Dependent Eligibility Audits: Scope, Verification, and Appeals

A dependent eligibility audit is a structured review of everyone enrolled as a dependent on your group health plan to confirm each person actually qualifies under the plan’s rules. Run correctly, it removes ex-spouses, aged-out children, and other ineligible enrollees who inflate claims and premiums, while keeping you on the right side of ERISA, HIPAA, COBRA, and the tax code. The sequence below is what a defensible audit looks like from scope-setting through record retention.

Set the Scope Against Your Plan Document

Before you send a single notice, decide exactly what the audit will cover. Scope usually includes every benefit tied to dependent status: medical, dental, vision, and prescription drug coverage. Identify each relationship category you’re reviewing: legal spouses, domestic partners, biological and adopted children, stepchildren, and anything else your plan recognizes.

Your Summary Plan Description is the controlling document. It defines who counts as an eligible dependent, what proof is required, and when eligibility ends. If the SPD is vague or inconsistent with your enrollment materials, fix that before launch. A common failure looks like this: the SPD says one thing, the benefits guide says another, and HR has been applying a third interpretation for years. Every document that references dependent eligibility — plan document, SPD, open enrollment materials, employee handbook — needs to state the same rules the same way.

Build the ACA rule into your criteria correctly. Plans that offer dependent child coverage must extend it until the child turns 26, regardless of the child’s student status, financial dependency, marital status, or residency.1U.S. Department of Labor. Young Adults and the Affordable Care Act Protecting Young Adults and Eliminating Burdens on Businesses and Families FAQs Auditors sometimes flag a 24-year-old who isn’t a full-time student as ineligible, which is wrong. In the other direction, a child’s own spouse or a grandchild doesn’t qualify under the parent’s plan unless your plan specifically extends coverage to them.

ERISA requires plan fiduciaries to act solely in the interest of participants and beneficiaries, which includes keeping plan expenses reasonable.2Office of the Law Revision Counsel. 29 USC 1104 – Fiduciary Duties Leaving ineligible dependents on the plan cuts against that duty, which gives the audit its compliance backbone in addition to its financial one.

Offer an Amnesty Period First

Before the formal verification launches, open a short amnesty window — usually two to four weeks — during which employees can voluntarily remove ineligible dependents without discipline or premium recoupment. This is where the fastest savings show up. Employees who know they enrolled someone who shouldn’t be on the plan will quietly remove them rather than risk submitting suspect documentation later.

The amnesty notice needs to be direct: a full dependent eligibility audit is coming, and this is the window to correct enrollment. Spell out what’s being waived — repayment of past claims, disciplinary action, benefit suspension — and make clear those protections vanish once the formal audit begins. Employees who remove dependents during amnesty should be treated the same as anyone who missed an open enrollment change, not flagged for further review.

Amnesty reduces the adversarial edge of the process. Not every ineligible enrollment is fraud. A forgotten divorce, a stepchild from a prior marriage, a domestic partner the employee separated from years ago: giving people a clean exit before the formal process starts cuts the volume of appeals and grievances on the back end.

Prepare Internally

In-House or Third-Party Administrator

Most mid-to-large employers outsource, for a reason. The audit involves collecting sensitive personal documents — birth certificates, marriage certificates, tax returns, court orders — from hundreds or thousands of employees. A TPA brings standardized processes, dedicated staff, and a degree of perceived impartiality that lowers employee suspicion about how their documents are being handled.

If you run it internally, designate a small team with defined roles: a project lead, document reviewers, a communications coordinator, and legal counsel on call. Everyone involved needs HIPAA training before touching a single document.

HIPAA-Safe Document Handling

The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards for electronic protected health information.3U.S. Department of Health and Human Services. The Security Rule Your audit plan needs to address secure collection (an encrypted upload portal, not email attachments), access controls on the document repository, and how documents will be destroyed after the audit concludes.

HIPAA doesn’t prescribe a specific destruction method, but the Privacy Rule requires that PHI be rendered unreadable and unrecoverable before disposal. Shred paper records or hire professional destruction, and put a Business Associate Agreement in place with any bulk destruction vendor. Train the staff involved in destruction on your specific policies.4U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule

Timeline

Give employees enough time to actually gather the documents. Birth certificates lost in a move, marriage certificates from another state, adoption decrees buried somewhere — these take time. A 45- to 60-day initial response window is standard. Add at least 30 days for document review, then notification of results and the appeals period. Start to finish, most audits run four to six months.

Communicate the Audit to Employees

Tone matters as much as content. This is routine plan administration, not a fraud investigation, and the messaging should reflect that. Send the initial notice through multiple channels: physical mail to the employee’s home address so spouses and partners see it, and email through the company system. Explain why the audit is happening — cost management and compliance — and itemize the required documentation by dependent type so there’s no ambiguity.

State clearly that failure to submit the required documentation by the deadline results in automatic removal of the unverified dependent from all covered plans. That’s the sentence employees will remember, so make it prominent. Send reminders at 30 days out and again at seven days before the deadline. A surprising number of dependents get removed not because they’re ineligible but because the employee lost the letter or procrastinated, and every unnecessary removal creates an appeal and a possible COBRA obligation.

Stand up a dedicated phone line or email address for audit questions, staffed by people who can give consistent answers. If employees call the general HR line and get different answers from different people, the audit loses credibility quickly.

Verify Documents by Dependent Type

Each dependent category requires specific proof:

  • Spouse: A government-issued marriage certificate. Some plans also request the first page of the most recent federal tax return (Form 1040) to confirm joint filing status.
  • Biological child: A birth certificate listing the employee or the employee’s spouse as a parent. Under the ACA age-26 rule, no proof of student status or financial dependency is needed.5Centers for Medicare and Medicaid Services. Young Adults and the Affordable Care Act
  • Adopted child: A final adoption decree from a court, or placement documentation for children in the process of being adopted.
  • Stepchild: The child’s birth certificate plus the marriage certificate connecting the employee to the child’s biological parent.
  • Domestic partner: An Affidavit of Domestic Partnership plus documents showing shared financial obligations or cohabitation. Requirements vary by plan.
  • Child covered under a court order: A Qualified Medical Child Support Order. ERISA requires the plan to provide benefits in accordance with any valid QMCSO, and the plan must have written procedures for determining whether an order qualifies.6Office of the Law Revision Counsel. 29 USC 1169 – Additional Standards for Group Health Plans7U.S. Department of Labor. Qualified Medical Child Support Orders

For dependents whose eligibility rests on financial support — most commonly disabled adult children or qualifying relatives — the auditor can request documentation showing the employee provides more than half of the individual’s total support during the tax year.8Internal Revenue Service. Dependents This applies mainly to non-standard categories and is invoked far less often than spousal or child verification.

Reviewers check three things: authenticity, consistency, and completeness. Authenticity means the document looks real, with proper seals and formatting. Consistency means names and dates on submitted documents match the enrollment records; a birth certificate showing a different last name isn’t automatically disqualifying, but it needs an explanation. Completeness means every required document for that dependent type was provided.

When something is missing or contains an obvious discrepancy, issue a written request for the missing item with a firm secondary deadline. Without that hard cutoff, incomplete submissions drag the audit past its planned close. Record the final status of each dependent as verified, ineligible, or removed for non-submission. Suspected fraudulent submissions — altered documents, fabricated certificates — should go to legal counsel rather than the audit team. The right response to fraud is a different process from the right response to a missing birth certificate.

Handle COBRA Correctly on Removal

Removals during an audit can trigger COBRA obligations, and this is where employers most often trip up. Under federal law, COBRA qualifying events include a dependent child ceasing to meet the plan’s eligibility requirements and the divorce or legal separation of the employee from a spouse.9Office of the Law Revision Counsel. 29 USC 1163 – Qualifying Event So if the audit discovers a child who aged out months ago, or an employee who divorced two years ago and never reported it, those dependents lost coverage due to a qualifying event. They should have been offered COBRA at the time, and you may now need to offer a retroactive election. Loop in legal counsel.

A dependent who was never eligible in the first place — someone fraudulently enrolled, a friend’s child listed as the employee’s own — was never a qualified beneficiary. Removing someone who never had a valid right to coverage is not a COBRA qualifying event.

The practical rule: categorize each removal by the reason for ineligibility before processing it. A blanket approach that offers COBRA to everyone or skips it for everyone will get you into trouble in one direction or the other.

Separately, when a dependent loses coverage through the audit and a spouse or other family member needs alternative coverage, HIPAA’s special enrollment rules give them at least 30 days to request enrollment in another group health plan after a loss-of-coverage event.10eCFR. 29 CFR 2590.701-6 – Special Enrollment Periods Mention this in your removal notices so affected employees know they have options.

Notify, Remove, and Address Tax Consequences

When a dependent is determined ineligible, the employee gets a written notice stating the specific reason: non-submission, a document that failed verification, or a dependent who doesn’t meet the plan’s criteria. Federal regulations require that this adverse benefit determination include the specific plan provisions the decision rests on, a description of any additional information the employee could submit, and a clear explanation of the appeal process and timeline.11eCFR. 29 CFR 2560.503-1 – Claims Procedure Effective date of removal is typically the first of the month after the final determination.

Removal also raises tax questions. Employer-provided health coverage is excluded from the employee’s income only when it covers the employee, their spouse, their tax-code dependents, or their children who haven’t turned 27 by the end of the tax year.12Office of the Law Revision Counsel. 26 USC 105 – Amounts Received Under Accident and Health Plans Coverage for anyone else — an ex-spouse, an unrelated individual, a child’s spouse — is taxable income to the employee.13Internal Revenue Service. IRS Notice 2010-38

If the audit reveals the employee received tax-free coverage for someone who didn’t qualify, the fair market value of that coverage should have been reported as imputed income. Depending on how long the ineligible dependent was enrolled and how payroll handled premiums, you may need a corrected W-2 for the affected year. Bring in a tax advisor, because the correction varies with whether the error spans one year or several.

Recouping the employer-paid premium for the period the ineligible dependent was covered is legally possible if your plan documents specifically authorize it, but most employers only pursue it in fraud cases.

Run a Compliant Appeals Process

Employees have a legal right to appeal under ERISA, and your audit must include a formal appeals mechanism. For group health plans, federal regulations require at least 180 days from the date of the adverse determination to file an appeal.14eCFR. 29 CFR 2560.503-1 – Claims Procedure Six months, far longer than the 30 or 60 days many employers assume. If your audit notices quote a shorter deadline, you’re out of compliance with ERISA’s claims procedure rules, which can expose the plan to legal challenges.

The appeal must be reviewed by someone other than the original decision-maker, and that reviewer cannot be a subordinate of the original decision-maker. The employee can submit new documentation, written arguments, and anything else supporting the case, and the reviewer must consider everything submitted regardless of whether it was part of the original review.11eCFR. 29 CFR 2560.503-1 – Claims Procedure

Communicate the final appeal decision in writing, with the specific reasons and plan provisions supporting the outcome. A denial must also inform the employee of the right to bring a civil action under ERISA Section 502(a). A successful appeal reinstates the dependent retroactively to the removal date.

Distinguish Fraud From Mistakes

Most ineligible enrollments are honest mistakes: an unreported divorce, confusion about when a stepchild’s eligibility ended, a domestic partnership that quietly dissolved. Handle those through the standard removal and appeals process.

Intentional fraud is different. An employee who submits an altered birth certificate, enrolls a girlfriend as a spouse, or fabricates adoption paperwork has committed benefits fraud. Your plan documents and employee handbook should spell out the consequences in advance: disciplinary action up to and including termination, potential repayment of claims paid on behalf of the fraudulently enrolled individual, and referral for criminal prosecution in egregious cases. The amnesty period earlier in the process gives employees a chance to quietly correct mistakes, which makes it much harder for anyone caught during the audit itself to claim they simply made an error.

Retain the Audit Records for Six Years

ERISA Section 107 requires records supporting plan filings to be retained for at least six years from the filing date.15U.S. Department of Labor. Recordkeeping in the Electronic Age For the audit, that means keeping the complete file: every notification sent, every document received, every determination made, every appeal filed and resolved. The six-year clock runs from the date of the relevant Form 5500 filing, not from the date the audit closes.

Store the records electronically in a system that prevents alteration and restricts access to authorized personnel. If you used a TPA, make sure the contract specifies who owns the audit records and how they transfer to you when the engagement ends. Losing the audit file doesn’t lift the retention requirement, and it leaves you unable to defend your decisions if they’re challenged later.