BREAKING
Registry insights
October 7, 2026
CMS Transparency in Coverage Rules: December 7 Disclosure Deadline

October 7, 2026
December 7, 2026 is the effective date for the new Transparency in Coverage final rules issued jointly by the IRS within the Department of the Treasury, the Employee Benefits Security Administration within the Department of Labor, and CMS within HHS. The rule is identified as CMS-9882-F, TD 10058, and RIN 0938-AV64. It was announced on October 5, 2026 and published on October 6, 2026 as Federal Register Document 2026-20447 at 91 FR 63748. December 7 is the effective date. The principal machine-readable file changes apply later in staggered intervals.
What the Final Rules Change
The final rules amend the Transparency in Coverage machine-readable file requirements for applicable health plans and issuers.
The principal changes include:
- In-network rate files organized at the provider network level rather than only at the plan level.
- Out-of-network allowed-amount files aggregated by market type.
- A reduction in the out-of-network claims threshold from 20 claims to 11 claims.
- Quarterly posting for in-network rate and out-of-network allowed-amount files instead of monthly posting.
- Taxonomy and utilization files that provide context for in-network rate disclosures.
- A plain-text file in the website root folder that lists file locations and includes a monitored contact email.
- A homepage footer link titled “Price Transparency” or “Transparency in Coverage.”
- A single machine-readable file format as specified in technical guidance. CMS identifies JSON as the expected format, except for required plain-text files.
- An attestation of accuracy and completeness in each required file.
- The encoded name of the CEO, president, or designated senior official responsible for overseeing the accuracy of the data.
- Telephone availability of required cost-sharing information for plan years or policy years beginning on or after January 1, 2027.
The final rules also add product type and provider network identification information to support file interpretation and comparison. They require public files to remain accessible without account creation, passwords, or other access conditions.

Who Is Affected
The primary scope includes non-grandfathered group health plans and health insurance issuers offering non-grandfathered group or individual health insurance coverage.
Affected organizations include:
- Fully insured employers and plan sponsors.
- Self-insured group health plans.
- Health insurance issuers.
- Third-party administrators and other service providers supporting file production.
- Benefits and plan compliance teams.
- Regulatory affairs and risk functions responsible for public disclosures.
- Audit leaders responsible for proving the timing, content, and ownership of compliance activity.
A written agreement with an issuer, third-party administrator, or other service provider does not eliminate the need for defined oversight. The final rule assigns operational responsibilities through contractual arrangements, but the plan or issuer remains responsible when the contracted party fails to provide compliant information under the applicable arrangement.
The phone-based cost-sharing requirement also has a separate applicability date. It applies to plan years, or policy years in the individual market, beginning on or after January 1, 2027.
The Compliance Dates to Add to the Register
A complete compliance register should record the announcement, publication, effective date, applicability intervals, and operational deadline.
October 5, 2026
CMS announced the final rule and issued the CMS-9882-F fact sheet and press release.October 6, 2026
The rule was published in the Federal Register as Document 2026-20447 at 91 FR 63748. The published rule spans 120 pages.December 7, 2026
The final regulations become effective.March 2027
The amendments for in-network rate files and out-of-network allowed-amount files apply five months after Federal Register publication. These amendments include network-level reporting, market-type aggregation, the lower claims threshold, quarterly posting, and related data requirements.September 2027
The contextual file amendments apply eleven months after publication. These include the taxonomy file, utilization file, and root-folder text file. The homepage footer link and related file-location requirements should be tracked with this implementation interval.January 1, 2027 plan or policy years
The phone-based cost-sharing disclosure requirement applies to plan years or policy years beginning on or after this date.
The register should preserve the source authority for each date. A compliance notice should not rely on a calendar entry alone. It should connect the date to CMS-9882-F, TD 10058, RIN 0938-AV64, and Federal Register Document 2026-20447.

Why This Is a Records Problem, Not Just a Publishing Problem
The rule changes the technical form of public disclosure, but the operational risk extends beyond file publication.
An organization must be able to establish:
- What requirement applied.
- Which plan, issuer, network, or market was within scope.
- Which file or consumer disclosure satisfied the requirement.
- Who owned the preparation and approval process.
- When the file was posted.
- Where the public could access it.
- Whether the link and contact information worked.
- Which version was available at a specific time.
- Which official approved the attestation.
- How the record was retained for later review.
This structure converts a publication task into a compliance evidence task. A file that exists today does not prove what was publicly available last quarter. A working URL does not prove that the correct file was posted. A vendor confirmation does not replace evidence of review, ownership, and approval.
The same discipline applies to broader compliance notice requirements. A notice of compliance should identify the governing authority, action date, artifact, recipient or public audience, and evidence of completion. The terminology differs between a price transparency file and a legal notice, but the evidentiary requirement remains consistent.
Organizations can align this work with an established notice record retention framework and audit trail framework.
What a Defensible Disclosure Record Contains
A defensible record should contain:
- The requirement and its citation.
- The effective date and applicability date.
- The responsible owner.
- The disclosed artifact or file version.
- The publication location and timestamp.
- The public-facing URL or posting evidence.
- The review and approval history.
- The retention period and access controls.
The record should also preserve the attestation information encoded in the file. This includes the name of the CEO, president, or designated senior official responsible for oversight of true, accurate, and complete data.

Version control is essential because quarterly disclosures will replace prior files while the historical record remains relevant. The retained evidence should show the version posted, the date of posting, the data period represented, the approval sequence, and any correction or replacement activity.
This approach supports regulatory notice requirements, audit preparation, vendor oversight, and notice record retention. It also clarifies whether a missing artifact reflects a technical failure, an ownership failure, or a failure to preserve evidence.
Five Steps to Readiness Before December 7
Establish scope and ownership
Identify every affected plan, issuer, provider network, market type, vendor, and consumer cost-sharing channel. Assign accountable owners for data, technology, benefits administration, legal review, and records.Map the rule to existing workflows
Compare current machine-readable files, public web locations, footer links, contact procedures, and cost-sharing tools against CMS-9882-F. Record each gap as a controlled remediation item.Build the disclosure register
Add the October 5 announcement, October 6 publication, December 7 effective date, March 2027 applicability interval, September 2027 applicability interval, and January 1, 2027 phone requirement. Link each entry to its primary authority.Define evidence and approval controls
Establish procedures for file generation, validation, attestation, executive designation, publication, URL testing, timestamp capture, and version retention. Require documented approval before each release.Test public access and preserve the record
Verify that the root-folder text file, monitored email, machine-readable files, and footer link operate as required. Capture the public-facing evidence and preserve the approved artifact in a controlled repository.
These steps provide a practical response to the rule before technical guidance and implementation activity create additional dependencies.
Frequently Asked Questions
Is December 7, 2026 the first posting date for every amended file?
No. December 7 is the effective date. The in-network rate and out-of-network allowed-amount amendments apply in March 2027. The contextual file and related discoverability amendments apply in September 2027. The phone requirement applies for plan or policy years beginning on or after January 1, 2027.
Which organizations are primarily covered?
The rule primarily covers non-grandfathered group health plans and issuers offering non-grandfathered group or individual coverage. Specific applicability depends on the organization, plan, coverage, and applicable federal requirements.
What evidence should be retained after a file is posted?
Retain the requirement citation, applicability date, responsible owner, approved file version, posting timestamp, public URL, access test, review history, attestation information, and retention record.
Does a service provider assume all compliance responsibility?
No. Written agreements can allocate operational duties, but the final rule addresses responsibility when a contracted party fails to provide compliant information. Contract terms, oversight controls, and evidence of review remain necessary.
Does the rule require JSON?
The final rule requires a single non-proprietary, open-standards format as specified in technical guidance. CMS identifies JSON as the expected machine-readable format, with plain-text files remaining an exception.
Next Step
A structured registry review should identify affected disclosures, owners, dates, evidence requirements, and retention controls before December 7, 2026. National Compliance Registry provides compliance registration management and credentialing controls for organizations that need secure, reviewable records. Contact the registry team to establish a controlled disclosure record.
General compliance information, not legal advice.
