H.R. 9486: Health Data Access, Transparency, and Affordability Act of 2026
This bill would change federal rules for employer-sponsored group health plans under ERISA to give plan sponsors more access to data, increase oversight of service providers, and add new anti-discrimination protections tied to health plan data.
Data access and auditing
The bill would require contracts between a group health plan and many types of outside service providers to allow the plan to audit de-identified claims and encounter data. This would apply to providers, provider networks, third-party administrators, pharmacy benefit managers, and similar entities.
The audit access would be intended to let plans:
- Check whether the service provider is following the contract and ERISA requirements
- Judge whether the fees or compensation charged are reasonable
The bill says contracts could not unduly restrict these audits. For example, they could not:
- Unreasonably limit how many audits can happen
- Limit how much de-identified claims data can be reviewed
- Block disclosure of pricing details for value-based or capitated payment arrangements, such as formulas, quality measures, payment amounts, contract terms, incentive periods, and related methodologies
- Limit disclosure of overpayments and recovery terms
- Restrict the plan’s choice of auditor
- Delay an audit by more than 60 days after a request
- Charge more than the reasonable direct costs needed to provide the information and help with the audit
Privacy rules
When data is shared under these audit rights, the bill would require it to be handled in line with existing federal privacy rules, including HIPAA-related privacy regulations. If the data is protected health information, its use and disclosure would remain limited by those privacy rules.
The bill also says group health plans must follow the HIPAA rule on business associate agreements, and plan sponsors must act according to those agreements.
Enforcement and penalties
The bill would give the Secretary of Labor authority to impose a civil penalty of $10,000 per day on a provider, network, third-party administrator, pharmacy benefit manager, or other service provider that violates the bill’s data-access rules.
It would also clarify that the Secretary can collect penalties assessed under the law.
In addition, the Labor Department would be required to collect attestations about “gag clauses” or other restrictions related to group health plan data. The bill says the department must make sure any service provider submitting such an attestation does not have a conflict of interest.
Fiduciary duty over plan data
The bill would expand the ERISA definition of fiduciary authority to include authority over the use, management, disposal, or safeguarding of data generated, used, or maintained by the plan or a service provider in connection with benefits administration or plan assets. In practical terms, this means control over plan-related data would be treated as part of fiduciary responsibility.
Anti-discrimination rules
The bill would make it unlawful for certain parties—such as employers, plan sponsors, plan administrators, and plan fiduciaries—to punish or discriminate against a participant or beneficiary based on information or data covered by the bill.
It would allow participants or beneficiaries to sue without first exhausting administrative remedies in certain cases involving this data. It would also allow courts to grant relief needed to restore a person to the position they would have been in without the violation.
The Labor Department could assess a civil penalty of $100 per day for each participant or beneficiary affected by a violation, for the period the violation continues.
Relationship to other laws
The bill states that it would not limit the application of other federal or state privacy or civil rights laws, including HIPAA privacy rules, GINA, the ADA, the Rehabilitation Act, Section 1557 of the ACA, and federal civil rights laws.
Relevant Companies
- UNH — UnitedHealth Group could be affected because its Optum and health plan administration businesses work with employer health plans and claims data.
- CVS — CVS Health could be affected through its pharmacy benefit management and health plan-related services.
- CNC — Centene could be affected through managed care and pharmacy benefit-related services tied to employer or plan data arrangements.
- ELV — Elevance Health could be affected through health plan administration, network, and claims-related services.
- HUM — Humana could be affected if its plan administration or service-provider arrangements with employer plans are subject to expanded audit and disclosure rules.
- CI — Cigna could be affected through its Evernorth pharmacy and health services businesses, including PBM and claims-data arrangements.
This is an AI-generated summary of the bill text. There may be mistakes.
Sponsors
1 sponsor
Actions
2 actions
| Date | Action |
|---|---|
| Jun. 25, 2026 | Introduced in House |
| Jun. 25, 2026 | Referred to the House Committee on Education and Workforce. |
Corporate Lobbying
0 companies lobbying
None found.
* Note that there can be significant delays in lobbying disclosures, and our data may be incomplete.