Most self-funded employers signed away a right they did not know they had. Buried in the network and administrative-services agreements that make a health plan run, a single clause can quietly forbid the plan from seeing what its own care actually costs — which providers charge what, how quality varies, and where the claims dollars go. The Consolidated Appropriations Act of 2021 outlawed those clauses, and it did something more pointed than that: it put the burden of proving their absence on the employer, not the carrier. Every year, that proof comes due on December 31.
The mechanism is the Gag Clause Prohibition Compliance Attestation, filed through the CMS webform. It applies broadly — fully insured plans, self-funded plans, ERISA plans, non-federal governmental plans, church plans, even grandfathered plans — and it has been due annually since the first attestation on December 31, 2023, covering the period since the last one. For a fully insured plan, the carrier generally attests. For a self-funded plan, the responsibility is the employer’s, and it does not transfer. A plan sponsor may delegate the filing to a third-party administrator by written agreement, but if the TPA fails to file, the legal exposure remains with the sponsor. The attestation is a fiduciary act wearing the costume of a compliance form.
What the law actually prohibits is worth stating plainly, because the phrase “gag clause” sounds narrower than the provision is. A prohibited clause is any contract term that restricts the plan from three things: sharing provider-specific cost and quality information with participants, plan sponsors, or referring providers; accessing de-identified claims and encounter data, by group or by individual, consistent with privacy law; and sharing that permitted information with a business associate such as a broker, an actuary, or an independent consultant. In other words, the exact data a self-funded employer needs to manage its plan is the data these clauses were written to withhold.
That is why this is not a peripheral compliance chore for a self-funded plan — it strikes at the premise of self-funding itself. An employer that has chosen to bear its own claims risk, whether directly or through a group captive, has made a decision to own the outcome. Ownership without information is a contradiction. A plan cannot steer members toward higher-value providers it is contractually forbidden to identify, cannot audit a claims administrator whose data it cannot see, and cannot demonstrate prudent management of plan assets when a vendor contract blindfolds the fiduciary. The gag clause and the self-funded strategy are working against each other, and the attestation is the moment that conflict surfaces.
The fiduciary stakes have risen alongside a broader wave of health-plan litigation. Plan participants and regulators have grown far more willing to test whether fiduciaries actually managed plan costs or merely rubber-stamped a renewal, and the same duty of prudence that governs a retirement plan governs a health plan. A gag clause that a fiduciary never read, never questioned, and never removed is precisely the kind of unexamined term that turns an ordinary administrative relationship into a breach. Non-compliance with the attestation itself can expose the plan to Department of Labor enforcement and the fiduciary to personal liability, and it undercuts any later argument that the plan was managed with care.
The 2026 attestation carries a sharper edge than earlier ones. Guidance now makes clear that the attestation reaches downstream — the agreements a TPA or insurer holds with other parties, such as the owner of a provider network, not merely the contract the plan signed directly. A sponsor is expected to require, contractually, that its vendors carry the prohibition down the chain, and where a vendor refuses to remove an offending clause, the plan reports the vendor to CMS through the webform rather than simply attesting around the problem. The disciplined move is to read the network and administrative agreements before the December deadline, not to sign a blanket attestation and hope the downstream contracts are clean.
None of this is difficult in principle; it is difficult only when it is left to the last week of December and treated as a signature rather than a review. The plan that treats the attestation as an annual audit of its own contracts — confirming its data-access rights, its transparency provisions, and its vendors’ downstream obligations — converts a compliance deadline into a governance advantage.
This is exactly the discipline our 4-Step Strategic Process is built to impose. Strategic Discovery inventories the plan’s administrative, network, and pharmacy agreements and the data-access rights inside each. Risk Assessment reads those contracts against the gag-clause prohibition and against the transparency a self-funded or captive strategy actually requires. Solution Design rewrites the vendor requirements so the plan owns its data by contract, not by request, and documents the attestation as the fiduciary record it is. Ongoing Optimization keeps the review on the calendar every year, so December 31 arrives as a confirmation rather than a scramble. A self-funded plan that cannot see its own claims is not truly self-funded — it is fully insured with extra steps, and the attestation is the annual reminder to close that gap.
Sources: Centers for Medicare & Medicaid Services — Gag Clause Prohibition Compliance Attestation; OneDigital — What Employers Need to Know about the GCPCA; MZQ Consulting — Gag Clause Attestations: Digesting the Changes for 2026; Word & Brown — Understanding the Gag Clause Attestation; International Foundation of Employee Benefit Plans (Word on Benefits) — Health Plan Gag Clause Attestation Update; NFP — Employer Compliance Guide to the CAA’s No Gag Clause and Attestation Requirements
— Ryan Mefford, President & Risk Advisor