Let our team help you navigate the ever-changing benefits compliance landscape each month. Check out this month’s latest alerts, additional updates, and resources hot off the press:

Employee Benefits Compliance Alerts

This month’s Compliance Matters newsletter provides a comprehensive review of the following topics. To obtain your copy, please use the form below to download.

  • Medicare Part D Notices Due to Individuals Before October 15
  • Gag Clause Prohibition Attestations Due December 31
  • Fifth Circuit Requires Changes to NSA Payment Calculations
  • EBSA Updates Mental Health Parity NQTL Analysis Guidance
  • Tobacco Surcharges: Regulation Refresher and New Guidance
  • State Series: Vermont’s Health Care Fund Assessment

Download this month’s alerts

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Newsletter Subscription

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
This field is hidden when viewing the form

Additional Updates & Resources

ICHRA is Now CHOICE

The Centers for Medicare and Medicaid Services (CMS) and the Small Business Bureau (SBA) announced that the Individual Coverage Health Reimbursement Arrangement (ICHRA) has been renamed the Custom Health Option and Individual Care Expense (CHOICE) Arrangement. The rules for how an ICHRA, now called a CHOICE Arrangement, operate are unchanged.

CMS posted an employer guide, and the SBA is presenting CHOICE Arrangements as an option for small businesses trying either to offer health benefits for the first time or to escape increasingly unaffordable group-plan renewals.

This name change corresponds with legislation introduced in both the House (HR 5463 – CHOICE Arrangement Act) and Senate (S. 2875 CHOICE Act), which would codify and expand ICHRAs. If either of those become law, we will provide updates as necessary.

Tax Avoidance Schemes Continue to be Problematic

We continue to encounter vendors aggressively marketing programs that promise substantial tax savings for both employers and employees by offering a variety of tax-favored benefits and reimbursement arrangements. While many of these programs include legitimate benefits (e.g., preventive care, telehealth services, counseling, etc.) that may be excluded from employees’ taxable income in appropriate circumstances, the tax savings often appear to be driven by the volume of payroll dollars being redirected into these arrangements rather than by the value of the qualifying benefits themselves. As a result, the amount withheld from employees’ pay and later reimbursed on a purportedly tax-free basis may significantly exceed what can reasonably be treated as tax-favored under existing tax rules, creating a risk that employees are underpaying income taxes and employers are underpaying payroll taxes.

Employers proceeding with such arrangements should understand the potential tax risks to employees and themselves if the Internal Revenue Service (IRS) decides to get more aggressive with enforcement around these types of programs. EPIC recommends that any employer considering one of these arrangements should seek guidance from their Employee Retirement Income Security Act (ERISA) counsel.

HHS Releases Updated Security Risk Assessment Tool

On September 9, 2026, the Department of Health and Human Services (HHS) released an updated Security Risk Assessment (SRA) Tool. The SRA tool can be used by employer plan sponsors subject to the Health Insurance Portability and Accountability Act (HIPAA) as a free resource to assist covered entities and business associates in meeting HIPAA Security Rule requirements to conduct and maintain a risk analysis of electronic protected health information (ePHI). The latest enhancements reflect evolving cybersecurity risks and include new questions addressing remote access to ePHI, coverage of all locations where ePHI is maintained, updated technology inventories and system activity logging, guidance on when risk assessments should be revisited following events such as mergers, acquisitions, technology changes, or security incidents, and improved reporting and software security features. Given ongoing Office of Civil Rights (OCR) enforcement efforts focused on risk analysis compliance, employer plan sponsors should consider using the updated tool to periodically reassess security risks, update risk management strategies, and ensure HIPAA privacy and security policies remain aligned with current regulatory expectations and cybersecurity best practices. Access the new SRA on the OCR website.

HRA Council Releases 2026 Report

The Health Reimbursement Arrangement (HRA) Council’s 2026 “Growth Trends for ICHRA & QSEHRA” report finds continued strong growth in employer use of Individual Coverage HRAs (ICHRAs) and Qualified Small Employer HRAs (QSEHRAs), with applicable large employers representing the fastest-growing ICHRA segment. The report also finds that ICHRA enrollees tend to be younger than the existing ACA individual-market population, with more than half of enrollments involving employees under age 45, potentially strengthening the Affordable Care Act (ACA) marketplace risk pool. Despite 2026 individual market changes, including the expiration of enhanced premium tax credits, the HRA Council describes ICHRA adoption as growing and playing an important role in benefit strategy for employers.

Updated CHIP Notice Published

The U.S. Department of Labor (DOL) has updated its Model CHIP Notice, with the latest version dated July 31, 2026. Employers that are subject to the CHIP notice requirement should use the updated model notice when providing information to employees about potential premium assistance opportunities available through Medicaid or the Children’s Health Insurance Program (CHIP). The notice is required to be provided upon initial eligibility and during open enrollment for group health plan coverage.

Court Rules Arkansas Reporting Requirement is Not Preempted by ERISA

Recently, the Seventh Circuit Court of Appeals, confirmed that the Employee Retirement Income Security Act (ERISA) does not preempt an Arkansas law requiring health plans and other payors, including ERISA-covered plans, to report pharmacy compensation data and, in certain circumstances, pay an additional dispensing fee when the state determines reimbursement is inadequate. The court concluded that these requirements are permissible state regulations of pharmacy reimbursement costs and do not impermissibly dictate plan design, network structure, benefit offerings, or participant cost-sharing arrangements. The decision reinforces that self-insured and other ERISA plan sponsors may still be subject to certain state pharmacy benefit manager (PBM)-related requirements when those laws primarily regulate costs and include only incidental reporting obligations necessary to enforce the state law. Accordingly, employers with health plans that provide pharmacy benefits in Arkansas should review their PBM arrangements and reporting obligations to determine whether the state requirements apply to their plans, while continuing to monitor ongoing ERISA preemption developments and forthcoming federal pharmacy reporting requirements.

Building with Columns in Front

More Compliance Resources