Group health plans are prohibited from entering into agreements containing contractual 'gag clauses' which operate to restrict access to provider cost, quality, or de-identified claims data. Most employer-sponsored group health plans must annually attest to compliance with these requirements via the Gag Clause Prohibition Compliance Attestation portal hosted by the Centers for Medicare and Medicaid Services (CMS).
CMS created a webpage with information about how to comply with the gag clause prohibition as well as how to attest to compliance, which you can find here - GCPCA - CMS
Which Plans Must Comply?
The gag clause prohibition and attestation requirements apply to most employer-sponsored health plans, but not excepted benefits (e.g., stand-alone dental or vision, health FSA), retiree-only plans, or account-based plans (e.g., HRAs). The employer should consider all contracts with service providers in connection with its health plan(s). Beyond the carriers and TPAs, there may be additional service providers that need to be considered. For example, provider contracts with and coordinated by PBMs, behavioral health vendors (e.g., network agreements for mental health providers), telehealth arrangements, direct primary care arrangements, and other medical providers (e.g., access to preferred pricing for certain procedures if using particular providers) are also prohibited from having gag clauses and should be considered by the employer when attesting to compliance.
Who Must Complete the Attestation?
Service providers (e.g., carriers or TPAs) may attest for the group health plan on behalf of sponsoring employers, but carriers and TPAs have taken a varied approach to this. If the carrier (on behalf of a fully-insured plan) or TPA (on behalf of a self-funded plan) agrees to attest on behalf of the plan, the employer can rely on that attestation. However, if the carrier, TPA, or any other service providers will not attest to compliance on the plan’s behalf, the employer needs to confirm that no gag clauses are present in the contracts they have entered into on behalf of the plan and will then need to attest accordingly.
Employer Responsibilities
Employers should establish procedures to identify all provider-related contracts, verify vendor compliance, and complete the annual CMS attestation when necessary, maintaining all documentation that supports the compliance process. Although carriers and TPAs frequently assist with filing obligations, the sponsoring employer remains legally responsible for the performance of the attestation requirement. Therefore, the gag clause attestation requirement gives rise to the following responsibilities:
- Identify all service providers that contract with plan providers (e.g., carrier, TPA, PBM, behavioral health, telehealth, etc.).
- Determine which vendors agree to submit the attestation on behalf of the underlying plan and, if possible, obtain written verification of the vendor’s agreement to perform the attestation requirement.
- If a particular vendor does not agree to submit the attestation, obtain written confirmation of actual compliance with the requirement from the vendor.
- Complete and submit the CMS attestation annually by December 31 (to the extent required).
- Maintain documentation of the vendor confirmation process and archive all CMS submission and acknowledgment receipts.
| Attestation Process |
|
The attestation process itself is a fairly straightforward, requiring only some plan identifying information, employer contact information, and a checked box and signature to indicate compliance. This is all done via a website portal. The attestation process can be broken down into 4 general steps:
|
