CBIZ

Insights. Applied. Integrated solutions that turn strategy into action.

  • Article
October 06, 2026

October 2026 Regulatory & Legislative Update

October 2026 Regulatory & Legislative Update
Table of Contents

This regulatory and legislative update covers issues involving open enrollment, MHPAEA guidance, HIPAA cybersecurity, and more.

Open Enrollment Is Upon Us — Points to Consider

As open enrollment is right around the corner, health plans will want to ensure compliance with the many standards to which they are subject. Following is a brief outline of some of the points to consider.

Preventive Services

The ACA requires first-dollar coverage of certain preventive services. Periodically, these preventive services are updated. The updated list of preventive services can be found here. Generally, when a new standard is initiated, a plan must comply at the beginning of the plan year that is one year following the recommendation.

Annual Communications to Employees

Plan communication is an essential part of ensuring that employees understand the benefits to which they are entitled. There are several notices that are required to be provided annually and several others for which it may be a best practice to provide annually. 

Annual notices include:

  • Medicare Part D Notice of Creditable/Non-Creditable Coverage
    • Annually before October 15
  • Children’s Health Insurance Program (CHIP) Notice
    • Annually, best practice is to provide with other required annual notices
  • Women’s Health and Cancer Rights Act (WHCRA) Notice
    • Annually, best practice is to provide with other required annual notices
  • Summary of Benefits and Coverage

Recommended best practice notices include:

  • HIPAA Special Enrollment Notice
    • Annually, best practice is to provide with other required annual notices
  • Primary Care Provider Patient Protection Notice
    • Annually, best practice is to provide in SPD
  • ADA Wellness Program Notice
    • Required if wellness plan collects medical information or requires physical exam
    • Best practice is to provide annually with other materials

For a full list of plan notices, contact your CBIZ representative. Make sure to coordinate all plan notices and delivery with insurers or other vendors. The goal is to ensure that all material is consistent, that no conflicting information is provided, and that duplication is avoided.

MHPAEA Guidance Issued

The Employee Benefit Security Administration (EBSA) has issued Field Assistance Bulletin (FAB) 2026-03 together with an updated enforcement guidance document “Identifying Potential Problems: If You See the Following in Your Health Plan.”

The FAB states that EBSA investigations are focused in three areas:

Treatment limitations and benefit exclusions

  • Investigating blanket treatment exclusions that apply only to mental health/substance use disorders
  • Plans and issuers cannot apply blanket exclusions of treatment for MH/SUD conditions when similar treatments are covered for medical/surgical conditions

Medical necessity standards and utilization management practices

  • Focus on prior authorization, concurrent review, and retrospective review
  • Streamlining the review processes used to evaluate care. Plans and issuers may use proprietary clinical guidelines to make medical necessity determinations, those guidelines must be applied to mental health and substance use disorder benefits in a manner that is comparable to, and no more restrictive than, how they are applied to medical and surgical benefits
  • Guidelines must be made available upon request during NQTL investigations and to participants and beneficiaries on request

Network adequacy and provider access

  • Inadequate network
  • If network parity issues exist, EBSA will ensure that plans and issuers consider all available options and assist participants and beneficiaries seeking covered MH/SUD treatments without exposing such participants and beneficiaries to out-of-network costs due to the lack of availability of a covered MH/SUD service in-network

While these three points are the focus, the EBSA reserves the right to investigate other issues.

The EBSA also issued an enforcement guidance tool to help plans and issuers comply with their obligations under MHPAEA, including the NQTL comparative analyses requirements. The tool, Identifying Potential Problems: If You See the Following in Your Health Plan, outlines EBSA’s updated enforcement guidance under MHPAEA, and provides clearer expectations for plans and issuers related to NQTL compliance.

As a reminder, Mental Health Parity final rules were issued in 2024. The ERISA Industry Committee (ERIC) challenged these final rules. During the pendency of the litigation, the regulations will not be enforced, but the law itself includes the Consolidated Appropriations Act of 2021 comparative analysis.

Requirements are being enforced. There is some indication that new regulations will be proposed before the end of the year. In the meantime, plans should continue diligence to ensure compliance with the law. The red flags tool linked above should be useful for compliance efforts.

HIPAA Cybersecurity: Is Your Risk Analysis Up to Date?

Cybersecurity remains a significant area of enforcement for health plans subject to HIPAA. Employer-sponsored health plans subject to HIPAA must maintain appropriate safeguards to protect ePHI. Among other things, OCR has emphasized the importance of performing and maintaining a current and accurate security risk assessment (SRA), implementing compliant policies and procedures, and providing workforce training.

To assist organizations in reviewing and evaluating HIPAA Security Rule compliance, the Office of the National Coordinator for Health Information Technology (ONC), in coordination with OCR, maintains a free Security Risk Assessment Tool. The SRA tool was developed to assist small and medium-sized organizations comply with the requirements of the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule.

The HIPAA Security Rule requires that a security risk assessment be conducted by covered entities and business associates. Recently, the U.S. Department of Health and Human Services’ (“HHS”) OCR and the Assistant Secretary for Technology Policy (“ASTP”) released a new version (Version 3.7) of their Security Risk Assessment (“SRA”) Tool, along with an updated SRA Tool User Guide. The updated tool is designed to help organizations identify potential vulnerabilities and document compliance efforts. For smaller plans and organizations, the tool may provide a useful starting point for assessing security risks and developing an ongoing compliance strategy.

Employers sponsoring self-funded health plans should review their current HIPAA compliance practices, confirm that risk analyses are conducted and updated periodically, and ensure that appropriate administrative, physical, and technical safeguards are in place to protect ePHI. Recent enforcement activity demonstrates that regulators continue to view cybersecurity and HIPAA security compliance as key priorities. For more information on a recent cybersecurity resolution agreement, see the August Benefit Beat. In addition, plan sponsors and fiduciaries will want to keep in mind the cybersecurity practices and strategies of service providers and select service providers with strong cybersecurity practices.

A risk analysis is not a one-time exercise. Health plans should periodically review and update their assessments to account for evolving cybersecurity threats, changes in technology, and operational changes that may affect the security of protected health information.

Trump Accounts – New Regulations Proposed

As discussed in prior Benefit Beat articles, Trump Accounts are tax-advantaged savings accounts established for children under age 18 created under the One Big Beautiful Bill Act (OBBBA). See the September Benefit Beat article. On Sept. 30, 2026, the IRS issued temporary regulations and accompanying proposed regulations that expand the program through automatic account enrollment and new contribution opportunities.

Beginning on or about Oct. 1, 2026, the IRS will automatically establish Trump Accounts for eligible children who have a Social Security number and do not already have an account. The IRS estimates that this approach could extend Trump Account coverage to more than 60 million additional children in 2026. The IRS also indicated that additional enrollment periods will occur for children who become eligible in the future.

A parent, guardian, legal custodian, or other authorized individual must still claim the account before exercising control over it. The claiming process includes identity verification and confirmation of authority to act on behalf of the child.

The guidance also addresses contributions made during the account’s growth period. In addition to the $1,000 government pilot contribution available for certain children born between 2025 and 2028, the regulations permit qualified general contributions funded by governmental entities and certain tax-exempt organizations. These contributions generally must be distributed equally among members of a qualifying class consisting of at least 5,000 beneficiaries.

The regulations also permit certain contributions to be funded with publicly traded stock of a domestic corporation, subject to holding-period requirements. According to the IRS, this guidance is intended to facilitate large-scale funding initiatives and responds to significant donor interest in supporting Trump Account programs.

The temporary regulations became effective Sept. 30, 2026, and generally apply to tax years beginning on or after Jan. 1, 2026. The IRS is accepting comments on the companion proposed regulations through Nov. 29, 2026.

Employers considering Trump Account contribution programs should continue to monitor regulatory developments, as Treasury and the IRS continue to refine the operational rules governing these arrangements.

San Francisco HCSO Expenditure Rates for 2027

Several years ago, the City and County of San Francisco passed the Health Care Security Ordinance (“HCSO”) requiring covered employers to contribute to the health care costs of its covered employees, either through private means, or through “Healthy San Francisco.” An employer is subject to the HCSO if it employs one or more workers within the geographic boundaries of the City and County of San Francisco, is required to obtain a valid San Francisco business registration certificate, and is a for-profit business employing 20 or more workers worldwide, or a nonprofit organization with 50 or more workers worldwide. A covered employee is one who has been employed for more than 90 days and who regularly works at least 8 hours per week in San Francisco.

Each year these health care expenditure amounts are adjusted. These expenditure rates do not apply to businesses with 19 or fewer employees, or to nonprofits with 49 or fewer employees. In determining employer size, all individuals performing work for compensation both in and outside of San Francisco should be counted, regardless of whether the individual is full-time, part-time, temporary, or seasonal.

The required minimum health care expenditure is calculated by multiplying the total number of “hours paid” to that employee by the applicable expenditure rates, which for 2027 and 2026 are as follows:

HCSO Health Care Expenditure Rates
Employer Size (company-wide) 2027 2026
100+ Employees $4.49/hour $4.11/hour
20-99 Employees
Nonprofits, 50-99 Employees
$2.99/hour $2.74/hour

An employee who is a manager, supervisor, or confidential employee and who earns at or above an annual salary of $128,861 (or $61.95 per hour) in 2026 is exempt from coverage under the HCSO. For 2027, the new threshold will be $131,763 per year (or $63.35 per hour).

Employers who have self-funded health plans (medical, dental, or vision) must calculate the actual value of their plans (using either premium amounts or claims paid) to determine if the expenditures meet or exceed the required health care expenditure rate. If the employer’s annual spending fell short of the HCSO expenditure rate, the employer must make top-off payments for employees enrolled in these plans by the end of February of the following year.

Employers are required to annually report their health care expenditures to the Office of Labor Standards Enforcement (OLSE) by April 30, each year. Employers who fail to timely submit the annual report could be subject to penalties for each quarter the violation occurs.

New Jersey TDI and PFL Rates for 2027

Individuals employed in the state of New Jersey may be entitled to temporary benefits for a disability caused by non-occupational sickness or accident, including pregnancy and related medical conditions. The law applies to those employers who are subject to the state’s Unemployment Insurance law.  Temporary disability insurance (TDI) is funded by both employer and employee contributions.

Individuals may also be eligible for family leave insurance when they need time off work for baby bonding or to care for a loved one. Family leave insurance (FLI) is fully funded by the employee. 

The maximum benefit rates, the alternative earnings and base week amounts, and the taxable wage base for temporary disability (TDI) and family leave insurance (FLI) for calendar year 2027 are as follows:

  • Maximum TDI and FLI weekly benefit rate: $1,158
  • Alternative earnings test amount for TDI: $16,000
  • Base week amount: $319
  • Employers taxable wage base for TDI: $46,400
  • Workers taxable wage base for TDI/FLI: $177,100

The employee contribution rate for temporary disability and family leave insurance will be announced later in the year. 

New Jersey’s Department of Labor and Workforce Development Division of Temporary Disability and Family Leave Insurance has additional information on its website, including employer toolkit, FAQs, workplace posters, and more.

2027 New York PFL Rates

New York’s Department of Financial Services has released the premium rate, maximum employee contribution, and the maximum weekly benefit for paid family leave benefits for the 2027 calendar year. 

The premium rate increases to 0.452% in 2027 (0.432% in 2026) of an employee’s gross wages each pay period, with a maximum annual contribution cap of $451.81 for 2027 ($411.91 for 2026). The maximum weekly benefit is $1,287.91 for 2027 ($1,228.53 in 2026).

As a reminder, the paid family leave law provides up to 12 weeks of paid time off for baby bonding, to care for a family member, or military exigency. The paid family leave benefit is fully funded by employees through a payroll deduction. Additional information about the New York Paid Family Leave Program is available on the state’s dedicated webpage.

District of Columbia PFL Updates

DC’s City Council implemented changes to the paid family leave program, which reduces the duration of medical leave and family leave and decreases the maximum weekly benefit amount. The changes take effect Oct. 1, 2026, as outlined in table below.

Benefit Type Prior to Oct. 1, 2026 Effective Oct. 1, 2026
Medical leave 12 weeks 10 weeks
Family leave 12 weeks 6 weeks
Weekly benefit maximum $1,190 $1,100

Prenatal and parental leave amounts remain the same at 2 weeks and 12 weeks. Employer contributions remain the same at 0.75% of the covered employee’s wages.

Employers must post an employee notice in a conspicuous location at the workplace. The Department of Employment Services has updated the mandatory employee notice.

Massachusetts HIRD Form

As a reminder, every employer in Massachusetts with six or more employees must annually submit a Health Insurance Responsibility Disclosure (HIRD) form. The HIRD form collects information about the health coverage offered by Massachusetts employers to their employees.

The HIRD form may be filed by either the employer or the employer’s payroll company; however, it is the employer’s responsibility to ensure that the HIRD form is timely filed. The HIRD report can be filed starting November 15 and must be completed by December 15 of each year with the current year’s information. Employers that do not offer any health coverage still must file a HIRD report. 

The HIRD form and FAQs can be found on the Massachusetts Department of Revenue website.

Arkansas PBM Reporting Survives Challenge

Arkansas has a fairly robust pharmacy benefit manager law. As part of the state’s effort to address prescription cost issues, Rule 128 was issued in December 2024. It allows the Commissioner of Insurance to impose a dispensing fee (payable to pharmacies) if pharmacy compensation is not fair and reasonable.  Rule 128 also has a reporting provision that requires health benefit plans covering pharmacy expenses received in the state to submit to the Commissioner certain pharmacy compensation information.

Self-funded health plans with less than 5,000 Arkansas resident covered lives have a simplified reporting requirement and only need to report the total annual percentage of pharmacy reimbursement above the drug acquisition cost or wholesale acquisition cost. The Commissioner of Insurance issued a bulletin to further explain the Rule 128 reporting requirement.

Rule 128 was challenged, claiming ERISA preemption. In 2025, the U.S. District Court for the Northern District of Illinois dismissed the lawsuit confirming that the rule is not pre-empted by federal ERISA law.  On Aug. 26, 2026, the 7th Circuit Court of Appeals upheld the lower court’s dismissal of the lawsuit.

This means, for now, health benefit plans must continue to comply with the Rule 128 reporting obligation.

© Copyright CBIZ, Inc. All rights reserved. Use of the material contained herein without the express written consent of the firms is prohibited by law. This publication is distributed with the understanding that CBIZ is not rendering legal, accounting or other professional advice. The reader is advised to contact a tax professional prior to taking any action based upon this information. CBIZ assumes no liability whatsoever in connection with the use of this information and assumes no obligation to inform the reader of any changes in tax laws or other factors that could affect the information contained herein. Material contained in this publication is informational and promotional in nature and not intended to be specific financial, tax or consulting advice. Readers are advised to seek professional consultation regarding circumstances affecting their organization.

“CBIZ” is the brand name under which CBIZ CPAs P.C. and CBIZ, Inc. and its subsidiaries, including CBIZ Advisors, LLC, provide professional services. CBIZ CPAs P.C. and CBIZ, Inc. (and its subsidiaries) practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CBIZ CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients. CBIZ, Inc. and its subsidiary entities provide tax, advisory, and consulting services to their clients. CBIZ, Inc. and its subsidiary entities are not licensed CPA firms and, therefore, cannot provide attest services.

Let’s Connect

Our team is here to help. Whether you’re looking for business solutions, financial strategies, or industry insights, we’re ready to collaborate. Fill out the form, and we’ll be in touch soon.

This field is for validation purposes and should be left unchanged.