A minor refinement. v2 adds an alternative short title, "Health DATA Act of 2026," and updates specific cross-references to civil enforcement penalties within the indemnification prohibition section. The bill's substantive policy provisions regarding health data access for group health plans remain unchanged.
Health DATA Act of 2026
- Sponsor
- Rep. Onder, Robert F. [R-MO-3]
- Committees
- Education and Workforce Committee (primary)
- Last action
- Sep 15, 2026
Bottom line
The bill aims to empower group health plan fiduciaries with unprecedented access to health claims data, potentially enabling better cost management and increased scrutiny of service provider practices, but may face significant opposition from the healthcare industry.
What it actually does
This bill amends the Employee Retirement Income Security Act of 1974 (ERISA) to mandate that network service providers grant group health plan fiduciaries comprehensive access to de-identified health claims and encounter information, including pricing terms and overpayment data. It also voids any contractual provisions that limit this access and establishes civil penalties for non-compliance, aiming to enhance transparency and accountability in health plan administration.
Proponents argue
Proponents argue that providing plan fiduciaries with detailed health claims data is essential for them to effectively manage plan assets, identify inefficiencies, negotiate better rates with service providers, and uncover potential fraud or erroneous payments. This increased transparency is expected to drive down healthcare costs for employers and employees, ensuring fiduciaries can meet their legal obligations to plan participants.
Opponents contend
Opponents, primarily network service providers such as health insurers and pharmacy benefit managers, contend that the bill's broad data sharing requirements could expose proprietary pricing information, create significant administrative and IT burdens, and potentially compromise patient privacy despite de-identification efforts. They may also argue that existing regulations offer sufficient oversight and that the bill's mandates are overly prescriptive and disruptive to current market practices.
The bill is concise and its core provisions are clearly articulated, allowing an informed reader to grasp its main implications and potential impacts within a reasonable review period.
Section 2(a)(1), amending ERISA Section 3
Definition of 'Network Service Provider'
This provision defines 'network service provider' broadly to include any person or entity with a direct or indirect arrangement to provide services to a group health plan. This encompasses health care providers, facilities, networks, third-party administrators, health insurance issuers, pharmacy benefit managers, and any intermediaries. However, it explicitly excludes health care providers solely in their capacity as providers of health care services.
Supporters argue
Proponents argue that a clear and comprehensive definition of 'network service provider' is crucial to prevent entities from sidestepping data transparency requirements by operating through complex contractual arrangements or intermediaries. This ensures that all relevant parties involved in managing health plan services are accountable.
Critics contend
Opponents might argue that the broad definition could inadvertently capture entities not directly involved in claims administration or create confusion regarding responsibilities, potentially leading to over-regulation and increased compliance costs for a wide range of healthcare entities.
Tradeoffs
The tension lies between ensuring comprehensive coverage for transparency mandates and avoiding overly broad definitions that might impose undue burdens on entities not central to the bill's primary intent.
Section 2(a)(2), amending ERISA Section 408(b)(2)
Mandatory Data Access for Plan Fiduciaries
This core provision establishes that contracts between group health plans and network service providers are only 'reasonable' if they allow the responsible plan fiduciary and their designated agent (e.g., plan sponsor, administrator, or business associate) access to all claims and encounter information, including supporting documentation. It prohibits contract terms that limit or delay access (beyond 15 days), restrict the amount of data, limit access to pricing terms for alternative payment arrangements, or restrict information on overpayments and audit rights.
Section 2(a)(2), amending ERISA Section 408(b)(2)(E) and (F)
HIPAA Compliance for Data Sharing
These subparagraphs require that all information or data provided under the new access mandates must be consistent with HIPAA privacy and security regulations. Group health plans receiving this data must also comply with HIPAA. It clarifies that this does not modify existing HIPAA requirements for protected health information but also does not abridge the disclosure requirements of this bill or impose additional privacy/security requirements on network service providers or plan sponsors.
Section 2(a)(2), amending ERISA Section 408(b)(2)(G)
Standardized Data Formats and Accessibility
This provision mandates specific data standards for claims, payment notices, and non-claim costs. Institutional, professional, and dental claims must be in ASC X12N 837 format, and pharmacy claims in NCPDP format. Claim payment and electronic remittance advice (ERA) notices must be in ASC X12N 835 format. All these files must be unmodified, accessible to the plan at no cost, and converted to electronic format if originally paper. Non-claim costs must be itemized and available in real-time via a web portal, API, and downloadable CSV file.
Section 2(a)(3), amending ERISA Section 502(c)
Civil Enforcement Penalties for Violations
This amendment authorizes the Secretary of Labor to assess a civil penalty of up to $10,000 per day against any person or entity, including a network service provider, that violates the data access requirements of Section 724 (as amended by this Act). These penalties are in addition to any other penalties prescribed by law.
Section 2(a)(4), amending ERISA Section 410(c)
Voiding Restrictive Contract Provisions
This provision declares any agreement or instrument void as against public policy if it delays or limits a group health plan, its fiduciary, sponsor, or administrator from accessing the claims and encounter information described in Section 724(a)(1)(B), or if it violates the requirements of Section 408(b)(2) (as amended by this Act).
Section 2(a)(5), amending ERISA Section 410(a)
Prohibition on Indemnification for Civil Penalties
This amendment prohibits any person or entity subject to a civil enforcement penalty under Section 502(c)(13) or 502(c)(14) (which includes the new penalties for data access violations) from being indemnified, directly or indirectly, or otherwise relieved from liability for such penalties. Any contract provision in violation of this prohibition is declared void as against public policy.
Section 2(b), amending ERISA Section 724(a)(3)
Updated Attestation for Price and Quality Information
This provision updates the annual attestation requirement for group health plans and issuers regarding compliance with price and quality information rules. The attestation must now explicitly verify that required information is available upon request and provided in a timely manner, and that no contract terms restrict or unduly delay auditing or accessing this information. It prohibits third-party administrators from submitting this attestation on behalf of plans/issuers. If a plan/issuer cannot obtain the information, they must submit a written statement explaining why, detailing efforts to remove 'gag clauses,' and identifying the non-compliant service provider.
Section 2(c)
Effective Date and Applicability
The amendments made by this Act will apply to group health plans starting with the first plan year that begins on or after one year after the date of enactment. Crucially, this applies 'regardless of the date of execution of any contract with a network service provider,' meaning existing contracts will be subject to the new requirements.
Exclusion of healthcare providers solely in their capacity as providers from the 'network service provider' definition.
Section 2(a)(1), amending ERISA Section 3(46)(B)
Why it matters:This is standard legislative practice to clarify scope and prevent unintended consequences, ensuring the bill targets administrative entities rather than direct care providers.
Case for: Supporters would argue this carve-out is necessary to focus the bill's requirements on the entities that control claims data and administrative processes, rather than burdening individual doctors or hospitals whose primary role is patient care.
Case against: No specific opposition is typically raised against this exclusion, as it narrows the scope in a logical manner. However, some might argue that direct providers also hold valuable data that could contribute to transparency.
Estimated impact: Limits the direct compliance burden of the bill to administrative and intermediary entities, rather than extending it to all healthcare providers.
The 15-day limit for data access or 'a period determined appropriate by the Secretary, whichever is shorter.'
Section 2(a)(2), amending ERISA Section 408(b)(2)(D)(i)(I)
Why it matters:This is a common legislative technique to provide flexibility to regulatory agencies in implementing specific timelines, allowing for adjustments based on practical realities or technological advancements.
Case for: Proponents would argue that granting the Secretary of Labor discretion allows for adaptive regulation, ensuring that data access timelines remain reasonable and effective as technology and industry practices evolve, potentially shortening the period if feasible.
Case against: Critics might express concern that this discretion could lead to uncertainty for service providers regarding compliance deadlines or that a future Secretary might impose an unreasonably short timeframe without adequate industry consultation.
Estimated impact: Provides regulatory flexibility for the Department of Labor to adjust the mandatory data access timeframe, potentially making it shorter than 15 days.
Requirement for all claims and payment data files to be accessible to the group health plan 'at no cost to the group health plan.'
Section 2(a)(2), amending ERISA Section 408(b)(2)(G)
Why it matters:This is a critical financial detail often placed within technical sections to ensure that the burden of data access does not fall on the plans, which is a common strategy to maximize the benefit of transparency mandates.
Case for: Supporters would highlight this as essential to ensure that plans can fully leverage the mandated data access without incurring additional, potentially prohibitive, fees from service providers, thereby maximizing the potential for cost savings.
Case against: Opponents would argue that this 'no cost' mandate imposes an unfunded burden on service providers, who will incur significant costs to develop and maintain the systems required to provide data in the specified formats, potentially leading to these costs being recouped through other fees or reduced services.
Estimated impact: Shifts the financial burden of providing standardized data from group health plans to network service providers.
The effective date applies 'regardless of the date of execution of any contract with a network service provider.'
Section 2(c)
Why it matters:This is a deliberate legislative choice to ensure the bill's provisions cannot be circumvented by existing long-term contracts, a common tactic to delay compliance with new regulations.
Case for: Proponents would argue this clause is indispensable to prevent service providers from using pre-existing contracts to avoid or delay compliance, ensuring immediate and comprehensive application of the transparency mandates across the industry.
Case against: Opponents would argue that this provision retroactively alters contractual obligations, potentially leading to legal challenges and requiring costly renegotiations or terminations of existing agreements, creating significant disruption for service providers and potentially for plans.
Estimated impact: Ensures that all current and future contracts between group health plans and network service providers must comply with the new data access requirements by the effective date, regardless of when they were signed.