Employer-sponsored group health plans must submit their 2025 Gag Clause Prohibition Compliance Attestation (GCPCA) to CMS by December 31, 2025, to confirm compliance with federal transparency rules. This annual filing covers the 2024 calendar year and applies regardless of employer size or funding arrangement.
What is a gag clause?
A gag clause is a contractual term that prevents a health plan from accessing or disclosing cost or quality information about care—such as provider reimbursement rates or de-identified claims data. The federal Consolidated Appropriations Act (CAA) prohibits plans and insurers from agreeing to such clauses in contracts with providers, networks, or TPAs.
What is the attestation?
The Gag Clause Prohibition Compliance Attestation (GCPCA) is an online submission confirming that your plan does not contain any prohibited gag clauses. Employers must submit an attestation for each health plan they sponsor, and the filing must be made through CMS’s Health Insurance Oversight System (HIOS).
Who is responsible for filing?
- Fully insured plans: The carrier is responsible, but employers should confirm in writing that the filing will be handled.
- Self-funded or level-funded plans: The employer (plan sponsor) is responsible under federal law, even if a TPA administers claims. Most TPAs do not file automatically, so confirm in writing whether yours will assist.
How to file
Submit the attestation via the CMS HIOS portal: https://hios.cms.gov.
Each plan must be registered individually, and CMS offers technical guidance online. If this is your first time using HIOS, begin the registration process early.
What happens if you don’t file?
Failure to comply may result in penalties of $100 per day per affected individual, in addition to the risk of audits or investigations by federal agencies.
Compliance tips
- Don’t assume your TPA or carrier is filing—get written confirmation.
- Retain documentation of your attestation and related communications for at least six years (or longer if your organization follows a seven-year record retention policy).
- Start early. Delays in registration or vendor responses can impact your ability to file on time.
This article is for informational purposes only and does not constitute legal advice. Employers should consult legal counsel or a qualified advisor before making compliance decisions.
For more Employee Benefits resources, contact INSURICA today.
This article is not intended to be exhaustive nor should any discussion or opinions be construed as legal advice. Readers should contact legal counsel or an insurance professional for appropriate advice.
About the Author
Share This Story
Related Blogs
New Federal Guidance Tightens Oversight of Health Plan Data Sharing
Federal regulators have issued new guidance that will affect how employers manage health plan data sharing for the rest of 2026. The update comes in response to a rise in cybersecurity incidents involving third-party administrators, payroll vendors, and benefits platforms. While the rules do not create new penalties, they clarify that employers—not vendors—are ultimately responsible for protecting employee health information.
Mental Health Parity Requirements Remain in Effect
Mental health parity continues to be an important compliance obligation for employer-sponsored group health plans. While recent federal actions have created some confusion, employers should understand that the core requirements of the Mental Health Parity and Addiction Equity Act (MHPAEA) remain in effect.
The 2026 Compliance Crunch: What Employers Must Do Before Fall
Employee benefits managers are facing one of the busiest compliance years in more than a decade. Several major federal requirements are converging at the same time, and most of them carry real penalties for employers that miss deadlines or fail to document their efforts. The result is a mid-year “compliance crunch” that is catching many organizations off guard.










