CMS fines are not the only enforcement vector. Plan sponsors, unions, and self-insured employers have filed ERISA fiduciary suits alleging they overpaid for care because hospitals hid negotiated rates. A non-compliant MRF is evidence in those cases — and hospitals are named defendants alongside the data vendors who should have published the rates.
ERISA fiduciaries must act prudently with plan assets. Plaintiffs argue that plan sponsors paid more than necessary because hospital negotiated-rate data — which should have been public under 45 CFR 180.50 — was either unavailable or wrong. The missing or incomplete MRF becomes the smoking gun: "the hospital withheld the data, so the plan overpaid."
| CMS exposure | $5,500/day per violation, no cap |
| ERISA exposure | Fiduciary damages, attorneys' fees, reputational — potentially far larger than CMS fines |
| Who brings suits | Plan sponsors, unions, class actions, state AGs |
| Your defense | A complete, current, accessible MRF — documented compliance |
The takeaway for hospital finance and compliance teams: a clean MRF is not just CMS compliance, it is litigation defense. If your file is incomplete or hidden behind a bot-block, you are exposed on both fronts — and the 2026 AI-audit ramp makes discovery of both more likely.
Free 24-hour risk check — the first piece of your defense file.
Get Your Free MRF Risk Check