McGohan Brabender Side Affects: Disrupting Health Care · 2026-06-05 · 7 min
Key moments - from our scoring
Substance score
28 / 100
Five dimensions, 20 points each
McGowan Brabender's June 2026 Compliance in Minutes episode covers four critical regulatory updates for HR professionals and plan sponsors managing self-funded health plans. A $245,000 HIPAA settlement involving a ransomware attack that exposed 9,300 individuals' PHI underscores that employers sponsoring self-funded plans cannot fully delegate HIPAA compliance to third-party administrators - the plan sponsor remains liable. Anticipated updates to the HIPAA security rule, the most significant in over a decade, will likely mandate multi-factor authentication, encryption of ePHI, enhanced vulnerability scanning, and eliminate flexibility between required and addressable safeguards. The episode also flags the July 31st PCORI fee deadline for self-funded, level-funded, and HRA arrangements, calculated at $3.47-$3.84 per covered life depending on plan year end date. Finally, a federal court's denial of a motion to dismiss a mental health parity lawsuit reveals heightened enforcement scrutiny: the court found the plan applied stricter nursing requirements to residential mental health treatment than comparable medical services, exposing both carriers and employers to fiduciary liability. HR leaders managing self-funded arrangements should immediately review HIPAA risk analyses, security policies, business associate agreements, and mental health parity compliance.
The Department of Health and Human Services settled with a self-funded employer health plan for $245,000 following a ransomware attack that exposed PHI of 9,300 individuals. The settlement highlighted that the plan lacked a comprehensive HIPAA risk analysis and effective risk management processes, and regulators emphasized that plan sponsors cannot delegate HIPAA compliance entirely to third-party administrators or vendors.
The anticipated HIPAA security rule updates include mandatory multi-factor authentication, encryption of electronic protected health information, enhanced vulnerability scanning, stronger audit controls, annual compliance reviews, detailed technology asset inventories, and elimination of the distinction between required and addressable security safeguards - the most significant changes in over a decade.
Self-funded medical plans, level-funded plans, and HRAs must file PCORI fees by July 31st using IRS Form 720. The fee is $3.47 per covered life for plan years ending before October 1, 2025, and $3.84 per covered life for plan years ending between October 1 and December 31, 2025, though the employer remains responsible even if a third-party administrator handles calculation.
A federal court denied dismissal of a lawsuit alleging a health plan imposed stricter requirements (around-the-clock nursing care) for residential mental health treatment than for comparable skilled nursing facilities used for medical services, finding the plan violated mental health parity requirements by applying inconsistent treatment limitations and authorization standards.
Both the carrier and the employer face fiduciary exposure when mental health parity requirements are not met, as demonstrated by the recent lawsuit naming both parties, making it critical for employers to work with carriers and TPAs to ensure mental health benefits are administered and documented consistently with medical benefits.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode packs a reasonable amount of substantive compliance information into 7 minutes - HIPAA enforcement specifics, proposed security rule changes, PCORI fee amounts, and a mental health parity ruling - but it reads as a newsletter recitation rather than analytical commentary, with no synthesis or so-what beyond basic 'review your policies' advice.
the plan lacked a comprehensive HIPAA risk analysis and did not have an effective risk management process in place to identify and address vulnerabilities before the breach occurred
mandatory multi factor authentication, encryption of electronic protected health information, enhanced vulnerability scanning, stronger audit controls, annual compliance reviews, and detailed inventories of technology assets
Every topic here is standard compliance newsletter fare - regulatory summaries with no contrarian angle, no first-principles reasoning, and no fresh interpretation; the episode adds zero original perspective on top of the regulatory developments it describes.
Compliance is the cornerstone of today's insurance landscape and for good reason
Staying on the topic of HIPAA uh, additional changes may be on the horizon
There is no guest at all; the sole speaker is self-identified as a marketing producer, not a practitioner, attorney, or compliance expert, and no credentials or direct experience are demonstrated anywhere in the episode.
I'm Hayden Parsons, the marketing producer at McGowan Brabender, bringing you the June 2026 edition of Compliance in Minutes
This is the episode's relative strength: specific dollar settlement amounts, individual counts, exact PCORI fee rates per covered life, a named IRS form, and a concrete filing deadline give B2B operators actionable reference points even in a short runtime.
a $245,000 settlement with a self funded employer health plan following a ransomware attack that exposed the protected health information of more than 9,300 individuals
For plan years ending before October 1, 2025, the fee is $3.47 per covered life. For plan years ending between October 1 and December 31, 2025, the fee increases to $3.84 per covered life
There is no conversation whatsoever - no host-guest dynamic, no questions, no follow-ups, no pushback; this is an uninterrupted marketing-producer monologue reading a compliance summary, which precludes any meaningful conversational craft.
With that in mind, let's dive into your June 2026 compliance updates
Thanks for tuning in and don't forget to subscribe for monthly updates on compliance, employee benefits and health plan
Computed from the transcript - who did the talking, and the words that came up most.
When employees hear “employee benefits,” they might think of healthcare, perks, wellness programs, PTO, 401(k) plans or disability coverage. But when HR professionals hear “employee benefits,” they’re likely thinking about cost management, compensation strategies, open enrollment, and - most importantly - compliance. Compliance is a cornerstone of today’s insurance landscape. With that in mind, let’s dive into your June 2026 breakdown of Compliance in Minutes.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Hello everyone. I'm Hayden Parsons, the marketing producer at McGowan Brabender, bringing you the June 2026 edition of Compliance in Minutes. When employees hear the words employee benefits, they might think of healthcare, PIRCs, wellness programs, PTO. The list goes on. But when HR professionals hear the words employee benefits, they're likely thinking about cost management, compensation, open enrollment, and most importantly, compliance. Compliance is the cornerstone of today's insurance landscape and for good reason. As your broker, MB is committed to delivering timely compliance updates, empowering our clients to operate efficiently, overcome challenges, and remain aligned with the ever evolving laws and regulations. With that in mind, let's dive into your June 2026 compliance updates. First up, A significant HIPAA enforcement action is serving as an important reminder for employers sponsoring self funded health plans. In April, the Department of Health and Human Services announced a $245,000 settlement with a self funded employer health plan following a ransomware attack that exposed the protected health information of more than 9,300 individuals. According to regulators, the plan lacked a comprehensive HIPAA risk analysis and did not have an effective risk management process in place to identify and address vulnerabilities before the breach occurred. The incident exposed sensitive information, including names, addresses, Social Security numbers, claims information and benefit enrollment data. While most HIPAA enforcement actions involve healthcare providers or hospitals, this case is notable because it directly involved an employer sponsored health plan. The key takeaway for employers is that HIPAA compliance is not something that can be delegated entirely to a third party administrator or vendor. Even when outside partners are involved, the health plan itself remains responsible for meeting HIPAA privacy and security rule requirements. Regulators also emphasized another important concept, the M minimum necessary standard. In many cases, employers may not need access to identifiable health information at all. DE identified reporting is often sufficient for plan oversight and strategy purposes. For organizations sponsoring self funded or level funded plans, now is a good time to review risk analysis, security policies, business associate agreements and internal access controls to ensure they remain up to date. Staying on the topic of HIPAA uh, additional changes may be on the horizon. Federal regulators are expected to finalize updates to the HIPAA security rule, which would represent the most significant changes to these requirements in more than a decade. While the final rule has not yet been released, so several proposed requirements are worth watching. These include mandatory multi factor authentication, encryption of electronic protected health information, enhanced vulnerability scanning, stronger audit controls, annual compliance reviews, and detailed inventories of technology assets that store or transmit protected health information. Another notable proposal would eliminate the distinction between required and addressable security safeguards, meaning organizations would have less flexibility in determining how certain security standards are implemented. Although the timeline remains uncertain, employers with access to protected health information should begin evaluating their cybersecurity posture now. Many of the proposed requirements align with current cybersecurity best practices, so preparing early could make future compliance efforts significantly easier. Next, a quick reminder about an annual compliance deadline that applies to many self funded health plans, employer sponsoring self funded medical plans, level funded plans, health reimbursement arrangements, and individual coverage HRAs may be required to file and pay patient centered uh, Outcomes Research Institute or PCORI fees by July 31st. The fee is reported using the second quarter IRS Form 720 and is calculated based on the average number of covered lives during the applicable plan year. For plan years ending before October 1, 2025, the fee is $3.47 per covered life. For plan years ending between October 1 and December 31, 2025, the fee increases to $3.84 per covered life. Most employers work with their third party administrator to determine the appropriate covered life count, but the responsibility for filing and payment ultimately remains with the employer. Fully insured plans are generally exempt because the insurance carrier pays the fee directly. If you sponsor a self funded arrangement, now is a good time to confirm who is handling the calculation and ensure the filing process is on track before the July deadline. Finally, a recent court decision highlights the continued scrutiny surrounding mental health parity compliance. Uh a federal court recently denied a motion to dismiss a lawsuit involving coverage requirements for residential treatment centers. The lawsuit alleges that the health plan imposed stricter requirements on residential mental health treatment than it did on comparable medical and surgical services. Specifically, the court noted that the plan appeared to require around the clock nursing care for residential treatment centers, while similar requirements were not consistently applied to comparable skilled nursing facilities. Because of the difference, the court concluded that the plaintiffs had raised a plausible mental health parity claim, allowing the case to move forward. This case serves as another reminder that parity compliance extends beyond simply covering mental health services. Employers and plan fiduciaries must also ensure that treatment limitations, authorization requirements, network standards, and reimbursement practices are applied consistently across both mental health and medical benefits. Notably, the lawsuit names both the carrier and the employer, reinforcing the reality that plan sponsors can face fiduciary exposure when parity requirements are not met. As enforcement activity in litigation continues to increase, employers should work closely with carriers, Team TPAs, and advisors to understand how mental health benefits are administered and documented. That's a wrap for our June 2026 compliance admittance. Thanks for tuning in and don't forget to subscribe for monthly updates on compliance, employee benefits and health plan.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.