Health Data Access, Transparency, and Affordability Act of 2026
Summary
What This Bill Does
The Health Data Access, Transparency, and Affordability Act of 2026 would amend ERISA to regulate contracts between group health plans and the companies that administer networks, claims, insurance, pharmacy benefits, or related services. It defines a network service provider broadly to include direct and indirect service providers and intermediaries. A health care provider would not fall within that definition solely because it delivers health care.
A service contract would qualify as reasonable under ERISA only if the responsible plan fiduciary and its designated agent can obtain all covered claims and encounter data plus medical records, policy documents, and other support for claim payments. The contract could not delay access beyond 15 days, or a shorter period set by the Labor Secretary, cap the amount of data supplied, restrict daily access, block the plan's choice or scope of an auditor, or prevent the plan from asking for action on suspected erroneous or fraudulent payments. It also could not conceal alternative-payment pricing, overpayment recovery terms, administrative and claims-processing fees, de-identified public information, or extra-contractual reimbursement formulas.
Claims and payment files would have to be unmodified and supplied to the plan at no cost in specified HIPAA transaction formats: ASC X12N 837 for institutional, professional, and dental claims; the National Council for Prescription Drug Programs format for pharmacy claims; and ASC X12N 835 for payment and remittance files. Non-claim costs would have to be itemized in real time through a web portal, an application programming interface, and a downloadable CSV file. The Labor Secretary could update standards and implement specified provisions through notice-and-comment rulemaking.
The bill preserves HIPAA privacy and security rules for both data providers and recipients. A plan could disclose received information only in a HIPAA-consistent manner, even where HIPAA might not otherwise apply directly. At the same time, the privacy language could not be used to narrow the bill's disclosure duties or impose extra privacy requirements on network service providers or plan sponsors.
A person or company violating the covered ERISA data-access provision could face a Labor Department civil penalty of up to $10,000 for each day the violation continues, in addition to other legal penalties. Contract terms that delay or limit required access, or otherwise violate the service-contract rules, would be void. The bill also would bar people or companies subject to specified ERISA civil penalties from being indemnified or otherwise relieved of that liability, and would void conflicting contract terms.
Group health plans and group health insurers would have to attest annually to the Labor Secretary that required information is available on request and that their contracts contain no terms restricting or unduly delaying audits, review, or access. They could not hire a third-party administrator or another service provider to submit the attestation. A plan or insurer unable to obtain the information could file a written statement instead, explaining the failure, its efforts to remove gag clauses, the provider's response, and the provider's name. The definition and reasonable-contract amendments would apply beginning with the first plan year starting at least one year after enactment, regardless of when the service contract was signed.
Who Benefits and How
Group health plan fiduciaries, plan sponsors, and administrators would gain faster and more complete access to the data needed to audit charges, compare payment arrangements, identify overpayments or fraud, understand service fees, and enforce fiduciary duties. Employers sponsoring health plans could use the information to evaluate vendors and control plan spending. Workers and family members covered by those plans could benefit if stronger oversight reduces waste or improves claims administration, although the bill does not guarantee lower premiums or out-of-pocket costs. Health care professionals acting solely as care providers avoid being treated as network service providers.
Who Bears the Burden and How
Third-party administrators, pharmacy benefit managers, health insurers, network companies, claims processors, and other covered vendors would have to revise contracts, produce unmodified files promptly and at no cost, build daily and real-time data access, disclose fees and pricing methods, accommodate plan-selected audits, and respond to suspected payment errors. Violations could produce daily civil penalties, and vendors could no longer rely on gag clauses or indemnification terms that the bill makes void. Plans and insurers would bear annual attestation and HIPAA-compliance duties. Labor Department staff would have new rulemaking, review, and enforcement work.
Key Provisions
- Defines covered network service providers while excluding a care provider acting solely in its provider capacity.
- Requires full claims, payment, pricing, fee, audit, overpayment, and fraud-review access.
- Mandates no-cost standardized files, daily claims access, and real-time non-claim cost data.
- Preserves HIPAA protections while preventing privacy terms from defeating disclosure.
- Authorizes penalties of up to $10,000 per day and voids prohibited contract terms.
- Bars indemnification for specified ERISA penalties and requires plan-filed annual attestations.
Evidence Chain:
This summary is generated from the full bill text using AI analysis. Expand "Detailed Analysis" below for identified beneficiaries/burden bearers with clause-level evidence links.
At a Glance
What This Bill Does
Give group health plans direct, timely, standardized access to claims, pricing, fee, audit, and payment data by regulating service contracts, attestations, and enforcement under ERISA.
Key Policy Areas
Health, Labor and Employment, Consumer Protection, Data Privacy, Federal Regulation
Primary Purpose
Give group health plans direct, timely, standardized access to claims, pricing, fee, audit, and payment data by regulating service contracts, attestations, and enforcement under ERISA.
Policy Domains
Section 2 - ERISA health-plan data access and enforcement
Identified Gains
- Group health plan fiduciaries auditing service contracts
- Employers sponsoring group health plans
- Workers covered by employer health plans
- Health care providers acting solely as care providers
Identified Costs
- Network service providers contracting with health plans
- Third-party health plan administrators
- Pharmacy benefit managers serving group plans
- Health insurance issuers offering group coverage
- Department of Labor ERISA enforcement staff
Sponsors
Legislative Progress
ReportedOrdered to be Reported (Amended) by the Yeas and Nays: …
Committee Consideration and Mark-up Session Held
Referred to the House Committee on Education and Workforce.
Introduced in House
Mr. Onder introduced the following bill; which was referred to …
Stakeholder Effects
cui bono?How this legislation distributes effects. Mention counts reflect frequency, not effect magnitude.
Employers sponsoring group health plans, Group health plan fiduciaries auditing service contracts, Workers covered by employer health plans
Network service providers contracting with health plans, Third-party health plan administrators
Health care providers acting solely as care providers
Pharmacy benefit managers serving group plans
Health insurance issuers offering group coverage
Bill Structure & Actor Mappings
Who is "The Secretary" in each section?
- "plans"
- → Group health plans and their responsible fiduciaries
- "issuers"
- → Health insurance issuers offering group coverage
- "sponsors"
- → Group health plan sponsors and administrators
- "providers"
- → Network service providers and intermediaries
- "secretary"
- → Secretary of Labor
Note: {'scope_ids': ['group_health_plan_data_access'], 'description': 'A health care provider is excluded from the network-service-provider definition only when acting solely in its capacity as a provider of care.'}
Key Definitions
Terms defined in this bill
An agent of the responsible plan fiduciary, potentially including the plan sponsor, administrator, or a qualifying business associate other than the contracting company or its affiliates.
A direct or indirect service provider or intermediary serving a group health plan, including networks, administrators, insurers, and pharmacy-benefit companies, but not a health care provider solely delivering care.
We use a combination of our own taxonomy and classification in addition to large language models to assess meaning and potential beneficiaries. High confidence means strong textual evidence. Always verify with the original bill text.
Learn more about our methodology