What your broker must tell you about how it is paid, what you must do with that information as a plan fiduciary, and how personal and health data is protected — including a plain statement of how Group Coverage, Inc. is compensated and how we handle information.
Employers sponsoring benefit plans are owed two very different disclosures, and they are frequently confused. Compensation transparency — what your broker is paid, by whom, and for what — has since the Consolidated Appropriations Act, 2021 been a condition of the arrangement being permissible under ERISA at all, and the obligation to obtain and review it falls on you as a plan fiduciary. Data transparency is governed by an overlapping set of rules: HIPAA, Gramm-Leach-Bliley, the New York DFS cybersecurity regulation, and the SHIELD Act. Paying more than reasonable compensation is a prohibited transaction — and you cannot determine whether compensation is reasonable if you do not know what it is.
The first is compensation transparency: what your broker or consultant is paid, by whom, and for what. Since the Consolidated Appropriations Act, 2021, this is not a courtesy — it is a condition of the arrangement being permissible under ERISA at all, and the obligation to obtain and review the disclosure falls on you as a plan fiduciary, not only on the broker who must provide it.
The second is data transparency: what personal and health information is collected about your employees and your business, who handles it, how it is protected, and what happens if it is exposed. This is governed by an overlapping set of federal and New York State rules, each with its own scope and its own notice requirements.
Why this matters to a plan fiduciary. Paying more than reasonable compensation to a service provider is a prohibited transaction under ERISA. You cannot determine whether compensation is reasonable if you do not know what it is. That is the entire logic of the disclosure rule: the fiduciary duty existed all along; the 2021 amendment simply forced the information into the open so the duty could be discharged.
A covered service provider — a broker or consultant reasonably expecting $1,000 or more in direct or indirect compensation in connection with brokerage or consulting services to an ERISA group health plan.
The services; whether the provider expects to act as a fiduciary; all direct compensation; all indirect compensation, identifying the payer and the arrangement; transaction-based compensation including commissions; and anything payable on termination.
Reasonably in advance of the date the contract is entered into, extended, or renewed — not after the fact, and not only on request. Changes are disclosed generally within 60 days of the provider learning of them.
ERISA-covered group health plans, fully insured or self-insured. Governmental and church plans sit outside ERISA and outside this requirement, though many request the same information voluntarily.
The rule creates an obligation on both sides. A contract is not “reasonable” — and therefore not exempt from the prohibited transaction rules — unless the required disclosure is made. Where a provider fails to disclose, the responsible plan fiduciary has a defined path: request the information in writing upon discovering the failure; if it is not furnished within 90 days, notify the Department of Labor within 30 days of the earlier of the refusal or the end of that 90-day period; and terminate the arrangement as promptly as prudent if the information relates to future services and is not supplied.
Reasonable is not the same as low. Nothing in ERISA requires a plan to select the cheapest service provider — it requires that compensation be reasonable in relation to the services rendered. A broker performing compliance support, claims advocacy, plan design analysis, and open enrollment execution earns more than one who markets the plan once a year, and should. What the fiduciary must be able to show is that they knew what was being paid and evaluated it against what was received.
In practice the obligation is simpler than it sounds: ask for the disclosure, read it, keep it in the plan file, and document that the fiduciary reviewed it and concluded the compensation was reasonable in light of the services provided. That contemporaneous record is the point. Compensation also surfaces elsewhere in your filings — Form 5500, Schedule A reports commissions and fees paid to agents and brokers for each insurance contract and should reconcile against the disclosure you received, while Schedule C requires large plans to report providers receiving $5,000 or more and to identify any who failed to supply the required information.
Understanding the categories makes any disclosure easier to read, whoever produced it.
A percentage of premium, or a per-employee-per-month amount, built into the rate by the carrier. Ask what the percentage or PEPM is by line and by carrier — and whether it varies between the carriers being presented to you.
A negotiated flat or hourly fee paid by the employer or the plan, often in place of or offsetting commission. Ask what is included, what is billed separately, and whether commission is being offset against the fee.
Additional compensation based on the volume placed with a carrier across the brokerage's whole book. Ask which carriers pay overrides, and at what thresholds.
Contingent on aggregate volume, growth, retention, or loss ratio across the book. Ask which carriers, on what metrics, and whether those metrics could influence a recommendation.
Periodic carrier programs tied to new business or persistency. Ask whether any are in effect during the period in which your renewal is being marketed.
Amounts received from TPAs, COBRA administrators, benefits technology platforms, PBMs, or wellness vendors. This is the least visible category and the one worth asking about explicitly: is the broker paid by any vendor it recommends?
New York adds a second, independent rule. Insurance Regulation 194 requires a producer to disclose, at or prior to application, its role in the sale, whether it will receive compensation from the insurer or a third party, that compensation may vary by product and insurer, and that the purchaser may request further detail — which the producer must then provide. Regulation 194 applies to all lines and all purchasers and operates on a request-driven model. The ERISA rule is broader and is not request-driven. Employers sponsoring ERISA group health plans in New York are covered by both, and should receive the ERISA disclosure automatically.
We provide a written compensation disclosure to every ERISA group health plan client reasonably in advance of entering into, extending, or renewing our agreement, and we update it when arrangements change. The following describes our general practice — the specific figures applicable to your plan appear in your own disclosure document. If you do not have a current copy, contact us and we will send one.
For most fully insured group placements we are compensated by the carrier through a commission built into the premium rate, expressed as a percentage of premium or as a PEPM amount. The amount varies by carrier, product line, group size, and market.
For consulting, compliance projects, and self-insured or level-funded arrangements, we may be compensated by a negotiated fee paid by the employer or the plan. Where a fee is in place, any commission received is disclosed and, where agreed, offset against the fee.
We may participate in carrier programs paying supplemental or contingent compensation based on aggregate volume, growth, retention, or loss experience across our entire book — not on any individual client. Where such programs apply, they are identified in your disclosure.
Where we receive compensation from a TPA, technology platform, or other vendor in connection with services to your plan, that compensation is disclosed. Training, marketing support, and conference attendance from carriers and vendors are received consistent with applicable law.
Ask us anything about how we are paid. We would rather answer the question directly than have you wonder. If you want a carrier-by-carrier breakdown of what we would earn on each option we present at renewal, ask for it and we will provide it in writing. A recommendation that cannot survive that question is not a recommendation worth making.
On managing conflicts: we present renewal and marketing results with the compensation associated with each option identified on request, so a comparison is not distorted by information you do not have. We do not condition access to any service on placement with a particular carrier. Contingent and supplemental programs are measured across our whole book and are not tied to the placement of any individual client’s coverage. And where we recommend an affiliated or compensating vendor, we disclose the relationship at the time of the recommendation, not afterward.
For an employer, the essential HIPAA distinction is between the plan and the employer. The group health plan is the covered entity; the employer sponsoring it is not, in that capacity. Information you hold as an employer — sick notes, FMLA certifications, workers’ compensation records — is generally employment information subject to the ADA and other laws, not PHI. Information the plan holds about claims and enrollment is PHI.
Before the plan may disclose PHI to the employer, the plan document must be amended to restrict the employer's use, and the employer must certify that it has done so. The employees who may access PHI must be identified and their access limited to plan administration functions.
Administrative, physical, and technical safeguards for electronic PHI, supported by a documented risk analysis and risk management plan. The risk analysis is the item enforcement actions most often find missing.
Required with every vendor that creates, receives, maintains, or transmits PHI on the plan's behalf — TPAs, COBRA administrators, brokers performing plan administration functions, benefits platforms, and their subcontractors.
Notify affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more require contemporaneous notice to HHS and to prominent media; smaller breaches are logged and reported within 60 days after the calendar year ends.
Licensed producers and your carriers are covered entities. All transition periods have passed: universal multi-factor authentication and written asset inventory procedures took effect November 1, 2025, alongside a CISO, annual penetration testing, and a written third-party service provider policy.
Notice to DFS within 72 hours of determining a cybersecurity event occurred, including ransomware deployments; notice of an extortion payment within 24 hours, with a written explanation within 30 days; and an annual certification filed by April 15.
The SHIELD Act reaches any person or business that owns or licenses computerized data including the private information of a New York resident, wherever located. Two obligations follow: reasonable administrative, technical, and physical safeguards — designating a coordinator, identifying risks, training employees, selecting capable service providers by contract, disposing of data securely — which small businesses may scale to their size; and breach notification to affected residents and, where thresholds are met, to the Attorney General, Department of State, and State Police. Note that the definition of a breach includes unauthorized access, not only acquisition. An entity compliant with HIPAA, GLBA, or Part 500 is deemed compliant with the safeguards requirement — but the notification obligations still apply. Separately, insurance producers are financial institutions for Gramm-Leach-Bliley purposes, which New York implements through Insurance Regulation 169.
One question belongs in every vendor review. If your broker, TPA, or benefits platform touches New York employee data, ask whether they are a DFS covered entity and, if so, whether they filed a Certification of Material Compliance or an Acknowledgement of Noncompliance for the most recent year. The answer tells you a great deal in a single question — and DFS has pursued enforcement actions with substantial penalties against entities that certified compliance they did not have.
Every insurance website collects personal information, usually through quote forms, contact forms, and analytics — and a privacy policy that says nothing specific protects no one. At minimum yours should distinguish information the visitor provides from information collected automatically; state how it is used and who it is shared with; say plainly whether personal information is sold (for a brokerage the answer should be no, and it should be said); describe cookies and analytics and how to control them; state retention periods and their basis; describe safeguards truthfully, since a promise of absolute security is both false and a liability; explain individual rights and marketing opt-outs; address whether any submitted information is PHI; state that the site is not directed to children; and give a real contact point with an effective date.
Consent is regulated separately from privacy. Telephone and text outreach implicates the Telephone Consumer Protection Act and its state analogues; email marketing implicates CAN-SPAM. Capture and retain evidence of consent at the point of collection, honor opt-outs promptly across every channel and every list, and make sure the consent language on the form matches what the privacy policy says you will do.
ERISA plan documents, SPDs, SMMs, and amendments permanently or for the life of the plan plus six years. Form 5500 filings and supporting records at least six years from filing, per ERISA §107.
Service provider compensation disclosures and the fiduciary review memoranda, six years from the end of the contract — filed together with the service agreement and the Schedule A data.
COBRA notices and proof of mailing, six years from the date of the notice. ACA Forms 1094-C and 1095-C and hours-of-service data, seven years in light of the six-year assessment limitations period.
HIPAA policies, BAAs, risk analyses, and training records six years from creation or last effective date; DFS Part 500 supporting documentation five years. A legal hold suspends routine disposal.
How we handle information ourselves, stated plainly: collection is limited to what is necessary to quote, place, and service your coverage and to meet our legal obligations. Disclosure is limited to carriers and their underwriters, administrators and vendors engaged to service your plan, and regulators where required or permitted by law — we do not sell personal information. Business associate agreements are executed where we perform functions involving PHI. Safeguards include role-based access controls, multi-factor authentication, encryption in transit, workforce training, vendor due diligence, and an incident response plan. And if you are about to email a spreadsheet of employee names, dates of birth, and dependents, contact us first and we will provide a secure method.
Why employers bring this work to GCI: transparency is not a document you file once. Group Coverage, Inc. treats compensation disclosure and data protection as ongoing obligations we owe you — and as areas where we can help you hold every other vendor in your benefits program to the same standard: furnishing our disclosure in advance of every agreement and renewal, providing carrier-by-carrier detail on request, helping assemble the fiduciary file that discharges your §408(b)(2) obligation, reconciling Schedule A against what was disclosed, reading the disclosures you receive from other vendors and flagging what is missing, and coordinating secure data exchange with your HIPAA and Part 500 obligations.
For the primary sources, see the Employee Benefits Security Administration on ERISA §408(b)(2)(B) service provider disclosure, HHS Office for Civil Rights on the HIPAA Privacy, Security, and Breach Notification Rules, and the New York State Department of Financial Services on 23 NYCRR Part 500 and Insurance Regulations 169 and 194.
If you cannot find one, request it in writing today — and if the request goes unanswered for 90 days, you have your own notification obligation to the DOL. Group Coverage, Inc. will provide a current copy of our disclosure and privacy notice, or help you review another provider’s, at no cost.
This article is for general educational purposes and is not legal, tax, or accounting advice. Disclosure requirements, privacy and cybersecurity regulations, penalty amounts, and retention standards change and vary by entity type, plan funding arrangement, and jurisdiction. The description of Group Coverage, Inc.’s compensation is general — the specific figures applicable to your plan appear in your own written disclosure document. Consult qualified counsel before acting on any item discussed here.