action.
How much did EBSA recover in FY 2025?
EBSA recovered $1.4 billion across all enforcement programs, including $714.4 million from civil investigations alone.
Is the plan sponsor or the TPA responsible for ERISA compliance?
The plan sponsor holds fiduciary responsibility under ERISA, even though the TPA handles day-to-day claims administration.
Does hiring a TPA satisfy fiduciary duty?
No. Selecting a TPA is itself a fiduciary act, and sponsors must also monitor performance and fees on an ongoing basis.
How often should a self-funded plan complete a claims audit?
Most compliance advisors recommend a recurring, independent audit rather than a one-time review, since TPA self-reported metrics rarely catch every error.
What is an MHPAEA comparative analysis?
It's a required written analysis comparing how a plan applies nonquantitative treatment limitations to mental health versus medical and surgical benefits.
Can participants request a copy of the comparative analysis?
Yes. Participants can request it at any time under ERISA Section 104, which starts a 30-day disclosure deadline.

Healthcare Fiduciary Oversight: The Next Lawsuit Wave
Fiduciary oversight in healthcare is becoming the next 401(k) lawsuit wave because self-funded plan sponsors face the same ERISA fiduciary duties that drove two decades of retirement plan litigation. Courts are now applying those standards to TPA contracts, PBM fees, and claims payment accuracy, and DOL enforcement is following the same path.
In 2024, Ann Lewandowski sued Johnson & Johnson, alleging its health plan fiduciaries mismanaged the prescription drug program and cost employees millions in higher premiums and out-of-pocket costs. A New Jersey court dismissed the case twice on standing grounds, most recently in November 2025.
But one month before that dismissal, the Sixth Circuit revived a nearly identical theory in Tiara Yachts v. Blue Cross Blue Shield of Michigan, ruling that a TPA can be held to ERISA fiduciary standards for how it processes and recovers overpaid claims.
Two courts, two different outcomes, one unmistakable signal: the legal theory that reshaped retirement plans twenty years ago has arrived in group health.
What "Fiduciary Oversight" Actually Means for a Self-Funded Health Plan
A self-funded health plan sponsor is a fiduciary the moment it exercises discretion over plan assets, and that duty cannot be delegated away by hiring a TPA. Most benefits leaders assume oversight is the TPA's job because the TPA processes claims, negotiates rates, and issues the reports the plan committee reviews each quarter. That assumption is where the fiduciary exposure begins.
ERISA Section 404 requires a named fiduciary to act with the care, skill, and diligence of a prudent expert, solely in the interest of participants. Hiring a competent TPA satisfies part of that duty. Monitoring the TPA's actual performance, not its self-reported accuracy scores, is the other part, and it is the part most plans skip.
The Tiara Yachts case makes the stakes concrete. The Sixth Circuit found that Blue Cross Blue Shield of Michigan could be a functional fiduciary because it controlled how claims were paid and how overpayment recoveries were split, not because a contract labeled it that way.
Why This Gap Exists Across So Many Plans
Health plan fiduciary duty developed later and more quietly than retirement plan duty. The 401(k) fee cases that started around 2006 forced plan committees to build documented, repeatable review processes for recordkeeper fees and fund lineups.
No equivalent discipline took hold for health plans, largely because TPA reporting looked authoritative enough to satisfy a busy HR or finance leader. Sixty-seven percent of covered workers are now in self-funded plans, according to the 2025 KFF Employer Health Benefits Survey, and at firms with 200 or more employees that figure reaches 80%, so the exposure is concentrated exactly where committees tend to assume the TPA has it handled.
Committees also rarely rotate or renegotiate audit rights when they renew a TPA contract. Restrictive audit clauses, limited sample sizes, and carrier-selected auditors are common, and few benefits teams push back because no one has flagged the gap as a liability issue yet.
The Real Cost of Skipping Independent Oversight
Unreviewed claims translate directly into plan asset losses, and those losses accrue every payment cycle, not just in a bad year. Industry-documented TPA error rates run from 1% to 3% on the low end and up to 5% to 12% when independent auditors review 100% of claims rather than a sample.
A regional manufacturer with 1,400 employees found $812,000 in overpayments across 18 months once it ran an independent audit, including a duplicate $47,000 inpatient claim and 63 ineligible dependents still active on the plan.
The Department of Labor's EBSA recovered $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, with $714.4 million coming from enforcement actions tied to 556 closed civil investigations. That total does not include the far larger pool of overpayments plan sponsors never identify because their contracted audit covers a few hundred claims out of hundreds of thousands.
Cost containment through claims oversight is not a rounding error. It is comparable to finding a leak in a pipe that has been running for years. The plan does not notice the loss on any single bill, but the cumulative drain shows up in renewal premiums the whole workforce eventually pays.
What's Actually Happening Behind the TPA's Reporting
Self-Reported Accuracy Scores Don't Match Independent Findings
TPAs commonly report financial accuracy near 96% to 97% against their own service level agreements. Independent post-payment reviews that examine the full claims file, rather than a carrier-selected sample, routinely find meaningfully higher error rates because the sampling methodology itself is built to minimize findings.
Sample Sizes Are Too Small to Catch Systemic Errors
Standard ASO audit clauses often cap the review at 300 to 350 claims per year. A peer-reviewed comparison of 100% claims audits against random-sample audits found the sampling approach missed error totals ranging from $200,000 to $750,000 that a full review caught.
Cross-Plan Offsetting and Spread Pricing Blur Whose Money Moves Where
In Peterson v. UnitedHealth Group, the Eighth Circuit found that using one employer's plan assets to offset another employer's overpayment was in tension with ERISA fiduciary duties. Spread pricing, where a TPA bills the plan more than it pays the provider, has been well documented in pharmacy benefit management and is now surfacing in medical claims reviews as well.
Dependent Eligibility Drift Goes Unchecked for Years
Employees change marital status, dependents age out, and COBRA elections lapse, but few plans run a dedicated eligibility audit outside of open enrollment. These reviews are often the fastest-paying audit workstream because ineligible dependents represent pure ongoing cost with no offsetting value.
Why TPA Self-Reporting Isn't Enough Anymore
How to Close the Fiduciary Oversight Gap
Red Flags That Signal Your Plan Is Exposed
The ROI of Independent Oversight Done Right
Plans that run independent claims audits commonly recover the full cost of the audit within the first review cycle, and ongoing monitoring compounds those savings across every subsequent plan year. Dependent eligibility audits alone often pay for themselves within months because every ineligible dependent removed is a recurring cost eliminated, not a one-time recovery.
The fiduciary protection value is harder to price but arguably more important. A documented, repeatable oversight process is the same evidence that helped a health plan sponsor defeat a DOL fiduciary breach claim in prior litigation, because the court found the sponsor had not simply delegated authority and looked away.
Conclusion and Next Steps
The parallel between today's health plan fiduciary exposure and the 401(k) excessive fee wave of the past two decades is not a marketing analogy. It is the same statute, the same duty to monitor, and increasingly the same courts applying settled retirement plan precedent to group health claims. The J&J dismissal shows plaintiffs still face real standing hurdles, but Tiara Yachts and EBSA's 2026 enforcement pivot show the underlying theory is gaining traction, not losing it.
Plan sponsors who wait for a lawsuit to force the issue will be building their prudent process defense after the fact, which is the position no fiduciary wants to be in. Start with a claims audit scope review this quarter, confirm your audit rights before your next renewal, and document the committee's review process going forward.
Frequently Asked Questions
Is my company a fiduciary for our self-funded health plan?
Yes, if you exercise any discretion over plan administration or assets. Most self-funded employers are named fiduciaries under ERISA Section 402.
Can our TPA also be held liable as a fiduciary?
Yes. Courts including the Sixth Circuit in Tiara Yachts have found TPAs can be functional fiduciaries when they control claims payment and recovery decisions.
How often should we audit our health plan claims?
Annual audits are the baseline. Quarterly or continuous monitoring catches errors before they compound across a full plan year.
What is a "prudent expert standard" under ERISA?
It requires fiduciaries to act with the care, skill, and diligence a knowledgeable person would use in managing plan assets, not just good intentions.
Does our TPA's self-reported accuracy rate satisfy our fiduciary duty to monitor?
No. Duty to monitor requires independent verification, not reliance on a service provider's self-graded performance.
What percentage of claims typically contain errors?
Industry estimates range from 1% to 3% under standard sampling, and 5% to 12% when independent auditors review the full claims file.
Is D&O insurance enough to cover a fiduciary breach claim?
Usually not. ERISA Section 409 imposes personal liability on fiduciaries, and standard D&O policies frequently exclude ERISA fiduciary breach claims.
Why are health plan lawsuits increasing now instead of years ago?
Retirement plan litigation matured first and established the legal playbook. DOL enforcement priorities and court rulings like Tiara Yachts are now applying that same scrutiny to health plans.

Stop Mistaking TPA Administration for Fiduciary Protection
TPA administration and fiduciary protection are not the same thing. A TPA processes and pays claims under contract, but ERISA Section 404 keeps fiduciary responsibility with the plan sponsor. Signing a TPA contract does not transfer that duty. Only active, documented oversight of claims activity satisfies the prudent expert standard.
Most self-funded plan sponsors sign a service agreement with a TPA and treat the relationship as a handoff. Once claims start getting paid, the assumption is that someone else is now watching the store. Independent research on claims administration tells a different story.
TPA error rates on processed claims commonly run between 1% and 6% of total volume, and on a plan spending $20 million a year on medical claims, even a conservative 2% error rate is $400,000 in avoidable losses. Fiduciary protection for self-funded health plans does not come from the TPA contract. It comes from what the plan sponsor does after the contract is signed.
What TPA Administration Actually Covers
Administering a health plan and protecting it as a fiduciary are two different jobs, and most TPA contracts only cover the first one. A TPA agreement typically spells out claims processing timelines, network access and customer service standards. It rarely includes an obligation to catch every coding error, flag every ineligible dependent or independently verify that billed rates match contracted rates.
Plan sponsors often assume that paying a reputable, well-known TPA is itself a form of due diligence. That assumption is understandable. It is also incomplete under ERISA, where the duty to monitor a service provider cannot be delegated away, even when claims decision authority has been assigned to the TPA.
The result is a structural gap. The TPA handles volume and workflow. The plan sponsor, as the named fiduciary, remains on the hook for verifying that the volume was handled correctly. Nothing in a standard administrative services agreement closes that gap on its own.
Why the Problem Exists
TPAs are built and compensated to process claims at scale, not to flag every dollar that could have been billed more cheaply. Their internal accuracy metrics are typically self-reported, drawn from small samples of their own work, and rarely audited by an outside party before being shared with the plan.
Prompt payment timelines add pressure in the same direction. Most administrative agreements require claims to be paid within 21 to 30 days of receipt, which leaves limited room for a detailed line-item review before a check goes out. Speed and accuracy pull against each other, and speed usually wins by contract design.
Plan sponsors compound the gap by treating the TPA relationship as "set and forget." Committees review premium trends and utilization reports at renewal, but few build a recurring, independent claims review into the plan's operating calendar. Without that cadence, errors accumulate quietly for years.
The Real Cost or Impact
A 2% to 6% error rate sounds small until it is applied to a plan's total claims spend. On a mid-size plan paying $15 million a year in claims, even the low end of that range represents $300,000 moving through the plan incorrectly, year after year, without anyone flagging it. Multiply that across a plan's life span and the number stops looking like a rounding error.
The financial exposure is only part of the picture. In FY 2024, the Department of Labor's Employee Benefits Security Administration recovered nearly $1.4 billion for plans, participants and beneficiaries, a large share of it tied to weak oversight of service providers and plan assets. That is federal enforcement money, not internal audit findings, which means it followed a formal investigation into how a plan was being run.
Self-funded plans are now the dominant funding model in the employer market. KFF's 2025 Employer Health Benefits Survey found that 67% of covered workers are enrolled in self-funded arrangements, rising to 80% at larger firms. That scale means the fiduciary exposure sitting inside unreviewed claims data is not a niche problem. It touches most employer-sponsored health coverage in the country.
What's Actually Happening Behind the Scenes
Sampling Audits Instead of Full Review
Most claims oversight today runs on small statistical samples rather than a full look at every payment. A TPA might review a few hundred claims out of hundreds of thousands processed in a year and extrapolate an accuracy rate from that subset. The math works fine for a general trend line. It does very little to catch the specific overpayment sitting in the other 95% of claims that never got a second look.
Coordination of Benefits Gaps
Coordination of benefits (COB) failures happen when a plan pays as primary on a claim that should have been paid by another carrier first. These errors are common in households with two working spouses or dependents aging onto other coverage. TPAs process COB updates reactively, based on member-submitted information, which means stale COB data can sit in the system for months before anyone notices the plan paid more than it owed.
Dependent Eligibility Drift
Dependent eligibility drift describes ineligible dependents, a divorced spouse, an adult child who aged out, staying on the plan because no one re-verified eligibility after enrollment. Every claim paid on behalf of an ineligible dependent is plan money spent outside the terms of the plan document, which is itself a fiduciary concern independent of the dollar amount involved.
Vendor Accountability and Legal Exposure
Courts have started drawing a sharper line around who actually carries fiduciary risk in these relationships. In *Tiara Yachts, LLC v. Blue Cross Blue Shield of Michigan*, the Sixth Circuit held that functional conduct, not contract labels, determines fiduciary status and liability. That precedent matters for any plan sponsor assuming that a well-worded services agreement automatically shields them from claims-related fiduciary exposure.
Why Current Approaches Aren't Enough
Renewal-cycle reviews and TPA-provided performance dashboards give plan sponsors a general sense of direction. They rarely provide the kind of documented, independent evidence that would hold up if a participant or the Department of Labor challenged how the plan was overseen.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Independent audits regularly identify overpayments in the 2% to 6% range of total claims spend, and those recoveries frequently offset the cost of the audit itself within the first review cycle. For a plan spending $20 million annually, recovering even the low end of that range translates into hundreds of thousands of dollars back in plan assets.
The ongoing value compounds once oversight becomes routine instead of occasional. A plan that reviews claims quarterly catches errors before they repeat across multiple pay cycles, which lowers the total leakage over time rather than just the one-time recovery from a single audit.
The fiduciary protection component is harder to price but just as real. Documented, independent oversight gives the plan sponsor evidence of a prudent process, which is the standard ERISA actually asks fiduciaries to meet. That documentation is the difference between a defensible governance record and an unverified assumption that the TPA had it covered.
Conclusion and Next Steps
TPA administration keeps claims moving. Fiduciary protection for self-funded health plans only comes from what a plan sponsor does to verify that movement is accurate, documented and reviewed on a defined schedule. Those are not the same function, and treating them as interchangeable leaves plan assets and personal fiduciary exposure sitting unmonitored.
The next step is straightforward: schedule an independent claims audit, formalize the benefits committee's charter, and build documentation habits before a complaint or investigation forces the issue. Talk to an independent claims audit specialist.
Frequently Asked Questions
Does hiring a TPA transfer fiduciary liability to them?
No. ERISA keeps the duty to monitor service providers with the plan sponsor, even when claims decisions are delegated to the TPA.
What percentage of claims do TPAs typically get wrong?
Industry-documented error rates on processed claims generally fall between 1% and 6%, depending on the source and plan complexity.
How often should a self-funded plan conduct an independent claims audit?
At least annually, with many advisors recommending quarterly or ongoing monitoring for larger plans.
Can a plan sponsor be sued personally for fiduciary breaches?
Yes. Individuals who exercise discretion over plan administration can face personal liability for breaches of fiduciary duty under ERISA.
Is a sampling audit from the TPA enough to satisfy fiduciary duty?
Sampling audits provide limited assurance. Independent, broader reviews offer stronger documentation of a prudent oversight process.
What is coordination of benefits and why does it matter for audits?
Coordination of benefits (COB) determines which plan pays first when a person has multiple coverages. Errors here often cause plans to overpay.
Does the TPA's size or reputation reduce fiduciary risk?
Not directly. Fiduciary risk is tied to oversight practices and documentation, not the TPA's brand or market share.
What should a benefits committee document to show prudent process?
Meeting minutes, audit reports, corrective action plans and vendor monitoring records, generally retained for at least six years.

Why Employers Need Independent Claims Oversight
A 1,400-employee manufacturer ran its first independent claims audit in 2024 after 18 months of routine TPA reporting had shown nothing unusual. The audit found $812,000 in overpayments, including a $47,000 inpatient claim paid twice, 63 ineligible dependents still active on the plan, and a specialty drug billed at 240% of the contracted rate. None of it had surfaced in the TPA's own reviews.
That gap between what a TPA reports and what an independent audit finds is not an isolated incident. It is a structural feature of how most self-funded plans operate today, and it is one that plan sponsors are increasingly on the hook for.
What Independent Claims Oversight Actually Means
Independent claims oversight is a third-party review of paid medical claims, conducted by an auditor with no financial relationship to the TPA that processed them. Most employers assume their TPA already does this work through its own quality assurance process. That assumption is the core misunderstanding this article addresses.
A TPA's internal audit measures the TPA's own performance using the TPA's own sample, methodology, and reporting standards. That is not oversight. It is self-assessment, and self-assessment has an obvious structural weakness: the entity being reviewed controls what gets reviewed.
Independent oversight replaces that arrangement with an outside party who audits a much larger share of claims, applies clinical and coding expertise the TPA's routine review does not, and reports findings directly to the plan sponsor rather than filtering them through the vendor being evaluated.
Why the Problem Exists
The root cause is not incompetence. Most TPAs process millions of claims accurately and efficiently, and their sampling audits are a legitimate part of normal operations. The problem is scope and incentive, not effort.
TPA sampling audits typically examine a small slice of total claims, often under 5%, leaving the remaining volume unreviewed by anyone with genuine independence. Complex errors such as coordination of benefits failures, upcoding, and unbundling require clinical coding expertise that standard sampling processes are not built to catch at scale.
There is also a quieter incentive dynamic. A TPA that repeatedly identifies its own errors invites tougher contract terms and more scrutiny at renewal. That is simply how vendor relationships work, not an accusation of misconduct, but it explains why relying solely on a vendor's self-reported accuracy leaves a structural blind spot that only independent review can close.
The Real Cost or Impact
The financial exposure from unreviewed claims is measured in real dollars, not theoretical risk. One documented audit of a TPA's claims processing found financial accuracy of 96.8% and payment accuracy of 96.1%, both below the plan's contracted 98% service level agreement, even though the TPA had self-reported 100% accuracy (Baker Tilly). At claims volumes of $10 million to $50 million a year, even a 2% to 5% error rate translates into hundreds of thousands of dollars annually (AIM Benefits).
Coordination of benefits failures are a common driver of this leakage. When a plan pays as primary on a claim that should have been billed secondary, the overpayment on that single claim can run 60% to 80% higher than it should. Multiply that pattern across a workforce of several thousand employees and the leakage compounds every renewal cycle.
There is also a regulatory dimension. EBSA recovered more than $1.4 billion for retirement, health, and welfare benefit plans and their participants in fiscal year 2025, with more than half of that total coming from enforcement actions rather than voluntary correction (U.S. Department of Labor). That figure reflects a broader enforcement environment in which undocumented vendor oversight is increasingly treated as a fiduciary gap, not an administrative footnote.
What's Actually Happening Behind the Scenes
Sampling Instead of Full Review
Most TPA audits work from a statistical sample rather than a full claims review. That approach is efficient for catching obvious errors but is not designed to surface the low-frequency, high-dollar errors, like a duplicate inpatient claim or a specialty drug billed above contract rate, that do the most damage to a plan's budget.
Eligibility Drift
Dependents who age out, spouses who gain other coverage, and employees who terminate but stay active in the claims system for months are a quiet but persistent source of leakage. Eligibility files are rarely reconciled against claims payment in real time, so ineligible claims can accumulate for a full plan year before anyone notices.
Coding Errors That Require Clinical Judgment
Upcoding bills a higher-acuity service code than the documentation supports. Unbundling charges separately for procedures that should be billed under one comprehensive code. Both require someone with clinical and coding expertise to catch, which is exactly the kind of review that high-volume, low-touch sampling processes tend to under-resource.
Why Current Approaches Aren't Enough
Annual TPA-led sampling audits satisfy a contractual checkbox, but they were never designed to serve as fiduciary evidence. The table below shows where the gap sits.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Independent claims audits routinely recover overpayments well above the cost of the audit itself, which is one reason the practice has become standard among large, well-governed plans. Beyond direct dollar recovery, ongoing oversight tends to reduce the error rate in future claims cycles because TPAs adjust processing behavior once they know independent review is a permanent fixture, not a one-time event.
The fiduciary protection value is harder to put a single number on, but it is arguably more important. A plan sponsor who can show continuous, independent review of claims payment occupies a materially stronger position in a DOL inquiry or participant lawsuit than one relying solely on an annual vendor-run sample.
Given that EBSA closed 878 civil investigations in FY 2025, with 556 resulting in repayments or required corrective action (per DOL enforcement data), documented independent oversight is no longer a nice-to-have. It is the evidence a plan sponsor needs on file before anyone asks for it.
Frequently Asked Questions
What is independent claims oversight?
A third-party review of paid medical claims by an auditor with no financial ties to the TPA, distinct from a TPA's internal quality checks.
Why can't I rely on my TPA's own audit?
A TPA auditing its own claims creates a conflict of interest and typically reviews only a small sample of total volume.
Who is legally responsible for claims errors under ERISA?
The plan sponsor, not the TPA, carries fiduciary liability for how the plan's claims are paid.
How often should a self-funded plan run an independent audit?
Best practice is quarterly or continuous review, not a single annual engagement, since leakage reappears every plan year.
What is the prudent expert standard?
ERISA Section 404 requires fiduciaries to act with the care and skill a knowledgeable expert would use, which independent audits help document.
What kinds of errors do independent audits usually find?
Duplicate payments, ineligible dependents, coordination of benefits failures, upcoding, and unbundling are the most common categories.
Does an independent audit replace my TPA relationship?
No. It adds an accountability layer alongside the TPA, not a replacement for claims processing services.
What size plan needs independent claims oversight?
Any self-funded plan, but the dollar exposure grows quickly for employers with 100 or more covered employees and claims spend in the millions.

Why Claims Data Transparency Alone Isn't Enough
A self-funded hospital system trusted its TPA's self-reported claims accuracy of 100%, year after year. An independent audit of a stratified sample of roughly 200 medical claims told a different story.
Financial accuracy landed near 96.8% and payment accuracy at 96.1%, both below the 98% service level agreement in the contract. The plan had data. Nobody outside the TPA had checked whether the data was true.
What Claims Data Transparency Actually Means
Claims data transparency is access to claims pricing, utilization or payment information, not verification that the information is accurate. Plan sponsors often equate transparency with oversight because both involve data. They are not the same function.
Transparency answers "what did we pay." Oversight answers "should we have paid that." A plan can have full access to its claims feed and still have no process for catching a duplicate payment, an ineligible dependent or a specialty drug billed above the contracted rate.
The Transparency in Coverage rule illustrates the gap well. It produced what has been called one of the largest government-mandated data releases in history, yet researchers found the machine-readable files inconsistent in structure, thin on index information and often too large for a standard computer to process. Access without usability is not transparency in any meaningful sense.
Why the Gap Exists
The gap exists because TPAs report their own performance, and self-reporting carries no independent verification. A TPA's contract may guarantee 99% payment accuracy while the TPA's own internal data shows a 1.4% claims processing error rate, a discrepancy that surfaced in one carrier's administrative services agreements. The guarantee and the reality are not required to match unless someone checks.
TPAs also lack a direct financial incentive tied to plan cost outcomes. Their compensation structure is generally built around processing volume and service fees, not around minimizing the plan's total spend, so error prevention competes with throughput.
Most plans compound the problem by reviewing claims infrequently. Annual audits built into ASO agreements often sample only 300 to 350 claims out of hundreds of thousands processed in a year. A snapshot that small can miss systemic issues entirely.
The Real Cost of Assuming Transparency Equals Oversight
Unverified claims errors compound into six- and seven-figure losses for mid-size self-funded plans. Industry claims audit findings put TPA error rates between 3% and 10% of processed claims, well above the 1% to 3% error rate typically cited as an industry baseline.
Independent claims analysis across a large multi-employer dataset found error detection rates of 5% to 15%, with average recoverable findings between $500 and $1,200 per covered employee per year. For a plan with 1,000 covered employees, that range alone represents $500,000 to $1.2 million in annual exposure.
The consequences are not only financial. In September 2025, Aetna and Optum reached an $8.4 million settlement tied to fabricated billing codes that concealed administrative fees inside medical charges for nearly a decade before litigation forced disclosure. Transparency did not surface that pattern. Litigation did.
What's Actually Happening Behind the Scenes
Benefit Determination Errors
The most common category of claims error involves how a plan's own provisions get applied: deductibles, coinsurance, copays and plan-specific exclusions. These errors are rarely intentional. They happen because claims processing blends automated adjudication with manual review, and manual steps introduce inconsistency.
Dependent Eligibility Drift
Dependents who age out, divorce out or otherwise lose eligibility often stay on a plan for months or years because no one is cross-checking enrollment against life events. Dependent eligibility audits are frequently the fastest-paying workstream in a claims review because the savings start the moment ineligible members are removed.
Duplicate and Miscoded Claims
Duplicate payments, upcoding and unbundling do not show up in a pricing dashboard. They show up when someone compares the billed procedure codes against the medical record or the plan's coding logic, a step that transparency tools are not built to perform.
Why Current Approaches Aren't Enough
Most plan sponsors rely on the transparency and reporting the TPA already provides. That approach leaves the same party that processed the claim responsible for verifying it, which is a conflict most plans would not accept in any other financial function.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
Independent claims audits routinely recover a meaningful share of the errors they identify, and the ongoing savings from corrected TPA behavior often exceed the one-time recovery. [internal link: claims audit ROI calculator] Dependent eligibility reviews in particular tend to pay for themselves within months, since removing an ineligible dependent stops future claims immediately rather than only recovering past ones.
Beyond dollars, a documented audit and monitoring process is the clearest evidence a plan sponsor has that it met the prudent expert standard under ERISA Section 404. That documentation matters most in the moment a plan can least afford to be without it: a DOL inquiry or a participant lawsuit. EBSA alone recovered $1.4 billion for plans, participants and beneficiaries in fiscal year 2025, a reminder that enforcement activity in this space is active and ongoing, not theoretical.
Frequently Asked Questions
Is claims data transparency required by law?
Yes. The Transparency in Coverage rule and the Consolidated Appropriations Act, 2021 require pricing disclosures, but neither requires payment accuracy verification.
Does transparency alone satisfy ERISA fiduciary duty?
No. ERISA Section 404 requires a prudent process for monitoring plan expenses, which access to data does not fulfill by itself.
How often should a self-funded plan audit its claims?
Most fiduciary advisors recommend an independent audit at least annually, supplemented by ongoing quarterly or monthly monitoring.
What percentage of claims typically contain errors?
Independent audits commonly find error rates between 3% and 10%, above the 1% to 3% often cited as an industry baseline.
Who is legally responsible for claims accuracy, the plan sponsor or the TPA?
The plan sponsor. ERISA places fiduciary responsibility on the plan sponsor even though the TPA processes the claims.
Can a plan sponsor audit claims without the TPA's permission?
Audit rights depend on the ASO agreement. Sponsors should negotiate unrestricted audit access before signing or renewing a contract.
What is the difference between a claims audit and ongoing monitoring?
An audit reviews a sample retrospectively. Ongoing monitoring reviews claims continuously, closer to the time they are paid.
Are machine-readable pricing files useful for claims oversight?
They provide pricing context but are not designed to verify individual claim accuracy, and many are difficult to process without specialized tools.

Fiduciary-Grade Healthcare Operations: A Plan Guide
Fiduciary-grade healthcare operations are the claims oversight, documentation and governance practices a self-funded plan sponsor uses to meet ERISA's prudent expert standard. This includes independent claims audits, documented TPA performance reviews and dependent eligibility checks, rather than relying on a TPA's self-reported accuracy numbers.
In September 2025, Aetna and Optum finalized an $8.4 million settlement over fabricated billing codes that had inflated member costs for nearly a decade before litigation forced disclosure. The case started with one retired plan member who noticed a pattern nobody else was checking.
Most self-funded plan sponsors never look closely enough to find that pattern on their own plan, and industry data suggests TPA error rates run between 1% and 10% of processed claims, depending on the audit methodology used. For a plan paying $20 million a year in claims, that range represents anywhere from $200,000 to $2 million in errors that nobody is actively hunting for.
What Are Fiduciary-Grade Healthcare Operations
Fiduciary-grade healthcare operations are the documented, independently verified claims oversight processes a plan sponsor uses to satisfy ERISA's prudent expert standard, rather than the minimum administrative reporting a TPA provides by default. Most plan sponsors assume their TPA's self-reported accuracy rate reflects reality. It often does not.
A TPA's administrative services agreement typically guarantees financial and payment accuracy in the 98% range. Independent audits regularly find actual accuracy closer to 96% to 97%, a gap that sounds small until it is multiplied across a plan paying eight or nine figures in annual claims. The difference between "TPA-reported" and "independently verified" is the entire fiduciary question.
Fiduciary-grade operations are not a single product or vendor. They are a standing practice: audit cadence, documentation, and a governance record that shows the plan sponsor acted as a prudent expert would, consistent with the standard set out in ERISA Section 404.
Why the Oversight Gap Exists
The oversight gap exists because TPAs have no direct financial stake in the plan's cost outcomes, and most plan sponsors lack the internal expertise to audit claims data themselves. A TPA is paid a fee to process claims, not a percentage of savings, so accuracy beyond the contracted service level agreement carries little upside for the TPA.
Plan sponsors, meanwhile, are often HR or finance leaders managing benefits as one responsibility among many. Building the coding expertise needed to catch upcoding, unbundling, or duplicate billing in-house is rarely realistic for a mid-size employer.
Restrictive audit clauses compound the problem. Many TPA contracts historically limited the number of claims a sponsor could audit, barred extrapolation of findings, or restricted which outside firms could perform the audit, though state laws such as Maine's L.D. 1906, effective for contracts issued or renewed after January 1, 2026, are starting to prohibit those restrictions.
The Real Cost of Skipping Fiduciary-Grade Oversight
Skipping independent claims oversight costs plans real money and creates fiduciary liability that follows the plan sponsor personally. A full-scope claims audit with 100% review, rather than a sampled TPA self-audit, typically recovers between 1% and 3% of annual claims spend, based on industry-reported audit outcomes.
On the enforcement side, the Department of Labor's Employee Benefits Security Administration recovered $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, with $714.4 million of that tied directly to civil enforcement actions. EBSA closed 878 civil investigations that year alone, a volume that signals oversight failures are common, not rare.
Litigation risk is following the same curve. The 401(k) excessive-fee lawsuit model, which produced more than $10 billion in settlements over the past decade, is now being applied to health plan administration, with plaintiffs' firms using DOL enforcement patterns as a roadmap for building breach-of-fiduciary-duty claims against plan sponsors.
What's Actually Happening Behind the Scenes
Sampled Audits Miss Most of the Plan
A standard TPA audit typically reviews a stratified sample of 250 to 400 claims out of hundreds of thousands processed annually, then extrapolates an overall accuracy score from that small slice. The unreviewed remainder, often more than 95% of total claims, never gets examined at all.
Coding Errors Hide in High-Dollar Claims
Upcoding, unbundling, and duplicate billing tend to concentrate in complex, high-dollar claims, exactly the claims a small random sample is least likely to catch. Specialty pharmacy and inpatient facility claims carry disproportionate risk for this reason.
Dependent Eligibility Drifts Without Anyone Noticing
Ex-spouses, aged-out children, and other ineligible dependents routinely remain on plan rolls for years because eligibility verification is rarely built into ongoing claims workflows. Each ineligible dependent represents ongoing claims spend the plan should never have paid.
Automated Adjudication Approves Errors at Scale
A growing share of claims are approved through automated adjudication with no human review, which processes errors just as efficiently as it processes legitimate claims. Duplicate claims and coordination-of-benefits failures are especially prone to slipping through automated systems undetected.
Why Current Approaches Aren't Enough
Most plans still treat claims oversight as a periodic compliance task instead of an ongoing operational discipline. The table below shows how that status quo compares with a fiduciary-grade approach.
How to Build Fiduciary-Grade Healthcare Operations
Red Flags That Signal Your Plan Needs This Now
The ROI of Doing It Right
Independent, full-scope claims audits typically recover 1% to 3% of annual claims spend in direct overpayment findings, and dependent eligibility audits frequently pay for themselves within months of completion.
Beyond direct recovery, fiduciary-grade documentation is itself a form of risk transfer. A plan sponsor that can produce board minutes, audit reports, and a documented TPA review process has evidence of the prudent expert standard that ERISA requires, which matters considerably if EBSA or a plaintiff's firm ever comes asking.
Think of it the way a building owner thinks about fire code compliance. The inspection itself does not prevent every fire, but the documented compliance record is what protects the owner when something goes wrong anyway. Claims audit documentation functions the same way for plan fiduciaries.
Conclusion and Next Steps
Fiduciary-grade healthcare operations are becoming the baseline expectation, not a differentiator, as EBSA enforcement activity and health plan litigation both continue climbing. Plan sponsors that wait for a regulator or a plaintiff's attorney to ask the first question have already lost the advantage of showing a prudent, documented process.
Start with an independent audit scoped to review all claims, not a sample, and build the documentation habit alongside it.
Frequently Asked Questions
What does "fiduciary-grade" mean for a health plan?
It means claims oversight and documentation practices that meet ERISA's prudent expert standard, not just a TPA's minimum reporting.
Who is legally responsible for claims accuracy on a self-funded plan?
The plan sponsor, under ERISA Section 404, regardless of which TPA processes the claims.
How often should a self-funded plan conduct a claims audit?
Independent audits should happen continuously or quarterly, not once every two to three years.
What percentage of claims contain errors?
Industry-documented TPA error rates range from roughly 1% to 10%, depending on audit scope and methodology.
How much money can a claims audit typically recover?
Full-scope, 100% claims audits typically recover 1% to 3% of annual claims spend.
Can a TPA restrict how a plan sponsor audits its own claims?
Some contracts historically did, though new state laws are increasingly prohibiting these restrictions.
Should a plan sponsor use the TPA's recommended audit firm?
No. Independent firms with no ownership or referral ties to the TPA reduce conflict-of-interest risk.
What is the fastest way to reduce fiduciary risk right now?
Document the plan's governance process, including committee minutes and retained audit reports, alongside commissioning an independent audit.

The Difference Between Payment Integrity and Fiduciary Intelligence
Payment integrity is a technical process that checks whether individual claims were coded and priced correctly. Fiduciary intelligence is a governance framework that documents whether the plan sponsor prudently monitored its vendors, as ERISA Section 404 requires. Payment integrity catches claim errors. Fiduciary intelligence protects the people legally responsible for the plan.
Most self-funded plans confuse a claims tool with a legal defense, and the gap between them is where lawsuits start.
A mid-size manufacturer with 1,400 employees paid $340,000 in claims for a coordination of benefits failure that ran undetected for eighteen months (Willis Towers Watson). The plan's payment integrity vendor never flagged it because the claims were coded correctly.
The problem wasn't accuracy. It was that nobody on the plan sponsor's side could show they had monitored the TPA's handling of COB determinations at all. That gap, between a clean claim and a documented oversight process, is the entire subject of this article.
Why Payment Integrity Is Not the Same as Fiduciary Responsibility
Sixty-seven percent of covered workers in the United States are enrolled in self-funded health plans, and that share climbs to 80 percent among firms with 200 or more employees (Kaiser Family Foundation, 2025).
Every one of those employers carries fiduciary duties under the Employee Retirement Income Security Act (ERISA) regardless of whether they know it. Payment integrity is one useful tool for managing plan spend.
It is not the same thing as meeting that legal duty, and treating the two as interchangeable leaves plan sponsors exposed.
What Payment Integrity Actually Does
Payment integrity is the set of technical processes and software that verify whether a submitted claim was billed, coded, and priced correctly before or after payment. It answers a narrow question: did the plan pay the right dollar amount for this specific service.
Most people assume payment integrity is a comprehensive safeguard for the plan. It is not designed to be one. It is a claims-accuracy layer, built to catch duplicate billing, upcoding, and pricing errors against contracted rates. The global payment integrity market has grown to roughly $9 billion, expanding at about 7 percent annually as payers invest more heavily in automated claims review (McKinsey).
The tools are genuinely useful. They catch a meaningful share of overpayments that would otherwise slip through automated adjudication. What they do not do is document whether the plan sponsor exercised the kind of ongoing, independent oversight that ERISA requires of a fiduciary.
A payment integrity report can show a clean claims file and still leave a plan sponsor unable to answer basic questions about vendor monitoring, fee reasonableness, or conflict of interest review.
Why the Gap Exists
The gap between payment integrity and fiduciary protection exists because most self-funded plans were designed for administrative efficiency, not employer oversight. Standard administrative services agreements typically treat a small sampling audit as the complete review, and plan sponsors accept it because it has been considered the industry standard for decades.
TPAs may have limited incentives to identify their own payment errors. Industry studies report claims processing error rates of 2% to 6%, depending on the source and plan complexity (Baker Tilly). At the same time, many TPAs report self-audit accuracy rates close to 99% (ClaimInformatics). This does not necessarily mean either number is wrong. They measure different things. Self-audits often focus on processing accuracy and system rules, not whether the correct amount was ultimately paid.
There is also a structural asymmetry in who has access to the data. Many TPAs release detailed claims files only upon request, often in formats that require technical expertise to analyze (Benosphere). Under ERISA Section 404(a)(1)(B), the fiduciary must act "with the care, skill, prudence, and diligence" of a prudent expert (U.S. Department of Labor). It is difficult to meet that standard when the party being monitored controls the data used to monitor it.
The Real Cost of Treating Payment Integrity as Sufficient
Self-funded employers spending between $10 million and $100 million annually in healthcare claims face $200,000 to $2 million in unrecovered leakage under even a conservative 2 percent error rate (ClaimInformatics). Payment integrity tools recover some of that. Independent claims audits with full review typically recover an additional 1 percent to 3 percent of annual claims spend on top of whatever the TPA's own systems caught (Benosphere).
The financial cost is real but it is not the largest exposure. The fiduciary cost is. ERISA fiduciaries who breach their duties can be held personally liable to restore plan losses, and courts have referred to fiduciary obligations under the statute as among "the highest known to law" (ASPPA). A plan sponsor that relied entirely on a TPA's self-reported payment integrity metrics, with no independent verification, has a documentation problem the moment a participant or the Department of Labor asks how oversight was performed.
Consider the analogy of a building inspector who only checks whether individual bricks meet code. That inspector can sign off on every brick and still miss that the foundation was never surveyed. Payment integrity checks bricks. Fiduciary intelligence checks whether anyone verified the foundation.
What's Actually Happening Behind the Scenes
Sampling Gaps
A standard TPA audit reviews a stratified sample, commonly 200 to 400 claims, against plan documents (Baker Tilly). For a plan processing 80,000 claims annually, that represents roughly 0.3 percent to 0.5 percent of total claims volume (Benosphere). The remaining 99.5 percent goes unreviewed by anyone independent of the TPA.
Coordination of Benefits Failures
COB errors occur when a plan pays as primary when another payer, such as Medicare or a spouse's plan, should have paid first. A COB failure can produce a 60 percent to 80 percent overpayment on the affected claim (Benosphere), and these errors are difficult for automated payment integrity tools to catch because the claim itself may be coded correctly.
Vendor Fee Structures on Recovered Dollars
When TPAs or carrier-affiliated vendors do identify and recover overpayments, they frequently retain a substantial share. Post-pay recovery programs commonly take 40 percent to 50 percent of recovered dollars (ClaimInformatics), which means even a functioning payment integrity process may return less value to the plan than the raw recovery number suggests.
Governance Documentation
DOL guidance emphasizes that fiduciaries must document their decision-making process, not simply achieve a good outcome (DOL elaws Fiduciary Advisor). A payment integrity dashboard, no matter how sophisticated, is not itself governance documentation unless the plan sponsor can show it was reviewed, questioned, and acted upon.
Why Current Approaches Aren't Enough
How to fix it
Red Flags That Signal the Gap Applies to Your Plan
The ROI of Doing It Right
Independent claims audits with full review typically find discrepancies in 3 percent to 5 percent of paid claims costs, with actual recoveries in the 1 percent to 2 percent range (MedInsight). On a $30 million annual claims spend, that is $300,000 to $600,000 in identified overpayments, with $300,000 to $600,000 recoverable even under conservative assumptions.
The larger return is harder to put a number on but matters more in a dispute. A documented fiduciary process, maintained consistently across plan years, is described by the DOL as the strongest defense against audits and litigation (Ascensus). Plans that can produce that record are simply in a different legal position than plans that cannot, regardless of how their payment integrity metrics look in isolation.
Dependent eligibility reviews, treated as a distinct workstream from claims audits, frequently pay for themselves within months (Benosphere) and are one of the fastest ways to demonstrate near-term ROI while the broader fiduciary documentation process is being built out.
Conclusion and Next Steps
Payment integrity and fiduciary intelligence solve different problems, and a self-funded plan needs both. Payment integrity keeps individual claims accurate. Fiduciary intelligence protects the plan sponsor and named fiduciaries by documenting that oversight actually happened, in the way ERISA requires.
The gap between the two is exactly where fiduciary breach claims originate. Closing it does not require replacing your payment integrity vendor. It requires building a separate, deliberate governance record alongside it. [internal link: TPA performance guarantees guide] can help you evaluate whether your current vendor contract measures the right things, and [internal link: claims audit vs payment integrity comparison] walks through how to structure both functions without duplicating cost.
Frequently Asked Questions
Is payment integrity the same as fiduciary compliance?
No. Payment integrity checks individual claims accuracy. Fiduciary compliance requires documented, independent oversight of vendors under ERISA Section 404.
Who is legally responsible for claims errors, the TPA or the plan sponsor?
The plan sponsor. ERISA places fiduciary responsibility on the sponsor, not the TPA, even though the TPA processes the claims.
What does ERISA Section 404 actually require?
It requires fiduciaries to act with the care, skill, prudence, and diligence of a prudent expert familiar with plan administration.
How often should a self-funded plan run an independent claims audit?
Industry guidance generally recommends every two to three years, with more frequent monitoring for larger or higher-risk plans.
Can a plan sponsor rely on a TPA's self-reported accuracy numbers?
Relying solely on self-reported data, without independent verification, does not demonstrate the prudent oversight ERISA requires.
What percentage of claims does a typical TPA audit actually review?
Often well under 1 percent of total claims volume, since standard TPA audits use small stratified samples.
Does the Consolidated Appropriations Act change plan sponsor audit rights?
Yes. It strengthened plan sponsors' rights to full claims data access from TPAs and PBMs upon request.
What is the single most common dollar-weighted claims error?
Duplicate billing, followed closely by coordination of benefits failures on claims that should have paid secondary.

Fiduciary Intelligence: The TPA Oversight Gap Explained
Fiduciary intelligence is the independent claims oversight layer that sits between a third-party administrator (TPA) and a self-funded employer. It combines ongoing claims monitoring, audit documentation and vendor accountability data so plan sponsors can meet ERISA Section 404 duties instead of relying solely on the TPA's self-reported performance numbers.
A regional manufacturer with 1,400 employees ran an independent claims audit in 2024 and found $812,000 in overpayments across 18 months. The errors included a $47,000 inpatient claim paid twice, 63 ineligible dependents still active on the plan, and a specialty drug billed at 240% of the contracted rate. None of it showed up in the TPA's internal reporting, because none of it was ever reviewed.
That is not a rare story. It is the default outcome for a self-funded plan that treats its TPA's word as the audit. Most employer plans have no independent layer checking whether claims were paid correctly, and by the time anyone notices, the money is gone and the fiduciary exposure has already accrued.
What Fiduciary Intelligence Actually Means
Fiduciary intelligence is the independent oversight layer that verifies TPA claims performance instead of trusting it. Most employers assume their TPA relationship already includes this. It does not.
A TPA's job is to process claims according to plan documents and network contracts. A TPA's incentive is speed and member satisfaction, not necessarily financial accuracy on every dollar. Those two things frequently pull in different directions, and nothing in a standard administrative services agreement forces alignment.
The common assumption is that performance guarantees in the ASO contract already cover this ground. In reality, most guarantees measure turnaround time and claims-processing speed, not whether the dollar amount paid was correct. A TPA can hit every service level target in its contract while still overpaying claims at a rate the plan sponsor never sees.
Why the Oversight Gap Exists
The gap exists because plan sponsors delegate claims processing but rarely build independent verification into the relationship. Self-funded plans took off because employers wanted to bend the cost curve and gain flexibility insurance carriers do not offer. What did not scale at the same pace was internal expertise to monitor what a TPA actually does with that authority.
TPAs are not financially responsible for the plan. Their costs are covered by administrative fees, not by how accurately claims are paid, so they lack the same financial incentive an insurer carrying its own risk would have. That is not a matter of bad faith. It is simply a structural incentive problem plan sponsors need to correct with independent checks, not TPA good intentions.
Carrier and TPA post-pay sampling reviews typically cover only 3% to 5% of claims, and many ASO agreements specify an annual sample of just 300 to 350 claims regardless of plan size. A plan processing 200,000 claims a year can have 99.8% of its payments never independently reviewed by anyone outside the TPA that made the payment.
The Real Cost of an Unreviewed Plan
Unreviewed claims translate directly into unrecovered dollars, and the scale is larger than most benefits committees assume. Independent, full-population claims analysis consistently identifies error rates between 5% and 12% once every claim is checked instead of a sample, according to third-party claims analytics data covering more than $16 billion in reviewed claims. Industry benchmarks that rely on standard TPA sampling report a narrower 1% to 3% error range, largely because sampling catches fewer error types than a comprehensive review.
The dollar impact compounds quickly. A plan spending $20 million a year that carries even a 2% unrecovered error rate is looking at $400,000 walking out the door annually, before accounting for coordination of benefits failures or dependent eligibility errors that carry their own separate cost.
Consider the manufacturer's numbers again. Sixty-three ineligible dependents sitting on a plan for even one plan year can add tens of thousands of dollars in claims paid for people who should never have been covered. A single misapplied coordination of benefits rule, where the plan should have paid secondary but paid as primary instead, often produces a 60% to 80% overpayment on that specific claim.
What's Actually Happening Behind the Scenes
Coordination of Benefits Failures
Coordination of benefits, or COB, determines which plan pays first when a member has more than one source of coverage. When a TPA's system fails to catch a spouse's other employer coverage or a dependent's eligibility for a separate plan, the self-funded plan can end up paying as primary when it should be secondary. That single misconfiguration routinely produces overpayments in the 60% to 80% range on the affected claims.
Upcoding and Unbundling
Upcoding happens when a provider bills a higher-acuity procedure code than the service actually supports. Unbundling separates a single comprehensive procedure into multiple line items billed individually, inflating the total. Both require clinical and coding expertise to catch, which is exactly why standard TPA sampling rarely flags them.
Dependent Eligibility Drift
Employees change marital status, dependents age out, and COBRA windows close, but eligibility files do not always update on schedule. A plan that has not run a dependent eligibility verification in several years is very likely still paying claims for people who are no longer eligible for coverage.
Out-of-Network and Surprise Billing Gaps
Even after the No Surprises Act took effect, out-of-network claims can still slip through with billed charges well above usual and customary rates when a plan is not actively reviewing them. Without active oversight, the plan simply pays whatever the TPA's repricing engine calculates, correct or not.
Specialty Pharmacy Spend
Specialty drugs now account for more than half of pharmacy spend on many self-funded plans, and pricing errors in this category carry outsized dollar impact per incident compared to medical claims. A single misapplied contract rate on a specialty drug claim can run into tens of thousands of dollars.
Why Current Approaches Aren't Enough
Standard TPA performance guarantees were built to measure operational speed, not financial accuracy, and that mismatch is the core problem plan sponsors need to solve.
How to Fix It
Red Flags That Signal the Problem Applies to Your Plan
The ROI of Doing It Right
A full independent claims audit typically recovers 1% to 3% of annual claims spending on its first pass. For a plan spending $20 million a year, that translates to $200,000 to $600,000 recovered, often within the first audit cycle. Ongoing monthly or quarterly monitoring tends to catch errors closer to the point of payment, which both prevents future leakage and creates a documented accountability trail with the TPA.
Audit costs are typically far lower than the amount recovered, particularly for mid-sized and large plans. Beyond the direct dollar recovery, the process strengthens vendor negotiating position at renewal and produces the kind of documentation that demonstrates a prudent fiduciary process, which matters enormously if the Department of Labor's Employee Benefits Security Administration ever opens an inquiry.
EBSA recovered more than $1.4 billion for retirement, health and welfare plans in fiscal year 2025 alone, closing 878 civil investigations with 556 producing monetary or corrective results.
Conclusion and Next Steps
Self-funded plans now cover the majority of American workers with employer health benefits, and that share keeps growing. Every one of those plans carries fiduciary duties that do not pause just because a TPA is handling the paperwork. Fiduciary intelligence, in the form of independent claims oversight, is what actually closes that gap between delegation and accountability.
The next step is straightforward. Pull your ASO agreement and check the audit rights clause, then ask your benefits committee when the plan's claims were last independently reviewed. If nobody has a confident answer, that is the signal to schedule a claims audit and dependent eligibility review before the next renewal cycle.
Frequently Asked Questions
What is fiduciary intelligence in the context of self-funded health plans?
It is the independent oversight layer, combining claims monitoring and audit documentation, that verifies TPA performance rather than relying on the TPA's own reporting.
Who holds fiduciary responsibility for claims accuracy under ERISA?
The plan sponsor, under ERISA Section 404, regardless of which vendor actually processes and pays the claims. [external link: DOL/EBSA fiduciary responsibilities guide]
How often should a self-funded plan audit its TPA?
At minimum every one to two years for larger plans, with ongoing monthly or quarterly monitoring recommended between formal audits.
What percentage of claims does a typical TPA sampling audit review?
Roughly 3% to 5%, often limited to a fixed sample of 300 to 350 claims per year regardless of total plan size.
How much can an independent claims audit typically recover?
Most first-time audits recover 1% to 3% of annual claims spend, which can total hundreds of thousands of dollars on mid-sized plans.
What is the difference between a TPA performance guarantee and a fiduciary audit?
Performance guarantees measure speed and procedural accuracy; a fiduciary audit measures whether the dollar amount paid was actually correct.
Can a plan sponsor be held personally liable for TPA errors it never discovered?
Yes. ERISA fiduciary duty requires a prudent ongoing process, and failing to monitor a TPA can itself constitute a breach regardless of who made the underlying error.
What is coordination of benefits and why does it matter for claims accuracy?
COB determines which plan pays first when a member has multiple coverage sources; failures here commonly cause 60% to 80% overpayments on affected claims.

