For overall benefits compliance, use ERISA guidance for retirement/welfare plan governance and reporting, ACA rules (and Forms 1094‑C/1095‑C) for large‑employer health coverage and IRS reporting, HIPAA for health‑data privacy, COBRA for continuation coverage, and FMLA for leave administration.
To ensure your benefits programs remain fully compliant with complex federal and state regulations, you must conduct regular internal audits, maintain up-to-date plan documents, and partner with qualified legal or third-party compliance experts.
Managing compliance effectively requires a structured approach across legal mandates, documentation, and continuous oversight.
Key Federal Regulations to Track
Affordable Care Act (ACA): Ensure applicable large employers (50+ full-time equivalents) meet minimum value, affordability standards, and file annual IRS Forms 1094 and 1095.
Employee Retirement Income Security Act (ERISA): Maintain comprehensive Wrap Plan Documents, file Form 5500 annually for applicable plans, and distribute accurate Summary Plan Descriptions (SPDs) to participants.
COBRA & HIPAA: Administer timely continuation of health coverage notices and protect the privacy and security of employee protected health information (PHI).
Align your leave policies and accommodation procedures with federal statutory definitions and notice timelines.
Build a benefits compliance calendar and audit process covering:
Federal: ERISA, ACA, COBRA, HIPAA, Mental Health Parity, FMLA, and applicable IRS rules. DOL provides self-compliance tools and model notices.
ChatGPT Search· Sep 19, 2026
Ensuring benefits programs comply with federal and state regulations requires a structured compliance process because requirements vary based on the type of benefit, employer size, funding arrangement, workforce location, and plan design. A practical approach is to build a compliance management system rather than relying on annual reviews alone.
1. Inventory every benefit plan and identify applicable laws
Ensuring benefits compliance is best treated as an ongoing compliance program, not a one-time legal review. The exact requirements depend on your workforce, plan types, employer size, funding arrangements, and the states where employees work.
1. Build a benefits compliance inventory
For every benefit, document:
Plan type: medical, dental, vision, HSA/FSA, HRA, life, disability, 401(k), PTO/leave, etc.
Whether the plan is insured, self-funded, or partially self-funded.
Who is eligible and when coverage begins.
Which states employees work in.
Plan year and renewal dates.
Third-party administrators, insurers, brokers, payroll providers, and other vendors.
Required employee notices, filings, testing, and disclosures.
Person responsible for each compliance obligation.
This gives you a single "source of truth" rather than relying on HR staff to remember individual deadlines.
2. Map the major federal requirements
For health and welfare plans, your review should generally cover ERISA, ACA, COBRA, HIPAA, MHPAEA, CHIPRA, WHCRA, the Newborns' and Mothers' Health Protection Act, and applicable federal nondiscrimination requirements. The Department of Labor specifically identifies these as important federal requirements affecting employer health plans.
Yes. The safest approach is to treat benefits compliance as an ongoing governance and audit program, not a once-a-year checklist. The exact requirements depend on your workforce, benefits, plan structure, and states where employees work.
1. Build a regulatory inventory
For each benefit, identify the federal and state rules that apply.
Common federal areas include:
ERISA — plan documents, fiduciary responsibilities, disclosures, reporting, claims procedures.
ACA — eligibility, affordability, employer mandate, coverage requirements, SBCs, preventive care, dependent coverage, and reporting.
COBRA — continuation coverage and required notices.
HIPAA — privacy, portability, special enrollment, and nondiscrimination requirements.
Mental Health Parity — comparable treatment of mental-health/substance-use benefits and medical/surgical benefits.
FMLA — leave administration and continuation of group health coverage.
You can ensure your benefits programs remain compliant by establishing formal written plan documents, conducting regular internal audits, and partnering with qualified legal counsel or a third-party administrator (TPA) to track shifting federal and state laws.
Google AI Mode· Sep 7, 2026
Ensuring your employee benefits programs remain fully compliant with a shifting landscape of federal and state regulations requires a structured, multi-layered approach. Because compliance is an ongoing process rather than a one-time fix, you need a routine cadence of audits, updates, and clear communication.
Core Steps for Benefits Compliance
Master the Federal Baselines
Review major federal acts governing employer-sponsored plans, including ERISA (Employee Retirement Income Security Act), the ACA (Affordable Care Act), COBRA, HIPAA , and the Mental Health Parity and Addiction Equity Act (MHPAEA).
Ensure large employers (50+ full-time equivalents) accurately prepare and file Forms 1094-C and 1095-C . You can review reporting guidance directly via the IRS Affordable Care Act Tax Provisions.
Yes. The safest approach is to treat benefits compliance as an ongoing governance and audit program, not a one-time legal review. Federal requirements can come from ERISA, the Internal Revenue Code, ACA, COBRA, HIPAA, MHPAEA, GINA, the No Surprises Act, and other laws; state requirements can apply particularly to insured benefits.
Sources AI cites
52% of citations to these sources link to brands' own websites.
State Paid Family and Medical Leave (PFML): Monitor state-specific payroll taxes, mandatory contributions, and leave durations where your employees reside.
State-Mandated Retirement Programs: Comply with auto-IRA programs (such as CalSavers or OregonSaves) if your state requires them and you do not sponsor a qualified retirement plan.
State Health Insurance Mandates: Adapt plan designs to adhere to state-specific coverage requirements, continuation rules (mini-COBRA), and local paid sick leave laws.
Best Practices for Ongoing Compliance
Appoint a Compliance Owner: Designate an internal professional or partner with a specialized Third-Party Administrator (TPA) to oversee regulatory tracking.
Conduct Annual Plan Audits: Review your Summary Plan Descriptions, administrative procedures, and eligibility audits at least once a year after open enrollment.
Automate with Certified Platforms: Ensure your benefits administration and payroll platforms accurately reflect current legal contribution limits, deduction rules, and reporting metrics.
Maintain Meticulous Records: Retain plan amendments, discrimination testing results (for Section 125/cafeteria plans), and notices for statutory minimum retention periods (typically 6 years for ERISA data).
If you'd like, let me know:
The approximate number of employees on your payroll
The states where your workforce operates
Whether you manage plans in-house or through a broker/TPA
I can provide a more tailored checklist for your specific organization size and footprint.
Reporting: Verify Forms 5500, 1094-C/1095-C, W-2 health-coverage reporting, and applicable self-insured-plan reporting.
State: Maintain a state-by-state matrix for insurance mandates, continuation coverage, paid leave, disability programs, and required notices.
Governance: Assign owners, document procedures, audit vendors/TPAs, retain records, and review changes at least annually.
Expert review: Have benefits counsel or a qualified compliance adviser review the program, particularly for self-funded plans or multi-state operations.
State requirements can vary substantially, so “federal compliance” alone isn't sufficient.
ERISA — plan administration, fiduciary responsibilities, reporting, disclosures, claims procedures, and participant rights for many private-sector benefit plans.
Affordable Care Act (ACA) — health coverage requirements, market reforms, employer reporting, and other obligations applicable to certain employer health plans.
HIPAA — privacy/security obligations for covered health information and health-plan portability and nondiscrimination rules.
COBRA — continuation coverage requirements for applicable group health plans.
Mental Health Parity and Addiction Equity Act (MHPAEA) — parity requirements for mental health and substance-use disorder benefits.
FMLA, ADA, GINA, and other employment laws where they affect benefits eligibility or administration.
The U.S. Department of Labor provides compliance tools and employer guidance for many group health plan obligations.
3. Monitor state-specific requirements
State obligations can differ significantly. Maintain a state-by-state checklist for employees in each location, including:
State insurance mandates
Paid leave programs
Disability benefits requirements
Payroll and tax treatment of benefits
State continuation coverage rules
Required employee notices
State privacy requirements
For insured benefits, coordinate with carriers and review state insurance department guidance because state insurance laws may apply even when federal ERISA rules are involved.
4. Establish a compliance calendar
Create recurring reminders for:
Required participant notices
Government filings (such as applicable annual reports)
Open enrollment materials review
Plan document updates
Vendor certifications
Regulatory changes
Required employee communications
Assign ownership for each item (HR, benefits team, legal, payroll, finance, or vendors).
5. Review plan documents and communications
At least annually, compare:
Plan documents
Summary Plan Descriptions (SPDs)
Enrollment materials
Employee handbooks
Carrier certificates
Vendor agreements
Check that employee-facing materials match actual plan operations.
6. Audit vendors and administrators
Ask benefit vendors for:
Compliance attestations
Security/privacy documentation
SOC reports where appropriate
Claims-processing procedures
Regulatory updates
Copies of required notices
Remember that outsourcing administration does not always transfer legal responsibility away from the plan sponsor.
7. Perform periodic compliance audits
A useful audit cycle includes:
Eligibility audit
Are employees enrolled correctly?
Are waiting periods applied correctly?
Are dependents verified consistently?
Payroll audit
Are deductions correct?
Are taxable/non-taxable benefits handled properly?
Claims and administration audit
Are claims handled according to plan documents?
Are appeals procedures compliant?
Data privacy audit
Are health-related employee records protected?
Are access controls appropriate?
8. Maintain written governance procedures
Document:
Who approves plan changes
Who monitors regulations
How employee complaints are handled
How errors are corrected
How compliance issues are escalated
9. Get specialized review when needed
Because benefits compliance involves overlapping federal and state rules, many employers use:
Employee benefits counsel
Benefits compliance consultants
Third-party administrators
Actuaries or retirement plan specialists
Insurance brokers with compliance teams
A strong compliance program is usually built around continuous monitoring, documented processes, regular audits, and clear accountability, rather than a single annual review.
If you want, I can also provide a benefits compliance checklist/calendar for a U.S. employer or a state-by-state compliance tracking template.
Ensuring compliance for your employee benefits programs requires a continuous, proactive strategy across federal and state landscapes. Here is a structured approach to keeping your programs fully compliant:
Audit Your Current Offerings : Review all existing health, retirement, and welfare plans to ensure they align with current plan documents, summary plan descriptions (SPDs), and actual administration practices.
Monitor Federal Regulations : Stay updated on mandates from key federal agencies like the Department of Labor (DOL), IRS, and EEOC. Key laws to track include ERISA, the Affordable Care Act (ACA), COBRA, HIPAA, and the Family and Medical Leave Act (FMLA). You can reference official updates directly via the US Department of Labor Employee Benefits Security Administration.
Track State-Specific Mandates : State laws often move faster and can be stricter than federal rules. Pay close attention to state-mandated paid family/medical leave programs, state-run retirement auto-IRA mandates, state-level continuation coverage (mini-COBRA), and reproductive health or preventive care mandates where you have employees living or working.
Partner with Compliance Experts : Utilize external brokers, third-party administrators (TPAs), and employment law counsel who specialize in benefits. They can catch legislative changes specific to your industry and footprint.
Establish a Regular Review Calendar : Set quarterly or annual checkpoints to review nondiscrimination testing (for 401(k) and cafeteria plans), Form 5500 filings, ACA reporting (Forms 1094/1095), and employee notification distributions.
To help tailor this compliance strategy, could you tell me:
What states do you currently have employees residing or working in?
Roughly how many employees do you have on your payroll?
Are you looking for help with a specific type of benefit (like health insurance vs. retirement plans)?
For retirement plans, review:
ERISA requirements
Internal Revenue Code qualification rules
Eligibility and contribution rules
Nondiscrimination testing
Vesting
Participant disclosures
Form 5500 and related filings
Required plan amendments
Distribution and withholding rules
Fiduciary responsibilities
The IRS emphasizes that employers remain responsible for both the terms of the plan document and how the plan actually operates, and recommends reviewing the plan annually.
3. Create a state-by-state matrix
Federal compliance isn't enough. For every state in which you have employees, identify requirements involving:
Paid sick/safe leave
Paid family and medical leave
State disability programs
State continuation coverage
State health-insurance mandates
Payroll deductions/contributions
Wage-and-hour rules affecting benefits
Retirement-plan requirements
Required notices
State tax treatment of benefits
State privacy requirements affecting employee/health information
This is particularly important for remote workforces because an employee's work location can create obligations even when your company is headquartered elsewhere.
For example, Virginia has enacted a paid family and medical leave insurance program with contribution collection scheduled to begin in 2028 and benefits beginning in December 2028.
4. Don't just review documents—test actual administration
One of the biggest compliance risks is a gap between the plan document and what HR/payroll actually does.
Test samples of employees for:
Correct eligibility dates
Correct deductions
Correct employer contributions
Correct waiting periods
Correct dependent eligibility
Correct enrollment after qualifying life events
Correct termination of coverage
COBRA/continuation notices
Leave-of-absence treatment
Retirement-plan eligibility and contributions
Required notices
The IRS specifically warns that compliance problems can arise from changes in personnel, procedures, payroll systems, and service providers.
5. Establish a formal compliance calendar
Create a calendar containing:
Area
Examples of things to monitor
Health plans
ACA, COBRA, HIPAA, MHPAEA, ERISA notices
Retirement
Form 5500, testing, participant notices, amendments
SBCs, notices, plan documents, employee communications
Vendors
Contracts, SOC reports, data/privacy obligations
States
New legislation, filings, notices and mandates
Assign an owner, backup owner, deadline, source of authority, and evidence of completion to every item.
6. Monitor regulatory changes continuously
Don't rely solely on your broker or benefits administrator. Establish a process for reviewing updates from agencies such as the Department of Labor, IRS, HHS, and relevant state agencies.
The DOL maintains a dedicated collection of health-plan compliance resources, including its Health Benefits Advisor and self-compliance tools.
For retirement plans, the IRS likewise provides current operating, correction, filing, and compliance resources.
Independent-contractor or employee classification issues
This is especially valuable because compliance obligations can overlap—for example, a benefits arrangement may simultaneously implicate ERISA, tax rules, state insurance law, privacy rules, and employment law.
8. Document your compliance evidence
For each requirement, retain evidence such as:
Plan documents and amendments
SPDs and required notices
Employee communications
Testing results
Filing confirmations
Payroll audits
Enrollment reports
COBRA records
Vendor certifications
Legal opinions
Corrective-action records
If regulators ever investigate, being able to demonstrate a systematic compliance process can be nearly as important as the underlying compliance itself.
A practical annual cycle
I'd recommend this cadence:
Quarterly: regulatory-change review + payroll/enrollment spot checks
Semiannually: vendor and state-law review
Annually: full federal/state compliance audit + plan-document review
At every plan change: legal/compliance review before implementation
After an error: document, quantify, correct, and determine whether participant/regulator notification is required
One important caveat: there is no universal checklist that guarantees compliance with "all" federal and state laws. The requirements depend heavily on your specific benefits and workforce. The DOL itself notes that different federal and state laws can apply to group health plans, while the IRS emphasizes that retirement-plan requirements must be satisfied both in the plan document and in actual operation.
If you tell me (1) number of employees, (2) states where they work, (3) benefits you offer, and (4) whether you're private, nonprofit, or government, I can turn this into a federal + state benefits compliance checklist and annual calendar tailored to your organization.
Ensuring your employee benefits programs remain fully compliant with a shifting landscape of federal and state laws requires a structured, proactive approach. Missed filings or out-of-date plan documents can trigger steep penalties from agencies like the Department of Labor (DOL) and the IRS.
Key Framework for Benefits Compliance
Master the Federal Baselines
Affordable Care Act (ACA) : Track your full-time equivalent employee count. If you have 50+ full-time employees, ensure you meet the employer mandate to offer affordable, minimum-value coverage to at least 95% of eligible staff, and accurately file Forms 1094-C and 1095-C annually.
ERISA (Employee Retirement Income Security Act) : Maintain written Plan Documents and Summary Plan Descriptions (SPDs) for all welfare and retirement plans, and file annual Form 5500 reports where required. You can utilize resources like the DOL EBSA Compliance Assistance Guide for self-assessment tools.
COBRA & HIPAA : Ensure timely distribution of initial and qualifying-event COBRA notices, and strictly protect the privacy and security of participant health data under HIPAA rules.
Account for State-Specific Mandates
State Family and Medical Leaves / Paid Sick Leave : Many states have enacted programs that go beyond federal FMLA. Check local state requirements for paid family leave, payroll taxes, and mandatory supplemental disability.
State-Mandated Retirement Programs : If you do not sponsor a qualified retirement plan (like a 401(k)), check if your operating states require automatic enrollment in a state-run IRA program (e.g., CalSavers, Illinois Secure Choice).
State Insurance Mandates : Group health plans must comply with specific state-level coverage mandates and continuation laws if you operate in multiple states or have fully insured plans anchored in a specific state.
Establish an Ongoing Audit and Calendar Routine
Conduct Regular Plan Audits : Review your eligibility audits, contribution levels, and nondiscrimination testing (for 401(k) and self-insured health plans) annually.
Maintain a Compliance Calendar : Keep track of annual disclosure deadlines, open enrollment windows, Form 5500 filings, and W-2 reporting of health care coverage. If managing administration internally or via software, platforms like Gusto Benefits Support can automate portions of tracking.
Monitor Transparency Rules : Keep pace with ongoing federal Transparency in Coverage mandates, ensuring participants have accessible tools for out-of-pocket cost-sharing data.
If you'd like to narrow this down, please let me know:
Approximately how many employees you have
Which states your workforce operates in
Whether your plans are fully insured or self-insured
I can tailor a more specific regulatory checklist for your organization.
State-mandated retirement programs where applicable
Notices
Required employee communications and posting deadlines
Privacy
State-specific employee/health-data requirements
Benefits eligibility
Rules affecting part-time, temporary, or other worker categories
If you have employees in California, for example, Cal-COBRA can apply to employers/group plans with 2–19 employees, while federal COBRA generally applies at 20+ employees. Department of Managed Health Care California also has its own CFRA and Paid Family Leave/State Disability Insurance considerations.
3. Audit your actual plan documents
For every benefit, compare three things:
What the law requires → what the plan document says → what HR/payroll actually does.
Look specifically for discrepancies involving:
Eligibility and waiting periods
Employee classifications
Enrollment and special enrollment
Employer/employee contribution amounts
Deduction calculations
Terminations and coverage end dates
Leave and benefit continuation
COBRA/continuation notices
Claims and appeals
Required employee notices
Nondiscrimination testing
Vendor responsibilities
For cafeteria plans, for example, the IRS says the written plan needs to describe the benefits and establish eligibility and election rules.
4. Put recurring compliance deadlines on a calendar
Create a centralized Benefits Compliance Calendar containing:
Annual nondiscrimination testing
ACA reporting
Form 5500 filings, where applicable
SBC distribution
Required ERISA disclosures
COBRA notices
HIPAA/privacy notices
State notices and filings
FSA/HSA deadlines
Open-enrollment communications
Plan-document updates
Vendor audits
Required payroll withholding updates
Assign an owner and backup owner to every deadline rather than leaving compliance responsibility with "HR."
5. Audit your vendors
Your broker, TPA, payroll provider, COBRA administrator, benefits administrator, and insurance carriers may perform important compliance functions—but don't assume outsourcing transfers all responsibility away from the employer/plan sponsor.
For each vendor, document:
What compliance obligation they handle
What data they rely on
Who reviews their work
What reports they provide
What deadlines they guarantee
How errors are escalated
Whether their contract contains appropriate indemnification/insurance provisions
6. Reconcile HR, payroll, and benefits data
Many benefits violations are operational rather than intentional.
At least periodically, reconcile:
HRIS → payroll → benefits enrollment system → carrier/vendor records
Look for:
Employees missing coverage
Incorrect eligibility dates
Incorrect deductions
Employees retained on coverage after termination
Dependents who should have been removed
Incorrect employer contributions
Leave-related coverage errors
Incorrect employee classifications
7. Establish a formal annual compliance review
A good annual review should produce a written report covering:
Applicable laws and states
Plan documents reviewed
Required notices
Required filings
Testing performed
Vendor compliance
Payroll/data reconciliation
Open deficiencies
Corrective actions
Responsible person and deadline for each correction
For health plans, DOL's compliance guide specifically provides self-compliance tools and model notices covering several major federal requirements.
8. Monitor regulatory changes continuously
Don't wait for open enrollment. Assign someone—internal HR/legal staff, outside benefits counsel, or your benefits consultant—to monitor changes throughout the year.
This matters because guidance can change during a plan year. For example, federal agencies issued additional ACA implementation guidance in October 2025.
9. Have benefits counsel review high-risk areas
For a mid-size or large employer, I would strongly recommend periodic review by an ERISA/employee-benefits attorney, particularly when you:
Change carriers or plan designs
Introduce an HSA/FSA or new reimbursement arrangement
Change eligibility rules
Acquire another company
Employ people in multiple states
Self-fund a health plan
Implement wellness programs
Change leave policies
Have a significant number of remote employees
Receive a government audit or employee complaint
This is especially important because the interaction among federal requirements, state insurance laws, tax rules, and the actual plan document can be complicated.
A practical target: maintain a single compliance matrix listing requirement → applicable employees/plans → responsible owner → deadline → evidence of compliance → last review → next review. That turns "Are we compliant?" into something you can actually audit and demonstrate.
If you're an employer with employees in California and other states, I can also build you a federal + state benefits compliance checklist/matrix, including ERISA, ACA, COBRA, HIPAA, FMLA/CFRA, payroll/tax rules, required notices, and recurring deadlines.
Managing employee benefits compliance requires continuous oversight across federal laws (such as ERISA, ACA, COBRA, and HIPAA) as well as a growing landscape of state-specific mandates.
Core Strategies for Benefits Compliance
Maintain Formal Plan Documents and SPDs : Create and formally adopt written plan documents and Summary Plan Descriptions (SPDs) for every benefit offering, ensuring they align strictly with IRS and ERISA requirements.
Conduct Regular Compliance Audits : Perform routine internal reviews of plan eligibility, enrollment records, dependent verification, and timely distribution of mandatory participant notices.
Monitor Regulatory Updates : Fastidiously track legislative changes at both the federal level and across every state where you have active employees, as state-mandated disability, leave, and healthcare rules frequently shift.
Outsource to Experts : Partner with an experienced Third-Party Administrator (TPA) or specialized legal counsel to manage complex filings, nondiscrimination testing, and plan design evaluations.
Leverage Correction Programs : Utilize official resources like the Employee Benefits Security Administration (EBSA) compliance assistance and correction programs if you identify operational errors or missed filings.
If you'd like to narrow this down, please share:
The approximate number of employees in your organization
Whether you operate in multiple states
The types of benefits you currently offer (e.g., retirement, health, flexible spending accounts)
I can provide a more tailored compliance checklist for your situation.
Do not rely solely on federal rules. Many states enforce individual state mandates, paid family leaves, and mini-COBRA laws that apply to smaller employers or offer more generous continuation periods than federal COBRA.
If you operate across state lines, ensure your policies adapt to each state's distinct legal thresholds.
Distribute Mandatory Notices on Time
Keep a strict calendar for distributing required documents, such as the Summary of Benefits and Coverage (SBC) , initial general COBRA notices, and Marketplace notices.
Utilize official resources like the Department of Labor EBSA for compliance assistance guides and model notices.
Conduct Regular Internal Audits
Review plan documents, non-discrimination testing (for cafeteria and retirement plans), contribution levels, and employee eligibility tracking at least annually.
Maintain meticulous records of all notices sent, proof of mailings, and election forms for a minimum of six years to satisfy ERISA requirements.
Leverage Technology and Professional Partners
Implement integrated HR and benefits administration platforms to automate workflow tracking for qualifying life events and notice distribution.
Partner with external ERISA attorneys, specialized brokers, or Third-Party Administrators (TPAs) to vet plan designs against newly enacted legislation.
To help tailor a compliance checklist, could you share:
How many employees do you currently have?
Do you operate in multiple states?
Are you looking at health/welfare plans, retirement plans , or both?
Plan type: medical, dental, vision, life, disability, HSA/FSA, 401(k), PTO, etc.
Funding arrangement: fully insured, self-funded, level-funded, HRA, etc.
Eligibility rules and employee classifications.
States in which employees are located.
Applicable vendors, insurers, TPAs, PBMs, brokers, and recordkeepers.
Required notices, filings, testing, and deadlines.
Plan documents and amendments.
This is important because the same benefit can have different federal and state requirements depending on how it is structured. For example, state insurance laws generally continue to apply to insured arrangements, while ERISA can preempt certain state requirements for ERISA plans.
2. Create a federal-law checklist
At minimum, evaluate whether each applicable plan complies with:
ERISA — plan documents, SPDs, fiduciary duties, claims/appeals, reporting and disclosures.
ACA — eligibility, dependent coverage, preventive care, SBCs, affordability/employer mandate where applicable, and applicable reporting.
COBRA — qualifying events, election notices, continuation coverage, and administration.
HIPAA — special enrollment, nondiscrimination, privacy/security obligations where applicable.
MHPAEA — mental-health/substance-use-disorder parity, including the increasingly important comparative analyses for nonquantitative treatment limitations.
No Surprises Act — applicable emergency, air-ambulance, and other surprise-billing protections and disclosure requirements.
GINA, ADA and other nondiscrimination laws — particularly for wellness programs and health-related information.
IRC requirements — cafeteria plans, HSA/FSA rules, nondiscrimination testing, taxation of fringe benefits, and retirement-plan requirements.
The Department of Labor specifically identifies ACA, COBRA, ERISA, HIPAA, MHPAEA and the No Surprises Act among the major federal laws governing job-based benefits.
For tax treatment and cafeteria-plan/fringe-benefit rules, use the current IRS guidance rather than relying on an old plan document or vendor assumption.
3. Build a state-by-state matrix
For every state where employees work, track:
State insurance mandates.
State continuation/conversion requirements.
Paid family/medical leave and disability programs.
State-specific HSA/FSA/tax treatment.
State privacy and health-data laws.
State-mandated notices.
Any state retirement-program requirements.
Rules affecting insured vs. self-funded plans.
Deadlines and responsible parties.
Don't assume that an ERISA exemption means state law is irrelevant. The DOL specifically advises employers with insured/HMO arrangements to check the applicable state's insurance department.
4. Establish a compliance calendar
Create one centralized calendar containing:
Area
What to track
ERISA
Form 5500, SPD/SMM requirements, participant disclosures
Contracts, SOC reports, compliance certifications and service-level obligations
The DOL provides a reporting/disclosure guide and model notices specifically for helping plan administrators manage these obligations.
5. Don't outsource responsibility blindly
Your broker, insurer, TPA, payroll provider and retirement recordkeeper can perform important compliance functions, but the employer/plan fiduciaries should maintain oversight.
For ERISA plans, fiduciaries have obligations to operate the plan according to its governing documents and applicable law and to act prudently and in participants' interests.
For each vendor, document:
What compliance responsibility the vendor accepts.
What remains your responsibility.
Required reports/certifications.
Data-security obligations.
Notice responsibilities.
Audit rights.
Who owns errors and corrective actions.
6. Perform an annual compliance audit
At least annually—and whenever you make a significant plan change—compare:
Plan document → insurance/administrative contract → employee communications → payroll configuration → actual administration → legal requirements.
That catches a surprisingly common problem: the written plan is compliant, but payroll or HRIS settings don't administer it correctly.
Also perform targeted audits after events such as:
Acquisitions or mergers.
Entering a new state.
Changing insurers or TPAs.
Switching from fully insured to self-funded.
Changing eligibility rules.
Introducing a wellness program.
Changing employee classifications.
Amending a retirement or cafeteria plan.
7. Have counsel review high-risk areas
For significant programs, I would have employee-benefits counsel periodically review the areas where mistakes can create substantial exposure—particularly ERISA fiduciary responsibilities, MHPAEA, ACA, COBRA, wellness programs, self-funded arrangements, and state-specific requirements.
The DOL itself provides self-compliance tools and a Health Benefits Advisor, which are useful starting points but aren't substitutes for legal advice on a complex plan.
A practical operating model
I'd recommend assigning each requirement an owner + frequency + evidence + deadline + backup owner. Then maintain a compliance dashboard showing:
Requirement → Applicable plans → Applicable states → Responsible person/vendor → Due date → Evidence of completion → Last legal review → Open issues.
That gives you an auditable trail rather than simply having a collection of plan documents.
If you tell me (1) number of employees, (2) states where they work, (3) benefits you offer, and (4) whether your health plan is fully insured or self-funded, I can turn this into a federal + state benefits compliance checklist and annual calendar tailored to your organization.