Explore Our Blog Library!

Your Library of Employee Wellbeing Resources.

Fiduciary intelligence is the ongoing practice of auditing claims data, TPA performance, and plan spend to prove healthcare dollars are managed prudently under ERISA. For brokers and captives, offering it as a standing service, rather than a renewal-season extra, is becoming the clearest way to differentiate and retain self-funded clients.

A mid-market manufacturer with 340 employees spent three years assuming its TPA had claims accuracy handled. Nobody had looked at a claim file directly since the plan moved self-funded. When a broker finally pulled an independent sample, the review found six figures in duplicate payments and dependents who should have been dropped two open enrollments ago.

Family health premiums hit $26,993 on average in 2025, up 6% for the third year running, and 67% of covered workers are now in self-funded plans. Every dollar of that spend sits on the plan sponsor's books, and under ERISA, the sponsor is on the hook for how it's managed, not the TPA. Brokers who can prove that oversight is happening, continuously and independently, are starting to win business that pure renewal negotiation can't touch.

Key Takeaways
The fiduciary responsibility stays with the plan sponsor: Self-funded plan sponsors carry ERISA fiduciary liability for claims spend, even when they rely entirely on their TPA to report claims accuracy.
Claims errors create measurable exposure: Industry-documented TPA error rates range from 2% to 10% of paid claims, while most plans review fewer than 5% of claims each year.
Enforcement has real financial consequences: DOL/EBSA recovered $1.4 billion in FY 2025, including $714.4 million tied directly to enforcement actions against plans and service providers.
Fiduciary intelligence is becoming a standalone service: Ongoing claims and TPA oversight, rather than a once-every-few-years audit, is emerging as a service that brokers and captives can clearly define, price and own.
Advisors have an opportunity to get ahead: Advisors that build fiduciary intelligence into their offering can position themselves ahead of increasing ERISA litigation that increasingly resembles the excessive-fee lawsuits seen in the 401(k) market.
Bottom line: Claims oversight is moving beyond renewal support. Advisors that can provide independent, ongoing and documented fiduciary oversight can create measurable value while helping plan sponsors address their fiduciary obligations.

What Fiduciary Intelligence Actually Means

Fiduciary intelligence is the continuous review of claims data, TPA performance, and plan spend to demonstrate that a self-funded plan is being run prudently under ERISA. Most people in this industry hear "claims audit" and picture a one-time project: a consultant pulls a sample, writes a report, and everyone moves on until the next renewal cycle.

That's not what fiduciary intelligence is. It's closer to a standing discipline, similar to how a CFO doesn't audit the books once every three years and call it done. The plan's claims data gets reviewed on a rolling basis, TPA performance gets benchmarked against contract terms, and the plan committee has a documented trail showing they actually looked.

Here's the part most sponsors get wrong: they assume their TPA's self-reported accuracy numbers are the audit. TPAs often report 98% to 100% payment accuracy on their own claims. Third-party reviews of the same claims routinely find something different, because TPAs are grading against their own processing rules, not against the plan document itself.

Why the Problem Exists

TPAs process claims fast because speed is what they're measured on internally. Accuracy against the specific plan document, the one with your custom exclusions, your dependent eligibility rules, your coordination of benefits language, isn't usually the metric that gets watched day to day.

Most TPA contracts include a self-reported accuracy guarantee, and most plan sponsors never verify it independently. That's not negligence exactly. It's a resourcing gap. HR teams running benefits alongside a dozen other responsibilities don't have the bandwidth to pull claim files and check them against plan language line by line.

Brokers, historically, haven't filled that gap either. Renewal negotiation and open enrollment support have been the job. Ongoing claims oversight sat outside the traditional scope, and nobody was pricing it as its own service line.

The Real Cost or Impact

Numbers make this concrete. Independent studies of self-funded plans put TPA payment error rates in the 2% to 6% range, with some reviews finding rates as high as 10% depending on plan complexity and audit method, according to Baker Tilly. Willis Towers Watson pegs the industry standard for financial accuracy, the share of total claim dollars paid incorrectly, at roughly 1%, which still translates into millions of dollars for a large plan, as WTW notes.

Run the math on a $20 million annual claims spend. Even a conservative 1% to 2% error rate represents $200,000 to $400,000 a year, money that may be recoverable but can easily go unnoticed without independent review. One Baker Tilly review of tribal self-funded plans found that independent testing identified accuracy gaps in 60% of cases, highlighting why claims oversight should extend beyond TPA reporting.

Beyond the dollars, there's regulatory exposure. DOL's Employee Benefits Security Administration recovered more than $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, and over half of that, $714.4 million, came directly from enforcement actions rather than voluntary corrections, per DOL's own fact sheet. Nearly 300 of those investigations started because participants complained repeatedly about the same plan or service provider, a pattern that's entirely avoidable with proactive oversight.

What's Actually Happening Behind the Scenes

Claims Leakage Nobody's Tracking

Duplicate payments, coding errors, and out-of-network claims processed at in-network rates rarely show up on a TPA's own dashboard, because the dashboard is measuring what the TPA chose to measure. An independent review checks against the actual plan document instead.

Dependent Eligibility Drift

Divorced spouses, aged-out dependents, and employees who left the company months ago quietly stay on plan rosters. Nobody catches it until an audit specifically checks eligibility files against HR records, and by then it's often been years.

Pharmacy and Specialty Drug Spend

Specialty pharmacy claims are complex enough that errors hide easily inside them. Coordination of benefits failures, meaning the plan pays first when another payer should have, are especially common on pharmacy claims involving Medicare-eligible dependents.

Vague or Missing Documentation

When the DOL or a plan participant asks how a claims decision was made, plans without a documented review process often can't produce one. That absence of a paper trail is itself a fiduciary problem, separate from whatever the underlying claim showed.

Why Current Approaches Aren't Enough

Most plans rely on whatever the TPA offers as standard, and that's rarely built for the sponsor's protection. The comparison below shows where the gap sits.

Dimension Status Quo (TPA Self-Report) Fiduciary Intelligence Approach
Review Frequency Once every 2 to 3 years, if at all Continuous or quarterly
Sample Size Small stratified sample (often under 5% of claims) Full claims population or statistically robust sample
Standard Used TPA's internal processing rules Actual plan document and contract terms
Who Conducts It TPA grades itself Independent third party
Documentation Informal, rarely retained Formal record supporting prudent process
Recovery Focus Limited or none Active recovery of overpayments
Fiduciary Protection Minimal, exposure remains with sponsor Demonstrable process defensible under ERISA Section 404

How to Fix It

1
Separate the Audit From the Administrator
Don't rely on the TPA to grade its own claims processing. An independent review measured against the actual plan document is the only way to know what's really happening.
2
Move From Periodic to Continuous
A single audit every few years leaves years of unreviewed spend in between. Quarterly or rolling reviews catch problems while they're still small and recoverable.
3
Benchmark the TPA Contractually
Build specific accuracy and turnaround guarantees into the administrative services agreement, then actually measure against them instead of taking self-reported numbers at face value.
4
Document Every Review
Keep dated records of what was checked, what was found, and what corrective action followed. That paper trail is what protects the plan committee if a fiduciary claim ever surfaces.
5
Price Oversight as Its Own Line Item
Brokers and captives that bundle claims oversight in for free tend to under-deliver it. Scoping it as a standalone service, with its own PEPM fee, makes it sustainable to actually do well.
6
Loop Stop-Loss and Captive Data In
For captive members, claims oversight data feeds directly into loss experience and renewal terms, so the audit isn't just protective, it's financially useful at the captive level too.

Red Flags That Signal the Problem Applies to Your Plan

Your last independent claims audit, if there has been one, was more than two years ago.
Your TPA reports accuracy above 98%, and nobody has verified it independently.
Nobody on the plan committee can produce meeting minutes or documentation from the last fiduciary review.
Dependent eligibility has not been re-verified since the last open enrollment cycle.
Your broker relationship is renewal-focused only, with no ongoing claims or TPA performance review built in.
Specialty pharmacy spend has grown faster than the overall claims trend, with no line-item review of why.
Your stop-loss carrier has flagged high-cost claimants without a corresponding internal review of how those claims were adjudicated.

The ROI of Doing It Right

Comprehensive claims audits with full population review typically recover 1% to 3% of annual claims spend in the first cycle, according to industry-documented ranges. For a $15 million plan, that's $150,000 to $450,000 recovered in year one alone, before counting the savings from fixing the process going forward.

The ongoing value compounds. Once dependent eligibility is cleaned up and the TPA knows it's being watched, error rates tend to drop on their own. Several audit firms report that plans moving from periodic to continuous oversight see meaningfully lower error rates within a year or two of implementation.

Then there's the fiduciary protection, which is harder to put a dollar figure on but matters just as much. A documented, defensible process is the single best protection a plan committee has if a participant or the DOL ever challenges how the plan was run.

Conclusion and Next Steps

The self-funded market isn't getting simpler, and the fiduciary exposure that comes with it isn't going away either. Brokers and captives that treat fiduciary intelligence as a real, priced service, not a favor thrown in at renewal, are the ones building relationships that survive past the next RFP cycle.

If your current broker relationship stops at renewal negotiation, that's worth a direct conversation. Ask what independent claims oversight looks like for your plan and what it would take to build a documented, defensible fiduciary process starting now.

Frequently Asked Questions

What is fiduciary intelligence in employee benefits?

It's the ongoing practice of auditing claims data and TPA performance to prove a self-funded plan is managed prudently under ERISA, not a one-time audit.

Who is legally responsible for claims accuracy on a self-funded plan?

The plan sponsor holds fiduciary responsibility under ERISA, even though the TPA processes the claims day to day.

How often should a self-funded plan be audited?

Best practice is continuous or quarterly review, not the once-every-two-to-three-years cadence most plans still use.

What's a typical TPA claims error rate?

Industry studies put it between 2% and 10% of paid claims, depending on plan complexity and how the review is conducted.

Can a broker offer fiduciary intelligence as a paid service?

Yes. Leading agencies now scope it as a standalone PEPM service rather than bundling it free into renewal work.

Does fiduciary intelligence apply to group captives too?

Yes. Claims oversight data feeds directly into loss experience, which affects captive renewal terms and member pricing.

What triggers a DOL/EBSA investigation into a self-funded plan?

Repeated participant complaints about the same plan or service provider are a common trigger, along with informal inquiry patterns.

What's the difference between a TPA self-audit and an independent claims audit?

A TPA self-audit measures against its own internal rules. An independent audit measures against the actual plan document and contract terms.

Fiduciary Intelligence

How to Make Fiduciary Oversight a Core Service

Abhishek Ghosh
August 24, 2026

Fiduciary oversight becomes a core service, not an add-on, when brokers provide it as an ongoing service with clear deliverables, such as regular claims reviews, documented TPA performance checks and reports prepared for fiduciary committees. This turns a responsibility plan sponsors already have under ERISA Section 404 into a defined, recurring and billable service.

A mid-size manufacturer with 340 covered employees discovered that its TPA had been using the wrong payment rate for out-of-network claims for 18 months. The error was found only after a new CFO ordered an independent claims audit before renewal. The audit helped the plan recover nearly $210,000. The broker had never provided ongoing oversight beyond mentioning it in the annual stewardship presentation.

This happens every year across the self-funded health plan market. It shows why fiduciary oversight is often treated as a free courtesy instead of a separate service that can provide real financial value.

Willis Towers Watson research shows that administrator errors typically affect 1% to 3% of total claims, while financial accuracy errors can be around 1% of paid claims, even when administrators meet industry standards.

For a plan spending $20 million a year, even a 1% error rate could mean $200,000 in potential overpayments or errors that go unnoticed.

Key Takeaways
Fiduciary oversight is a legal duty: ERISA Section 404 makes fiduciary oversight a legal responsibility, not a courtesy line item. Treating it as optional can leave plan sponsors exposed while undervaluing the work brokers perform.
Enforcement is intensifying: DOL/EBSA recovered more than $1.4 billion for benefit plans in FY 2025 across 878 closed civil investigations, signaling continued enforcement attention on health and welfare plans.
Claims errors create real exposure: Administrator error rates commonly range from 1% to 3% of total claims, while independent reviews can identify higher error rates when the full claims population is examined instead of a sample.
Make oversight a defined service: Treat fiduciary oversight as a core offering with clear deliverables, a defined review cadence and separate pricing rather than bundling it into annual renewal work.
Documentation is part of the value: Plan sponsors that treat oversight as an ongoing service can build the documented record needed to demonstrate the prudent expert standard under ERISA Section 404.
Bottom line: Fiduciary oversight should be structured, documented and priced as a core service. It protects the plan sponsor while giving brokers a clear way to demonstrate and monetize the value of ongoing oversight.

What "Positioning Fiduciary Oversight as a Core Service" Actually Means

Positioning fiduciary oversight as a core service means clearly defining it, explaining what it includes and charging for it separately instead of burying it in a renewal presentation. Most brokers already do parts of this work: they review claims trends, flag stop-loss issues or mention TPA performance guarantees. But these actions alone do not create documented, ongoing oversight or give the plan sponsor evidence of a prudent process if the DOL asks for it.

The common assumption is that TPAs handle accuracy internally and that a broker's job ends at plan design and carrier negotiation. The reality is that ERISA places the fiduciary burden on the plan sponsor, not the administrator, for every dollar the plan pays out. A TPA's self-reported accuracy rate is not oversight. It is the vendor grading its own homework.

Why Fiduciary Oversight Keeps Getting Treated as an Add-On

The root cause is structural, not a lack of awareness. Broker compensation has historically been tied to placement and renewal, so revenue flows from the sale, not from ongoing monitoring, and monitoring gets deprioritized by default.

A second root cause is capability. Genuine claims oversight requires access to raw claims data, analytics tools and clinical or coding expertise that a generalist broker team was never built around, so the work gets waved off as "the TPA's job" rather than built out as a service.

A third factor is inertia inside plan sponsor organizations. HR and finance leaders assume that because a TPA is contractually obligated to pay claims correctly, someone is already checking that they do. Baker Tilly notes it is common for organizations to perform a claim audit only once every three years, which leaves long windows where nothing is being verified at all.

The Real Cost of Leaving Oversight Unpriced

Unreviewed claims dollars do not disappear. They compound, and the compounding is the real cost most plan sponsors never see on a single line item.

An independent claims analytics firm's client data across a large self-funded book found 5% to 15% error detection rates once claims were fully reviewed, with average findings landing between $500 and $1,200 per employee per year.

A peer-reviewed study found that sample-based claims audits can miss significant errors. In two Fortune 100 companies, random sampling failed to detect errors worth $200,000 to $750,000 because only a portion of claims were reviewed. The takeaway is simple: a small sample can leave significant dollars undetected.

What's Actually Happening Behind the Scenes

TPA Sampling Covers a Sliver of the Plan

Standard TPA-conducted audits typically review a stratified sample of a few hundred claims out of tens of thousands processed annually, then extrapolate an accuracy score from that sample. The extrapolation looks clean on a stewardship slide, but it was never designed to catch every category of error, only the categories most likely to show up in a small, structured sample.

Financial Accuracy Is Not the Same as Payment Accuracy

A plan can hit its financial accuracy target, meaning the dollar amount paid was close to correct, while still failing payment accuracy, meaning the claim was processed against the wrong plan rule, provider contract or coordination of benefits determination entirely. Baker Tilly's audit example showed exactly this split, with financial and payment accuracy landing at different rates against the same set of claims.

Broker Compensation Structures Rarely Reward Vigilance

The CAA 2021 rules require brokers and consultants to disclose how they are compensated, giving plan sponsors more visibility into broker fees. But compensation tied to placing or renewing coverage does not necessarily reflect the time spent on ongoing claims and TPA oversight. This gives brokers an opportunity to clearly define fiduciary oversight as a separate service and charge for the work they perform.

Why Current Approaches Aren't Enough

Most plans default to whatever oversight the TPA offers as part of the base contract, and that default carries structural conflicts that a standalone, independently priced oversight engagement does not.

Dimension Status Quo (TPA Self-Audit, Bundled) Fiduciary Oversight as a Core Service
Who Performs the Review The TPA reviews its own claims processing An independent party reviews the TPA's work
Claims Reviewed A stratified sample, often a few hundred claims Full-population or near-full review using automated tools
Reporting Cadence Annual or once every few years Quarterly or ongoing, matched to committee meetings
Documentation Produced Summary accuracy percentage Committee-ready findings tied to specific plan provisions
Conflict of Interest The reviewer and the reviewed are the same entity Independent of the TPA relationship
Pricing Model Bundled into administrative fees Priced and scoped as its own line item
Fiduciary Protection Limited documented process to point to Builds the paper trail ERISA Section 404 expects

How to Fix It: A Framework for Positioning Oversight as a Core Service

1
Name the Service Explicitly
Give it a defined title in every proposal and renewal deck, such as "Fiduciary Oversight Program," rather than folding it into "stewardship" or "renewal support."
2
Scope Concrete Deliverables
Specify claims sampling frequency, TPA performance benchmarking against the service level agreement and a documented findings report that the committee actually receives.
3
Set an Independent Cadence
Schedule quarterly reviews tied to plan committee meetings. This creates a recurring touchpoint that demonstrates value and generates the documentation regulators look for.
4
Price It Apart From Placement
Use a retainer or per-employee-per-month fee separate from commission or renewal compensation. This reduces conflicts of interest and makes the cost and value of the work clear.
5
Use CAA Disclosure as an Opening
Since brokers must already disclose compensation over $1,000 under the CAA 2021 rule, use that conversation to introduce fiduciary oversight as a distinct and transparently priced service.
6
Document Everything in Writing
Maintain committee minutes, findings memos and corrective action logs. These records form the evidence supporting a prudent expert standard defense and only exist when someone produces them on a defined schedule.
7
Report Findings in Dollars, Not Just Percentages
An error rate means little to a CFO. Show the recovered or avoided dollar amount and tie it to a specific claims category. That is what demonstrates the financial value of the service.

Red Flags That Signal Your Plan Needs This Now

Our last claims audit was performed by the same TPA whose claims were being audited.
Nobody on your benefits committee can name the date of the last independent claims review.
Your broker's stewardship report shows trend and renewal numbers but no claims accuracy findings.
Your plan has never seen a full-population claims review, only sample-based audits.
You cannot produce a written record showing how your organization selected and monitored its TPA.
Your stop-loss carrier has flagged high-dollar claims that were never independently verified before payment.
Nobody has confirmed that your broker's CAA 2021 compensation disclosure was received and reviewed.

The ROI of Doing It Right

Independent claims reviews can uncover far more money than they cost. ClaimInformatics client data shows 5% to 15% error detection rates in full-population reviews, with average findings of $500 to $1,200 per employee per year.  For a 500-employee plan, even the low end could mean $250,000 in findings that a sample-based audit might have missed.

The value goes beyond recovering money. A documented, ongoing oversight process gives plan sponsors evidence that they are actively monitoring their plan if the DOL asks questions. EBSA's FY 2025 enforcement activity shows why this matters. The agency closed 878 civil investigations, with 556 resulting in repayments or corrective action, and recovered more than $1.4 billion for benefit plans overall.

Making fiduciary oversight a defined, paid service helps brokers deliver measurable value while giving plan sponsors a stronger record of prudent oversight.

Conclusion and Next Steps

Fiduciary oversight was never meant to be a courtesy add-on to a broker renewal. It is a standing legal obligation under ERISA Section 404, and the plans that treat it as core, priced and documented are the ones building a real defense against both financial leakage and regulatory exposure. Positioning it that way is also the clearest path for brokers and consultants to build a recurring, defensible revenue line instead of competing on placement alone.

Start with one step: pull your plan's last claims audit and ask who performed it, what percentage of claims it actually reviewed and what happened to the findings. If you cannot answer all three, fiduciary oversight is still an add-on in your organization, not a core service. [internal link: TPA performance guarantees guide] can help you evaluate whether your current administrator's contract even supports the level of oversight your plan needs.

Frequently Asked Questions

What does "fiduciary oversight as a core service" mean?

It means naming, scoping and pricing claims and TPA oversight as its own engagement rather than bundling it free into a broker or consulting contract.

Is fiduciary oversight legally required under ERISA?

Yes. ERISA Section 404 requires plan fiduciaries to act as a prudent expert would in monitoring how plan assets, including claims payments, are handled.

How is fiduciary oversight different from a standard TPA claims audit?

A TPA audit reviews the TPA's own work using a small claims sample. Independent oversight reviews the TPA using outside tools and a much larger claims population.

How often should a self-funded plan review its TPA's claims accuracy?

Quarterly reviews aligned to benefits committee meetings build a stronger, more defensible record than the once-every-few-years cadence many plans currently use.

What is a typical TPA claims error rate?

Industry sources place standard error rates around 1% to 3% of total claims, with some independent full-population reviews finding 5% to 15% error detection rates.

Can brokers charge separately for fiduciary oversight services?

Yes, and the CAA 2021 compensation disclosure rule makes that separate pricing more transparent, not less viable, since compensation must already be disclosed.

What documentation proves a plan sponsor met its fiduciary duty?

Committee meeting minutes, written TPA performance reviews, claims audit findings and corrective action logs together form the paper trail regulators expect to see.

What happens if a self-funded plan skips independent oversight entirely?

The plan sponsor carries undocumented fiduciary exposure, and EBSA's FY 2025 enforcement data shows regulators are actively pursuing exactly these gaps in health and welfare plans.

Fiduciary Intelligence

Why Brokers Are Becoming Fiduciary Advisors

Abhishek Ghosh
August 20, 2026

A fiduciary intelligence advisor is a broker who goes beyond annual renewal negotiation to monitor TPA claims accuracy, flag ERISA compliance gaps, and help plan sponsors document prudent oversight. The shift responds to rising DOL enforcement of health plans and growing recognition that a good renewal doesn't satisfy a sponsor's fiduciary duty.

In 2024, a 1,400-employee manufacturer switched TPAs after eighteen months of unremarkable renewal cycles. Its broker had negotiated a competitive rate every year without incident. Nobody had checked whether the claims underneath that rate were being paid correctly.

An independent audit, run separately from the broker relationship, found $812,000 in overpayments across eighteen months, including a $47,000 inpatient claim paid twice and 63 ineligible dependents still active on the plan.

Key Takeaways
Renewal negotiation controls price: Negotiating your renewal may reduce the cost of coverage or administration, but it does not verify that claims are being paid correctly under the negotiated terms.
Independent audits uncover payment errors: Independent audits routinely find TPA error rates between 1% and 10% of claims dollars, even when TPAs self-report accuracy above 96%.
Regulatory scrutiny is increasing: EBSA recovered $1.4 billion for benefit plans in fiscal year 2025 and has shifted FY 2026 enforcement priorities toward health and welfare plans.
Claims oversight is becoming a standing service: A growing share of brokers now offer claims oversight, dependent eligibility audits and fiduciary documentation support as ongoing services rather than renewal-only add-ons.
The fiduciary responsibility remains with the plan sponsor: Under ERISA, plan sponsors, not brokers or TPAs, carry fiduciary liability for claims accuracy.
Bottom line: A negotiated renewal is not the same thing as verified claims oversight. Plan sponsors need independent review and documented monitoring to know whether the plan is actually paying what it should.

What "Fiduciary Intelligence Advisor" Actually Means

A broker's traditional renewal cycle was never designed to catch claims payment errors. Most employers assume that once a broker negotiates favorable rates and a strong network, the plan is being watched. In reality, renewal work happens once a year and focuses on price, plan design, and carrier or TPA selection.

Claims payment accuracy is a separate discipline entirely. It requires reviewing how individual claims were adjudicated against plan documents, contracted rates, and coordination of benefits rules, month after month, not once a year.

A fiduciary intelligence advisor is a broker who has added that discipline to the relationship. They monitor claims data on a recurring basis, flag patterns that suggest overpayment or compliance risk, and help the plan sponsor build the documentation record ERISA Section 404 requires of a prudent fiduciary.

Why the Renewal-Only Model Persists

Broker compensation has historically been tied to placement and renewal, not ongoing claims monitoring. Commission structures reward closing a deal, and claims oversight work sits outside that transaction entirely.

The Consolidated Appropriations Act of 2021 requires brokers and consultants who receive $1,000 or more from a group health plan to disclose their direct and indirect compensation in writing to the plan fiduciary. This makes potential conflicts more visible and is pushing some brokers to provide broader fiduciary support.

Historically, few brokers had claims-level expertise on staff. Reviewing adjudication logic, contracted rate tables, and coordination of benefits data requires a different skill set than plan design or carrier negotiation, and many brokerages simply never built it.

That capability gap, more than a lack of will, has kept most broker relationships confined to the renewal calendar.

The Real Cost of Watching Only at Renewal

Claims errors are not rare edge cases. Across one national analytics platform's client base, claims analysis identified error detection rates of 5% to 15%, with average findings of $500 to $1,200 per employee per year. On a 1,000-employee plan, that range alone represents hundreds of thousands of dollars in annual leakage.

Industry-standard estimates put administrator error rates at 1% to 3% of total claims processed, and other audit firms report a wider band of 2% to 6%. The manufacturer's $812,000 finding sits comfortably inside that range once you apply it to real claims volume.

The regulatory cost is rising alongside the financial one. EBSA recovered more than $1.4 billion for retirement, health and welfare plans in fiscal year 2025, and announced a shift of FY 2026 enforcement resources toward health and welfare plans, service providers, and plan sponsors after decades of retirement-plan focus.

What's Actually Happening Behind the Scenes

Compensation structures limit scope

A broker paid on commission has little financial incentive to add unpaid claims oversight work. Fee-based and hybrid arrangements are changing that calculus, but the shift is uneven across the industry.

TPA reporting is not independent verification

A TPA's internal quality assurance measures its own process against its own standards. It is not the same as an outside party checking claims against the plan document and the contracted rates.

Annual cycles miss continuous risk

Claims errors accumulate every pay period, not once a year. A broker who reviews the plan only at renewal is, by definition, looking backward at a year of unmonitored payment activity.

Dependent eligibility rarely gets its own review

Ineligible dependents, ex-spouses, adult children who aged out, individuals added without documentation, tend to stay on a plan for years once enrolled. Most renewal reviews never ask the eligibility question at all, because it falls outside price negotiation entirely.

Why Renewal-Only Advisory Isn't Enough

Dimension Renewals-Only Broker Fiduciary Intelligence Advisor
Primary Focus Price and plan design at renewal Claims accuracy, compliance and documentation year-round
Review Frequency Annual Ongoing, typically monthly or quarterly
Claims Data Source TPA self-reported summaries Independent claims-level review
Dependent Eligibility Rarely addressed Standing audit workstream
Documentation for DOL/EBSA Minimal Structured record of prudent process
Compensation Model Commission tied to placement Fee or hybrid tied to oversight value

How Plan Sponsors Can Move Toward Fiduciary Intelligence

1
Ask What Your Broker Actually Provides
Ask your broker directly whether they provide independent claims oversight or focus only on carrier and TPA placement.
2
Add Audit Rights to Your TPA or ASO Agreement
Require the agreement to allow any qualified independent firm to review claims at any time, without restrictive audit limitations.
3
Request Quarterly Claims Accuracy Reporting
Request claims accuracy reporting every quarter rather than relying only on the annual summary provided during renewal.
4
Make Dependent Eligibility a Recurring Audit
Treat dependent eligibility verification as its own recurring audit workstream, separate from the medical claims review.
5
Document Every Review
Record every broker and committee review in meeting minutes to create a clear, defensible record of the plan's oversight process.

Red Flags That Your Plan Is Still Renewal-Only

Red Flags That Signal Your Plan Is Exposed
Your broker only engages substantively once a year, around renewal.
Your TPA agreement has no audit clause, or restricts who can perform an audit.
Claims accuracy reporting comes exclusively from the TPA, with no outside verification.
No committee minutes or documentation exist showing how claims oversight decisions were made.
You've never received a written CAA compensation disclosure from your broker.

he ROI of Fiduciary Intelligence

A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend in its first year, often covering the cost of the audit itself. For a plan spending $20 million annually on claims, that range translates to $200,000 to $600,000 in first-year recoveries alone.

The less visible return is fiduciary protection. A documented, ongoing oversight process is the evidence a plan sponsor needs if EBSA opens an inquiry, and it is the same evidence that has shielded 401(k) plan fiduciaries from personal liability in excessive-fee litigation.

Ongoing monitoring also compounds. Catching a coding error or an ineligible dependent in month three, rather than at next year's renewal, stops that leakage before it repeats twelve more times. There's a talent retention angle too. A benefits committee that can point to a documented, ongoing oversight process has a stronger answer for skeptical CFOs asking why healthcare spend keeps climbing, and a stronger defense if a participant or regulator ever asks the same question in less friendly terms.

Conclusion and Next Steps

A strong renewal has never been proof that a self-funded plan is being watched. The plans avoiding six and seven-figure claims leakage are the ones whose brokers have expanded into ongoing fiduciary intelligence: independent claims review, dependent audits, and documented oversight, not just annual price negotiation.

Ask your broker where their scope actually ends. If claims accuracy monitoring, compliance documentation, and audit rights aren't part of the relationship, that gap belongs to your plan, not theirs.

Frequently Asked Questions

Is my broker legally a fiduciary?

Usually not automatically. Brokers generally aren't ERISA fiduciaries unless they exercise discretionary control, though CAA disclosure rules now increase transparency into their role.

Who holds fiduciary liability for claims accuracy?

The plan sponsor, typically through its benefits committee or board, regardless of whether claims administration is delegated to a TPA.

How often should claims be reviewed?

Ongoing monthly or quarterly review catches errors faster than annual audits and creates a stronger documentation trail for regulators.

What's the difference between a claims audit and TPA quality assurance?

A claims audit is performed by an independent party against plan documents and contracts. TPA quality assurance is internal and self-reported.

Does adding claims oversight cost more than it recovers?

Typically not. First-year recoveries of 1% to 3% of claims spend usually exceed the cost of an independent audit.

What does CAA 2021 require of brokers?

Brokers earning $1,000 or more must disclose direct and indirect compensation to the plan fiduciary in writing before the contract is finalized.

Can a broker perform the claims audit themselves?

Some can, but plan sponsors should confirm the reviewer has healthcare claims expertise and no ownership ties to the TPA being reviewed.

How does this connect to 401(k) fiduciary litigation?

Courts and regulators increasingly expect health plan fiduciaries to document prudent process, the same standard already tested in retirement plan excessive-fee cases.

Fiduciary Intelligence

How to Document Fiduciary Prudence and Protect Your Plan

Abhishek Ghosh
August 18, 2026

A fiduciary paper trail is simply a record of how a benefits committee makes and reviews decisions about a self-funded health plan. It can include meeting notes, vendor reviews, and claims audit results. Under ERISA, this documentation helps show that the committee took a careful, reasonable approach to its decisions, even if one of those decisions later turned out to be wrong.

In fiscal year 2025, the Department of Labor’s Employee Benefits Security Administration recovered more than $1.4 billion for retirement, health and welfare plans. More than half came from enforcement actions, not voluntary corrections. Plaintiff firms filed 155 ERISA fiduciary class actions in 2025, including 39 involving health plans.

That is a major shift from the retirement-plan lawsuits that dominated a decade ago. Most benefits committees can explain what their plan did. Far fewer can show why they made those decisions, and that gap is often where investigators and plaintiffs’ attorneys start.

Key Takeaways
Process matters: ERISA judges fiduciaries on the process they follow, not just the outcome. A documented, repeatable review process is the primary legal defense against a breach claim.
Enforcement has real consequences: EBSA closed 878 civil investigations in FY 2025, with 63% resulting in monetary or corrective action against the plan.
Health plan litigation is increasing: ERISA litigation involving health plans is following the fee-scrutiny pattern that produced more than 600 excessive-fee lawsuits against 401(k) plans over the past decade.
Independent review finds hidden errors: Independent claims audits routinely identify 1% to 10% of claims dollars paid in error, compared with the 96% to 98% accuracy typically self-reported by TPAs.
Documentation can pay for itself: A defensible fiduciary paper trail costs a fraction of a single litigation defense and can also generate value through claims recoveries.
Bottom line: The strongest protection is not simply having good claims results. It is being able to prove that your plan followed a consistent, documented and prudent oversight process.

What a Fiduciary Paper Trail Actually Is

A fiduciary paper trail is the documented evidence that a benefits committee followed a prudent, repeatable process when making decisions about the plan. Most plan sponsors assume that if the plan works reasonably well and the TPA has a good reputation, the fiduciary duty is satisfied. That assumption is wrong under ERISA Section 404, which requires fiduciaries to act with the care, skill and diligence of a prudent expert, not merely to reach an acceptable result.

Courts and the DOL do not ask whether a claim got paid correctly in hindsight. They ask whether the committee had a process for finding out, and whether that process left a record. A plan that overpaid on a handful of claims but can show quarterly TPA reviews, documented vendor comparisons and audit engagement letters is in a fundamentally different legal position than a plan with the same errors and no record at all.

The key difference is between substantive and procedural prudence. Substantive prudence asks whether the decision was reasonable. Procedural prudence asks whether the committee used a careful, reasonable process to make it. Under ERISA, that process matters, which is why documentation, not perfection, is a committee’s strongest fiduciary protection.

Why Most Plans Have a Documentation Gap

The gap exists because benefits committees are staffed by HR and finance professionals whose core job is running the business, not building a compliance record. Claims administration gets outsourced to a TPA, and plan sponsors quietly extend that outsourcing to include oversight itself, even though ERISA does not allow fiduciary responsibility to be delegated away.

TPAs can make things look better than they really are by reporting their own performance numbers. They often report payment and financial accuracy rates above 96%, which may meet their contract requirements. But independent audits of the same claims can find very different results.

The problem is that a benefits committee cannot rely only on a TPA’s own scorecard to prove it provided proper oversight. Reviewing the vendor’s numbers shows that the committee checked the report. It does not necessarily show that the committee independently tested whether those numbers were accurate.

Turnover makes this problem worse. Committee members leave, brokers change, and people forget why certain plan decisions were made years ago. Without clear meeting notes and supporting documents, a plan sponsor facing a DOL investigation or lawsuit may have to piece together what happened from memory instead of showing a clear record.

The Real Cost of an Undocumented Process

When a fiduciary process is not documented, a simple vendor mistake can become a much bigger legal problem. Under ERISA, fiduciaries who fail to meet their duties may have to repay losses suffered by the plan. This liability can apply to the individual committee members involved, not just the employer.

The scale of enforcement shows why this matters. In FY 2025, EBSA’s civil investigations recovered $714.4 million. The agency also closed 253 criminal investigations, leading to 62 indictments and 45 convictions involving the way plan assets were handled and controlled.

Health plan lawsuits are now following a similar path to the 600+ excessive-fee lawsuits filed against 401(k) plans over the past decade. Plaintiff firms are increasingly using the same arguments about excessive fees and poor oversight against health and welfare plans, especially as the Consolidated Appropriations Act, 2021 increased disclosure requirements.

What's Actually Happening Behind the Scenes

Committees That Meet Without Minutes

Many benefits committees hold regular meetings but treat them as informal check-ins rather than fiduciary proceedings. Decisions about plan design, stop-loss renewal or TPA retention get discussed and agreed upon verbally, with no minutes capturing what alternatives were considered or why the chosen option was selected.

Vendor Oversight That Stops at the Contract

Signing a services agreement with a TPA is treated as the end of the oversight process instead of the beginning. ERISA places fiduciary responsibility for claims accuracy on the plan sponsor regardless of delegation, yet many committees have no calendar for reviewing TPA performance against that contract after signature.

Audit Activity That Is Self-Reported, Not Independent

A claims audit conducted by the TPA on its own claims is not independent evidence of prudent oversight. Objectivity is inherently limited when the party being reviewed also produces the review, and reviews conducted this way are typically performed only once every three years, if at all.

Dependent Eligibility and Data Hygiene Left Unchecked

Ineligible dependents remaining on a plan after a divorce, a dependent aging out or a change in employment status is one of the most common and most avoidable sources of claims leakage, yet dependent eligibility is rarely treated as its own documented review workstream separate from broader claims auditing.

Why Current Approaches Aren't Enough

Status Quo Practice Fiduciary-Grade Approach
Annual or informal committee check-ins Scheduled quarterly meetings with a standing agenda and retained written minutes
TPA self-reported accuracy accepted at face value Independent, contingency-fee claims audit performed by a firm with no TPA ownership ties
Vendor contract filed away after signature Documented quarterly TPA performance review against SLA benchmarks
Claims reviewed only after a complaint or renewal Continuous or quarterly sampling across 100% of claim categories
Dependent eligibility assumed accurate Dedicated annual dependent eligibility audit with documented findings
Fiduciary training treated as optional Documented annual fiduciary training for every committee member, recorded in minutes

How to Fix It

1
Adopt a Written Committee Charter
Define who serves as a fiduciary, what decisions require committee approval and how often the committee meets. A charter turns informal habit into a documented governance structure.
2
Put Meeting Minutes on a Fixed Template
Record attendance, agenda items, alternatives discussed, the rationale for each decision and any dissenting views. Store minutes in a retained, searchable archive rather than a shared inbox.
3
Schedule TPA Oversight on a Calendar
Conduct quarterly reviews against SLA benchmarks and maintain a written summary of findings. A scheduled process demonstrates active oversight rather than passive trust.
4
Engage an Independent Claims Auditor
Choose a firm with healthcare claims expertise and no ownership ties to the TPA. Confirm your ASO agreement allows any qualified firm to audit any claim at any time.
5
Treat Dependent Eligibility as Its Own Audit Line
Review dependent eligibility as a separate audit workstream. These reviews are typically inexpensive relative to the savings they can identify and often pay for themselves within months.
6
Document Fiduciary Training Annually
Conduct an annual session covering ERISA Section 404 duties and retain an attendance sheet. This creates evidence that committee members understood their fiduciary obligations.
7
Set a Record Retention Schedule
Establish and follow a defined retention schedule for committee minutes, audit reports, vendor contracts and correspondence that exceeds the applicable statute of limitations for fiduciary breach claims.
8
Close the Loop on Every Finding
Document the corrective action for every finding and track it through completion. Record the remediation steps and the date each issue was closed.

Think of fiduciary documentation like a flight data recorder. Nobody expects a plan year to run without any turbulence, and regulators do not expect one either. What they want to know after something goes wrong is whether the committee followed procedure the whole way through.

The paper trail does not prove the plan never made a mistake. It proves the committee was flying the plane on purpose.

Red Flags That Signal Your Plan Is Exposed

Committee meetings happen, but no one takes or retains formal minutes.
The plan has never had an independent claims audit performed by a firm unaffiliated with the TPA.
TPA performance is measured only through the vendor's self-reported scorecard.
No one on the committee can produce documentation explaining why the current TPA or stop-loss carrier was selected.
Dependent eligibility has not been independently audited in more than two years.
The ASO agreement restricts who can audit claims or how often an audit can be performed.
New committee members receive no fiduciary training or formal orientation.
Audit findings exist in email threads but were never formally logged, assigned for remediation or closed out.

The ROI of Doing It Right

A defensible fiduciary process pays for itself twice, once in claims recoveries and once in avoided liability. A comprehensive independent claims audit typically recovers between 1% and 3% of annual claims spend in its first year, an amount that regularly exceeds the full cost of the audit engagement itself. On a $15 million claims book, that range translates to $150,000 to $450,000 in first-year recoveries alone.

The liability side of the equation is harder to quantify but larger in scale. EBSA's FY 2025 enforcement activity alone moved $1.4 billion, and individual ERISA breach settlements in the 401(k) space have run into the tens of millions of dollars per case over the past decade. A documented process is inexpensive insurance against exposure of that magnitude, and unlike claims recoveries, its value is realized only when it is needed most.

Good documentation can also make a DOL investigation faster and less expensive. If a plan has its records organized and ready, investigators can quickly see what happened and why. Without those records, the plan may have to spend extra time searching for documents and piecing together what happened, which can lead to more questions and requests.

Conclusion and Next Steps

Fiduciary prudence is not measured by whether a self-funded plan avoided every error. It is measured by whether the committee overseeing that plan can produce a record showing it looked, asked the right questions and acted on what it found. That record, built consistently over time, is what separates an ordinary vendor mistake from a documented fiduciary breach.

Start with what is fastest to fix. Put a committee charter and minutes template in place this quarter [internal link: benefits committee charter template], schedule your next TPA performance review [internal link: TPA performance guarantees guide], and confirm your ASO agreement actually allows independent claims auditing [internal link: independent claims oversight guide]. If it has been more than a year since your plan's last independent claims audit, that is the single highest-leverage next step available.

Frequently Asked Questions

What does ERISA Section 404 actually require of a plan fiduciary?

It requires fiduciaries to act with the care, skill and diligence of a prudent expert, solely in the interest of participants.

Is a self-funded plan sponsor personally liable for TPA errors?

Yes. Fiduciary responsibility for claims accuracy stays with the plan sponsor even when claims processing is delegated to a TPA.

How often should a benefits committee meet to stay fiduciary-compliant?

Quarterly meetings with retained minutes are the common baseline used by fiduciary-grade committees.

Can a TPA's self-reported audit satisfy fiduciary oversight requirements?

No. Independent review is needed because a TPA auditing its own claims lacks the objectivity courts and regulators expect.

How long should fiduciary committee records be retained?

Retain minutes, audit reports and vendor contracts beyond ERISA's statute of limitations for breach claims, typically six years or longer.

What triggers a DOL investigation of a self-funded health plan?

Common triggers include participant complaints, Form 5500 irregularities, and EBSA's targeted enforcement priorities for a given year.

Does a documented process protect against every fiduciary breach claim?

No single record eliminates risk, but a consistent, documented process is the strongest evidence of prudence available in litigation or investigation.

What is the difference between substantive and procedural prudence?

Substantive prudence judges the decision itself; procedural prudence judges the process used to reach it, and ERISA case law favors the latter.

Fiduciary Intelligence

Every Healthcare Dollar Should Be Reviewed and Justified

Abhishek Ghosh
August 17, 2026

A self-funded health plan claims audit is an independent review of paid medical claims that verifies payment accuracy, confirms contract compliance and recovers overpayments. ERISA Section 404 places this oversight duty on the plan sponsor, not the TPA. Most plans review fewer than 5% of claims, leaving the rest unchecked.

A 1,400-employee manufacturer ran its first independent claims audit eighteen months into a new TPA relationship. The review found more than $800,000 in overpayments, including one inpatient claim paid twice and a specialty drug billed well above the contracted rate. None of it had appeared in the TPA's own accuracy reporting.

That gap is not unusual. Industry benchmarks put administrator error rates at 1% to 3% of total claims processed, and most self-funded plans independently review only a small slice of what gets paid. Sixty-seven percent of covered workers, including 80% at large employers, are now enrolled in self-funded plans according to KFF's 2025 Employer Health Benefits Survey, which means the unreviewed portion represents real money moving through systems almost nobody independently checks.

Key Takeaways
Most claims remain unreviewed: Most self-funded plans review fewer than 5% of paid claims and rely heavily on TPA-reported accuracy figures.
Errors create measurable financial exposure: Industry-documented claims error rates start around 1% to 3%, with some independent reviews identifying higher rates.
The fiduciary duty stays with the plan sponsor: ERISA Section 404 places responsibility for prudent claims oversight and accuracy on the plan sponsor, even when claims processing is outsourced to a TPA.
Independent audits can recover significant costs: A full independent claims audit typically recovers 1% to 3% of annual claims spend in its first year, based on the benchmarks provided.
Regulatory scrutiny is increasing: The DOL's EBSA recovered $1.4 billion in FY 2025 and has identified health plan oversight as a 2026 enforcement priority.
Bottom line: Relying on TPA reporting alone leaves a significant oversight gap. Independent claims review, ongoing monitoring and documented fiduciary processes give plan sponsors a stronger way to identify leakage and demonstrate prudent oversight.

What a Claims Audit Actually Verifies

A claims audit is an independent, line-by-line review of paid medical claims against plan documents, contracted rates and coding rules. Most employers assume this already happens because their TPA reports a high accuracy score every quarter. That figure is usually self-reported and calculated against the TPA's own sample, not an outside standard.

The reality looks different once someone outside the TPA checks the work. Most self-funded employer health plans review fewer than 5% of claims, typically through a stratified sample the TPA selects and grades itself. Grading your own homework produces a different number than an outside reviewer checking the same file.

An audit is not an accusation. It is closer to a financial reconciliation: matching what the plan document promises, what the contract with the provider specifies and what actually got paid.

Audit frequency compounds the problem. It is common for employers to run a full claims audit or provider billing review only once every three years, according to Baker Tilly's analysis of self-funded plan billing reviews. Between those audits, errors accumulate quietly and rarely show up in a quarterly dashboard.

Why the Oversight Gap Exists

The gap exists because TPAs are not the ones bearing financial risk when a claim gets paid wrong. The plan sponsor pays the claim either way, so the administrator has limited financial incentive to catch every error before it goes out the door. That is a structural fact of the outsourcing arrangement, not a statement about any single TPA's intent.

Audit frequency compounds the problem. It is common for employers to run a full claims audit or provider billing review only once every three years, according to Baker Tilly's analysis of self-funded plan billing reviews. Between those audits, errors accumulate quietly and rarely show up in a quarterly dashboard.

Contract language plays a role too. Some administrative services agreements historically limited how many claims a sponsor could audit, who could perform the audit or what data the auditor could access, which narrowed what oversight was even possible.

The Real Cost of an Unreviewed Plan

Unreviewed claims translate directly into dollars the plan never should have paid. Industry benchmarks estimate payment errors typically affect 1% to 3% of total claims dollars, and some comprehensive independent audits identify a wider range depending on plan complexity and TPA type. On a plan paying $20 million a year in claims, even the low end of that range is $200,000 sitting unrecovered.

Think of it like a bank account that is never properly checked. A small error might not seem like much on one transaction, but when thousands of transactions have small errors, the total can become huge.

That is what happens with many healthcare audit findings. It is usually not one big fraud. It is thousands of small errors that nobody was checking for.

The average family health insurance premium is now $26,993. Employers and employees share this cost. When an audit finds and recovers money that was paid incorrectly, that money can help reduce future healthcare costs instead of forcing employers to raise premiums or cut benefits.

What's Actually Happening Behind the Scenes

Coding and Billing Errors

Upcoding, unbundling and duplicate billing are the most common findings in independent audits. A procedure billed at a higher-complexity code than performed, or a bundled service billed as separate line items, both inflate the paid amount without an obvious red flag in a summary report.

Coordination of Benefits Gaps

When a member has coverage under more than one plan, claims should be split according to coordination of benefits rules. Gaps here mean the self-funded plan sometimes pays a share that another payer should have covered.

Why Current Approaches Aren't Enough

Relying solely on the TPA's own reporting leaves the plan sponsor with an incomplete picture, because the reviewer and the reviewed party are the same entity. The table below lays out the practical difference between the status quo and an independent oversight model.

Dimension TPA Self-Reported Review Independent Claims Audit
Sample Size Stratified sample, often 250 to 400 claims Can extend to 100% of claims with modern tools
Reviewer Independence Same entity that processed the claims Third party with no processing role
Accuracy Standard Self-defined and self-graded Measured against plan documents and contract terms
Typical Findings Near 100% accuracy self-reported Error rates and overpayments the TPA report did not surface
Fiduciary Documentation Limited, since the sponsor did not commission the review Creates a defensible record of prudent process

How to Fix It

1
Commission an Independent Audit Every 12 to 18 Months
Waiting three years lets errors compound and makes recovery harder.
2
Choose an Independent Claims and Coding Firm
Use a firm with claims and coding expertise that has no ownership ties to your TPA. Independence is what makes the finding credible to a regulator or a court.
3
Negotiate Audit Access
Negotiate audit access into your administrative services agreement. Confirm the plan can audit any claim, at any time, with the auditor of its choice.
4
Make Dependent Eligibility a Separate Workstream
Treat dependent eligibility as its own review workstream. These reviews are separate from claims accuracy but often surface fast, low-effort savings.
5
Move From Retrospective to Ongoing Review
Quarterly or monthly checks catch errors before they compound and create an accountability rhythm with the administrator.
6
Document Everything in Committee Minutes
Board minutes and audit reports are the record that demonstrates the plan sponsor followed a prudent process.

Red Flags That Signal Your Plan Needs This Now

Red Flags That Signal Your Plan Needs This Now
You cannot remember the last time anyone outside the TPA reviewed a sample of claims.
Your administrative services agreement restricts audit scope, frequency or auditor choice.
Claims costs have grown faster than enrollment or utilization would explain.
Specialty pharmacy or high-dollar claims are not flagged for a second look before payment.
Your benefits committee has no documented process for reviewing TPA performance.
Nobody on your team can name the plan's current claims payment accuracy from an independent source.

The ROI of Doing It Right

A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend in its first year, often more than covering the cost of the audit itself. On a plan spending $30 million annually, that is a recovery range of $300,000 to $900,000 before counting the value of catching future errors sooner.

The fiduciary protection matters as much as the dollar recovery. DOL/EBSA recovered $1.4 billion in FY 2025 and closed 878 civil investigations, with 63% producing monetary or corrective results, and the agency has signaled health plan oversight is a growing FY 2026 focus. A documented, independent audit process is the evidence a plan sponsor needs if that scrutiny ever reaches their plan.

Litigation risk reinforces the same point. Plaintiff firms that spent two decades pursuing excessive-fee claims against 401(k) plans have expanded into health plan cases, including Lewandowski v. Johnson & Johnson and Navarro v. Wells Fargo, both alleging fiduciaries failed to prudently monitor PBM and administrative costs. An audit trail is the difference between a defensible process and an unmonitored one.

Conclusion and Next Steps

Every dollar a self-funded plan pays out should be able to withstand a question: was this claim reviewed, is the payment justified, and can the plan sponsor defend it if asked. Right now, most plans cannot answer that question for the majority of what they pay, because the only review happening is the one the TPA runs on itself.

The fix does not require replacing your TPA relationship. It requires adding an independent layer of oversight, documenting the process, and treating claims accuracy as a fiduciary obligation rather than an assumption. Schedule a claims audit scoping call to see what an independent review would find on your plan.

Frequently Asked Questions

What is a self-funded health plan claims audit?

An independent review of paid claims that checks payment accuracy against plan terms, contracted rates and coding rules.

Who is legally responsible for claims accuracy under ERISA?

The plan sponsor, under the fiduciary duty in ERISA Section 404, not the TPA that processes the claims.

How often should a self-funded plan be audited?

Every twelve to eighteen months, with ongoing quarterly or monthly spot reviews between full audits.

What percentage of claims does a typical TPA review internally?

A stratified sample, usually 250 to 400 claims, far short of the full claims population.

How much money does an independent audit typically recover?

About 1% to 3% of annual claims spend in the first year, based on industry benchmarks.

Can a TPA restrict how a plan sponsor audits its own claims?

Some contracts historically limited audit scope or auditor choice; sponsors should negotiate these restrictions out.

Does an audit create legal protection for plan fiduciaries?

Yes. Documented, independent review is core evidence of the prudent process ERISA requires.

What is the difference between a claims audit and dependent eligibility review?

A claims audit checks payment accuracy; a dependent eligibility review confirms covered dependents still qualify for the plan.

Fiduciary Intelligence

When Fiduciaries Fail: ERISA Litigation Cases and Key Lessons

Abhishek Ghosh
August 11, 2026

An ERISA fiduciary breach occurs when a plan sponsor fails to act prudently and solely in participants' interest when managing a health plan, such as failing to monitor a PBM's pricing or negotiate reasonable fees. Recent lawsuits against Johnson & Johnson and Wells Fargo show courts scrutinizing these failures closely, even when claims get dismissed on legal technicalities.

In February 2024, a Johnson & Johnson employee filed a 75-page class action alleging the company let its prescription drug benefit program bleed money through an unmonitored pharmacy benefit manager contract.

Five months later, four Wells Fargo plan participants filed a nearly identical suit, claiming the bank squandered its bargaining power and let Express Scripts overcharge the plan.

In 2025, Illinois recovered $45 million from CVS Caremark after alleging the PBM withheld manufacturer rebates it owed the state's employee health plan. These are not isolated incidents. They are the opening chapters of a litigation wave that mirrors the excessive-fee lawsuits that reshaped 401(k) plan governance a decade ago, and self-funded employer health plans are now the target.

Key Takeaways
Dismissal does not mean the conduct was acceptable: Federal courts dismissed the two highest-profile ERISA health plan fiduciary cases, Lewandowski v. Johnson & Johnson and Navarro v. Wells Fargo, on standing grounds rather than ruling that the underlying conduct was proper.
PBM disputes can produce real recoveries: CVS Caremark's $45 million settlement with Illinois demonstrates that disputes involving PBM rebates and fees can result in significant recoveries when the claims are supported by documentation.
Documentation is the recurring weakness: Across these cases, the common issue is the absence of a documented, ongoing process for monitoring PBM pricing, fees and rebate pass-through.
Standing does not eliminate fiduciary duties: Even when plaintiffs cannot establish standing, ERISA Section 404's prudent expert standard still applies to plan fiduciaries.
Independent oversight addresses both risks: Building independent claims oversight and documented PBM monitoring can help plan sponsors reduce litigation exposure while also identifying the underlying pricing, fee and rebate leakage described in these disputes.
The practical takeaway: A court dismissal is not a fiduciary safe harbor. Plan sponsors still need evidence that they actively monitored PBM pricing, fees, rebates and vendor performance through a documented and prudent process.

What ERISA Fiduciary Breach Actually Means for a Health Plan

A fiduciary breach happens when the people responsible for running a health plan fail to act with the care, skill and diligence ERISA requires, regardless of whether a lawsuit ever gets filed. Most HR leaders assume fiduciary duty is a retirement plan concept that only applies to 401(k) committees. That assumption is increasingly wrong.

ERISA Section 404 imposes the same prudent expert standard on anyone who exercises discretion over a group health plan's assets or administration. If your organization signs a PBM contract, approves plan design or reviews claims data even occasionally, you likely function as a fiduciary. The exclusive benefit rule adds a second layer, requiring that plan assets be used only to provide benefits and pay reasonable expenses, not to preserve a convenient vendor relationship.

The common misconception is that hiring a reputable TPA or PBM satisfies the duty. It does not. Delegating administration does not delegate the fiduciary's obligation to monitor that vendor's performance on an ongoing basis.

Why the Problem Exists

Health plan fiduciary duty gets overlooked because most plan sponsors treat benefits as an HR function rather than a financial oversight function. The committee structure, meeting cadence and documentation habits that retirement plan fiduciaries built over 20 years of ERISA litigation simply do not exist yet on the health plan side.

PBM and TPA contracts also compound the problem through complexity. Rebate formulas, spread pricing and administrative fee structures are often opaque by design, and few internal teams have the claims data expertise to audit them without outside help.

Finally, self-funded plans grew faster than fiduciary governance kept pace. KFF's 2025 Employer Health Benefits Survey found 67 percent of covered workers are now in self-funded plans, rising to 80 percent at large firms. Many of those plans still run on the oversight habits of a fully insured plan, where the carrier absorbed the risk and the scrutiny.

The Real Cost or Impact

Prescription drug spending is where fiduciary failures show up fastest. KFF found that 36 percent of large firms say drug prices contributed "a great deal" to premium increases in 2025, and the average family premium reached $26,993 that year.

Litigation creates a second layer of cost on top of the original overpayment. The Johnson & Johnson complaint alone was 75 pages and named individual committee members, not just the company. That should concern HR leaders who assume the company will always fully protect them from personal liability.

The Illinois settlement shows that vendor-related payment problems can involve millions of dollars. If similar problems exist across many self-funded employer plans, the total financial impact could be huge.

What's Actually Happening Behind the Scenes

PBM Contracts Nobody Re-Negotiates

Most self-funded plans sign a PBM contract and revisit it only when it expires. The Wells Fargo complaint alleged the company paid Express Scripts administrative fees that "greatly exceeded" what comparable plans paid, a gap that persisted because nobody benchmarked it mid-contract.

Rebates That Never Reach the Plan

Rebate pass-through language sounds protective on paper but is rarely audited in practice. Illinois only uncovered CVS Caremark's shortfall through a formal state investigation into an affiliated rebate aggregator, not through routine contract review.

Formulary and Mail-Order Steering

Both the J&J and Wells Fargo complaints alleged fiduciaries steered participants toward higher-cost mail-order channels and branded drugs without evaluating whether cheaper, clinically equivalent options existed. That is a design choice a committee approved once and never revisited.

No Independent Claims Data Review

In every one of these cases, the plaintiffs' core allegation is not that fiduciaries acted maliciously. It is that nobody with independent authority was checking the PBM's own numbers against outside benchmarks on a recurring basis.

Why Current Approaches Aren't Enough

Most plan sponsors believe their existing TPA or broker relationship already covers this ground. It usually does not, because the entity administering the plan has limited incentive to flag its own pricing.

Status Quo Approach Fiduciary-Grade Approach
Annual broker renewal review Continuous claims-level monitoring against outside benchmarks
Trust PBM-reported rebate figures Independent audit of rebate pass-through and spread pricing
Committee meets once a year, informally Documented committee meetings with minutes and a monitoring calendar
Vendor selection based on reputation Vendor selection and retention based on documented RFP and performance data
No written monitoring policy Written Investment Policy Statement equivalent for the health plan

How to Fix It

1
Establish a Documented Health Plan Fiduciary Committee
Create a fiduciary committee with defined roles, a regular meeting cadence and written minutes, using the structured governance approach that retirement plan committees have used since the early 2000s.
2
Commission an Independent Claims Audit
Conduct an independent claims audit at least annually using a firm outside your TPA or PBM relationship. Check pricing and rebate claims against external benchmarks rather than relying solely on vendor-reported figures.
3
Strengthen PBM and TPA Contracts
Rebuild contract language to require full rebate pass-through, transparent pricing and meaningful audit rights. Do not stop at negotiating the rights; actually exercise those audit rights to verify vendor performance.
4
Benchmark Administrative Fees
Compare administrative fees against similarly sized plans every 12 to 24 months rather than waiting until the next contract renewal. Document the benchmark results and any resulting vendor decisions.
5
Document Every Fiduciary Decision
Maintain written records explaining why vendors were retained, why plan design decisions were made and how fiduciary choices were evaluated. Internal Link: Claims Audit Checklist for Self-Funded Plans

Red Flags That Signal the Problem Applies to Your Plan

Your health plan committee has never met formally or maintained written meeting minutes.
Nobody outside your PBM has independently verified rebate pass-through within the last two years.
Administrative fees have not been benchmarked since your current contract was signed.
Your plan sponsor has never reviewed a full claims-level data extract and relies only on summary reports from the TPA.
Renewal decisions are based primarily on relationship continuity rather than a documented review of vendor performance.
Nobody on your team could explain, in writing, the process used to select your current PBM.
Reality Check: If several of these red flags apply, your health plan may lack the documented, independent oversight needed to identify PBM leakage, evaluate vendor performance and demonstrate a prudent fiduciary process.

The ROI of Doing It Right

Independent claims audits typically recover a meaningful share of total plan spend in overpayments and billing errors that routine TPA review misses. On a plan spending $20 million annually, even a modest recovery rate represents a substantial six-figure return.

Beyond recovery, documented fiduciary governance is itself protective. Courts in the Lewandowski and Navarro cases dismissed claims on standing grounds partly because plaintiffs could not tie specific harm to specific fiduciary failures. A plan sponsor with clean documentation is in a materially stronger position if that standing bar shifts in future litigation.

The ongoing savings compound. Fee benchmarking and rebate audits performed annually, rather than once at contract signing, tend to catch cost creep before it accumulates into a multi-year shortfall like the one Illinois uncovered.

Conclusion and Next Steps

Every case examined here traces back to the same gap: nobody independent was checking the numbers. Courts have so far dismissed the highest-profile suits on procedural grounds, but that offers plan sponsors a narrowing window, not a permanent shield. The prudent expert standard doesn't pause while standing law develops.

Start by asking whether your plan could produce, today, a written record of when your PBM contract was last benchmarked and by whom. If the honest answer is "not recently" or "never," that's the gap to close first.

An independent claims audit is the fastest way to establish both the documentation and the cost recovery this article describes.

Frequently Asked Questions

Is an HR director personally liable for ERISA fiduciary breaches?

Yes, if they exercise discretion over plan administration. The J&J case named individual committee members, not just the company.

Does hiring a PBM or TPA transfer fiduciary liability to them?

No. Delegating administration does not delegate the ongoing duty to monitor that vendor's performance.

Why were the Johnson & Johnson and Wells Fargo lawsuits dismissed?

Courts found plaintiffs lacked Article III standing, meaning they hadn't shown concrete, traceable financial injury, not that the conduct was proper.

How often should a self-funded plan audit its PBM?

At minimum annually, with rebate pass-through and administrative fees benchmarked independently of the PBM's own reporting.

What is the prudent expert standard under ERISA?

It requires fiduciaries to act with the care and skill a knowledgeable person familiar with plan administration would use under similar circumstances.

Can a plan sponsor be sued even if premiums didn't rise?

Yes, though recent rulings suggest plaintiffs must show a clearer causal link between fiduciary conduct and specific financial harm.

What triggered the CVS Caremark settlement with Illinois?

A state investigation found Caremark's affiliate withheld manufacturer rebates owed to the state's employee health plan over a four-year contract period.

Is a written fiduciary policy legally required?

ERISA doesn't mandate a specific document, but documented process is the primary evidence fiduciaries have if their conduct is challenged.

Fiduciary Intelligence

Fiduciary vs. Non-Fiduciary Advisors: What It Costs You

Abhishek Ghosh
August 10, 2026

A fiduciary advisor is legally bound under ERISA Section 404 to act solely in a health plan's best interest and disclose every source of compensation. A non-fiduciary advisor only has to recommend suitable options, often while earning commissions that reward higher-cost vendors. That gap can cost self-funded plans millions in unmanaged claims spend.

In 2024, an employee of Johnson & Johnson sued the company's own benefits committee, alleging that mismanaged pharmacy benefit contracts cost the health plan and its participants millions of dollars in inflated drug prices.

The Lewandowski v. Johnson & Johnson case has since been dismissed twice on standing grounds, but it opened a door that had stayed shut for years: ERISA fiduciary breach claims aimed squarely at health plan sponsors, not just retirement plan committees.

Average family premiums for employer-sponsored coverage hit $26,993 in 2025, according to the KFF Employer Health Benefits Survey, a 6 percent jump in a single year. Most plan sponsors have no idea whether the person advising them on that spending is legally required to act in their interest, or simply required to avoid recommending something unsuitable.

Key Takeaways
Fiduciary status changes the legal standard: A fiduciary advisor must act solely in your plan's best interest under ERISA Section 404 and disclose all compensation. A non-fiduciary advisor is generally required only to provide recommendations that are suitable.
Most benefits brokers are not fiduciaries by default: Unless a broker provides a written fiduciary acknowledgment, plan sponsors should not assume the broker is legally obligated to act as an ERISA fiduciary.
Compensation disclosures require active review: Under the Consolidated Appropriations Act of 2021 (CAA 2021), brokers receiving $1,000 or more in direct or indirect compensation must disclose those payments, but many plan sponsors never evaluate the information they receive.
Independent audits uncover significantly more errors: Comprehensive claims audits routinely identify error rates of 5% to 15% on reviewed claims, substantially higher than the 1% to 3% error rates commonly reported through industry benchmarks and routine oversight.
Regulatory enforcement is increasing: The Department of Labor's Employee Benefits Security Administration (EBSA) recovered approximately $1.4 billion for employee benefit plans and participants during fiscal year 2025, highlighting the financial consequences of weak fiduciary oversight.
Choosing a fiduciary advisor is only the starting point. Effective ERISA governance also requires reviewing compensation disclosures, independently verifying claims accuracy and maintaining a documented oversight process that demonstrates decisions were made in the plan's best interest.

What Actually Separates a Fiduciary From a Non-Fiduciary Advisor

A fiduciary advisor owes your plan an undivided duty of loyalty. A non-fiduciary advisor only owes you a suitable recommendation. That single distinction determines who is legally exposed when a decision goes wrong, and it is where most plan sponsors get confused.

Under ERISA Section 404, a fiduciary must act with the care, skill, and diligence of a prudent expert, and must place the plan's interests ahead of their own. A non-fiduciary broker, operating under a suitability standard, can recommend a product that pays a higher commission as long as it technically fits the client's needs. Most employers assume their broker already carries fiduciary obligations. In practice, unless a broker or consultant has signed a written fiduciary acknowledgment for the health plan specifically, they almost certainly have not.

The confusion runs deeper because retirement plan fiduciary roles are well defined under ERISA 3(21) and 3(38), while health and welfare plan fiduciary roles were left comparatively vague for decades.

Why the Confusion Exists

The fiduciary rules that apply to 401(k) plans took shape starting in 2012, when the Department of Labor required retirement plan service providers to disclose their compensation. Group health plans went without an equivalent rule for nearly a decade. Brokers built entire compensation models around that gap, often earning commissions, override bonuses, and contingent payments from carriers without ever disclosing them to the employer.

The CAA closed part of that gap. Under ERISA Section 408(b)(2) as amended by the CAA, any broker or consultant who reasonably expects $1,000 or more in direct or indirect compensation must disclose it in writing to the plan's responsible fiduciary before the arrangement begins. The rule took effect December 27, 2021. Disclosure alone does not create a fiduciary relationship, and most plan sponsors still are not reviewing what lands in their inbox.

The Real Cost of Non-Fiduciary Advice

Family premiums have grown 26 percent over the past five years, according to KFF, while employer contributions absorbed most of that increase. A plan paying $27,000 per family per year has almost no room for advisor conflicts of interest or unreviewed claims spend. Every dollar steered toward a higher-commission vendor instead of the best available option compounds across thousands of employees.

Independent claims audits show why this matters beyond premiums. TPA self-reported error rates typically run 1 to 3 percent, according to Willis Towers Watson, but independent third-party reviews that examine claims the TPA never flagged routinely find error rates between 5 and 15 percent. On a plan processing tens of millions in annual claims, that gap alone can represent six figures in unrecovered overpayments every year.

EBSA's enforcement record adds another layer of cost. The agency recovered $1.4 billion for benefit plans, participants, and beneficiaries in fiscal year 2025, with 63 percent of closed civil investigations producing monetary or corrective results. Plan sponsors who cannot demonstrate a prudent process for selecting and monitoring advisors are the ones investigators focus on first.

What's Actually Happening Behind the Scenes

Commission Structures and Spread Pricing

Many non-fiduciary brokers are paid through carrier commissions tied to premium volume, which means their income rises when the plan's costs rise. Some arrangements also involve spread pricing, where a vendor bills the plan more than it actually pays a provider and keeps the difference. Neither practice is illegal on its own, but neither one is disclosed by default.

Undisclosed or Buried Compensation

CAA disclosures technically satisfy the law even when compensation is described in vague, bundled categories rather than itemized dollar figures. A plan sponsor who receives a disclosure but never asks a follow-up question has, in effect, accepted whatever arrangement the broker chose to describe.

Undisclosed or Buried Compensation

CAA disclosures technically satisfy the law even when compensation is described in vague, bundled categories rather than itemized dollar figures. A plan sponsor who receives a disclosure but never asks a follow-up question has, in effect, accepted whatever arrangement the broker chose to describe.

Claims Oversight That Never Happens

Most self-funded plans review a small sample of claims once a year through the TPA's own reporting, rather than an independent party examining the full claims file. That self-reported review structure is precisely why error rates identified by outside auditors run several times higher than what TPAs report internally.

Claims Oversight That Never Happens

Most self-funded plans review a small sample of claims once a year through the TPA's own reporting, rather than an independent party examining the full claims file. That self-reported review structure is precisely why error rates identified by outside auditors run several times higher than what TPAs report internally.

Why Current Broker Relationships Aren't Enough

Factor Status Quo (Non-Fiduciary Broker) Fiduciary-Grade Oversight
Legal Standard Suitability Prudent expert, duty of loyalty (ERISA 404)
Compensation Disclosure CAA-required, often bundled or vague Itemized, reviewed annually against market
Claims Review TPA self-reported sample Independent audit of the full claims file
Conflict of Interest Commission and override-driven Written fiduciary acknowledgment, fee-based options
Documentation for DOL Inquiry Limited or reactive Ongoing, proactive fiduciary file

How to Fix It

1
Request a Written Fiduciary Acknowledgment
Request a written fiduciary acknowledgment from your broker or consultant specifically for the health plan, not just for the retirement plan.
2
Review CAA 408(b)(2) Disclosures
Pull the most recent CAA 408(b)(2) disclosure and request itemized dollar figures for every source of compensation rather than accepting bundled or vague categories.
3
Benchmark Advisor Fees
Compare broker and consultant fees against current market rates at every renewal cycle. Document the comparison and the rationale for the compensation you approve.
4
Commission an Independent Claims Audit
Commission an independent claims audit covering the full claims file rather than relying on a sample selected by the TPA. Internal Link: TPA Performance Guarantees Guide
5
Establish a Dependent Eligibility Audit
Make dependent eligibility verification a standing, separate workstream. These audits can frequently identify recoverable costs within months.
6
Build a Fiduciary File
Maintain documentation of every advisor selection, monitoring decision and claims audit finding. A complete fiduciary file creates a clear record of the plan's oversight process.

Red Flags That Signal the Problem Applies to Your Plan

Your broker has never signed a written fiduciary acknowledgment.
The last CAA compensation disclosure described fees in vague or bundled terms.
No independent claims audit has been performed in the last three years.
Your TPA reports claims accuracy at or near 100 percent every year.
Renewal recommendations consistently favor the same carrier or vendor, regardless of changes in the market.
Nobody on your benefits committee can explain how your broker gets paid.
Reality Check: If several of these red flags apply to your plan, your advisor compensation, claims oversight and vendor-selection process may warrant closer fiduciary review.

The ROI of Doing It Right

Plans that move from TPA self-reporting to independent, full-file claims review typically recover findings in the range of $500 to $1,200 per employee per year, based on independent audit firm data. A 1,500-employee plan sitting in the middle of that range recovers well over $1 million annually in previously invisible overpayments. Fiduciary-grade compensation review adds a second layer of savings by exposing commission structures that inflate premium costs without improving service.

Beyond the dollar recovery, a documented fiduciary process is itself protection. When EBSA investigates or a participant files a claim, the plans that fare best are the ones that can show a prudent, ongoing process rather than a single annual conversation with a broker.

Conclusion and Next Steps

The gap between fiduciary and non-fiduciary advice is not a technicality. It determines who is legally required to put your plan first, and it shapes every dollar your organization spends on premiums, claims, and vendor fees. Plan sponsors who treat this as a compliance checkbox rather than an ongoing process are the ones facing DOL inquiries and participant lawsuits.

Start with a written fiduciary acknowledgment, an itemized compensation review, and an independent claims audit. These three steps alone move a plan from reactive to prudent.

Frequently Asked Questions

Is my benefits broker automatically a fiduciary?

No. Most brokers operate under a suitability standard unless they sign a written fiduciary acknowledgment for the health plan.

What does ERISA Section 404 require of a fiduciary?

Acting solely in the plan's interest with the care and skill of a prudent expert, avoiding conflicts of interest.

Does the CAA make brokers fiduciaries?

No. It only requires compensation disclosure for brokers earning $1,000 or more; it does not change their legal standard.

How often should a self-funded plan audit its claims?

At minimum annually, using an independent auditor reviewing the full claims file rather than a small sample.

What is spread pricing?

When a vendor bills the plan more than it pays a provider and retains the difference, often undisclosed.

Can a plan sponsor be personally liable for fiduciary breaches?

Yes. ERISA allows personal liability for fiduciaries who fail to act prudently or loyally.

What triggered the recent wave of health plan fiduciary lawsuits?

The 2024 Lewandowski v. Johnson & Johnson case, alleging mismanaged PBM contracts inflated drug costs plan-wide.

What's the fastest first step toward fiduciary protection?

Request itemized CAA compensation disclosures and an independent claims audit within the next renewal cycle.

Fiduciary Intelligence

Top DOL Audit Triggers Every Self-Funded Employer Should Know

Abhishek Ghosh
August 7, 2026

The Department of Labor (DOL) often starts investigating a self-funded health plan when employees complain about their benefits, required compliance documents are missing, fee disclosures are incomplete, or the employer cannot prove it is monitoring its third-party administrator (TPA). In FY 2025, the DOL completed 878 civil investigations and recovered $714.4 million. If several employees raise similar complaints about the same plan, it may prompt the DOL to take a closer look.

A mid-size employer gets a letter from the Department of Labor. Not a lawsuit. A request for documents. The plan sponsor has never seen the claims data behind their own health plan, has no comparative analysis on file, and has no record of ever asking the TPA a hard question.

That letter is not random. EBSA closed 878 civil investigations in FY 2025 and recovered $714.4 million in the process, and most of those cases started with a pattern someone could have caught first.

Key Takeaways

1
DOL enforcement is active. In FY 2025, EBSA recovered $1.4 billion across all enforcement programs, including $714.4 million from 556 of 878 closed civil investigations.
2
Employee complaints can trigger investigations. Repeated complaints about the same health plan or service provider are a common reason the Department of Labor opens an investigation.
3
Mental health parity remains under scrutiny. Federal reviews continue to identify MHPAEA compliance gaps, with nearly all plans cited for violations being self-funded.
4
Limited claims reviews increase risk. Many self-funded employers review only a small percentage of paid claims, allowing payment errors and compliance issues to remain undetected.
5
Documented oversight is your strongest defense. Maintaining a recurring, documented claims oversight process demonstrates prudent fiduciary governance under ERISA Section 404 and helps prepare your plan for regulatory scrutiny.

What "DOL Audit Triggers" Actually Means

A DOL audit trigger is any pattern, complaint, or documentation gap that gives EBSA a reason to open a formal investigation into a self-funded health plan. Most plan sponsors assume audits are random, similar to a tax audit lottery. That assumption is wrong.

EBSA investigations are largely pattern-driven. Complaint volume, missing required disclosures, and known compliance gaps like NQTL comparative analyses generate referrals long before any letter arrives.

The gap between assumption and reality matters because plan sponsors who believe audits are random tend to under-invest in the documentation that would protect them. Prudent process, not luck, is what EBSA looks for once an investigation opens.

Why This Problem Exists

Self-funded plans hand claims processing, network access, and much of the compliance workload to a TPA. That arrangement creates a documentation and accountability gap that most sponsors never notice until it's tested.

ERISA places fiduciary responsibility for the plan on the sponsor, not the TPA. Selecting a service provider is itself a fiduciary act, and DOL guidance is explicit that hiring a TPA does not end the sponsor's duty to monitor performance and fees on an ongoing basis.

Most HR and finance teams were never trained to monitor a TPA the way they'd monitor a retirement plan recordkeeper. The retirement side of ERISA has decades of litigation and case law teaching sponsors to document process. The health side is catching up fast, and sponsors who haven't adjusted are exposed.

The Real Cost and Impact

EBSA's FY 2025 numbers show the scale of federal enforcement. The agency closed 878 civil investigations, and 556 of those, or 63 percent, produced monetary results or required corrective action, totaling $714.4 million in recoveries from enforcement alone.

Complaint-driven referrals are a meaningful share of that activity. EBSA opened 291 investigations from Benefits Advisor referrals in FY 2025, cases that typically start with repeated complaints about the same plan, employer, or service provider rather than a scheduled review.

DOL audits aren't the only concern. Many claim payment errors can remain hidden because most TPAs use sampling to review claims rather than examining every paid claim. Independent audits that review 100% of claims often identify overpayments that sampling-based reviews did not detect.

What's Actually Happening Behind the Scenes

MHPAEA Comparative Analysis Gaps

Mental health parity compliance is one of the clearest current audit triggers. A joint DOL and CMS review examined 56 plans for MHPAEA compliance and found 33 violations, and nearly every noncompliant plan was self-funded or included a self-funded option.

For plan years beginning on or after January 1, 2025, a named ERISA fiduciary must certify that the plan followed a prudent process to select and monitor whoever performs the NQTL comparative analysis. A comparative analysis that was written once and filed away does not meet that bar.

Participants can request a copy of the comparative analysis at any time under ERISA Section 104, which starts a 30-day disclosure clock. A plan that cannot produce a current, complete analysis on short notice has already created its own audit trigger.

Missing CAA 2021 Disclosures

The Consolidated Appropriations Act, 2021 requires brokers and consultants earning more than $1,000 annually in direct or indirect compensation to disclose those fees to the plan sponsor. Sponsors are responsible for confirming those disclosures exist and reviewing them, not just receiving them.

Gag clause attestations, another CAA 2021 requirement, must be submitted annually confirming the plan hasn't agreed to contract terms that restrict access to cost and quality data. A missed attestation is a simple, easily documented compliance failure, which makes it an easy first data point for an investigator.

Why Current Compliance Approaches Aren't Enough

Area Status Quo Recommended Approach
Claims Review TPA self-reports its own claims accuracy. Independent, plan-specific claims audit reviewing a full or high-percentage sample.
MHPAEA Compliance Comparative analysis is prepared once and rarely revisited. Named fiduciary performs and certifies an annual review of the NQTL comparative analysis.
Fee Transparency Broker compensation is disclosed only during renewal. CAA 2021 compensation disclosures are tracked, reviewed and archived every year.
Documentation Verbal approvals and scattered email records. Dated, written documentation supporting every fiduciary decision.
Vendor Monitoring TPA performance is largely left unmonitored between renewals. Continuous performance benchmarking against contractual obligations and service guarantees.

How to Fix It

1
Schedule Independent Claims Audits
Commission an independent claims audit on a recurring basis using a firm with no financial relationship to your TPA. Do not rely solely on the TPA's self-reported accuracy statistics when evaluating plan performance.
2
Assign an MHPAEA Fiduciary
Designate a named fiduciary to oversee the MHPAEA Non-Quantitative Treatment Limitation (NQTL) comparative analysis and formally document its annual review and approval.
3
Maintain CAA 2021 Disclosure Records
Track, review and archive all CAA 2021 broker and consultant compensation disclosures for every service provider supporting your health plan.
4
Create a Fiduciary Governance Calendar
Establish a written governance calendar covering quarterly claims reviews, annual TPA performance evaluations and yearly MHPAEA comparative analysis reviews to ensure oversight occurs on schedule.
5
Document Participant Complaints
Respond to every participant complaint in writing and maintain a log of the issue, investigation and resolution. Repeated complaints can become evidence during regulatory reviews.
6
Benchmark Your TPA Agreement
Review your TPA contract against current industry standards to evaluate audit rights, performance guarantees, reporting requirements and fiduciary protections before your next renewal.
Effective fiduciary oversight requires more than annual compliance. A structured governance calendar, independent claims verification, documented decision-making and regular vendor reviews help demonstrate the prudent process expected under ERISA while strengthening overall plan performance.

Red Flags That Signal Your Plan Is Exposed

Your health plan has never undergone an independent claims audit.
Your MHPAEA comparative analysis was completed once but has never been reviewed or updated.
CAA 2021 broker and consultant compensation disclosures are missing, incomplete or not retained for review.
Fiduciary committee meeting minutes either do not exist or never document discussions about claims oversight, vendor performance or payment accuracy.
Multiple employees have reported the same type of denied claim, suggesting a recurring operational or plan administration issue.
Your TPA has never been asked to provide a sample of paid claims for independent review or validation.
Reality Check: If three or more of these statements describe your plan, your fiduciary oversight process may have significant gaps. Independent claims audits, updated compliance reviews and documented governance help reduce financial leakage while strengthening ERISA compliance and regulatory readiness.

The ROI of Doing It Right

Independent oversight isn't just a compliance cost. Claims-auditing benchmarks across the industry typically show recoverable overpayments in the low single digits as a percentage of annual claims spend, and for many self-funded plans that translates into six or seven figures a year in identified errors alone.

Beyond dollars recovered, a documented oversight process is the single strongest piece of evidence a fiduciary can produce during an EBSA inquiry. Prudent process, not a clean outcome, is what ERISA actually requires.

The plans least likely to face a lengthy, costly investigation are the ones that can hand over a complete file the day a request arrives.

Conclusion and Next Steps

DOL audit triggers aren't a mystery, and they aren't random. They come from documentable gaps: complaints that pile up, a comparative analysis that's gone stale, fee disclosures nobody tracked, and a TPA relationship nobody independently checked. Self-funded employers who close those gaps before a letter arrives put themselves in a fundamentally different position than plans that wait.

Start with an honest inventory. If your plan can't produce a current comparative analysis, a full CAA 2021 disclosure file, and a recent independent claims audit today, that's the starting point for next quarter's fiduciary calendar.

Frequently Asked Questions

What triggers a DOL audit of a self-funded health plan?

Common triggers include repeated participant complaints, incomplete MHPAEA comparative analyses, missing CAA 2021 fee disclosures, and no documented TPA oversight process.

How many investigations did EBSA close in FY 2025?

EBSA closed 878 civil investigations in FY 2025, with 556 producing monetary results or corrective action.

How much did EBSA recover in FY 2025?

EBSA recovered $1.4 billion across all enforcement programs, including $714.4 million from civil investigations alone.

Is the plan sponsor or the TPA responsible for ERISA compliance?

The plan sponsor holds fiduciary responsibility under ERISA, even though the TPA handles day-to-day claims administration.

Does hiring a TPA satisfy fiduciary duty?

No. Selecting a TPA is itself a fiduciary act, and sponsors must also monitor performance and fees on an ongoing basis.

How often should a self-funded plan complete a claims audit?

Most compliance advisors recommend a recurring, independent audit rather than a one-time review, since TPA self-reported metrics rarely catch every error.

What is an MHPAEA comparative analysis?

It's a required written analysis comparing how a plan applies nonquantitative treatment limitations to mental health versus medical and surgical benefits.

Can participants request a copy of the comparative analysis?

Yes. Participants can request it at any time under ERISA Section 104, which starts a 30-day disclosure deadline.

Fiduciary Intelligence

Healthcare Fiduciary Oversight: The Next Lawsuit Wave

Abhishek Ghosh
August 5, 2026

Fiduciary oversight in healthcare is becoming the next 401(k) lawsuit wave because self-funded plan sponsors face the same ERISA fiduciary duties that drove two decades of retirement plan litigation. Courts are now applying those standards to TPA contracts, PBM fees, and claims payment accuracy, and DOL enforcement is following the same path.

In 2024, Ann Lewandowski sued Johnson & Johnson, alleging its health plan fiduciaries mismanaged the prescription drug program and cost employees millions in higher premiums and out-of-pocket costs. A New Jersey court dismissed the case twice on standing grounds, most recently in November 2025.

But one month before that dismissal, the Sixth Circuit revived a nearly identical theory in Tiara Yachts v. Blue Cross Blue Shield of Michigan, ruling that a TPA can be held to ERISA fiduciary standards for how it processes and recovers overpaid claims.

Two courts, two different outcomes, one unmistakable signal: the legal theory that reshaped retirement plans twenty years ago has arrived in group health.

Key Takeaways
Health plan litigation is accelerating: Fiduciary lawsuits involving employer health plans are following a trajectory similar to the wave of 401(k) excessive fee litigation, which has produced more than $1 billion in settlements since 2020.
Courts are expanding fiduciary accountability: The Sixth Circuit's May 2025 decision in Tiara Yachts v. BCBSM confirmed that TPAs can act as ERISA fiduciaries when exercising discretion over claims payment and recovery practices—not just plan sponsors.
Regulatory focus is shifting: The Department of Labor's Employee Benefits Security Administration (EBSA) identified health and welfare plans as a national enforcement priority for fiscal year 2026 after years of concentrating primarily on retirement plans.
Most payment errors remain hidden: While most self-funded plans independently review fewer than 5% of claims, comprehensive audits that examine the full claims population routinely identify error rates between 5% and 12%.
Personal fiduciary liability remains with plan sponsors: Under ERISA Section 409, fiduciaries may be held personally responsible for breaches of duty, and traditional D&O insurance generally does not cover fiduciary breach claims.
The legal landscape for self-funded health plans is changing rapidly. Independent claims oversight, documented governance and continuous monitoring are becoming essential not only for reducing payment errors, but also for demonstrating the prudent fiduciary process expected by regulators and the courts.

What "Fiduciary Oversight" Actually Means for a Self-Funded Health Plan

A self-funded health plan sponsor is a fiduciary the moment it exercises discretion over plan assets, and that duty cannot be delegated away by hiring a TPA. Most benefits leaders assume oversight is the TPA's job because the TPA processes claims, negotiates rates, and issues the reports the plan committee reviews each quarter. That assumption is where the fiduciary exposure begins.

ERISA Section 404 requires a named fiduciary to act with the care, skill, and diligence of a prudent expert, solely in the interest of participants. Hiring a competent TPA satisfies part of that duty. Monitoring the TPA's actual performance, not its self-reported accuracy scores, is the other part, and it is the part most plans skip.

The Tiara Yachts case makes the stakes concrete. The Sixth Circuit found that Blue Cross Blue Shield of Michigan could be a functional fiduciary because it controlled how claims were paid and how overpayment recoveries were split, not because a contract labeled it that way.

Why This Gap Exists Across So Many Plans

Health plan fiduciary duty developed later and more quietly than retirement plan duty. The 401(k) fee cases that started around 2006 forced plan committees to build documented, repeatable review processes for recordkeeper fees and fund lineups.

No equivalent discipline took hold for health plans, largely because TPA reporting looked authoritative enough to satisfy a busy HR or finance leader. Sixty-seven percent of covered workers are now in self-funded plans, according to the 2025 KFF Employer Health Benefits Survey, and at firms with 200 or more employees that figure reaches 80%, so the exposure is concentrated exactly where committees tend to assume the TPA has it handled.

Committees also rarely rotate or renegotiate audit rights when they renew a TPA contract. Restrictive audit clauses, limited sample sizes, and carrier-selected auditors are common, and few benefits teams push back because no one has flagged the gap as a liability issue yet.

The Real Cost of Skipping Independent Oversight

Unreviewed claims translate directly into plan asset losses, and those losses accrue every payment cycle, not just in a bad year. Industry-documented TPA error rates run from 1% to 3% on the low end and up to 5% to 12% when independent auditors review 100% of claims rather than a sample.

A regional manufacturer with 1,400 employees found $812,000 in overpayments across 18 months once it ran an independent audit, including a duplicate $47,000 inpatient claim and 63 ineligible dependents still active on the plan.

The Department of Labor's EBSA recovered $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, with $714.4 million coming from enforcement actions tied to 556 closed civil investigations. That total does not include the far larger pool of overpayments plan sponsors never identify because their contracted audit covers a few hundred claims out of hundreds of thousands.

Cost containment through claims oversight is not a rounding error. It is comparable to finding a leak in a pipe that has been running for years. The plan does not notice the loss on any single bill, but the cumulative drain shows up in renewal premiums the whole workforce eventually pays.

What's Actually Happening Behind the TPA's Reporting

Self-Reported Accuracy Scores Don't Match Independent Findings

TPAs commonly report financial accuracy near 96% to 97% against their own service level agreements. Independent post-payment reviews that examine the full claims file, rather than a carrier-selected sample, routinely find meaningfully higher error rates because the sampling methodology itself is built to minimize findings.

Sample Sizes Are Too Small to Catch Systemic Errors

Standard ASO audit clauses often cap the review at 300 to 350 claims per year. A peer-reviewed comparison of 100% claims audits against random-sample audits found the sampling approach missed error totals ranging from $200,000 to $750,000 that a full review caught.

Cross-Plan Offsetting and Spread Pricing Blur Whose Money Moves Where

In Peterson v. UnitedHealth Group, the Eighth Circuit found that using one employer's plan assets to offset another employer's overpayment was in tension with ERISA fiduciary duties. Spread pricing, where a TPA bills the plan more than it pays the provider, has been well documented in pharmacy benefit management and is now surfacing in medical claims reviews as well.

Dependent Eligibility Drift Goes Unchecked for Years

Employees change marital status, dependents age out, and COBRA elections lapse, but few plans run a dedicated eligibility audit outside of open enrollment. These reviews are often the fastest-paying audit workstream because ineligible dependents represent pure ongoing cost with no offsetting value.

Why TPA Self-Reporting Isn't Enough Anymore

Dimension Status Quo: TPA Self-Reported Accuracy Recommended: Independent Claims Oversight
Sample Size Typically 300 to 350 claims reviewed each year Up to 100% of claims reviewed through comprehensive analytics
Reporting Source TPA evaluates and reports on its own performance Independent third party with no financial or recovery conflict
Error Visibility Limited to issues identified within the audit sample Identifies systemic payment errors, trends and root causes
Fiduciary Documentation Committee minutes reference TPA reports only Committee reviews independent findings, documents decisions and tracks corrective actions
Cost to the Plan Hidden claims leakage compounds each renewal cycle Audit often pays for itself through recovered overpayments and future savings
Legal Exposure Duty-to-monitor claims are difficult to defend Documented prudent process strengthens an ERISA fiduciary defense

How to Close the Fiduciary Oversight Gap

1
Identify Your Fiduciaries
Review plan documents and TPA agreements to determine who serves as both the named fiduciaries and the functional fiduciaries exercising discretion over claims payment, recoveries and plan assets.
2
Strengthen Audit Rights Before Renewal
Renegotiate your ASO agreement before the next renewal to remove restrictive audit clauses, including limits on sample size, auditor selection and excessive advance notice requirements.
3
Use an Independent Claims Auditor
Engage a claims audit firm with no ownership or financial relationship to your TPA. Contingency or hybrid fee arrangements align the auditor's incentives with identifying recoverable overpayments rather than producing favorable-looking reports.
4
Audit Dependent Eligibility Separately
Run dependent eligibility verification as its own recurring audit workstream. It often delivers one of the fastest returns on investment by identifying ineligible participants before unnecessary claims continue.
5
Document Committee Oversight
Record independent audit findings, committee discussions, decisions and corrective actions in meeting minutes. A prudent process depends on evidence that fiduciaries actively reviewed and acted on the information.
6
Create a Recurring Oversight Calendar
Replace one-time audit projects with a structured monthly or quarterly monitoring schedule. Continuous oversight identifies payment leakage early, reducing financial losses before they compound throughout the plan year.
Strong fiduciary oversight depends on more than hiring a TPA. Clear fiduciary roles, independent claims audits, documented committee review and continuous monitoring create a governance process that improves claims accuracy, strengthens ERISA compliance and reduces long-term financial risk.

Red Flags That Signal Your Plan Is Exposed

Your only claims audit is the limited sample your TPA is contractually required to perform.
No one on your benefits committee can identify who is contractually authorized to perform an independent audit of your claims.
Your TPA agreement restricts which firms may perform an audit or limits how often your plan can request one.
Benefits committee meeting minutes do not document reviews of claims accuracy, payment errors or overpayment recovery efforts.
Dependent eligibility has not been independently verified in more than two years.
You cannot explain, in plain language, how your TPA calculates the claims accuracy rate it reports to your organization.
Reality Check: If three or more of these statements describe your plan, you likely have significant gaps in claims oversight and fiduciary governance. Strengthening audit rights, implementing independent claims reviews and documenting committee oversight can substantially reduce both financial leakage and ERISA fiduciary risk.

The ROI of Independent Oversight Done Right

Plans that run independent claims audits commonly recover the full cost of the audit within the first review cycle, and ongoing monitoring compounds those savings across every subsequent plan year. Dependent eligibility audits alone often pay for themselves within months because every ineligible dependent removed is a recurring cost eliminated, not a one-time recovery.

The fiduciary protection value is harder to price but arguably more important. A documented, repeatable oversight process is the same evidence that helped a health plan sponsor defeat a DOL fiduciary breach claim in prior litigation, because the court found the sponsor had not simply delegated authority and looked away.

Conclusion and Next Steps

The parallel between today's health plan fiduciary exposure and the 401(k) excessive fee wave of the past two decades is not a marketing analogy. It is the same statute, the same duty to monitor, and increasingly the same courts applying settled retirement plan precedent to group health claims. The J&J dismissal shows plaintiffs still face real standing hurdles, but Tiara Yachts and EBSA's 2026 enforcement pivot show the underlying theory is gaining traction, not losing it.

Plan sponsors who wait for a lawsuit to force the issue will be building their prudent process defense after the fact, which is the position no fiduciary wants to be in. Start with a claims audit scope review this quarter, confirm your audit rights before your next renewal, and document the committee's review process going forward.

Frequently Asked Questions

Is my company a fiduciary for our self-funded health plan?

Yes, if you exercise any discretion over plan administration or assets. Most self-funded employers are named fiduciaries under ERISA Section 402.

Can our TPA also be held liable as a fiduciary?

Yes. Courts including the Sixth Circuit in Tiara Yachts have found TPAs can be functional fiduciaries when they control claims payment and recovery decisions.

How often should we audit our health plan claims?

Annual audits are the baseline. Quarterly or continuous monitoring catches errors before they compound across a full plan year.

What is a "prudent expert standard" under ERISA?

It requires fiduciaries to act with the care, skill, and diligence a knowledgeable person would use in managing plan assets, not just good intentions.

Does our TPA's self-reported accuracy rate satisfy our fiduciary duty to monitor?

No. Duty to monitor requires independent verification, not reliance on a service provider's self-graded performance.

What percentage of claims typically contain errors?

Industry estimates range from 1% to 3% under standard sampling, and 5% to 12% when independent auditors review the full claims file.

Is D&O insurance enough to cover a fiduciary breach claim?

Usually not. ERISA Section 409 imposes personal liability on fiduciaries, and standard D&O policies frequently exclude ERISA fiduciary breach claims.

Why are health plan lawsuits increasing now instead of years ago?

Retirement plan litigation matured first and established the legal playbook. DOL enforcement priorities and court rulings like Tiara Yachts are now applying that same scrutiny to health plans.

Fiduciary Intelligence

Stop Mistaking TPA Administration for Fiduciary Protection

Abhishek Ghosh
August 3, 2026

TPA administration and fiduciary protection are not the same thing. A TPA processes and pays claims under contract, but ERISA Section 404 keeps fiduciary responsibility with the plan sponsor. Signing a TPA contract does not transfer that duty. Only active, documented oversight of claims activity satisfies the prudent expert standard.

Most self-funded plan sponsors sign a service agreement with a TPA and treat the relationship as a handoff. Once claims start getting paid, the assumption is that someone else is now watching the store. Independent research on claims administration tells a different story.

TPA error rates on processed claims commonly run between 1% and 6% of total volume, and on a plan spending $20 million a year on medical claims, even a conservative 2% error rate is $400,000 in avoidable losses. Fiduciary protection for self-funded health plans does not come from the TPA contract. It comes from what the plan sponsor does after the contract is signed.

Key Takeaways
Delegation is not liability transfer: Hiring a Third-Party Administrator (TPA) transfers claims processing responsibilities, but it does not transfer the plan sponsor's fiduciary duties under ERISA Section 404.
Most claims are never independently reviewed: Industry research places TPA claims payment error rates between 1% and 6%, while most self-funded plans review only 5% to 10% of claims through routine sampling audits.
Regulatory scrutiny is increasing: The Department of Labor's Employee Benefits Security Administration (EBSA) recovered nearly $1.4 billion in fiscal year 2024 through enforcement actions and complaint resolutions, underscoring the importance of effective plan oversight.
Courts focus on actions, not contracts: Fiduciary liability is determined by how parties actually exercise authority and control over plan administration, not simply by the wording of the TPA agreement.
The solution is independent oversight: Closing the fiduciary gap requires independent claims reviews, documented monitoring and a structured governance process—not simply negotiating a larger or more detailed TPA contract.
Self-funded employers remain accountable for how plan assets are managed, even when claims administration is outsourced. Independent oversight, documented governance and regular claims auditing provide the evidence needed to satisfy ERISA's prudent fiduciary standard while reducing financial leakage and regulatory risk.

What TPA Administration Actually Covers

Administering a health plan and protecting it as a fiduciary are two different jobs, and most TPA contracts only cover the first one. A TPA agreement typically spells out claims processing timelines, network access and customer service standards. It rarely includes an obligation to catch every coding error, flag every ineligible dependent or independently verify that billed rates match contracted rates.

Plan sponsors often assume that paying a reputable, well-known TPA is itself a form of due diligence. That assumption is understandable. It is also incomplete under ERISA, where the duty to monitor a service provider cannot be delegated away, even when claims decision authority has been assigned to the TPA.

The result is a structural gap. The TPA handles volume and workflow. The plan sponsor, as the named fiduciary, remains on the hook for verifying that the volume was handled correctly. Nothing in a standard administrative services agreement closes that gap on its own.

Why the Problem Exists

TPAs are built and compensated to process claims at scale, not to flag every dollar that could have been billed more cheaply. Their internal accuracy metrics are typically self-reported, drawn from small samples of their own work, and rarely audited by an outside party before being shared with the plan.

Prompt payment timelines add pressure in the same direction. Most administrative agreements require claims to be paid within 21 to 30 days of receipt, which leaves limited room for a detailed line-item review before a check goes out. Speed and accuracy pull against each other, and speed usually wins by contract design.

Plan sponsors compound the gap by treating the TPA relationship as "set and forget." Committees review premium trends and utilization reports at renewal, but few build a recurring, independent claims review into the plan's operating calendar. Without that cadence, errors accumulate quietly for years.

The Real Cost or Impact

A 2% to 6% error rate sounds small until it is applied to a plan's total claims spend. On a mid-size plan paying $15 million a year in claims, even the low end of that range represents $300,000 moving through the plan incorrectly, year after year, without anyone flagging it. Multiply that across a plan's life span and the number stops looking like a rounding error.

The financial exposure is only part of the picture. In FY 2024, the Department of Labor's Employee Benefits Security Administration recovered nearly $1.4 billion for plans, participants and beneficiaries, a large share of it tied to weak oversight of service providers and plan assets. That is federal enforcement money, not internal audit findings, which means it followed a formal investigation into how a plan was being run.

Self-funded plans are now the dominant funding model in the employer market. KFF's 2025 Employer Health Benefits Survey found that 67% of covered workers are enrolled in self-funded arrangements, rising to 80% at larger firms. That scale means the fiduciary exposure sitting inside unreviewed claims data is not a niche problem. It touches most employer-sponsored health coverage in the country.

What's Actually Happening Behind the Scenes

Sampling Audits Instead of Full Review

Most claims oversight today runs on small statistical samples rather than a full look at every payment. A TPA might review a few hundred claims out of hundreds of thousands processed in a year and extrapolate an accuracy rate from that subset. The math works fine for a general trend line. It does very little to catch the specific overpayment sitting in the other 95% of claims that never got a second look.

Coordination of Benefits Gaps

Coordination of benefits (COB) failures happen when a plan pays as primary on a claim that should have been paid by another carrier first. These errors are common in households with two working spouses or dependents aging onto other coverage. TPAs process COB updates reactively, based on member-submitted information, which means stale COB data can sit in the system for months before anyone notices the plan paid more than it owed.

Dependent Eligibility Drift

Dependent eligibility drift describes ineligible dependents, a divorced spouse, an adult child who aged out, staying on the plan because no one re-verified eligibility after enrollment. Every claim paid on behalf of an ineligible dependent is plan money spent outside the terms of the plan document, which is itself a fiduciary concern independent of the dollar amount involved.

Vendor Accountability and Legal Exposure

Courts have started drawing a sharper line around who actually carries fiduciary risk in these relationships. In *Tiara Yachts, LLC v. Blue Cross Blue Shield of Michigan*, the Sixth Circuit held that functional conduct, not contract labels, determines fiduciary status and liability. That precedent matters for any plan sponsor assuming that a well-worded services agreement automatically shields them from claims-related fiduciary exposure.

Why Current Approaches Aren't Enough

Renewal-cycle reviews and TPA-provided performance dashboards give plan sponsors a general sense of direction. They rarely provide the kind of documented, independent evidence that would hold up if a participant or the Department of Labor challenged how the plan was overseen.

Dimension Status Quo (TPA Self-Reporting) Recommended Approach (Independent Oversight)
Claims Reviewed Small statistical sample, often under 5% to 10% of claims Full or near-full review of the claims population
Source of Accuracy Data TPA's own internal audit team Independent third-party auditor with no TPA affiliation
Review Frequency Annual, typically aligned with renewal Ongoing monthly or quarterly monitoring
Documentation for Fiduciary Defense Limited, informal documentation Committee minutes, audit reports and corrective action logs
Dependent & COB Verification Reactive and primarily member-submitted Proactive, scheduled eligibility and COB re-verification
Contract Audit Rights Often restrictive or silent Explicit right to audit any claim, at any time

How to Fix It

1
Establish a Benefits Committee
Create a benefits committee with a written charter that clearly defines fiduciary responsibilities, meeting frequency and documentation requirements. Oversight should be an ongoing governance process rather than a one-time activity.
2
Commission an Independent Claims Audit
Conduct an independent claims audit at least once each year using a firm with no financial relationship to your TPA. Whenever possible, review the full claims population instead of relying on a small statistical sample.
3
Strengthen Audit Rights
Review your TPA agreement to confirm the plan can audit any claim, at any time, using any qualified independent firm. Remove contract provisions that unnecessarily restrict audit scope or timing.
4
Schedule Eligibility Verification
Implement a recurring dependent eligibility verification schedule instead of relying solely on enrollment-time attestations. Regular reviews help identify ineligible coverage before unnecessary claims accumulate.
5
Monitor COB Data Proactively
Request updated coordination of benefits (COB) reports from your TPA on a defined schedule instead of waiting for members to report other coverage. Proactive monitoring reduces avoidable overpayments.
6
Document Every Fiduciary Decision
Retain committee minutes, audit findings and corrective action records for at least six years. A well-documented decision-making process provides strong evidence of prudent fiduciary oversight if the plan is ever challenged.
Fiduciary oversight is built on structure, independent verification and consistent documentation. Establishing formal governance, auditing claims regularly and maintaining complete records creates a defensible process that strengthens ERISA compliance while reducing long-term financial risk.

Red Flags That Signal the Problem Applies to Your Plan

No independent claims audit has been performed within the last 12 months.
Your plan relies entirely on the TPA's self-reported claims accuracy metrics with no independent validation.
Your Administrative Services Only (ASO) agreement restricts who can audit claims or how frequently audits may be conducted.
Dependent eligibility has not been independently re-verified since employees first enrolled in the plan.
Benefits committee meetings focus primarily on premiums and renewal discussions rather than claims accuracy, payment integrity or fiduciary oversight.
No one representing the plan sponsor can clearly explain how Coordination of Benefits (COB) information is updated, monitored and verified.
If three or more of these statements describe your plan, your claims oversight process likely has significant gaps. Independent audits, proactive eligibility reviews and documented fiduciary governance can help reduce payment errors while strengthening ERISA compliance.

The ROI of Doing It Right

Independent audits regularly identify overpayments in the 2% to 6% range of total claims spend, and those recoveries frequently offset the cost of the audit itself within the first review cycle. For a plan spending $20 million annually, recovering even the low end of that range translates into hundreds of thousands of dollars back in plan assets.

The ongoing value compounds once oversight becomes routine instead of occasional. A plan that reviews claims quarterly catches errors before they repeat across multiple pay cycles, which lowers the total leakage over time rather than just the one-time recovery from a single audit.

The fiduciary protection component is harder to price but just as real. Documented, independent oversight gives the plan sponsor evidence of a prudent process, which is the standard ERISA actually asks fiduciaries to meet. That documentation is the difference between a defensible governance record and an unverified assumption that the TPA had it covered.

Conclusion and Next Steps

TPA administration keeps claims moving. Fiduciary protection for self-funded health plans only comes from what a plan sponsor does to verify that movement is accurate, documented and reviewed on a defined schedule. Those are not the same function, and treating them as interchangeable leaves plan assets and personal fiduciary exposure sitting unmonitored.

The next step is straightforward: schedule an independent claims audit, formalize the benefits committee's charter, and build documentation habits before a complaint or investigation forces the issue. Talk to an independent claims audit specialist.

Frequently Asked Questions

Does hiring a TPA transfer fiduciary liability to them?

No. ERISA keeps the duty to monitor service providers with the plan sponsor, even when claims decisions are delegated to the TPA.

What percentage of claims do TPAs typically get wrong?

Industry-documented error rates on processed claims generally fall between 1% and 6%, depending on the source and plan complexity.

How often should a self-funded plan conduct an independent claims audit?

At least annually, with many advisors recommending quarterly or ongoing monitoring for larger plans.

Can a plan sponsor be sued personally for fiduciary breaches?

Yes. Individuals who exercise discretion over plan administration can face personal liability for breaches of fiduciary duty under ERISA.

Is a sampling audit from the TPA enough to satisfy fiduciary duty?

Sampling audits provide limited assurance. Independent, broader reviews offer stronger documentation of a prudent oversight process.

What is coordination of benefits and why does it matter for audits?

Coordination of benefits (COB) determines which plan pays first when a person has multiple coverages. Errors here often cause plans to overpay.

Does the TPA's size or reputation reduce fiduciary risk?

Not directly. Fiduciary risk is tied to oversight practices and documentation, not the TPA's brand or market share.

What should a benefits committee document to show prudent process?

Meeting minutes, audit reports, corrective action plans and vendor monitoring records, generally retained for at least six years.

Fiduciary Intelligence

Why Employers Need Independent Claims Oversight

Abhishek Ghosh
July 30, 2026

A 1,400-employee manufacturer ran its first independent claims audit in 2024 after 18 months of routine TPA reporting had shown nothing unusual. The audit found $812,000 in overpayments, including a $47,000 inpatient claim paid twice, 63 ineligible dependents still active on the plan, and a specialty drug billed at 240% of the contracted rate. None of it had surfaced in the TPA's own reviews.

That gap between what a TPA reports and what an independent audit finds is not an isolated incident. It is a structural feature of how most self-funded plans operate today, and it is one that plan sponsors are increasingly on the hook for.

Key Takeaways
The fiduciary responsibility is significant: About 67% of covered workers are enrolled in self-funded health plans, and every sponsoring employer is directly responsible under ERISA for ensuring claims are administered prudently.
Self-reported accuracy is not independent verification: One documented audit found 96.8% financial accuracy and 96.1% payment accuracy, both below the plan's 98% service-level guarantee and well below the TPA's reported 100% accuracy.
Independent audits provide defensible oversight: Comprehensive claims audits that review the full claims population, rather than TPA-run statistical samples, help demonstrate the ERISA prudent expert standard expected of fiduciaries.
Regulatory scrutiny is increasing: The Employee Benefits Security Administration (EBSA) recovered more than $1.4 billion for employee benefit plans in fiscal year 2025, with more than half resulting from enforcement actions, highlighting increased attention to fiduciary oversight.
Small errors become large losses: Overpayment error rates of 2% to 5% of total claims spend can persist even in well-managed plans, compounding year after year when claims are not independently reviewed.
Self-funded employers cannot rely solely on TPA reports to demonstrate prudent oversight. Independent claims audits, continuous monitoring and documented governance provide the evidence needed to reduce financial leakage, satisfy ERISA fiduciary obligations and withstand growing regulatory scrutiny.

What Independent Claims Oversight Actually Means

Independent claims oversight is a third-party review of paid medical claims, conducted by an auditor with no financial relationship to the TPA that processed them. Most employers assume their TPA already does this work through its own quality assurance process. That assumption is the core misunderstanding this article addresses.

A TPA's internal audit measures the TPA's own performance using the TPA's own sample, methodology, and reporting standards. That is not oversight. It is self-assessment, and self-assessment has an obvious structural weakness: the entity being reviewed controls what gets reviewed.

Independent oversight replaces that arrangement with an outside party who audits a much larger share of claims, applies clinical and coding expertise the TPA's routine review does not, and reports findings directly to the plan sponsor rather than filtering them through the vendor being evaluated.

Why the Problem Exists

The root cause is not incompetence. Most TPAs process millions of claims accurately and efficiently, and their sampling audits are a legitimate part of normal operations. The problem is scope and incentive, not effort.

TPA sampling audits typically examine a small slice of total claims, often under 5%, leaving the remaining volume unreviewed by anyone with genuine independence. Complex errors such as coordination of benefits failures, upcoding, and unbundling require clinical coding expertise that standard sampling processes are not built to catch at scale.

There is also a quieter incentive dynamic. A TPA that repeatedly identifies its own errors invites tougher contract terms and more scrutiny at renewal. That is simply how vendor relationships work, not an accusation of misconduct, but it explains why relying solely on a vendor's self-reported accuracy leaves a structural blind spot that only independent review can close.

The Real Cost or Impact

The financial exposure from unreviewed claims is measured in real dollars, not theoretical risk. One documented audit of a TPA's claims processing found financial accuracy of 96.8% and payment accuracy of 96.1%, both below the plan's contracted 98% service level agreement, even though the TPA had self-reported 100% accuracy (Baker Tilly). At claims volumes of $10 million to $50 million a year, even a 2% to 5% error rate translates into hundreds of thousands of dollars annually (AIM Benefits).

Coordination of benefits failures are a common driver of this leakage. When a plan pays as primary on a claim that should have been billed secondary, the overpayment on that single claim can run 60% to 80% higher than it should. Multiply that pattern across a workforce of several thousand employees and the leakage compounds every renewal cycle.

There is also a regulatory dimension. EBSA recovered more than $1.4 billion for retirement, health, and welfare benefit plans and their participants in fiscal year 2025, with more than half of that total coming from enforcement actions rather than voluntary correction (U.S. Department of Labor). That figure reflects a broader enforcement environment in which undocumented vendor oversight is increasingly treated as a fiduciary gap, not an administrative footnote.

What's Actually Happening Behind the Scenes

Sampling Instead of Full Review

Most TPA audits work from a statistical sample rather than a full claims review. That approach is efficient for catching obvious errors but is not designed to surface the low-frequency, high-dollar errors, like a duplicate inpatient claim or a specialty drug billed above contract rate, that do the most damage to a plan's budget.

Eligibility Drift

Dependents who age out, spouses who gain other coverage, and employees who terminate but stay active in the claims system for months are a quiet but persistent source of leakage. Eligibility files are rarely reconciled against claims payment in real time, so ineligible claims can accumulate for a full plan year before anyone notices.

Coding Errors That Require Clinical Judgment

Upcoding bills a higher-acuity service code than the documentation supports. Unbundling charges separately for procedures that should be billed under one comprehensive code. Both require someone with clinical and coding expertise to catch, which is exactly the kind of review that high-volume, low-touch sampling processes tend to under-resource.

Why Current Approaches Aren't Enough

Annual TPA-led sampling audits satisfy a contractual checkbox, but they were never designed to serve as fiduciary evidence. The table below shows where the gap sits.

Factor Status Quo (TPA Self-Reported Sampling) Independent Claims Oversight
Claims Reviewed Typically under 5% of total claims volume Comprehensive review across the entire claims population
Reviewer Independence TPA reviews its own work Independent third party with no vendor relationship
Error Detection Depth Primarily identifies obvious processing errors Includes clinical coding, coordination of benefits (COB) and eligibility review
Reporting Relationship Filtered through the vendor being assessed Reports directly to the plan sponsor
Fiduciary Documentation Value Limited, self-interested source Defensible evidence of prudent fiduciary oversight
Frequency Often annual or less Continuous or quarterly monitoring

How to Fix It

1
Commission an Independent Claims Audit
Complete an independent claims audit before your next renewal cycle. Select an audit firm with no ownership, referral or financial relationship with your TPA or stop-loss carrier so the findings remain objective and unbiased.
2
Secure Full Claims Data Access
Negotiate the right to receive detailed claims data, not just summary reports, in every TPA agreement. Full data access allows independent verification of payment accuracy and supports stronger contract negotiations at renewal.
3
Review Eligibility Every Quarter
Reconcile eligibility files against paid claims every quarter instead of waiting for the annual audit. Regular reviews identify enrollment drift and prevent ongoing payment errors from accumulating.
4
Document Every Oversight Activity
Maintain committee minutes, governance records, audit reports and follow-up actions. ERISA's prudent expert standard is supported by a documented oversight process, not simply by achieving favorable results.
5
Use Audit Findings in Vendor Negotiations
Treat recurring claims errors as leverage during renewal discussions. A documented history of payment inaccuracies can strengthen negotiations around pricing, service guarantees and contract terms.
6
Establish an Ongoing Audit Cadence
Replace one-time audit engagements with a recurring quarterly or continuous review program. Claims leakage returns every plan year unless payment accuracy is monitored on an ongoing basis.
Independent oversight is most effective when it becomes part of your annual governance process rather than a periodic project. Continuous claims monitoring, documented fiduciary review and objective audit findings help reduce financial leakage while strengthening ERISA compliance.

Red Flags That Signal the Problem Applies to Your Plan

Your last claims audit was performed or arranged by the TPA that processes your claims.
You have never received or reviewed raw claims data, relying instead on summary reports prepared by your administrator.
Dependent eligibility has not been reconciled or independently verified within the last 12 months.
Your plan has never hired an audit firm with no financial relationship to your TPA or stop-loss carrier.
You could not produce documentation showing how your organization actively monitored TPA performance if the Department of Labor requested it.
Specialty pharmacy spending has increased, but those claims have never been independently audited for pricing or payment accuracy.
Your broker or benefits consultant has a financial relationship with your current TPA, creating potential conflicts when evaluating claims performance.
If three or more of these statements apply to your plan, your claims oversight process may not be sufficiently independent to identify payment errors or demonstrate prudent fiduciary oversight. Establishing independent audits, ongoing monitoring and documented governance can significantly reduce both financial and compliance risk.

The ROI of Doing It Right

Independent claims audits routinely recover overpayments well above the cost of the audit itself, which is one reason the practice has become standard among large, well-governed plans. Beyond direct dollar recovery, ongoing oversight tends to reduce the error rate in future claims cycles because TPAs adjust processing behavior once they know independent review is a permanent fixture, not a one-time event.

The fiduciary protection value is harder to put a single number on, but it is arguably more important. A plan sponsor who can show continuous, independent review of claims payment occupies a materially stronger position in a DOL inquiry or participant lawsuit than one relying solely on an annual vendor-run sample.

Given that EBSA closed 878 civil investigations in FY 2025, with 556 resulting in repayments or required corrective action (per DOL enforcement data), documented independent oversight is no longer a nice-to-have. It is the evidence a plan sponsor needs on file before anyone asks for it.

Frequently Asked Questions

What is independent claims oversight?

A third-party review of paid medical claims by an auditor with no financial ties to the TPA, distinct from a TPA's internal quality checks.

Why can't I rely on my TPA's own audit?

A TPA auditing its own claims creates a conflict of interest and typically reviews only a small sample of total volume.

Who is legally responsible for claims errors under ERISA?

The plan sponsor, not the TPA, carries fiduciary liability for how the plan's claims are paid.

How often should a self-funded plan run an independent audit?

Best practice is quarterly or continuous review, not a single annual engagement, since leakage reappears every plan year.

What is the prudent expert standard?

ERISA Section 404 requires fiduciaries to act with the care and skill a knowledgeable expert would use, which independent audits help document.

What kinds of errors do independent audits usually find?

Duplicate payments, ineligible dependents, coordination of benefits failures, upcoding, and unbundling are the most common categories.

Does an independent audit replace my TPA relationship?

No. It adds an accountability layer alongside the TPA, not a replacement for claims processing services.

What size plan needs independent claims oversight?

Any self-funded plan, but the dollar exposure grows quickly for employers with 100 or more covered employees and claims spend in the millions.

Fiduciary Intelligence

Why Claims Data Transparency Alone Isn't Enough

Abhishek Ghosh
July 30, 2026

A self-funded hospital system trusted its TPA's self-reported claims accuracy of 100%, year after year. An independent audit of a stratified sample of roughly 200 medical claims told a different story.

Financial accuracy landed near 96.8% and payment accuracy at 96.1%, both below the 98% service level agreement in the contract. The plan had data. Nobody outside the TPA had checked whether the data was true.

Key Takeaways
Transparency is not verification: Claims data, pricing files and TPA reports show what was paid, but they do not confirm that payments were calculated correctly.
Independent audits tell a different story: TPA-reported error rates are typically low, yet independent reviews frequently identify financial and payment accuracy below contracted performance standards.
Most claims are never independently reviewed: Self-funded plans often examine only a small sample of claims each year, usually through the TPA's own audit process rather than an independent review.
The fiduciary responsibility remains with the employer: Under ERISA Section 404, plan sponsors are responsible for ensuring claims are paid accurately, even when every claim is processed by a TPA.
Continuous oversight closes the gap: Ongoing claims monitoring and independent verification provide the accountability needed to confirm that what the plan was told matches what actually occurred.
Data transparency improves visibility, but visibility alone does not prevent payment errors. Combining transparent claims data with continuous, independent oversight gives plan sponsors the evidence needed to reduce financial leakage, strengthen fiduciary governance and meet ERISA expectations.

What Claims Data Transparency Actually Means

Claims data transparency is access to claims pricing, utilization or payment information, not verification that the information is accurate. Plan sponsors often equate transparency with oversight because both involve data. They are not the same function.

Transparency answers "what did we pay." Oversight answers "should we have paid that." A plan can have full access to its claims feed and still have no process for catching a duplicate payment, an ineligible dependent or a specialty drug billed above the contracted rate.

The Transparency in Coverage rule illustrates the gap well. It produced what has been called one of the largest government-mandated data releases in history, yet researchers found the machine-readable files inconsistent in structure, thin on index information and often too large for a standard computer to process. Access without usability is not transparency in any meaningful sense.

Why the Gap Exists

The gap exists because TPAs report their own performance, and self-reporting carries no independent verification. A TPA's contract may guarantee 99% payment accuracy while the TPA's own internal data shows a 1.4% claims processing error rate, a discrepancy that surfaced in one carrier's administrative services agreements. The guarantee and the reality are not required to match unless someone checks.

TPAs also lack a direct financial incentive tied to plan cost outcomes. Their compensation structure is generally built around processing volume and service fees, not around minimizing the plan's total spend, so error prevention competes with throughput.

Most plans compound the problem by reviewing claims infrequently. Annual audits built into ASO agreements often sample only 300 to 350 claims out of hundreds of thousands processed in a year. A snapshot that small can miss systemic issues entirely.

The Real Cost of Assuming Transparency Equals Oversight

Unverified claims errors compound into six- and seven-figure losses for mid-size self-funded plans. Industry claims audit findings put TPA error rates between 3% and 10% of processed claims, well above the 1% to 3% error rate typically cited as an industry baseline.

Independent claims analysis across a large multi-employer dataset found error detection rates of 5% to 15%, with average recoverable findings between $500 and $1,200 per covered employee per year. For a plan with 1,000 covered employees, that range alone represents $500,000 to $1.2 million in annual exposure.

The consequences are not only financial. In September 2025, Aetna and Optum reached an $8.4 million settlement tied to fabricated billing codes that concealed administrative fees inside medical charges for nearly a decade before litigation forced disclosure. Transparency did not surface that pattern. Litigation did.

What's Actually Happening Behind the Scenes

Benefit Determination Errors

The most common category of claims error involves how a plan's own provisions get applied: deductibles, coinsurance, copays and plan-specific exclusions. These errors are rarely intentional. They happen because claims processing blends automated adjudication with manual review, and manual steps introduce inconsistency.

Dependent Eligibility Drift

Dependents who age out, divorce out or otherwise lose eligibility often stay on a plan for months or years because no one is cross-checking enrollment against life events. Dependent eligibility audits are frequently the fastest-paying workstream in a claims review because the savings start the moment ineligible members are removed.

Duplicate and Miscoded Claims

Duplicate payments, upcoding and unbundling do not show up in a pricing dashboard. They show up when someone compares the billed procedure codes against the medical record or the plan's coding logic, a step that transparency tools are not built to perform.

Why Current Approaches Aren't Enough

Most plan sponsors rely on the transparency and reporting the TPA already provides. That approach leaves the same party that processed the claim responsible for verifying it, which is a conflict most plans would not accept in any other financial function.

Dimension Status Quo (Transparency Only) Recommended Approach (Active Oversight)
Data Source TPA self-reported dashboards and files Independent claims audit with ongoing monitoring
Claims Reviewed Small annual sample (roughly 300 to 350 claims) Continuous review across the full claims feed
Error Detection Limited to what the TPA discloses Independent reviews typically identify 5% to 15% error rates
Fiduciary Documentation Minimal and reactive Documented audit trail supporting the ERISA Section 404 prudent process
Financial Recovery Rare and dependent on TPA cooperation Structured recovery process built into the independent audit

How to Fix It

1
Commission an Independent Claims Audit
Engage an audit firm with healthcare claims and coding expertise that has no ownership, referral or financial relationship with your TPA or insurance carrier. Independent reviews provide an objective assessment of claims accuracy.
2
Strengthen Your Audit Rights
Negotiate audit provisions into every ASO agreement that allow the plan to review any claim, at any time, without restrictive sampling requirements, extrapolation limits or barriers to independent audits.
3
Separate Eligibility Audits
Make dependent eligibility verification a recurring workstream rather than combining it with medical claims auditing. Separate reviews often identify ineligible dependents quickly and generate meaningful savings.
4
Implement Continuous Claims Monitoring
Replace infrequent annual audits with quarterly or monthly monitoring of claims activity. Continuous oversight identifies payment leakage earlier, reducing financial losses before they accumulate.
5
Document Every Oversight Activity
Retain board minutes, committee charters, audit reports and follow-up actions. Documenting the review process is just as important as documenting the audit findings for demonstrating prudent fiduciary oversight under ERISA Section 404.
6
Use Independent Performance Metrics
Tie TPA performance guarantees to independently verified claims accuracy rather than relying solely on the TPA's own reporting. Independent validation ensures performance commitments can be objectively measured.
Moving from periodic audits to continuous, independent oversight strengthens claims accuracy, improves financial accountability and creates the documented fiduciary process needed to meet ERISA obligations while reducing long-term claims leakage.

Red Flags That Signal the Problem Applies to Your Plan

Your last independent claims audit was conducted more than two years ago, or your plan has never completed one.
Your TPA reports 99% or higher claims accuracy, but you have never reviewed the underlying sample size, methodology or validation process.
Claims spending continues to increase even though employee enrollment and healthcare utilization remain relatively stable.
Your ASO agreement limits how many claims can be audited or restricts which independent firms are permitted to perform the review.
No one on your benefits committee can identify the most recent claims error the plan discovered and corrected.
Specialty pharmacy spending has increased faster than every other plan cost category without a dedicated pricing or payment accuracy review.
If three or more of these statements apply to your plan, your current oversight process may be leaving payment errors, financial leakage and fiduciary risks undetected. Regular independent audits and continuous claims monitoring can help identify issues before they become significant financial or compliance problems.

The ROI of Doing It Right

Independent claims audits routinely recover a meaningful share of the errors they identify, and the ongoing savings from corrected TPA behavior often exceed the one-time recovery. [internal link: claims audit ROI calculator] Dependent eligibility reviews in particular tend to pay for themselves within months, since removing an ineligible dependent stops future claims immediately rather than only recovering past ones.

Beyond dollars, a documented audit and monitoring process is the clearest evidence a plan sponsor has that it met the prudent expert standard under ERISA Section 404. That documentation matters most in the moment a plan can least afford to be without it: a DOL inquiry or a participant lawsuit. EBSA alone recovered $1.4 billion for plans, participants and beneficiaries in fiscal year 2025, a reminder that enforcement activity in this space is active and ongoing, not theoretical.

Frequently Asked Questions

Is claims data transparency required by law?

Yes. The Transparency in Coverage rule and the Consolidated Appropriations Act, 2021 require pricing disclosures, but neither requires payment accuracy verification.

Does transparency alone satisfy ERISA fiduciary duty?

No. ERISA Section 404 requires a prudent process for monitoring plan expenses, which access to data does not fulfill by itself.

How often should a self-funded plan audit its claims?

Most fiduciary advisors recommend an independent audit at least annually, supplemented by ongoing quarterly or monthly monitoring.

What percentage of claims typically contain errors?

Independent audits commonly find error rates between 3% and 10%, above the 1% to 3% often cited as an industry baseline.

Who is legally responsible for claims accuracy, the plan sponsor or the TPA?

The plan sponsor. ERISA places fiduciary responsibility on the plan sponsor even though the TPA processes the claims.

Can a plan sponsor audit claims without the TPA's permission?

Audit rights depend on the ASO agreement. Sponsors should negotiate unrestricted audit access before signing or renewing a contract.

What is the difference between a claims audit and ongoing monitoring?

An audit reviews a sample retrospectively. Ongoing monitoring reviews claims continuously, closer to the time they are paid.

Are machine-readable pricing files useful for claims oversight?

They provide pricing context but are not designed to verify individual claim accuracy, and many are difficult to process without specialized tools.

Fiduciary Intelligence

Fiduciary-Grade Healthcare Operations: A Plan Guide

Abhishek Ghosh
August 3, 2026

Fiduciary-grade healthcare operations are the claims oversight, documentation and governance practices a self-funded plan sponsor uses to meet ERISA's prudent expert standard. This includes independent claims audits, documented TPA performance reviews and dependent eligibility checks, rather than relying on a TPA's self-reported accuracy numbers.

In September 2025, Aetna and Optum finalized an $8.4 million settlement over fabricated billing codes that had inflated member costs for nearly a decade before litigation forced disclosure. The case started with one retired plan member who noticed a pattern nobody else was checking.

Most self-funded plan sponsors never look closely enough to find that pattern on their own plan, and industry data suggests TPA error rates run between 1% and 10% of processed claims, depending on the audit methodology used. For a plan paying $20 million a year in claims, that range represents anywhere from $200,000 to $2 million in errors that nobody is actively hunting for.

Key Takeaways
The core problem: Most self-funded health plans independently review fewer than 5% of claims, relying primarily on TPA self-reported accuracy instead of independent verification.
The fiduciary exposure: ERISA Section 404 places the responsibility for prudent oversight on the plan sponsor, not the TPA, regardless of who processes the claims.
The dollar impact: Comprehensive independent claims audits typically recover 1% to 3% of annual claims spend, according to industry benchmarks.
The fix: Build fiduciary-grade healthcare operations through documented, ongoing and independent claims oversight rather than relying on a once-every-few-years audit.
The trend: Regulators and plaintiffs' firms are increasingly applying the 401(k) fee-litigation playbook, which has produced more than $10 billion in settlements, to the oversight of employer-sponsored health plans.
Claims accuracy is only one part of fiduciary responsibility. Self-funded employers increasingly need independent verification, documented oversight and a repeatable governance process to reduce financial leakage, strengthen ERISA compliance and withstand growing regulatory and litigation scrutiny.

What Are Fiduciary-Grade Healthcare Operations

Fiduciary-grade healthcare operations are the documented, independently verified claims oversight processes a plan sponsor uses to satisfy ERISA's prudent expert standard, rather than the minimum administrative reporting a TPA provides by default. Most plan sponsors assume their TPA's self-reported accuracy rate reflects reality. It often does not.

A TPA's administrative services agreement typically guarantees financial and payment accuracy in the 98% range. Independent audits regularly find actual accuracy closer to 96% to 97%, a gap that sounds small until it is multiplied across a plan paying eight or nine figures in annual claims. The difference between "TPA-reported" and "independently verified" is the entire fiduciary question.

Fiduciary-grade operations are not a single product or vendor. They are a standing practice: audit cadence, documentation, and a governance record that shows the plan sponsor acted as a prudent expert would, consistent with the standard set out in ERISA Section 404.

Why the Oversight Gap Exists

The oversight gap exists because TPAs have no direct financial stake in the plan's cost outcomes, and most plan sponsors lack the internal expertise to audit claims data themselves. A TPA is paid a fee to process claims, not a percentage of savings, so accuracy beyond the contracted service level agreement carries little upside for the TPA.

Plan sponsors, meanwhile, are often HR or finance leaders managing benefits as one responsibility among many. Building the coding expertise needed to catch upcoding, unbundling, or duplicate billing in-house is rarely realistic for a mid-size employer.

Restrictive audit clauses compound the problem. Many TPA contracts historically limited the number of claims a sponsor could audit, barred extrapolation of findings, or restricted which outside firms could perform the audit, though state laws such as Maine's L.D. 1906, effective for contracts issued or renewed after January 1, 2026, are starting to prohibit those restrictions.

The Real Cost of Skipping Fiduciary-Grade Oversight

Skipping independent claims oversight costs plans real money and creates fiduciary liability that follows the plan sponsor personally. A full-scope claims audit with 100% review, rather than a sampled TPA self-audit, typically recovers between 1% and 3% of annual claims spend, based on industry-reported audit outcomes.

On the enforcement side, the Department of Labor's Employee Benefits Security Administration recovered $1.4 billion for retirement, health, and welfare plans in fiscal year 2025, with $714.4 million of that tied directly to civil enforcement actions. EBSA closed 878 civil investigations that year alone, a volume that signals oversight failures are common, not rare.

Litigation risk is following the same curve. The 401(k) excessive-fee lawsuit model, which produced more than $10 billion in settlements over the past decade, is now being applied to health plan administration, with plaintiffs' firms using DOL enforcement patterns as a roadmap for building breach-of-fiduciary-duty claims against plan sponsors.

What's Actually Happening Behind the Scenes

Sampled Audits Miss Most of the Plan

A standard TPA audit typically reviews a stratified sample of 250 to 400 claims out of hundreds of thousands processed annually, then extrapolates an overall accuracy score from that small slice. The unreviewed remainder, often more than 95% of total claims, never gets examined at all.

Coding Errors Hide in High-Dollar Claims

Upcoding, unbundling, and duplicate billing tend to concentrate in complex, high-dollar claims, exactly the claims a small random sample is least likely to catch. Specialty pharmacy and inpatient facility claims carry disproportionate risk for this reason.

Dependent Eligibility Drifts Without Anyone Noticing

Ex-spouses, aged-out children, and other ineligible dependents routinely remain on plan rolls for years because eligibility verification is rarely built into ongoing claims workflows. Each ineligible dependent represents ongoing claims spend the plan should never have paid.

Automated Adjudication Approves Errors at Scale

A growing share of claims are approved through automated adjudication with no human review, which processes errors just as efficiently as it processes legitimate claims. Duplicate claims and coordination-of-benefits failures are especially prone to slipping through automated systems undetected.

Why Current Approaches Aren't Enough

Most plans still treat claims oversight as a periodic compliance task instead of an ongoing operational discipline. The table below shows how that status quo compares with a fiduciary-grade approach.

Dimension Status Quo Approach Fiduciary-Grade Approach
Audit Frequency Once every 2 to 3 years Continuous or quarterly review
Claims Reviewed Sampled (250 to 400 claims) 100% claims review using analytics
Auditor Selection TPA-recommended or TPA-owned firm Independent firm with no TPA affiliation
Documentation Informal and rarely retained Board minutes, committee charters and retained audit reports
Dependent Eligibility Reviewed sporadically, if at all Ongoing, separate audit workstream
Contract Terms Restrictive audit clauses are common Unrestricted audit rights with negotiated performance guarantees

How to Build Fiduciary-Grade Healthcare Operations

1
Commission an Independent Claims Audit
Engage an audit firm with no ownership, referral or financial relationship with your TPA. Require a comprehensive review of 100% of claims using analytics instead of relying on a limited statistical sample.
2
Strengthen Your Audit Rights
Review your administrative services agreement and remove restrictive audit clauses wherever possible. Ensure the plan can audit any claim, at any time, using any qualified independent firm, while eliminating unnecessary limitations on recoveries.
3
Separate Eligibility Audits
Treat dependent eligibility verification as its own recurring audit workstream instead of combining it with claims review. Many employers recover significant savings within months by identifying ineligible dependents early.
4
Document Every Oversight Decision
Preserve more than audit findings. Maintain committee minutes, board documentation, governance records and retained audit reports that clearly demonstrate a prudent oversight process to regulators, auditors and potential litigants.
5
Negotiate Outcome-Based TPA Guarantees
Move beyond service-level metrics such as processing speed and call-center performance. Tie TPA guarantees to independently verified financial accuracy and measurable claims performance.
6
Create an Ongoing Oversight Calendar
Replace infrequent audits with a structured monthly or quarterly review calendar. Regular oversight creates continuous accountability and establishes a documented fiduciary process that stands up to regulatory and legal scrutiny.
Fiduciary-grade healthcare operations are built through continuous oversight, independent verification and documented governance. Together, these practices improve claims accuracy, reduce financial leakage and create a defensible record of prudent fiduciary decision-making under ERISA.

Red Flags That Signal Your Plan Needs This Now

1
Commission an Independent Claims Audit
Engage an audit firm with no ownership, referral or financial relationship with your TPA. Require a comprehensive review of 100% of claims using analytics instead of relying on a limited statistical sample.
2
Strengthen Your Audit Rights
Review your administrative services agreement and remove restrictive audit clauses wherever possible. Ensure the plan can audit any claim, at any time, using any qualified independent firm, while eliminating unnecessary limitations on recoveries.
3
Separate Eligibility Audits
Treat dependent eligibility verification as its own recurring audit workstream instead of combining it with claims review. Many employers recover significant savings within months by identifying ineligible dependents early.
4
Document Every Oversight Decision
Preserve more than audit findings. Maintain committee minutes, board documentation, governance records and retained audit reports that clearly demonstrate a prudent oversight process to regulators, auditors and potential litigants.
5
Negotiate Outcome-Based TPA Guarantees
Move beyond service-level metrics such as processing speed and call-center performance. Tie TPA guarantees to independently verified financial accuracy and measurable claims performance.
6
Create an Ongoing Oversight Calendar
Replace infrequent audits with a structured monthly or quarterly review calendar. Regular oversight creates continuous accountability and establishes a documented fiduciary process that stands up to regulatory and legal scrutiny.
Fiduciary-grade healthcare operations are built through continuous oversight, independent verification and documented governance. Together, these practices improve claims accuracy, reduce financial leakage and create a defensible record of prudent fiduciary decision-making under ERISA.

The ROI of Doing It Right

Independent, full-scope claims audits typically recover 1% to 3% of annual claims spend in direct overpayment findings, and dependent eligibility audits frequently pay for themselves within months of completion.

Beyond direct recovery, fiduciary-grade documentation is itself a form of risk transfer. A plan sponsor that can produce board minutes, audit reports, and a documented TPA review process has evidence of the prudent expert standard that ERISA requires, which matters considerably if EBSA or a plaintiff's firm ever comes asking.

Think of it the way a building owner thinks about fire code compliance. The inspection itself does not prevent every fire, but the documented compliance record is what protects the owner when something goes wrong anyway. Claims audit documentation functions the same way for plan fiduciaries.

Conclusion and Next Steps

Fiduciary-grade healthcare operations are becoming the baseline expectation, not a differentiator, as EBSA enforcement activity and health plan litigation both continue climbing. Plan sponsors that wait for a regulator or a plaintiff's attorney to ask the first question have already lost the advantage of showing a prudent, documented process.

Start with an independent audit scoped to review all claims, not a sample, and build the documentation habit alongside it.

Frequently Asked Questions

What does "fiduciary-grade" mean for a health plan?

It means claims oversight and documentation practices that meet ERISA's prudent expert standard, not just a TPA's minimum reporting.

Who is legally responsible for claims accuracy on a self-funded plan?

The plan sponsor, under ERISA Section 404, regardless of which TPA processes the claims.

How often should a self-funded plan conduct a claims audit?

Independent audits should happen continuously or quarterly, not once every two to three years.

What percentage of claims contain errors?

Industry-documented TPA error rates range from roughly 1% to 10%, depending on audit scope and methodology.

How much money can a claims audit typically recover?

Full-scope, 100% claims audits typically recover 1% to 3% of annual claims spend.

Can a TPA restrict how a plan sponsor audits its own claims?

Some contracts historically did, though new state laws are increasingly prohibiting these restrictions.

Should a plan sponsor use the TPA's recommended audit firm?

No. Independent firms with no ownership or referral ties to the TPA reduce conflict-of-interest risk.

What is the fastest way to reduce fiduciary risk right now?

Document the plan's governance process, including committee minutes and retained audit reports, alongside commissioning an independent audit.

Fiduciary Intelligence

The Difference Between Payment Integrity and Fiduciary Intelligence

Abhishek Ghosh
July 31, 2026

Payment integrity is a technical process that checks whether individual claims were coded and priced correctly. Fiduciary intelligence is a governance framework that documents whether the plan sponsor prudently monitored its vendors, as ERISA Section 404 requires. Payment integrity catches claim errors. Fiduciary intelligence protects the people legally responsible for the plan.

Most self-funded plans confuse a claims tool with a legal defense, and the gap between them is where lawsuits start.

A mid-size manufacturer with 1,400 employees paid $340,000 in claims for a coordination of benefits failure that ran undetected for eighteen months (Willis Towers Watson). The plan's payment integrity vendor never flagged it because the claims were coded correctly.

The problem wasn't accuracy. It was that nobody on the plan sponsor's side could show they had monitored the TPA's handling of COB determinations at all. That gap, between a clean claim and a documented oversight process, is the entire subject of this article.

Why Payment Integrity Is Not the Same as Fiduciary Responsibility

Sixty-seven percent of covered workers in the United States are enrolled in self-funded health plans, and that share climbs to 80 percent among firms with 200 or more employees (Kaiser Family Foundation, 2025).

Every one of those employers carries fiduciary duties under the Employee Retirement Income Security Act (ERISA) regardless of whether they know it. Payment integrity is one useful tool for managing plan spend.

It is not the same thing as meeting that legal duty, and treating the two as interchangeable leaves plan sponsors exposed.

Key Takeaways
Payment integrity focuses on whether individual claims were priced, coded and paid correctly. It is primarily a claims accuracy function.
Fiduciary intelligence goes beyond claims accuracy by documenting that the plan sponsor prudently monitored service providers and fulfilled its oversight responsibilities under ERISA Section 404.
A plan can achieve excellent payment integrity results and still fail a fiduciary review if it cannot demonstrate a documented, prudent oversight process.
TPA-reported error rates are often lower than independent audit findings because most TPA self-audits review less than 1% of total claims rather than the full claims population.
Even when a TPA processes every claim, ERISA places fiduciary responsibility for claims oversight and payment accuracy on the plan sponsor.
Payment integrity helps ensure claims are paid correctly. Fiduciary intelligence demonstrates that the plan sponsor exercised prudent oversight. Self-funded plans need both to reduce financial leakage, strengthen governance and satisfy ERISA fiduciary expectations.

What Payment Integrity Actually Does

Payment integrity is the set of technical processes and software that verify whether a submitted claim was billed, coded, and priced correctly before or after payment. It answers a narrow question: did the plan pay the right dollar amount for this specific service.

Most people assume payment integrity is a comprehensive safeguard for the plan. It is not designed to be one. It is a claims-accuracy layer, built to catch duplicate billing, upcoding, and pricing errors against contracted rates. The global payment integrity market has grown to roughly $9 billion, expanding at about 7 percent annually as payers invest more heavily in automated claims review (McKinsey).

The tools are genuinely useful. They catch a meaningful share of overpayments that would otherwise slip through automated adjudication. What they do not do is document whether the plan sponsor exercised the kind of ongoing, independent oversight that ERISA requires of a fiduciary.

A payment integrity report can show a clean claims file and still leave a plan sponsor unable to answer basic questions about vendor monitoring, fee reasonableness, or conflict of interest review.

Why the Gap Exists

The gap between payment integrity and fiduciary protection exists because most self-funded plans were designed for administrative efficiency, not employer oversight. Standard administrative services agreements typically treat a small sampling audit as the complete review, and plan sponsors accept it because it has been considered the industry standard for decades.

TPAs may have limited incentives to identify their own payment errors. Industry studies report claims processing error rates of 2% to 6%, depending on the source and plan complexity (Baker Tilly). At the same time, many TPAs report self-audit accuracy rates close to 99% (ClaimInformatics). This does not necessarily mean either number is wrong. They measure different things. Self-audits often focus on processing accuracy and system rules, not whether the correct amount was ultimately paid.

There is also a structural asymmetry in who has access to the data. Many TPAs release detailed claims files only upon request, often in formats that require technical expertise to analyze (Benosphere). Under ERISA Section 404(a)(1)(B), the fiduciary must act "with the care, skill, prudence, and diligence" of a prudent expert (U.S. Department of Labor). It is difficult to meet that standard when the party being monitored controls the data used to monitor it.

The Real Cost of Treating Payment Integrity as Sufficient

Self-funded employers spending between $10 million and $100 million annually in healthcare claims face $200,000 to $2 million in unrecovered leakage under even a conservative 2 percent error rate (ClaimInformatics). Payment integrity tools recover some of that. Independent claims audits with full review typically recover an additional 1 percent to 3 percent of annual claims spend on top of whatever the TPA's own systems caught (Benosphere).

The financial cost is real but it is not the largest exposure. The fiduciary cost is. ERISA fiduciaries who breach their duties can be held personally liable to restore plan losses, and courts have referred to fiduciary obligations under the statute as among "the highest known to law" (ASPPA). A plan sponsor that relied entirely on a TPA's self-reported payment integrity metrics, with no independent verification, has a documentation problem the moment a participant or the Department of Labor asks how oversight was performed.

Consider the analogy of a building inspector who only checks whether individual bricks meet code. That inspector can sign off on every brick and still miss that the foundation was never surveyed. Payment integrity checks bricks. Fiduciary intelligence checks whether anyone verified the foundation.

What's Actually Happening Behind the Scenes

Sampling Gaps

A standard TPA audit reviews a stratified sample, commonly 200 to 400 claims, against plan documents (Baker Tilly). For a plan processing 80,000 claims annually, that represents roughly 0.3 percent to 0.5 percent of total claims volume (Benosphere). The remaining 99.5 percent goes unreviewed by anyone independent of the TPA.

Coordination of Benefits Failures

COB errors occur when a plan pays as primary when another payer, such as Medicare or a spouse's plan, should have paid first. A COB failure can produce a 60 percent to 80 percent overpayment on the affected claim (Benosphere), and these errors are difficult for automated payment integrity tools to catch because the claim itself may be coded correctly.

Vendor Fee Structures on Recovered Dollars

When TPAs or carrier-affiliated vendors do identify and recover overpayments, they frequently retain a substantial share. Post-pay recovery programs commonly take 40 percent to 50 percent of recovered dollars (ClaimInformatics), which means even a functioning payment integrity process may return less value to the plan than the raw recovery number suggests.

Governance Documentation

DOL guidance emphasizes that fiduciaries must document their decision-making process, not simply achieve a good outcome (DOL elaws Fiduciary Advisor). A payment integrity dashboard, no matter how sophisticated, is not itself governance documentation unless the plan sponsor can show it was reviewed, questioned, and acted upon.

Why Current Approaches Aren't Enough

Dimension Payment Integrity Alone Fiduciary Intelligence Framework
Primary Question Answered Was this claim priced correctly? Did the plan sponsor prudently monitor its vendors?
Data Source Often TPA self-reported Independent, plan sponsor-controlled
Coverage Sampled or automated claims review Full documentation of oversight activities, decisions and rationale
Legal Standard Addressed None directly ERISA Section 404(a) prudent expert standard
Primary Output Error reports and recovery opportunities Governance record including committee minutes, vendor reviews and documented oversight
Who It Protects The plan's financial assets The plan sponsor and named fiduciaries

How to fix it

1
Separate Payment Integrity from Fiduciary Oversight
Ask your payment integrity vendor what claim errors it identifies, then separately determine who is responsible for documenting your fiduciary oversight process. These are different responsibilities and are rarely delivered by the same provider.
2
Request Full Claims Data Access
Obtain detailed claims data instead of relying on summary reports. The Consolidated Appropriations Act strengthened plan sponsors' ability to access detailed claims information from TPAs and PBMs, making independent review more practical.
3
Establish a Regular Review Cadence
Hold monthly or quarterly committee meetings to review vendor performance and document decisions. Meeting minutes create the governance record regulators and courts expect to see.
4
Use an Independent Claims Auditor
Select an audit firm with no ownership or financial relationship to your TPA. Independence strengthens both the credibility of audit findings and the fiduciary value of the review.
5
Benchmark Vendor Fees
Understand how your audit vendor is compensated, including any share of recovered overpayments, before signing the agreement. Transparent pricing supports better vendor governance.
6
Build a Fiduciary File Every Year
Maintain a complete record of audit reports, committee minutes, vendor scorecards and correspondence related to identified issues. This documentation demonstrates a consistent, prudent oversight process under ERISA.
Effective fiduciary oversight combines independent verification, documented governance and regular vendor accountability. Together, these practices improve claims accuracy, strengthen ERISA compliance and create a defensible record of prudent decision-making.

Red Flags That Signal the Gap Applies to Your Plan

You receive a payment integrity or TPA audit summary but cannot describe the sample size or methodology behind it.
Your administrative services agreement restricts which firms can audit your claims or limits when audits can be performed.
You have not obtained detailed claims data independently within the last 12 months.
Pharmacy and specialty drug claims are not reviewed separately against contract pricing terms.
Your plan changed TPAs within the last three years, and claims from the previous administrator were never independently reviewed.
You cannot produce committee minutes or documentation showing vendor performance was actively reviewed rather than simply received.
No one on your team can answer "What was our overpayment rate last year?" with a specific number.
If three or more of these statements describe your plan, there is a strong possibility that payment errors, hidden overpayments and fiduciary risks are going undetected. Independent claims oversight, documented governance and regular vendor reviews help close these gaps before they become costly.

The ROI of Doing It Right

Independent claims audits with full review typically find discrepancies in 3 percent to 5 percent of paid claims costs, with actual recoveries in the 1 percent to 2 percent range (MedInsight). On a $30 million annual claims spend, that is $300,000 to $600,000 in identified overpayments, with $300,000 to $600,000 recoverable even under conservative assumptions.

The larger return is harder to put a number on but matters more in a dispute. A documented fiduciary process, maintained consistently across plan years, is described by the DOL as the strongest defense against audits and litigation (Ascensus). Plans that can produce that record are simply in a different legal position than plans that cannot, regardless of how their payment integrity metrics look in isolation.

Dependent eligibility reviews, treated as a distinct workstream from claims audits, frequently pay for themselves within months (Benosphere) and are one of the fastest ways to demonstrate near-term ROI while the broader fiduciary documentation process is being built out.

Conclusion and Next Steps

Payment integrity and fiduciary intelligence solve different problems, and a self-funded plan needs both. Payment integrity keeps individual claims accurate. Fiduciary intelligence protects the plan sponsor and named fiduciaries by documenting that oversight actually happened, in the way ERISA requires.

The gap between the two is exactly where fiduciary breach claims originate. Closing it does not require replacing your payment integrity vendor. It requires building a separate, deliberate governance record alongside it. [internal link: TPA performance guarantees guide] can help you evaluate whether your current vendor contract measures the right things, and [internal link: claims audit vs payment integrity comparison] walks through how to structure both functions without duplicating cost.

Frequently Asked Questions

Is payment integrity the same as fiduciary compliance?

No. Payment integrity checks individual claims accuracy. Fiduciary compliance requires documented, independent oversight of vendors under ERISA Section 404.

Who is legally responsible for claims errors, the TPA or the plan sponsor?

The plan sponsor. ERISA places fiduciary responsibility on the sponsor, not the TPA, even though the TPA processes the claims.

What does ERISA Section 404 actually require?

It requires fiduciaries to act with the care, skill, prudence, and diligence of a prudent expert familiar with plan administration.

How often should a self-funded plan run an independent claims audit?

Industry guidance generally recommends every two to three years, with more frequent monitoring for larger or higher-risk plans.

Can a plan sponsor rely on a TPA's self-reported accuracy numbers?

Relying solely on self-reported data, without independent verification, does not demonstrate the prudent oversight ERISA requires.

What percentage of claims does a typical TPA audit actually review?

Often well under 1 percent of total claims volume, since standard TPA audits use small stratified samples.

Does the Consolidated Appropriations Act change plan sponsor audit rights?

Yes. It strengthened plan sponsors' rights to full claims data access from TPAs and PBMs upon request.

What is the single most common dollar-weighted claims error?

Duplicate billing, followed closely by coordination of benefits failures on claims that should have paid secondary.

Fiduciary Intelligence

Fiduciary Intelligence: The TPA Oversight Gap Explained

Abhishek Ghosh
July 10, 2026

Fiduciary intelligence is the independent claims oversight layer that sits between a third-party administrator (TPA) and a self-funded employer. It combines ongoing claims monitoring, audit documentation and vendor accountability data so plan sponsors can meet ERISA Section 404 duties instead of relying solely on the TPA's self-reported performance numbers.

A regional manufacturer with 1,400 employees ran an independent claims audit in 2024 and found $812,000 in overpayments across 18 months. The errors included a $47,000 inpatient claim paid twice, 63 ineligible dependents still active on the plan, and a specialty drug billed at 240% of the contracted rate. None of it showed up in the TPA's internal reporting, because none of it was ever reviewed.

That is not a rare story. It is the default outcome for a self-funded plan that treats its TPA's word as the audit. Most employer plans have no independent layer checking whether claims were paid correctly, and by the time anyone notices, the money is gone and the fiduciary exposure has already accrued.

Key Takeaways
Approximately 67% of covered workers are enrolled in self-funded health plans, rising to nearly 80% among employees at large organizations, making claims oversight a widespread employer responsibility.
Most self-funded plans independently review fewer than 5% of claims each year, relying primarily on TPA-run sampling that examines only a few hundred claims from a much larger population.
Industry research places typical TPA payment error rates between 1% and 6%, while comprehensive independent audits often identify error rates of 5% to 12% when every claim is reviewed.
ERISA Section 404 assigns fiduciary responsibility for claims accuracy to the plan sponsor, even when claims administration is delegated to a third-party administrator.
A comprehensive independent claims audit typically recovers 1% to 3% of annual claims spend. For a plan spending $20 million each year, that can translate into approximately $200,000 to $600,000 in recoverable overpayments.
As self-funded plans continue to grow, relying solely on TPA sampling leaves significant financial and fiduciary risk unchecked. Independent claims oversight provides the visibility needed to recover overpayments, validate payment accuracy and demonstrate a prudent governance process under ERISA.

What Fiduciary Intelligence Actually Means

Fiduciary intelligence is the independent oversight layer that verifies TPA claims performance instead of trusting it. Most employers assume their TPA relationship already includes this. It does not.

A TPA's job is to process claims according to plan documents and network contracts. A TPA's incentive is speed and member satisfaction, not necessarily financial accuracy on every dollar. Those two things frequently pull in different directions, and nothing in a standard administrative services agreement forces alignment.

The common assumption is that performance guarantees in the ASO contract already cover this ground. In reality, most guarantees measure turnaround time and claims-processing speed, not whether the dollar amount paid was correct. A TPA can hit every service level target in its contract while still overpaying claims at a rate the plan sponsor never sees.

Why the Oversight Gap Exists

The gap exists because plan sponsors delegate claims processing but rarely build independent verification into the relationship. Self-funded plans took off because employers wanted to bend the cost curve and gain flexibility insurance carriers do not offer. What did not scale at the same pace was internal expertise to monitor what a TPA actually does with that authority.

TPAs are not financially responsible for the plan. Their costs are covered by administrative fees, not by how accurately claims are paid, so they lack the same financial incentive an insurer carrying its own risk would have. That is not a matter of bad faith. It is simply a structural incentive problem plan sponsors need to correct with independent checks, not TPA good intentions.

Carrier and TPA post-pay sampling reviews typically cover only 3% to 5% of claims, and many ASO agreements specify an annual sample of just 300 to 350 claims regardless of plan size. A plan processing 200,000 claims a year can have 99.8% of its payments never independently reviewed by anyone outside the TPA that made the payment.

The Real Cost of an Unreviewed Plan

Unreviewed claims translate directly into unrecovered dollars, and the scale is larger than most benefits committees assume. Independent, full-population claims analysis consistently identifies error rates between 5% and 12% once every claim is checked instead of a sample, according to third-party claims analytics data covering more than $16 billion in reviewed claims. Industry benchmarks that rely on standard TPA sampling report a narrower 1% to 3% error range, largely because sampling catches fewer error types than a comprehensive review.

The dollar impact compounds quickly. A plan spending $20 million a year that carries even a 2% unrecovered error rate is looking at $400,000 walking out the door annually, before accounting for coordination of benefits failures or dependent eligibility errors that carry their own separate cost.

Consider the manufacturer's numbers again. Sixty-three ineligible dependents sitting on a plan for even one plan year can add tens of thousands of dollars in claims paid for people who should never have been covered. A single misapplied coordination of benefits rule, where the plan should have paid secondary but paid as primary instead, often produces a 60% to 80% overpayment on that specific claim.

What's Actually Happening Behind the Scenes

Coordination of Benefits Failures

Coordination of benefits, or COB, determines which plan pays first when a member has more than one source of coverage. When a TPA's system fails to catch a spouse's other employer coverage or a dependent's eligibility for a separate plan, the self-funded plan can end up paying as primary when it should be secondary. That single misconfiguration routinely produces overpayments in the 60% to 80% range on the affected claims.

Upcoding and Unbundling

Upcoding happens when a provider bills a higher-acuity procedure code than the service actually supports. Unbundling separates a single comprehensive procedure into multiple line items billed individually, inflating the total. Both require clinical and coding expertise to catch, which is exactly why standard TPA sampling rarely flags them.

Dependent Eligibility Drift

Employees change marital status, dependents age out, and COBRA windows close, but eligibility files do not always update on schedule. A plan that has not run a dependent eligibility verification in several years is very likely still paying claims for people who are no longer eligible for coverage.

Out-of-Network and Surprise Billing Gaps

Even after the No Surprises Act took effect, out-of-network claims can still slip through with billed charges well above usual and customary rates when a plan is not actively reviewing them. Without active oversight, the plan simply pays whatever the TPA's repricing engine calculates, correct or not.

Specialty Pharmacy Spend

Specialty drugs now account for more than half of pharmacy spend on many self-funded plans, and pricing errors in this category carry outsized dollar impact per incident compared to medical claims. A single misapplied contract rate on a specialty drug claim can run into tens of thousands of dollars.

Why Current Approaches Aren't Enough

Standard TPA performance guarantees were built to measure operational speed, not financial accuracy, and that mismatch is the core problem plan sponsors need to solve.

Status Quo (TPA Self-Reporting) Fiduciary Intelligence Approach
Reviews only 3% to 5% of claims through internal sampling. Reviews close to 100% of claims through ongoing independent monitoring.
Measures turnaround time and procedural accuracy. Measures financial accuracy and actual overpayment rates.
Findings are reported by the same organization being evaluated. Findings are reported by an independent party with no claims processing conflict.
Periodic audit every two to three years, if conducted at all. Continuous monthly or quarterly monitoring supported by a documented audit trail.
Little or no fiduciary documentation between audits. Board-ready documentation demonstrating a prudent, ongoing oversight process.
Recovery fees are often deducted from the plan's own recovered assets. Transparent fee structure negotiated independently of the TPA.

How to Fix It

1
Confirm Your Audit Rights
Review your ASO agreement to ensure the plan can audit any claim, at any time, using any qualified independent firm. Renegotiate restrictive clauses at the next renewal if they limit these rights.
2
Audit Dependent Eligibility Separately
Treat dependent eligibility verification as its own workstream rather than part of the claims audit. These reviews often recover enough unnecessary costs to pay for themselves within months.
3
Replace Periodic Audits with Ongoing Monitoring
A claims audit performed every few years identifies problems after they have accumulated. Monthly or quarterly independent reviews catch payment errors while they are still small and easier to recover.
4
Choose an Independent Auditor
Select an audit firm with no ownership or financial relationship to your TPA. Look for organizations that combine clinical review, coding expertise and contingency or hybrid pricing models.
5
Strengthen TPA Performance Guarantees
Expand TPA performance guarantees beyond procedural metrics by including measurable financial accuracy standards and overpayment rate targets tied to contractual remedies.
6
Document the Oversight Process
Keep board minutes, committee charters, audit reports and corrective actions on file. This documentation demonstrates that a prudent fiduciary process was followed if your plan is ever reviewed by the Department of Labor or challenged in litigation.
Effective claims oversight depends on strong audit rights, independent verification and continuous monitoring. Together, these practices improve payment accuracy, strengthen fiduciary governance and reduce long-term financial leakage.

Red Flags That Signal the Problem Applies to Your Plan

You cannot state your plan's overpayment rate for the last plan year with an actual number.
Your TPA's performance guarantees measure processing speed and procedural compliance rather than financial accuracy.
Independent claims audit reporting is not a standing agenda item for your benefits committee.
Your last independent claims audit was conducted more than three years ago, or your plan has never had one.
Your audit rights clause restricts which firms can review claims or limits how often audits can be performed.
Dependent eligibility has not been independently verified since your last major open enrollment update.
If three or more of these statements describe your plan, it is likely carrying recoverable overpayments along with meaningful fiduciary exposure. Independent claims oversight can help uncover hidden payment errors, strengthen governance and create a documented process that supports ERISA compliance.

The ROI of Doing It Right

A full independent claims audit typically recovers 1% to 3% of annual claims spending on its first pass. For a plan spending $20 million a year, that translates to $200,000 to $600,000 recovered, often within the first audit cycle. Ongoing monthly or quarterly monitoring tends to catch errors closer to the point of payment, which both prevents future leakage and creates a documented accountability trail with the TPA.

Audit costs are typically far lower than the amount recovered, particularly for mid-sized and large plans. Beyond the direct dollar recovery, the process strengthens vendor negotiating position at renewal and produces the kind of documentation that demonstrates a prudent fiduciary process, which matters enormously if the Department of Labor's Employee Benefits Security Administration ever opens an inquiry.

EBSA recovered more than $1.4 billion for retirement, health and welfare plans in fiscal year 2025 alone, closing 878 civil investigations with 556 producing monetary or corrective results.

Conclusion and Next Steps

Self-funded plans now cover the majority of American workers with employer health benefits, and that share keeps growing. Every one of those plans carries fiduciary duties that do not pause just because a TPA is handling the paperwork. Fiduciary intelligence, in the form of independent claims oversight, is what actually closes that gap between delegation and accountability.

The next step is straightforward. Pull your ASO agreement and check the audit rights clause, then ask your benefits committee when the plan's claims were last independently reviewed. If nobody has a confident answer, that is the signal to schedule a claims audit and dependent eligibility review before the next renewal cycle.

Frequently Asked Questions

What is fiduciary intelligence in the context of self-funded health plans?

It is the independent oversight layer, combining claims monitoring and audit documentation, that verifies TPA performance rather than relying on the TPA's own reporting.

Who holds fiduciary responsibility for claims accuracy under ERISA?

The plan sponsor, under ERISA Section 404, regardless of which vendor actually processes and pays the claims. [external link: DOL/EBSA fiduciary responsibilities guide]

How often should a self-funded plan audit its TPA?

At minimum every one to two years for larger plans, with ongoing monthly or quarterly monitoring recommended between formal audits.

What percentage of claims does a typical TPA sampling audit review?

Roughly 3% to 5%, often limited to a fixed sample of 300 to 350 claims per year regardless of total plan size.

How much can an independent claims audit typically recover?

Most first-time audits recover 1% to 3% of annual claims spend, which can total hundreds of thousands of dollars on mid-sized plans.

What is the difference between a TPA performance guarantee and a fiduciary audit?

Performance guarantees measure speed and procedural accuracy; a fiduciary audit measures whether the dollar amount paid was actually correct.

Can a plan sponsor be held personally liable for TPA errors it never discovered?

Yes. ERISA fiduciary duty requires a prudent ongoing process, and failing to monitor a TPA can itself constitute a breach regardless of who made the underlying error.

What is coordination of benefits and why does it matter for claims accuracy?

COB determines which plan pays first when a member has multiple coverage sources; failures here commonly cause 60% to 80% overpayments on affected claims.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Stay informed about employee wellness

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.