Compliance & Governance
ACA affordability thresholds and penalty amounts shift every year, and the pace of change keeps accelerating. HUB's employee benefits compliance work keeps organizations ahead of that pace, before a gap becomes a fine, an audit or a lawsuit.
Stay Ahead of Business Challenges
Three compliance gaps that surface only during an audit
Vendor compliance an organization can't independently verify, plan designs that drift as thresholds move and compliance deadlines split across Human Resources (HR), payroll and legal all quietly create exposure long before a regulator ever asks a question. HUB addresses all three as one coordinated discipline.
New federal and state rules increasingly hold employers accountable for their PBM, Third-Party Administrator (TPA) and carrier partners' fee transparency and disclosure practices, and most employers have no independent way to confirm those vendors are actually complying.
In practice, employers rely on their PBM's own compliance attestations, with no contract right to audit the underlying fee data — and a vendor compliant in one state may not be in another. That verification gap typically surfaces during a Department of Labor (DOL) audit or a claims dispute, after the exposure has already accumulated.
A broker relationship that actively monitors PBM/TPA/carrier compliance obligations on the employer's behalf, including state-specific variation, gives employers visibility into vendor accountability they can't reasonably build internally, vendor by vendor, state by state.
Employers assume their PBM is handling its own compliance. Increasingly, the employer is the one who gets the fine if it isn't.
Employers gain independent visibility into whether their PBM, TPA and carrier partners are meeting current fee-transparency and disclosure obligations, rather than assuming compliance by default.
The ACA affordability safe harbor and penalty amounts are recalculated every year, and they have moved in the same direction for several years running. A plan built for last year's numbers can drift out of compliance without anyone changing a thing.
A benefit plan that was fully compliant when designed can fall out of compliance purely because regulatory thresholds move every year, and some compliance failures (parity testing, nondiscrimination testing) are invisible without a deliberate comparative review — meaning a plan can look fine and still be non-compliant.
An annual plan-design compliance review, checked against that year's specific thresholds and including parity/nondiscrimination testing, not just a policy read-through, catches drift before a regulator or plaintiff's attorney does it for them at the worst possible time.
Nobody designs a non-compliant plan on purpose. They design a compliant one and then the rules move without anyone re-checking.
Employers' benefit plans stay compliant with current-year thresholds and testing requirements, rather than drifting out of compliance unnoticed year over year until an audit brings it to light.
ACA reporting, Employee Retirement Income Security Act (ERISA) disclosures, Health Insurance Portability and Accountability (HIPAA) privacy and Family and Medical Leave Act (FMLA) administration each touch a different internal function. Without one coordinated calendar and one accountable owner, deadlines get missed, audits get skipped and gaps are only found when a regulator goes looking.
ACA reporting, ERISA disclosures, HIPAA privacy obligations and FMLA policy administration each touch a different internal function — HR, payroll, legal and outside vendors — and without one coordinated calendar and one accountable owner, deadlines get missed, audits get skipped and gaps are only found when a regulator, not the employer, goes looking.
A single, coordinated compliance calendar and periodic self-audit process — spanning HR, payroll, legal and vendor relationships — replaces reactive, function-by-function compliance with one proactive, centrally owned discipline instead of four separate, uncoordinated ones that each catch only part of the picture.
Every compliance failure we see looks obvious after the fact. It just wasn't obvious to the four different people who each owned one piece of it.
Employers operate from one coordinated compliance calendar and self-audit process spanning every function involved, instead of discovering gaps only when a regulator does it for them.
Our Areas of Expertise
One compliance discipline spanning legislation, plan design and audits
Generic compliance guidance gets read once and shelved, even as thresholds and rules change every year. HUB structures Compliance & Governance as one connected discipline, so legislative monitoring, plan design review and audit practices reinforce each other instead of operating as separate, once-a-year checks.

New PBM fee-transparency rules under H.R. 7148 and proposed DOL disclosure requirements are just the latest example of a compliance burden that shifts every year, often mid-year. HUB's tracks these changes as they happen, including state-specific variation in PBM and carrier requirements that a national employer's single vendor contract may not account for. That monitoring extends to actively reviewing whether an employer's own PBM, TPA and carrier partners are meeting their disclosure obligations, rather than assuming compliance by default.
HUB reviews a plan's design against that year's specific thresholds, not just a general policy read-through, catching drift before it becomes a finding. That review includes advising on parity and nondiscrimination testing, including Mental Health Parity and Addiction Equity Act (MHPAEA) non-quantitative treatment limitation review, since a plan can look compliant on its face while still failing a more nuanced comparative test.
ACA reporting, ERISA disclosures and gag clause attestations each have their own deadline, and each typically sits with a different function. HUB's ERISA annual disclosure calendar brings these obligations into one coordinated schedule spanning HR, payroll, legal and vendor relationships, rather than leaving each function to track its own piece separately. Periodic internal audits, including dependent eligibility audits and FMLA policy and correspondence review, catch gaps proactively instead of waiting for a DOL or CMS examination to find them first.


