Health Plan No Surprises Act Action Alert: Update Health Plans For New Final Rule & Federal IDR Gateway Plus Audit Your Plan’s 2026 No Surprises Act Compliance and Out-of-Network Cost Assumptions

September 4, 2026

Employer- and union-sponsored group health plans, their fiduciaries, third-party administrators (TPAs) and administrative services-only (ASO) vendors should take immediate actions ensure their health plan’s compliance under the No Surprises Act (“NSA”) responsibilities in response to new final rules and emerging data suggesting many health plans and their fiduciaries already are incurring signficantly increased cost and other unrecognized liability risks from liabilities preexisting NSA compliance deficiencies.

  • First, the Departments of Health and Human Services, Labor and the Treasury and the Office of Personnel Management have finalized sweeping changes to the No Surprises Act (NSA) Federal Independent Dispute Resolution (IDR) process — including retirement of the current single-use web forms in favor of a new online case-management platform, the “IDR Gateway.”
  • Second, and just as urgent, mounting federal court rulings and IDR performance data are exposing widespread payer- and TPA-side compliance failures that are driving actual 2026 out-of-network (OON) claim costs well above what many plans budgeted.
  • Plan sponsors and fiduciaries should treat this as a multi-pronged project:
  • Get ready for the new rules and Gateway and confirm plan documentation, communications, vendor contracts, out-of-network cost forecasts and processes are legally compliant and operationally ready to manage out-of-network costs and liabilities; and
  • Assess your health plan’s 2026 out-of-network claims to evaluate if legal, operational or other weaknesses in your 2026 plan year reference based pricing or other claims assumptions, forecasts or administration have or are likely to expose your plan to higher than projected costs and other financial and legal exposures.

Part 1 — The IDR Gateway Transition & New Final Rule Required Updates

The Final Rule: What Changed

On May 28, 2026, HHS, the Department of Labor, the Department of the Treasury and OPM finalized the “Federal Independent Dispute Resolution Operations” rule, published June 4, 2026 at 91 Fed. Reg. 33900 (RINs 0938-AV15, 1210-AC17, 1545-BQ55 and 3206-AO48), amending 45 C.F.R. Part 149, 29 C.F.R. Part 2590, 26 C.F.R. Part 54 and 5 C.F.R. Part 890. See also the CMS Fact Sheet and CMS Press Release announcing the rule. The rule is intended to speed up dispute resolution, cut costs and improve transparency in the process health plans, providers and IDR entities use to resolve payment disputes over certain out-of-network claims under the No Surprises Act. Key operational changes include:

  • Lower administrative fees. The per-party administrative fee to initiate a dispute drops from $115 to $15 — an 85% reduction — effective approximately June 11, 2026 (five business days after publication).
  • Revised batching rules. Claims may be batched in three new circumstances (same-patient/consecutive-date services on one claim; identical or comparable procedure codes across systems; and certain anesthesiology, radiology, pathology and laboratory services within the same CPT category), subject to a new 50-line-item cap per dispute.
  • Portal-based open negotiation. Open negotiation notices must be submitted through the Federal IDR portal, starting the 30-business-day negotiation clock on submission, with a response notice due from the recipient by business day 15.
  • Faster eligibility determinations. Certified IDR entities must determine dispute eligibility within 5 business days of being selected — a firm deadline where none previously existed.
  • Standardized claim codes. Payers must communicate using standardized claim adjustment reason codes/remittance advice remark codes (CARC/RARC) on No Surprises Act claims, helping providers identify IDR eligibility earlier.
  • New IDR Registry. Payers will be required to register and obtain an assigned registration number to support provider identification and CMS enforcement tracking.

See CMS Fact Sheet, Federal Independent Dispute Resolution Operations Final Rule; 91 Fed. Reg. 33900 (June 4, 2026)

As these changes are being phased in with some already effective and others scheduled to rollout over the next few months in future agency guidance, plans must update policies and practices for changes already effective, while keeping a watch out for and building the compliance infrastructure to meet each future change by its deadline as CMS issues additional guidance. Pending future guidance, Plans need to act now to respond to the currently issued rules:

  • The general rule took effect August 3, 2026;
  • The reduced fee is already in effect; and
  • The final rules on batching, portal-based negotiation/eligibility, and Registry provisions take effect on rolling 90-day (or 90-business-day) timelines tied to forthcoming CMS guidance and system-functionality announcements.

Coming Soon: The IDR Gateway

In late 2026, the Federal IDR process will transition from single-use web forms to the new IDR Gateway, a secure, centralized platform for managing disputes. According to CMS, SeeCMS, “Coming Soon: IDR Gateway,” cms.gov/nosurprises/notices

According to CMS, the IDR Gateway users will be able to:

  • Start and respond to disputes;
  • Access dispute dashboards and reports associated with their organization;
  • Track dispute information, including disputes assigned to a certified IDR entity;
  • Monitor assigned disputes by process phase; and
  • Review notifications regarding dispute activity.

The Gateway also adds new security features, including identity verification and protocols limiting access to the Federal IDR process to U.S.-based users.

Who Must Sign Up

Organizations and individuals that process disputes, represent parties, or submit IDR web forms in the current Federal IDR process must sign up to manage disputes in the IDR Gateway. If a plan or issuer uses a TPA or other organization to process disputes on its behalf, the plan itself does not need to sign up — but it must confirm that the TPA or other organization responsible for managing its dispute-processing activities has signed up for an IDR Gateway account. Plan sponsors and fiduciaries relying on a TPA or ASO vendor should get this confirmation in writing.

Details about signing up for the IDR Gateway are still forthcoming from CMS. Until sign-up instructions are released, parties should continue using the existing Federal IDR web forms.

Recommended IDR Gateway Action Steps for Plan Sponsors, Fiduciaries and Administrators

  1. Select your IDR Gateway administrator(s) now. Every organization that will use the Gateway should designate at least one administrator (CMS recommends two; no more than ten) to set up the organization’s Gateway account before the September 15, 2026 account-creation window opens.
  2. Confirm who is responsible for signing up. Where a TPA or other vendor handles IDR disputes on the plan’s behalf, obtain written confirmation that the vendor will register for its own IDR Gateway account and has a compliance plan in place.
  3. Watch for CMS outreach. The Federal IDR Team will email selected administrators instructions for creating accounts and setting up the organization. If your organization designates an administrator who does not receive that email, contact IDRGatewayHelp@cms.hhs.gov.
  4. Update plan documents and claims/disputes procedures. Revise summary plan descriptions, claims and appeals procedures, and internal desk procedures to reflect the new $15 administrative fee, revised batching rules, portal-based open negotiation timelines, and standardized CARC/RARC code communications.
  5. Refresh fiduciary oversight practices. Treat administrator selection, TPA/ASO monitoring, and IDR Gateway readiness as fiduciary functions: document the decision-making process, update committee charters and meeting minutes, and confirm the plan’s fiduciary liability insurance and indemnification provisions address IDR-related exposures.
  6. Update vendor agreements. Amend TPA, ASO and business associate agreements to require timely IDR Gateway registration, IDR Registry compliance (for payers), and standardized code usage, with reporting obligations back to the plan.
  7. Train staff. Brief HR, benefits and claims personnel handling out-of-network claims on the new open-negotiation notice process (30-business-day clock, 15-business-day response deadline) and the accelerated 5-business-day eligibility determination timeline.
  8. Keep using the current web forms for now. Continue submitting disputes through the existing Federal IDR web forms until CMS releases IDR Gateway sign-up details and formally transitions the process.

Why This Matters

For ERISA-covered group health plans, decisions about how the plan manages No Surprises Act disputes — including who administers the IDR Gateway account and how vendors are monitored — implicate fiduciary duties of prudence and loyalty. Missing the administrator sign-up window, failing to confirm a TPA’s Gateway registration, or continuing to rely on procedures that do not reflect the new fee, batching, and timing rules could expose plans and their fiduciaries to processing delays, forfeited dispute rights, or claims of fiduciary breach. Because CMS is rolling these changes out in phases tied to forthcoming guidance, plans, fiduciaries and their advisors should treat this as a standing agenda item for plan committee meetings through the end of 2026.

Part 2 — Audit & Fix Your 2026 NSA Compliance and Out-of-Network Cost Assumptions

While preparing for the IDR Gateway and other future changes, plan sponsors and fiduciaries should also use the fall renewal and budgeting cycle to prudently audit and evaluate their out-of-network benefit design, reference based or other pricing assumptions and models and NSA and other out-of-network claims compliance and processes.

Aside from providing invaluable insights about plan cost and liability drivers and opportunities to mitigate current and future liabilities arising from NSA covered and other out-of-network claims, plan sponsors and officers, directors or employees serving as named fiduciaries or functioning performing these responsibilities bear fiduciary responsibility for arranging and verifying the prudent performance of these responsibilities under ERISA Section 404.\

In fact, many plan sponsors or their officers, directors or management employees will be horrified to discover that due to less than optimal provisions in their usually vendor provided plan documents and administrative services agreements, the plan sponsor, an officer, director or employee of the plan sponsor or both is the fiduciary responsible under ERISA Section 404, not the third party administrator or other plan vendor, for prudently ensuring proper handling of these responsibilities and the resulting added costs and liabilities resulting from their mishandling.

Emerging litigation and IDR performance data also strongly suggests that many plans, their sponsors and fiduciaries conducting these assessments will be unhappily surprised by the results of their investigation. Emerging litigation, IDR performance data and other emerging information suggests many health plans have and continue incurring significantly and arguably unnecessarily higher than projected costs and liabilities due to their plan’s design and administration in reliance upon reference based pricing models rendered unsustainable by the NSA, bungled handling of NSA responsibilities by plan vendors, and other NSA compliance and administration defects rather than provider abuse of the NSA process often bemoaned by plan vendors and insurers.

At minimum, this review within the scope of attorney-client privilege generally should evaluate:

  • Review 2026 and 2027 plan documents and services agreements to confirm the identity of the party assigned fiduciary responsibility for proper handling of NSA and other out-of-network NSA and other claims handling processes and that the those assigned fiduciary responsibility in operation actually are handling these actions prudently in accordance with their designated responsibility and the NSA rules.
  • Assess how well the plan, its fiduciaries and its vendors actually complied with NSA procedural requirements during the 2026 plan year and any heightened cost or liability exposures resulting from any suboptimal performance.
  • Assess the likelihood that the plan is or between now and year end is likely to be exposed to liability for existing or potential NSA arbitration awards, lawsuits, or penalties from unpaid NSA awards on out-of-network claims, consult experienced legal counsel about steps that the plan should take to minimize potential forfeiture of stop loss coverage for these amounts and other actions that may help resolve and mitigate these liabilities
  • If the assessment reveals that the plan or its fiduciaries are exposed to increased costs, claims or fiduciary liabilities, or penalties due to service providers’ mishandling of NSA out-of-network negotiations, arbitration or other responsibilities, consult with experiencd legal counsel about potential avenues of recourse against plan service providers or others for
  • Evaluate actual 2026 out-of-network claim costs against the 2026 reference based pricing and other claims and cost projections relied upon in formulating 2026 plan year pricing and cost forecasts

Step 1: Audit Procedural Compliance

For each out-of-network claim that reached the NSA process during the 2026 plan year, confirm that the plan or its TPA:

  • Sent timely notice of the qualifying payment amount (QPA) and other required disclosures with the initial payment or denial;
  • Opened and responded to open negotiation within the required 30-business-day window (now triggered by portal submission under the final rule);
  • Prepared complete, timely, and well-supported IDR offers and written arguments — including QPA methodology and any additional credible information — rather than default or boilerplate submissions;
  • Paid or collected payment on IDR determinations within the required timeframe; and
  • Calculated participant cost-sharing using the QPA rather than provider billed charges.

Gaps in any of these areas are not just paperwork problems. As discussed below, incomplete or untimely IDR responses are now a documented, widespread driver of adverse — and expensive — outcomes.

Step 2: Compare Actual 2026 OON Costs to Your Projections

Ask your actuary, broker, TPA or reference-based pricing (RBP) vendor to reconcile actual 2026 plan-year OON claim costs (including IDR administrative fees, negotiated settlements, and arbitration awards) against the assumptions used to build the 2026 budget and the 2027 renewal projection. Where actual costs materially exceeded projections, plans should press their vendors to explain why — and should not simply accept “providers are gaming the system” as the answer without testing it against the data below.

Step 3: Diagnose the Variance

In Solutions Law Press, Inc.’s experience, unfavorable OON cost variances typically trace to one or both of two root causes, both of which are increasingly well-documented:

(1) Unreasonably low pricing assumptions. CMS’s own published IDR performance data show that the prevailing (winning) offer exceeded the qualifying payment amount (QPA) in approximately 88% of payment determinations in the first half of 2025 and approximately 87% of determinations in the second half of 2025 — see CMS, Federal IDR PUF Supplemental Background, Jan.–June 2025 and CMS, Federal IDR PUF Supplemental Background, July–Dec. 2025. If the QPA is exceeded in roughly nine out of ten decided disputes, a plan, TPA, or reference-based pricing (RBP) vendor that is still pricing anticipated out-of-network exposure primarily off of QPA figures or “usual and customary” tables — without reasonably accounting for actual IDR outcome data — is likely understating 2026 and 2027 out-of-network cost projections.

(2) Administrative deficiencies. The same official CMS reports show providers prevailing in approximately 88% of decided disputes in the first half of 2025 and approximately 85% in the second half of 2025; default decisions (meaning a party, often the plan or its TPA, failed to timely or adequately participate) at 22% in the first half of 2025, improving to 17% in the second half; non-initiating parties (typically plans/issuers) raising eligibility challenges in 40% and 42% of disputes, respectively; and only 37% of determinations issued within the required 30-business-day timeframe in the first half of 2025, improving to 62% in the second half. See CMS, Federal IDR PUF Supplemental Background, Jan.–June 2025 and CMS, Federal IDR PUF Supplemental Background, July–Dec. 2025; see also the full set of CMS Independent Dispute Resolution reports. Every default decision, missed deadline, or incomplete submission is a preventable cost. Plans should ask their TPA for a log of every 2026 dispute showing eligibility challenges raised, response timeliness, and outcome, to see whether their own vendor’s administration is contributing to the losses.

The Litigation Backdrop: Courts Are Rejecting the “Provider Fraud” Narrative

Several major insurers have recently tried to recharacterize high-volume IDR activity as fraud rather than a symptom of underpricing. Beginning in 2026, Anthem Blue Cross, Blue Cross Blue Shield of Texas, Aetna, and a Blue Cross Blue Shield of Georgia affiliate of Elevance Health each sued healthcare providers and IDR-support companies (including HaloMD and Radiology Partners), alleging the defendants ran a coordinated scheme — through federal RICO, wire fraud, and related state-law claims — to systematically flood the IDR process with disputes and extract improper arbitration awards. Federal courts have now rejected each of these suits at the pleading stage (one is currently on appeal):

  • Anthem Blue Cross Life & Health Ins. Co. v. HaloMD LLC, No. 8:25-cv-01467 (C.D. Cal., order granting motion to dismiss entered Apr. 9, 2026) — dismissed as an “end run” around the NSA’s limits on judicial review of IDR determinations. See PACER, the federal judiciary’s official case-record system.
  • Blue Cross Blue Shield of Texas v. HaloMD LLC, No. 5:25-cv-00132 (E.D. Tex., order dismissing with prejudice entered May 22, 2026) — dismissed as “no more than a collateral attack” on IDR awards. See PACER.
  • Aetna Health Inc. v. Radiology Partners Inc., No. 3:24-cv-01343 (M.D. Fla., order granting motion to dismiss entered Apr. 16, 2026; notice of appeal filed May 6, 2026 — currently pending before the Eleventh Circuit). See PACER.
  • Blue Cross Blue Shield Healthcare Plan of Georgia, Inc. v. HaloMD, Inc., No. 1:25-cv-02919 (N.D. Ga., order dismissing with prejudice entered July 10, 2026) — the court found it “far more plausible” that the insurer “engages in a consistent practice of submitting lowball offers” than that thousands of providers conspired to defraud it. See GovInfo.gov (U.S. Government Publishing Office) case file and PACER.
DateWhat Happens
April 2022Federal IDR process launched under the No Surprises Act.
May 28, 2026HHS, DOL, Treasury and OPM finalize the “Federal Independent Dispute Resolution Operations” rule.
June 4, 2026Final rule published at 91 Fed. Reg. 33900 (Doc. No. 2026-11140).
~June 11, 2026Reduced $15 per-party administrative fee takes effect (5 business days after publication).
August 3, 2026General effective date of the final rule (91 Fed. Reg. 33900).
September 15, 2026All potential IDR Gateway users may begin creating accounts; organizations should have selected their administrator(s) by this date.
90 days after related CMS guidance/functionality announcementsPhased rollout of batching changes, portal-based open negotiation/eligibility processing, and the IDR Registry.
Late 2026Federal IDR web forms are retired; the IDR Gateway becomes the required platform for managing disputes.

In each case, the courts held that Congress deliberately shielded IDR determinations from broad collateral judicial review, and that insurers cannot use RICO or similar theories to relitigate arbitration outcomes they simply dislike. (The Aetna/Radiology Partners dismissal is on appeal, so it is not yet final.) Read together with the official CMS performance data above, these rulings support a different conclusion than “provider abuse”: that a meaningful share of the OON cost pressure plans are seeing may reflect payers’ and TPAs’ own pricing and administrative shortfalls, not a corrupted dispute process. Plan fiduciaries should not assume unfavorable IDR experience is explained away by “provider gaming” without independently testing that assumption against their own vendor’s performance data. Federal district court filings are maintained in the judiciary’s PACER system; full copies of the pleadings and orders cited above can be retrieved there by case number, and the Georgia order is additionally available through GovInfo.gov.

Exposure Beyond Higher Claim Costs

NSA compliance gaps do more than inflate OON spend. They can expose the plan, its fiduciaries and its administrators to:

  • Benefits and fiduciary-breach litigation. Participants can bring claims under ERISA § 502(a), 29 U.S.C. § 1132(a) over mishandled cost-sharing, wrongful denials, or QPA miscalculation, and fiduciaries can face breach-of-duty claims for failing to prudently monitor how the plan and its TPA are administering NSA obligations.
  • Regulatory enforcement and civil penalties. DOL’s Employee Benefits Security Administration administers and helps enforce No Surprises Act requirements for ERISA-covered group health plans — see DOL, Surprise Billing and Price Transparency (EBSA). Plans under DOL investigation also face independent exposure for recordkeeping and document-production failures: under ERISA § 502(c)(6), civil penalties for failing to timely furnish documents the Department requests run up to $195 per day, not to exceed $1,956 per request — see Federal Register, ERISA Civil Penalties Inflation Adjustments for 2025 — on top of any substantive NSA violations found.
  • Loss of stop-loss or other reinsurance recovery. Most stop-loss and reinsurance contracts condition reimbursement on the plan and its TPA properly and timely administering claims (including NSA negotiation and IDR deadlines) and on timely submission of proof of loss and stop-loss claims within the policy’s contractual deadlines. Administrative missteps or late claim filings driven by NSA non-compliance can jeopardize specific or aggregate stop-loss recovery — compounding, rather than offsetting, the plan’s excess OON costs. [This point reflects Solutions Law Press, Inc.’s general observation of common stop-loss contract terms, not a specific ruling or study — plans should confirm the actual terms of their own stop-loss contract.]
  • Vendor and contractual exposure. Poor TPA or RBP vendor performance uncovered by an audit may support renegotiating fees, invoking indemnification provisions, or replacing a vendor — but only if the plan has documented the deficiency.
  • Reputational and participant-relations costs. Underpriced or mishandled OON claims frequently surface as balance-billing complaints, appeals, and participant dissatisfaction, even where the plan is not ultimately liable.

Recommended Audit and Action Steps

  1. Commission a 2026 NSA compliance audit covering negotiation timeliness, IDR response completeness and timeliness, QPA calculation methodology, notice content, and payment timing.
  2. Reconcile actual 2026 OON claim costs (including administrative fees and IDR awards) against the assumptions used for the 2026 budget and 2027 renewal, and require material variances to be explained.
  3. Request a full 2026 IDR dispute log from your TPA/ASO vendor — disputes initiated, eligibility challenges raised, defaults, timeliness of responses, and outcomes relative to QPA — to identify systemic administration issues.
  4. Benchmark your plan’s or vendor’s QPA/reference-based-pricing methodology against actual contracted-rate and IDR outcome data, and challenge assumptions that do not reasonably account for NSA experience.
  5. Review stop-loss and reinsurance contracts for claim-filing deadlines and proper-administration conditions, and confirm your TPA is meeting them for NSA-related claims.
  6. Document the audit, findings, and any corrective action plan in fiduciary committee minutes as part of the plan’s ongoing prudent-process record.
  7. Engage counsel to assess potential fiduciary-breach exposure, vendor indemnification rights, and recovery options where the audit reveals material vendor deficiencies.

For Help or More Information

The author of this update, Cynthia Marcotte Stamer has decades of experience advising and assisting health industry clients to design, audit, and defend their organizations and practices including conducting audits and investigations, designing and updating compliance and risk management programs, responding to government investigations, conducting transaction, governance, and other due diligence, and assisting with other legal and operational compliance and risk management and legislative and regulatory affairs. She is available to assist your organization in assessing the impact of these developments and navigating the compliance and strategic steps that follow. For more information about these or other health care, managed care and other health benefits, or other health industry laws or concerns, contact Ms. Stamer via e-mail or via telephone at (214) 452 -8297.

About the Author

Cynthia Marcotte Stamer is an American College of Employee Benefits Counsel and a Martindale-Hubble “AV-Preeminent” (Top 1%) attorney and advisor board certified in labor and employment law by the Texas Board of Legal Specialization peer peer celebrated as “Top Rated Lawyer” and “LEGAL LEADER™ “Top Rated Lawyer” and “Best Lawyer” for her work in ERISA & Employee Benefits Law, Health Care Law, Labor and Employment Law, and Business and Commercial Law.

Nationally recognised for her decades of leading edge health and other employee benefits and insurance, compensation, human resources and other management work, public policy leadership and advocacy, coaching, teachings, and publications, Ms. Stamer is well known for her decades of pragmatic, leading edge work, scholarship and thought leadership on health benefit and other health and managed care, privacy and data security and other employee benefit, insurance, and health industry legal, public policy and operational concerns. 

Ms. Stamer’s work throughout her career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns.  As a a key focus of this work, she has continuously and extensively worked with domestic and international health plans, their sponsors, fiduciaries, administrators, and insurers; managed care and insurance organizations; third party administrators and other health benefit service providers; hospitals, health care systems and other health care providers, accreditation, peer review and quality committees and organizations; billing, utilization management, management services organizations, group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; consultants; investors; EMR, claims, payroll and other technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, self-insured health and other employee benefit plans, their sponsors, fiduciaries, administrators and service providers, insurers and other payers, health industry advocacy and other service providers and groups and other health and managed care industry clients as well as federal and state legislative, regulatory, investigatory and enforcement bodies and agencies.

Her experience includes more than 35 years of leading edge work for employer and other plan sponsors, plans and their fiduciaries, insurers, third party administrators, health care clearinghouses and other health care, insurance and other data and technology providers, and others on health and other employee benefits design, administration, compliance, and policy including decades of work on fiduciary compliance and risk management; eligibility, coverage and other plan mandates; administrative simplification and transparency; PBM, pharmacy and pharmaceutical management and regulation; surprise billing and other non-par provider; direct provider, vendor and other credentialing, contracting and management; and other managed care and insurance; high deductible, minimum or level premium, captive and other non traditional funding; and agency and private audits, investigations and enforcement; and other insured and self-insured health benefit contracting, design, administration, regulation, fiduciary and other liability managment, and other design, compliance, risk management, defense, and operations solutions.

She also has extensive experience helping health care systems and organizations, group and individual health care providers, health plans and insurers, health IT, life sciences and other health industry clients prevent, investigate, manage and resolve  sexual assault, abuse, harassment and other organizational, provider and employee misconduct and other performance and behavior; manage Section 1557, Section 504, Civil Rights Act and other discrimination and accommodation, and other regulatory, contractual and other compliance; vendors and suppliers; contracting and other terms of participation, medical billing, reimbursement, claims administration and coordination, Medicare, Medicaid, CHIP, Medicare/Medicaid Advantage, ERISA and other payers and other provider-payer relations, contracting, compliance and enforcement; Form 990 and other nonprofit and tax-exemption; fundraising, investors, joint venture, and other business partners; quality and other performance measurement, management, discipline and reporting; physician and other workforce recruiting, performance management, peer review and other investigations and discipline, wage and hour, payroll, gain-sharing and other pay-for performance and other compensation, training, outsourcing and other human resources and workforce matters; board, medical staff and other governance; strategic planning, process and quality improvement; meaningful use, EMR, HIPAA and other technology,  data security and breach and other health IT and data; STARK, ant kickback, insurance, and other fraud prevention, investigation, defense and enforcement; audits, investigations, and enforcement actions; trade secrets and other intellectual property; crisis preparedness and response; internal, government and third-party licensure, credentialing, accreditation, HCQIA and other peer review and quality reporting, audits, investigations, enforcement and defense; patient relations and care;  internal controls and regulatory compliance; payer-provider, provider-provider, vendor, patient, governmental and community relations; facilities, practice, products and other sales, mergers, acquisitions and other business and commercial transactions; government procurement and contracting; grants; tax-exemption and not-for-profit; privacy and data security; training; risk and change management; regulatory affairs and public policy; process, product and service improvement, development and innovation, and other legal and operational compliance and risk management, government and regulatory affairs and operations concerns. to establish, administer and defend workforce and staffing, quality, and other compliance, risk management and operational practices, policies and actions; comply with requirements; investigate and respond to Department of Insurance, Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, trucking, alcohol and firearm, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry actions: regulatory and public policy advocacy; training and discipline; enforcement;  and other strategic and operational concerns.

Former lead advisor to the Government of Bolivia on its Social Security Privatization reform, miss Stamer also has extensive legislative and regulatory affairs experience on federal, state and international employee benefits, healthcare, workforce, education, insurance, data privacy and security, antitrust, and other regulations and reforms.

In addition, Ms. Stamer contributes her time and leadership to numerous policy, professional, civil and other organizations, Ms. Stamer currently or previously served as the Scribe leading annual agency meetings on HIPAA and other issues with the Department of Health and Human Services; leadership Council Representative, speaker, author and faculty lead for the American Bar Association (“ABA”) Joint Committee on Employee Benefits; the ABA International Section International Employment Law Committee and International Life Sciences Committee Chair; the ABA Tort Trial and Insurance Practice Section Medicine and Law Committee Chair and Employee Benefits and Worker’s Compensation Committees Vice Chair; the ABA Health Law Section Managed Care & Insurance Interest Group Chair and Risk Management Interest Group Chair; the ABA RPTE Employee Benefits & Other Compensation Group Chair and Welfare Benefit, Fiduciary Responsibility, and Plan Terminations and Transactions Committees Chair; Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association; a Southwest Benefits Association Board Member; a SHRM Consultants National and Region IV Board Chair; WEB National Board Member and Dallas Chapter President; National Kidney Foundation of North Texas Board Member and Compliance Chair; Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency Board President; a North Texas United Way Long Range Planning Committee Member; and other leadership involvement in a broad range of other professional and civic organizations.

Author of hundreds of highly regarded works on health and other benefits, human resources, health care, insurance, data privacy and security and other related concerns, examples of these publications include “Transparent PBM Contracting,” “ACOs, Direct Contracting: Legal & Practical Challenges For Employers, Providers & TPAs,” “The Medicare Advantage Contracting Manual,” “Third Party Administrator (TPA) Contracting Principles and Strategies and a multitude of other publications and presentations. 

For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.


Reference-Based Pricing Plans Beware: No Surprises Act Awards and Narrow Networks May Create Significant Unbudgeted Out-of-Network Liabilities

September 4, 2026

Employers sponsoring and fiduciaries administering health plans that rely upon Medicare-based or other reference-based pricing (“RBP”) methodologies with or without narrow network design features to project and control out-of-network health plan costs likely are incurring higher than expected out-of-network costs, as well as avoidable NSA enforcement and noncompliance liabilities. To mitigate these exposures and avoid unknowingly continuing these exposures into the 2027 plan year sponsors and fiduciaries should verify their NSA compliance, compare their actual out-of-network expenses against their original assumptions, and ensure timely and effective administration of out-of-network claims to mitigate NSA and other liabilities before year-end.

Recently published data suggests most self-funded employer plans RBP formulas bear little relationship to the amounts those plans ultimately pay when a claim falls within the No Surprises Act (“NSA”) and proceeds through negotiation or federal Independent Dispute Resolution (IDR).

The disparity between predictions and ultimate payouts increasingly leaves many employers with unexpectedly higher health plan costs, often made worse by delayed payout of NSA-required payments falls outside stop-loss coverage timelines, added administration and enforcement costs and penalties.

For employers relying on RBP assumptions to establish plan funding, premiums, employee contributions, stop-loss attachment points, reserves, or expected out-of-network claim costs, this disparity can translate into material and potentially significantly lighter than projected plan liabilities. The same data also call for closer scrutiny of the narrow-network health plan designs often touted as reducing in-network unit prices, as these narrow networks can increase the frequency or severity of out-of-network and NSA-protected claims when participants cannot obtain needed care from participating providers.

New Data Highlight the Potential RBP/NSA Gap

Reference-based pricing remains an important cost-management strategy for many self-funded employer health plans. Rather than paying providers based upon a negotiated percentage discount from billed charges, a health plan relying a RBP strategy to price out of network claims commonly establishes payment by reference to Medicare reimbursement, provider cost, or another external benchmark.

A significant Health Affairs Scholar study examined a reference-based pricing program covering approximately 300,000 lives nationwide for self-funded employers. The program generally paid hospitals the greater of cost plus 12% or Medicare plus 20%, producing payments averaging approximately 140% of Medicare. Analysis of 2024 claims found average payments of approximately 122% of Medicare for inpatient facility services and 149% for outpatient facility services. Replying on this data without considering the NSA mandates, researchers estimated referenced based savings of approximately $417 million, or 56.5% compared with ordinary commercial prices. When the NSA is considered, however, these projections substantially underestimate plan costs.

NSA Arbitration Outcomes Can Be Multiples of Medicare-Based RBP Amounts

The NSA protects participants from certain surprise bills for out-of-network emergency services, certain non-emergency services furnished by out-of-network providers at participating facilities, and covered air ambulance services. When the plan and provider cannot agree upon payment for claims governed by the federal NSA process, the dispute can proceed to federal IDR.

Federal IDR is a baseball-style final-offer arbitration process in which each side submits an offer and the certified IDR entity selects one of the two offers. Brookings overview of federal IDR.

Brookings analysis of CMS data found average IDR prices during the second half of 2023 of approximately 400% of Medicare for emergency professional services and approximately 660% of Medicare for imaging services. Brookings IDR outcome analysis.

More recent analysis of CMS’s 2024 federal IDR data found average imaging IDR pricing approaching approximately 767% of Medicare. Brookings NSA Arbitration Databook.

Thus, a plan assuming an out-of-network claim will cost approximately 140% of Medicare under its RBP methodology could face an IDR award of roughly 400% of Medicare for some emergency services – nearly 2.9 times the RBP assumption – or roughly 767% of Medicare for certain imaging claims – approximately 5.5 times the RBP assumption.

These figures do not establish a single national RBP rate or guarantee any particular NSA award. But they demonstrate a risk that employers using RBP methodologies should not ignore: the amount used to price an out-of-network liability for plan design and budgeting purposes can be substantially lower than the ultimate amount payable if the claim becomes subject to NSA negotiation and IDR.

The Latest CMS Data Show This Is No Longer a Marginal Risk

CMS reported in May 2026 that more than 5 million disputes had been initiated through the federal IDR system since it began operating in April 2022. CMS May 2026 release.

During July 1 through December 31, 2025, certified IDR entities rendered payment determinations in 1,145,039 disputes. Emergency department services represented 52% of those determinations, radiology another 15%, providers prevailed in about 85% of payment determinations, and the prevailing offer exceeded the QPA in about 87% of determinations. Providers also prevailed in about 90% of default determinations. CMS Federal IDR Supplemental Background, 2025 Q3-Q4.

RBP Plan Sponsors Should Distinguish Three Different Numbers

Plan sponsors reviewing this exposure should avoid treating the RBP amount, the Qualifying Payment Amount (“QPA”), and the ultimate NSA payment amount as interchangeable.

The RBP amount is established under the particular terms of the plan or payment methodology and may, for example, approximate 120%, 140%, 150%, 200%, or another percentage of Medicare.

The QPA generally reflects the plan or issuer’s median contracted rate for the same or similar item or service, calculated under the NSA methodology. CMS maintains detailed guidance regarding QPA calculation and federal IDR responsibilities. CMS Plans and Issuers Requirements and Resources.

The ultimate NSA payment amount may result from agreement during negotiation or from the offer selected by a certified IDR entity. Since data shows these NSA payment amounts tend to run significantly higher than the RBPs used to predict plan costs, forecasting a plan’s liability initially at its RBP amount sets up plans and their sponsors for unexpected financial exposure.

Narrow Networks May Create an NSA Cost-Control Paradox

The emerging NSA payment data also should cause employers to question another increasingly popular cost-control strategy: aggressively narrowing provider networks.

Narrow networks traditionally are designed to lower health plan costs by excluding higher-cost providers, concentrating volume among selected providers, strengthening negotiating leverage, and steering participants toward lower-cost facilities and physicians.

Published research confirms that narrow networks can lower premiums and spending when care actually obtained within the network. One Health Affairs study found that Marketplace plans with both narrow physician and hospital networks had premiums approximately 16% lower than comparable broad-network plans. Health Affairs study of network breadth and premiums

Another study found that narrow-network plans reduced utilization and spending in an employer setting in part by selecting lower-cost providers. Journal of Health Economics study

KFF’s 2025 Employer Health Benefits Survey reported that about 9% of employers offering health benefits reported offering a plan characterized as a narrow-network plan, with the strategy more common among very large employers. KFF 2025 Employer Health Benefits Survey

Fewer Network Providers Can Mean More Opportunities for Out-of-Network Care

By definition, a narrower network reduces the number of physicians, hospitals, and other providers available to participants at negotiated in-network prices. When excluded providers are geographically concentrated, specialty providers are scarce, or the nearest appropriate hospital or physician does not participate, the probability that a participant will receive care outside the network logically increases.

A Health Affairs study of California provider networks found that Marketplace networks contained only slightly more than half as many providers as commercial networks and that network design sometimes created ‘artificial local provider deserts’ in which otherwise available physicians were effectively unavailable because they were excluded from the network. Health Affairs study of network adequacy and local provider access

A systematic review of narrow and tiered networks concluded that these arrangements generally reduce health care costs, while evidence regarding access and quality remains more limited and warrants further study. Systematic review of narrow and tiered provider networks.

Accordingly, employers should not assume that shrinking a network necessarily reduces every category of plan cost. A network can produce lower negotiated prices for claims that remain in-network while simultaneously increasing the frequency with which participants encounter providers outside the network.

Emergency and Hospital Care Demonstrate the Exposure

Before the NSA, a JAMA Internal Medicine study examining approximately 5.5 million inpatient admissions and 13.6 million emergency department visits found that by 2016 an out-of-network bill was associated with approximately 42.8% of emergency department visits and 42.0% of inpatient admissions at in-network hospitals in the study population. JAMA Internal Medicine study.

Research involving employer-sponsored insurance likewise found meaningful out-of-network spending exposure, particularly for hospitalists, pathology, laboratory, and other facility-based services. Health Affairs study of out-of-network spending in employer-sponsored insurance.

A 2024 Health Affairs Scholar study using employer-sponsored commercial claims found that approximately 34% of ICU hospitalizations contained out-of-network services, and more than half of those mixed-network hospitalizations included out-of-network services delivered within the ICU itself. Health Affairs Scholar ICU surprise-billing study.

These findings matter because patients requiring emergency, intensive-care, anesthesia, radiology, pathology, and similar services frequently have little practical ability to select every professional involved in their care. The NSA protects patients from many resulting balance bills, but it does not eliminate the economic dispute between the out-of-network provider and the plan. It moves that dispute to negotiation and, where applicable, IDR.

The NSA Can Convert a Network-Access Problem Into a Plan Liability

The latest CMS data show why this can matter. During the second half of 2025, emergency department services accounted for 52% of federal IDR determinations and radiology another 15%; providers prevailed in about 85% of determinations, and the prevailing offer exceeded the QPA in about 87% of cases. CMS Federal IDR Supplemental Background.

Separate analysis of 2023 emergency-medicine IDR data found providers won approximately 86% of disputes involving a commonly disputed moderate-to-severe emergency visit, with the mean selected payment approximately 2.7 times the QPA. Health Affairs Scholar emergency-services IDR study.

Those outcomes create a potential cost-control paradox. An employer may narrow its network to negotiate a lower contracted rate or eliminate a provider demanding what the employer considers an excessive in-network price. But if participants nevertheless require services from that provider – particularly in an emergency or other NSA-protected setting – the employer may lose much of the financial advantage it expected to achieve from excluding that provider.

In the extreme case, a network strategy intended to avoid paying an allegedly excessive negotiated rate could expose the plan instead to an NSA IDR award materially greater than the amount at which the provider might have participated in-network. The data do not yet establish that this occurs systematically across employer plans, but the possibility warrants plan-specific analysis. However, these costs unquestioningly increase if a RBP health plan fails to timely and effectively use the NSA procedures to mitigate its NSA risks.

Aggressive Network Negotiations May Have a Second-Order Cost

Selective contracting is one mechanism through which narrow networks reduce costs. One economic analysis found that lower negotiated prices accounted for about 15% of narrow-network savings, while steering patients away from higher-cost hospitals accounted for another 18%. Health Economics analysis of narrow-network savings

If a plan or network administrator presses reimbursement rates below the level at which a sufficient number of physicians and facilities are willing to remain in-network, however, the network may become narrower not merely because inefficient providers were intentionally excluded, but because providers participants actually need are unwilling to contract at the offered rate.

Economic research has shown that out-of-network options historically influenced emergency physician contracting behavior and reimbursement. In one study, regulatory changes weakening emergency physicians’ out-of-network bargaining position reduced out-of-network billing by 34% and reduced in-network emergency physician payments by about 9%. NBER study of out-of-network emergency physician bargaining.

That research does not prove that aggressive payer negotiations presently are causing NSA arbitration volume. It does demonstrate that network participation, negotiated rates, and the economic value of remaining out-of-network are interconnected. The NSA therefore should be incorporated into network contracting analysis rather than treated as a separate claims-processing issue.

Recent Federal Data Provide an Important Counterpoint

A February 2026 GAO report found that in-network emergency-medicine physician participation declined before implementation of the NSA but rebounded beginning in 2022, suggesting that the NSA may have strengthened incentives for some providers to participate in networks. GAO report on provider participation before and after the NSA.

A February 2026 HHS Assistant Secretary for Planning and Evaluation report found that, compared with 2021, the prevalence of out-of-network bills declined approximately 15% for emergency services and 11% for covered non-emergency services at in-network facilities in 2022, the first year of NSA implementation. HHS ASPE No Surprises Act report

These findings are important because they show that the NSA itself may reduce some out-of-network utilization and improve incentives to contract. They do not eliminate the concern for narrow-network employers. Even if the frequency of out-of-network encounters falls, the financial severity of the remaining disputes can still be material when IDR awards substantially exceed RBP assumptions, the QPA, or expected negotiated rates. Network design along with health plan’s RBP assumptions and preparedness and effectiveness in using the NSA negotiation and IDR process therefore should be evaluated by considering both frequency and severity.

Sponsors Should Revisit RBP Funding Assumptions and Network Breadth

Employers and fiduciaries sponsoring RBP plans should consider incorporating an NSA risk factor into plan budgeting and forecasting rather than assuming that all out-of-network claims ultimately will be payable at the plan’s ordinary RBP amount. They also should test whether the breadth and geographic distribution of the network are contributing to avoidable out-of-network exposure.

  • the number and dollar amount of NSA-eligible claims;
  • the specialties and facilities generating the largest number of disputes;
  • initial RBP allowed amounts and applicable QPAs;
  • provider demands, negotiated settlements, and IDR outcomes;
  • the number of disputes attributable to providers excluded during network negotiations;
  • participant travel distances and practical access to in-network emergency, hospital, and specialty care;
  • administrative and IDR fees; and
  • recoveries actually obtained under stop-loss coverage.

Plan actuaries, consultants, TPAs, network administrators, and stop-loss advisers should be asked expressly how NSA liabilities are reflected in projections and whether historical claims data include ultimate NSA settlement or arbitration amounts rather than merely original RBP adjudication amounts.

Conduct a Year-End NSA Liability Review Now

The approaching end of the year creates an immediate administrative concern. Employer plan sponsors should identify existing claims that could produce additional NSA liability before those claims fall through administrative cracks during year-end processing.

  • claims subject to an open negotiation period;
  • claims already submitted to federal or applicable state IDR;
  • claims awaiting an eligibility determination or required submission;
  • claims awaiting a determination;
  • provider demands or correspondence that have not been appropriately escalated;
  • IDR determinations not yet fully paid;
  • claims potentially payable under stop-loss coverage but not yet submitted; and
  • claims approaching contractual notice, submission, proof-of-loss, run-out, or reimbursement deadlines under the stop-loss policy.

Don’t Let Stop-Loss Reimbursement Fall Through the Cracks

The difference between an initial RBP allowance and a later NSA settlement or IDR award can create a stop-loss administration problem. A plan that initially adjudicates a claim below its specific attachment point may later incur a substantial additional NSA liability that moves the claim above the attachment point. Whether and when that additional amount is reimbursable depends on the actual stop-loss contract.

Particular attention should be paid to provisions defining when a claim is incurred, paid, or otherwise eligible for reimbursement; run-in and run-out provisions; claims submission deadlines; proof-of-loss requirements; exclusions; specific and aggregate attachment points; terminal liability provisions; and notice requirements for potentially large claims.

An employer should not assume that its medical TPA, RBP vendor, IDR administrator, network administrator, and stop-loss carrier are communicating effectively with one another. The employer and appropriate plan fiduciaries should verify it.

Plan Sponsors and Fiduciaries Should Examine Their NSA Compliance and Administration Strategy

Compliance with the NSA is mandatory. Meanwhile, fiduciaries’ duties to prudently administer the plan includes responsibility to ensure the prudent administration of the plan in accordance with the NSA’s negotiation and IDR procedures and payment of resulting benefit liabilities. Mishandling of these responsibilities both can increase plan costs and liabilities and create fiduciary liability for responsible plan fiduciaries. Since absent special negotiated provisions, most plan administrative services agreements designate the sponsoring employer or its leaders the named fiduciary, this means most current plan administration arrangements leave the plan sponsor and its leaders responsible for plan matters with significant cost and liability exposure.

To fulfill these duties and mitigate exposures, employers sponsoring group health plans and plan fiduciaries should act quickly to prudently audit and address their plan’s current and future fulfillment of NSA responsibilities and resulting costs and expenses.

CMS maintains a federal IDR checklist and related resources specifically for plans and issuers. CMS NSA resources for plans and issuers.

The Departments also finalized new federal IDR operational rules in May 2026 designed to improve communications, eligibility determinations, disclosures, and IDR administration. CMS Federal IDR Operations Final Rule fact sheet

Employers and fiduciaries should work with experienced legal counsel to evaluate and confirm that administrators have implemented and prudently administered plans in accordance with current requirements and prepared to administer the plan effectively with the evolving rules going forward.

This evaluation generally should include documented prudent evaluation of historical compliance as well as evaluation of the advisability of tightening contractual and operational responsibility among the plan’s third party administrator, RBP administrator, network administrator, NSA negotiation vendor, IDR administrator, legal counsel, and stop-loss carrier or managing general underwriter.

Recognizing the ERISA’s fiduciary responsibility requirement that these service providers be prudently selected and paid no more than reasonable compensation, these evaluations also should include and document prudent evaluation and findings of these matters with respect to these NSA administrative arrangements.

Strategic Negotiation May Be Worth Real Money

The potential difference between an RBP amount and an adverse IDR award changes the economics of negotiation. A plan ordinarily expecting to pay 140% of Medicare should not necessarily approach an NSA demand in the same manner as an ordinary balance-billing dispute. Competent pre-IDR analysis should evaluate the QPA, applicable Medicare reimbursement, relevant contracted rates, prior payment history, provider market characteristics, complexity and acuity of the service, permissible statutory considerations, prior negotiations, the provider’s likely IDR position, and the economic value of a defensible negotiated resolution compared with proceeding to IDR.

The objective is not indiscriminate settlement. It is prudent efforts to reach informed settlement and where settlement can’t be prudently reached, a informed arbitration strategy.

Fiduciary Oversight Matters

For ERISA-covered self-funded plans, these concerns also implicate fiduciary administration. An employer or fiduciary need not personally process every NSA dispute, but prudent delegation of those functions to a TPA or specialized vendor requires thoughtful vendor selection, monitoring, contracting, and oversight.

  • avoiding preventable IDR disputes;
  • identifying appropriate settlement opportunities;
  • developing defensible IDR submissions;
  • meeting every deadline and avoiding defaults;
  • tracking final payment obligations;
  • coordinating stop-loss submissions; and
  • reporting material NSA exposure to the employer and fiduciaries.

The Lowest Negotiated Rate Is Not Necessarily the Lowest Total Cost

The object of health plan network contracting should be the lowest prudent total cost of providing promised benefits – not simply obtaining the lowest possible negotiated unit price or the narrowest possible network. An employer may negotiate a reduction in a physician’s proposed contracted rate and regard exclusion of the physician as a success when the provider refuses. That conclusion may be wrong if removing the provider forces participants into NSA-protected out-of-network care that ultimately costs the plan substantially more.

Employers should require administrators, brokers and consultants to accept accountability in their contracts, acknowledge fiduciary status when exercising discretion, and measure network prices, utilization, out-of-network incidence, NSA settlements, IDR awards, administrative costs, and stop-loss recoveries together. The appropriate metric is total plan cost within the bounds of prudent administration of the plan in accordance with the NSA and other laws, not merely network discount.

Action Steps Before Year-End

Considering these and other responsibilities and risks, plan sponsors and fiduciaries should take several actions before year end to manage these responsibilities and risks. Some key steps include:

  • Plan sponsors and fiduciaries should evaluate the plan’s NSA compliance and RBP assumptions. Compare the RBP percentage used for plan pricing against actual NSA settlements and IDR outcomes and evaluate an appropriate reserve or contingency assumption.
  • Plan sponsors should critically assess network breadth. Identify geographic and specialty gaps, recurring out-of-network providers, and whether excluded providers are generating disproportionately expensive NSA claims.
  • Plan fiduciaries should prudently audit compliance and reconcile outstanding NSA claims. Obtain a claim-level inventory of every pending negotiation, state or federal IDR dispute, unresolved provider payment challenge, and unpaid IDR determination. Also assess paid out-of-network claims for potential outstanding NSA or other liability.
  • Identify the financial delta. For each significant claim, compare the original RBP allowance, QPA, provider demand, current settlement exposure, and reasonably possible IDR exposure.
  • Review high-risk claims strategically. Determine whether well-supported negotiations before IDR could reduce exposure and whether pending arbitration submissions contain the factual and legal information needed to defend the plan’s position.
  • Calendar every NSA deadline. Avoid preventable defaults and missed response dates.
  • Audit past NSA claims. If the audit of previous processed put-of-network claims indicates higher than necessary liability due to mishandling of the NSA negotiation or IDR processes, consult with legal counsel regarding prudent actions, if any, as may be warranted to address those missteps and to prevent their reoccurrence.
  • Coordinate with stop-loss coverage now. Identify claims that have exceeded or could approach attachment points and determine applicable notice, proof-of-loss, reimbursement, and run-out deadlines.
  • Audit TPA and vendor performance. Determine who is responsible for identifying NSA claims, negotiating them, initiating or defending IDR, approving offers, paying awards, reporting outcomes, and pursuing stop-loss reimbursement.
  • Evaluate 2027 budgeting. Do not assume the plan’s RBP percentage represents the maximum probable liability for NSA-eligible out-of-network services.
  • Preserve and analyze the data. Require claim-level records that allow the employer to measure RBP allowance versus QPA versus negotiated amount versus IDR award versus stop-loss recovery, together with the provider’s network status and geographic availability.

Bottom Line

Reference-based pricing and narrow networks both can be powerful tools for controlling employer health plan costs. Published research supports that conclusion. But the No Surprises Act has changed the financial environment in which those strategies operate.

A plan that ordinarily expects to pay approximately 120% to 200% of Medicare for an out-of-network service may face dramatically different economics when the claim is protected by the NSA and proceeds through negotiation or IDR. At the same time, a network strategy that lowers in-network unit prices may create greater out-of-network exposure if it leaves participants without practical access to needed providers.

No published study identified to date establishes that narrow networks have caused aggregate employer NSA costs to exceed the savings those networks generate. The more relevant question for an individual plan is whether its particular combination of network design, reference-based pricing, NSA claims experience, and stop-loss coverage is actually producing the savings assumed when the arrangement was designed.

With CMS reporting more than 1.1 million federal IDR determinations during the final six months of 2025 alone, employers should evaluate that question using their own claims data before renewing network strategies, establishing 2027 budgets, and allowing unresolved 2026 NSA and stop-loss liabilities to disappear into year-end claims administration.

The prudent strategy is not necessarily broader networks, nor necessarily narrower networks. It is a deliberately designed network broad enough to provide meaningful access to needed care, negotiated at defensible prices, coupled with reference-based pricing and NSA administration that is legally compliance and prudently administered to minimize the plan’s total expected cost rather than merely its apparent in-network unit prices.

For Help or More Information

The author of this update, Cynthia Marcotte Stamer has decades of experience advising and assisting health industry clients to design, audit, and defend their organizations and practices including conducting audits and investigations, designing and updating compliance and risk management programs, responding to government investigations, conducting transaction, governance, and other due diligence, and assisting with other legal and operational compliance and risk management and legislative and regulatory affairs. She is available to assist your organization in assessing the impact of these developments and navigating the compliance and strategic steps that follow. For more information about these or other health care, managed care and other health benefits, or other health industry laws or concerns, contact Ms. Stamer via e-mail or via telephone at (214) 452 -8297.

About the Author

Cynthia Marcotte Stamer is an American College of Employee Benefits Counsel and a Martindale-Hubble “AV-Preeminent” (Top 1%) attorney and advisor board certified in labor and employment law by the Texas Board of Legal Specialization peer peer celebrated as “Top Rated Lawyer” and “LEGAL LEADER™ “Top Rated Lawyer” and “Best Lawyer” for her work in ERISA & Employee Benefits Law, Health Care Law, Labor and Employment Law, and Business and Commercial Law.

Nationally recognised for her decades of leading edge health and other employee benefits and insurance, compensation, human resources and other management work, public policy leadership and advocacy, coaching, teachings, and publications, Ms. Stamer is well known for her decades of pragmatic, leading edge work, scholarship and thought leadership on health benefit and other health and managed care, privacy and data security and other employee benefit, insurance, and health industry legal, public policy and operational concerns. 

Ms. Stamer’s work throughout her career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns.  As a a key focus of this work, she has continuously and extensively worked with domestic and international health plans, their sponsors, fiduciaries, administrators, and insurers; managed care and insurance organizations; third party administrators and other health benefit service providers; hospitals, health care systems and other health care providers, accreditation, peer review and quality committees and organizations; billing, utilization management, management services organizations, group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; consultants; investors; EMR, claims, payroll and other technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, self-insured health and other employee benefit plans, their sponsors, fiduciaries, administrators and service providers, insurers and other payers, health industry advocacy and other service providers and groups and other health and managed care industry clients as well as federal and state legislative, regulatory, investigatory and enforcement bodies and agencies.

Her experience includes more than 35 years of leading edge work for employer and other plan sponsors, plans and their fiduciaries, insurers, third party administrators, health care clearinghouses and other health care, insurance and other data and technology providers, and others on health and other employee benefits design, administration, compliance, and policy including decades of work on fiduciary compliance and risk management; eligibility, coverage and other plan mandates; administrative simplification and transparency; PBM, pharmacy and pharmaceutical management and regulation; surprise billing and other non-par provider; direct provider, vendor and other credentialing, contracting and management; and other managed care and insurance; high deductible, minimum or level premium, captive and other non traditional funding; and agency and private audits, investigations and enforcement; and other insured and self-insured health benefit contracting, design, administration, regulation, fiduciary and other liability managment, and other design, compliance, risk management, defense, and operations solutions.

She also has extensive experience helping health care systems and organizations, group and individual health care providers, health plans and insurers, health IT, life sciences and other health industry clients prevent, investigate, manage and resolve  sexual assault, abuse, harassment and other organizational, provider and employee misconduct and other performance and behavior; manage Section 1557, Section 504, Civil Rights Act and other discrimination and accommodation, and other regulatory, contractual and other compliance; vendors and suppliers; contracting and other terms of participation, medical billing, reimbursement, claims administration and coordination, Medicare, Medicaid, CHIP, Medicare/Medicaid Advantage, ERISA and other payers and other provider-payer relations, contracting, compliance and enforcement; Form 990 and other nonprofit and tax-exemption; fundraising, investors, joint venture, and other business partners; quality and other performance measurement, management, discipline and reporting; physician and other workforce recruiting, performance management, peer review and other investigations and discipline, wage and hour, payroll, gain-sharing and other pay-for performance and other compensation, training, outsourcing and other human resources and workforce matters; board, medical staff and other governance; strategic planning, process and quality improvement; meaningful use, EMR, HIPAA and other technology,  data security and breach and other health IT and data; STARK, ant kickback, insurance, and other fraud prevention, investigation, defense and enforcement; audits, investigations, and enforcement actions; trade secrets and other intellectual property; crisis preparedness and response; internal, government and third-party licensure, credentialing, accreditation, HCQIA and other peer review and quality reporting, audits, investigations, enforcement and defense; patient relations and care;  internal controls and regulatory compliance; payer-provider, provider-provider, vendor, patient, governmental and community relations; facilities, practice, products and other sales, mergers, acquisitions and other business and commercial transactions; government procurement and contracting; grants; tax-exemption and not-for-profit; privacy and data security; training; risk and change management; regulatory affairs and public policy; process, product and service improvement, development and innovation, and other legal and operational compliance and risk management, government and regulatory affairs and operations concerns. to establish, administer and defend workforce and staffing, quality, and other compliance, risk management and operational practices, policies and actions; comply with requirements; investigate and respond to Department of Insurance, Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, trucking, alcohol and firearm, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry actions: regulatory and public policy advocacy; training and discipline; enforcement;  and other strategic and operational concerns.

Former lead advisor to the Government of Bolivia on its Social Security Privatization reform, miss Stamer also has extensive legislative and regulatory affairs experience on federal, state and international employee benefits, healthcare, workforce, education, insurance, data privacy and security, antitrust, and other regulations and reforms.

In addition, Ms. Stamer contributes her time and leadership to numerous policy, professional, civil and other organizations, Ms. Stamer currently or previously served as the Scribe leading annual agency meetings on HIPAA and other issues with the Department of Health and Human Services; leadership Council Representative, speaker, author and faculty lead for the American Bar Association (“ABA”) Joint Committee on Employee Benefits; the ABA International Section International Employment Law Committee and International Life Sciences Committee Chair; the ABA Tort Trial and Insurance Practice Section Medicine and Law Committee Chair and Employee Benefits and Worker’s Compensation Committees Vice Chair; the ABA Health Law Section Managed Care & Insurance Interest Group Chair and Risk Management Interest Group Chair; the ABA RPTE Employee Benefits & Other Compensation Group Chair and Welfare Benefit, Fiduciary Responsibility, and Plan Terminations and Transactions Committees Chair; Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association; a Southwest Benefits Association Board Member; a SHRM Consultants National and Region IV Board Chair; WEB National Board Member and Dallas Chapter President; National Kidney Foundation of North Texas Board Member and Compliance Chair; Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency Board President; a North Texas United Way Long Range Planning Committee Member; and other leadership involvement in a broad range of other professional and civic organizations.

Author of hundreds of highly regarded works on health and other benefits, human resources, health care, insurance, data privacy and security and other related concerns, examples of these publications include “Transparent PBM Contracting,” “ACOs, Direct Contracting: Legal & Practical Challenges For Employers, Providers & TPAs,” “The Medicare Advantage Contracting Manual,” “Third Party Administrator (TPA) Contracting Principles and Strategies and a multitude of other publications and presentations. 

For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.