Compliance Monthly Update: March 2026

Compliance Monthly Update

March 2026

A brief update on what happened the prior month in group health plan compliance at the federal level, organized chronologically. An update for the state and local level are further down. If you would like additional information, please reach out to the GBS Compliance Team.

Federal Compliance Update

Reporting instructions released for 2025 RxDC reporting due June 1, 2026.

On March 3, CMS released updated instructions and template data forms for group health plans and insurers to report prescription drug and health care spending data, as required by the Consolidated Appropriations Act, 2021 (CAA 2021).  The updated Prescription Drug Data Collection (RxDC) Reporting Instructions are for the 2025 reference year reporting that is due June 1, 2026.  There are no substantive changes to the instructions or templates other than revising the reference year from 2024 to 2025.  The instructions provide step-by-step guidance for submitting data through the RxDC module in the Health Insurance Oversight System (HIOS).  See the CMS RxDC webpage for more information and for the updated instructions and forms.  Employers should (a) reach out to their carriers, TPAs, or PBMs (as applicable) to confirm that they will submit the RxDC reports for their group health plan(s), (b) make sure their written agreements with these third parties have been updated to reflect this reporting responsibility, (c) be on the lookout for communications and data requests from these third parties and respond in a timely manner so they can submit data on behalf of the group health plan, and (d) monitor and document their carrier’s, TPA’s, or PBM’s compliance.  Employers who miss the carrier/TPA/PBM deadlines (as well as employers whose carrier/TPA/PBM will not complete the filing for them) will need to register and upload files in the HIOS system.  Employers who need to file using HIOS will want to make sure they carefully review and follow the reporting instructions.

IRS issues proposed rules on Trump Accounts and $1000 pilot contribution program

On March 6, the IRS issued two proposed regulations on Trump Accounts.  The first proposed rule (and associated new release) is on the governing basics of setting up Trump Accounts.  The second proposed rule (and associated news release) discusses the $1000 pilot contribution program that is available for children born between 2025 and 2028.  These proposed rules mirror guidance in the previously issued Notice 2025-68 (that we discussed in our December 2025 monthly update) and provides limited additional details.  Note that these proposed rules do not include guidance on employer contributions to Trump accounts under new IRS Code Section 128 or employee cafeteria (Section 125) plan elections to contribute pre-tax amounts to the accounts.  Guidance on those issues as well as other issues such as investments, distributions, and the rollover of amounts from the initial Trump accounts are expected to be issued later this year.

 

Updates on PBM fiduciary lawsuits.

There have been several class action lawsuits against large employers that alleged fiduciary breaches related to prescription drug costs.  We discussed last December that a federal court dismissed (on standing grounds) the putative class action lawsuit against Johnson & Johnson that alleged the plan fiduciaries had mismanaged its self-funded health plan’s prescription drug benefits in its selection of the PBM and by overpaying for specialty generic drugs offered on the plan’s formulary.  The Johnson & Johnson case has been appealed to the Third Circuit Court of Appeals.  Here are some updates on other PBM fiduciary cases.

  • On March 3, a federal court dismissed a class action lawsuit alleging that Wells Fargo imprudently managed its self-funded health plan’s prescription drug benefit, causing the plan participants to overpay for health benefits. Like the Johnson & Johnson case, the lawsuit against Wells Fargo was dismissed on standing  It is likely this ruling will be appealed to the Eight Circuit Court of Appeals. 
  • Then on March 9, in a similar case against JPMorgan, a federal court ruled (in part) for the plaintiffs at the motion-to-dismiss stage finding that the plaintiffs did have standing and could continue with the case. However, the breach of fiduciary allegations were dismissed, which dismantles most of the plaintiff’s claims.  What remains to proceed are ERISA prohibited transaction claims because a U.S. Supreme Court decision in April of 2025 said that ERISA plaintiffs need only plausibly allege that defendants engaged in prohibited transactions to survive a motion to dismiss.  But JPMorgan may have ample defenses to the surviving claims when they provide an affirmative defense under the exemptions to the prohibited transaction claims. 
  • Regardless of the ultimate outcome of these cases, plan sponsors should make sure to continue engaging in prudent fiduciary decision-making processes for designing their benefit plans and in their selection of PBMs and other vendors. ERISA does not require plan fiduciaries to select the lowest cost vendors, rather they should make a prudent decision taking in the various factors in the vendor selection process to ensure the plans are designed and administered in participants best interests.  Having good documentation and a process in place for making prudent group health plan decisions will generally be the most effective shield against potential lawsuits.

State/Local Compliance Update

A brief update on what happened the prior month in group health plan compliance at the state and local level, listed alphabetically. If you would like additional information, please reach out to the GBS Compliance Team.

California

San Francisco Health Care Security Ordinance (HCSO) annual report due May 1.

As a reminder, the San Francisco HCSO requires covered employers to spend a minimum amount per hour on health care for eligible San Francisco covered employees.  And each year covered employers must report information about how their organization complied with the health care expenditure requirement in the prior calendar year.

    • A covered employer is an employer that (a) employs one or more workers within the geographic boundaries of the City and County of San Francisco, (b) is required to obtain a San Francisco business registration certificate, and (c) has 20 or more employees worldwide (or 50 or more worldwide for nonprofit organizations).
    • A covered employee is someone who works for a covered employer and: (a) is entitled to be paid minimum wage, (b) has been employed for at least 90 calendar days, (c) performs at least 8 hours of work per week within the geographic boundaries of San Francisco, and (d) does not meet one of the five exemption criteria.
    • Information required to be reported by May 1 about how a covered employer complied with the HCSO in the prior calendar year includes: the 7-digit San Francisco business account number for the covered employer, the number of employees who worked in San Francisco in 2025, and the types of health care expenditures made for San Francisco employees and the total amount spent.
    • The 2025 Employer Annual Reporting Form (along with instructions and resources) is available on the San Francisco HCSO website and is due May 1, 2026. Information required to be reported

Massachusetts

Court rejects individual liability and aiding-and-abetting claims under Massachusetts PFML.

A Massachusetts court has held that the Massachusetts Paid Family and Medical Leave (PFML) law does not impose individual liability and does not recognize aiding-and-abetting claims.  So, unlike other laws covering Massachusetts employers that statutorily and expressly permit claims against individual corporate officers and agents, the PFML law limits liability to the employer entity itself. 

Oklahoma

Oklahoma enacts new data privacy law.

Oklahoma became the latest state to enact a comprehensive consumer data privacy law when Governor Stitt signed SB 546 on March 20 (that takes effect on January 1, 2027).  This law is similar to other states that take a more business-friendly approach (like Virginia and Tennessee).  The new Oklahoma law applies to any businesses that conducts business in Oklahoma or produces products or services that target Oklahoma residents and that, during a calendar year either (a) controls or processes the personal data of at least 100,000 consumers, or (b) controls or processes the personal data of at least 25,000 consumers and derives more than 50% of gross revenue from the sale of personal data.  Consistent with most other state data privacy laws, the Oklahoma law contains both entity-level exemptions and data-specific exemptions.  For example, the law exempts covered entities and business associates governed by HIPAA.  And the law’s data-specific exemptions include PHI under HIPAA.

West Virginia

New West Virginia law authorizes portable benefits for independent contractors.

On March 14, the West Virginia legislature passed HB 4009 (and Governor Morrisey signed it on April 1) that will allow employers (effective June 2026) to contribute to a worker’s portable benefit account while still classifying that worker as an independent contractor (i.e., without needing to classify those workers as employees).  Portable benefits are benefits that stay with the individual and accumulate based on hours worked or a percentage of transaction fees (e.g., for rideshare or food delivery gig workers).  They can function similar to a 401(k), paid time off program, or HSA.  Instead of benefits offered by one employer, portable benefits allow workers to receive funding from multiple companies in a single account.  The law will provide an income tax deduction for contributions to and funds received in portable benefits accounts.  This is similar to other laws recently enacted in Utah and Alabama. 

Share this post
Facebook
Twitter
Telegram
WhatsApp
Pinterest
You may also like
Comments
Search
Get CRITICAL employee benefits information delivered right to your inbox!
Featured Post
Recent posts