1. Home
  2. |Insights
  3. |DOL Compliance Guidance for Health Plans

DOL Compliance Guidance for Health Plans

Client Alert | 1 min read | 05.15.03

The Department of Labor (DOL) has initiated a compliance assistance program to help employers, health plans and health insurers satisfy the requirements of certain federal health laws, such as the Health Insurance Portability and Accountability Act (HIPAA), the Mental Health Parity Act, the Newborns' and Mothers' Health Protection Act, and the Women's Health and Cancer Rights Act. In general, health plans covered by ERISA are subject to these laws, with certain limited exceptions for small businesses.

The HIPAA Compliance Assistance Program (H-CAP) is designed to address specific compliance issues. H-CAP is one of a number of programs sponsored by the DOL and Internal Revenue Service (IRS) to encourage and assist benefit plans with voluntary compliance with ERISA and the Internal Revenue Code. H-CAP consists of three major parts:

(1) new DOL publications designed to assist group health plans and health insurers comply with the laws,

(2) a new section of the DOL's Web page devoted to health law material at http://www.dol.gov/ebsa/compliance_assistance.html#section2, and

(3) DOL sponsorship of compliance assistance workshops around the U.S.

The new publications include a self-audit checklist for plans and employers; a guide summarizing the notice requirements of the various laws, including sample language; and tips for avoiding the 15 most common mistakes made by health plans and their sponsors. The list includes such matters as "hidden" pre-existing condition limitations, timely provision of special enrollment notices and certificates of creditable coverage and non-confinement clauses.

In light of DOL's increasing audit activity in the health plan area, these tools are a useful starting point to monitor plan compliance, but are not a substitute for a full HIPAA compliance review.

If you have any questions or need any additional information, please contact your regular Crowell & Moring contact or any attorney on our Health Care team.

Insights

Client Alert | 13 min read | 06.12.26

EU Cyber Resilience Act Countdown: 11 September 2026 Incident/Vulnerability Reporting Deadline Less Than 100 Days Away

The EU Cyber Resilience Act (CRA) is an EU product cybersecurity law for connected products (formally, “products with digital elements” under the CRA) commercialized in the EU; it entered into force on 10 December 2024, with direct application across the EU. Full application begins 11 December 2027, but one of its most operationally demanding provisions takes effect in just under 100 days, on 11 September 2026: the mandatory vulnerability and incident reporting under Article 14 CRA....