Inside a Litigated Claims Review: What One Unsealed Report Reveals About Every Self-Funded Plan
- Jun 26
- 8 min read

Almost no self-funded plan sponsor will ever see an independent expert review of their carrier’s claims administration. The reasons are structural: contractual audit restrictions, gag clauses that, in practice if not in law, survived the Consolidated Appropriations Act (CAA), and the near-universal use of non-disclosure agreements when disputes settle. Most of what carriers do at the line-item level happens behind a wall that fiduciaries are told to trust but are rarely permitted to examine.
Then there is Comau LLC v. Blue Cross Blue Shield of Michigan, Case 2:19-cv-12623, Eastern District of Michigan, where an expert report prepared by VerSan Consulting was unsealed by court order. The report documents what an independent expert found after being given complete access to a carrier’s claims data. The findings are not anomalies. They are systemic. And they are almost certainly not unique to BCBSM.
Healthcare consultant Chris Deacon, in her widely circulated Substack analysis “A Rare Look Inside a Litigated Claims Audit,” calls the report “one of the most consequential documents the self-funded benefits industry has ever produced.” The reason: it is one of the only times the inside of a carrier’s claims operation has been forced into public view by litigation.
Why You’ve Rarely Seen an Independent Claims Review
If independent oversight of carrier claims administration were routine, the Comau expert report would be unremarkable. It is the opposite of unremarkable, and the reasons are worth naming:
Contract architecture restricts audit rights. Standard ASO and TPA agreements limit which fields can be audited, how often, by whom, at what cost, and under what confidentiality terms. Most contracts prohibit field-level review of denied claims, repricing logic, or vendor recovery economics, the exact areas where the Comau audit found the largest discrepancies.
CAA gag-clause prohibitions are under-enforced. Section 201 of the CAA banned contractual restrictions on plan sponsor access to de-identified claims data. In practice, enforcement has been minimal, and many ASO contracts continue to operate as if the rule does not exist. The DOL EBSA gag clause attestation requirement depends on plan sponsors actually verifying compliance. Most cannot, because they lack access to verify.
Settlements come wrapped in NDAs. When self-funded employers do sue, settlements typically include confidentiality terms that bar disclosure of audit findings, methodology, or recovery amounts. The result is an information vacuum: the industry rarely learns from its own disputes.
Discovery is the only path to disclosure, and most cases never reach it. More than 200 cases have been filed against BCBSM since 2011 (per public court records and industry tracking). The Comau case is one of the few where expert analysis became part of the public docket. Most others were settled, dismissed, or sealed.
Chris Deacon’s framing is the right one: the document's rarity is itself the story. Plan fiduciaries should not assume the Comau findings are an outlier. They should assume the findings reflect what happens when an expert is allowed to look at any other carrier’s data, and most fiduciaries will never get that look.
What the Comau Expert Report Actually Found
VerSan Consulting was engaged to perform an independent analysis of BCBSM’s administration of the Comau self-funded health plan. The expert had access to the underlying claims data, the settlement reports that BCBSM produced for the plan, and the contractual representations that BCBSM made regarding its payment accuracy. Among the findings (all drawn from the publicly available expert report):
$8.1 million in unreconciled financial reporting. Over 12 years, the settlement reports BCBSM produced for Comau did not reconcile the underlying claims data. The gap was not a rounding error. It was a structural inability to tie the financial reporting back to the transactions it purported to summarize.
238,000 claims with “approved amount” inconsistencies. The carrier’s own claims system contained “approved amount” values that did not match the actual allowable. In one cited example, the system reflected approximately $42,261, while the actual allowable was closer to $16,700, a discrepancy that directly affects member coinsurance calculations and Transparency in Coverage filings.
Approximately 30,000 claims with missing payee data. The data field identifying who actually received the payment was incomplete. A fiduciary cannot verify that plan assets were used exclusively for participant benefits when the record of where the money went is missing.
38% of facility claims with rolled-up financials. More than one in three facility claims reviewed, roughly $18 million in payments, consolidated multiple service lines into a single financial entry, making line-level audit impossible. This is not a fringe data architecture issue. It is the system design that the plan paid the carrier to administer.
$7.3 million in identified overpayments from editing failures. Basic, industry-standard coding edits, including NCCI, MUE, and similar edits, had not been applied consistently. The overpayments were not exotic. They were the kind of errors a competent Pre-Pay editing system catches before payment.
Carrier representations of 99%+ payment accuracy. Throughout the period covered by the audit, BCBSM’s contractual and performance reporting reflected payment accuracy of at least 99%. The expert report’s findings are difficult to reconcile with that figure.
It Took a Whistleblower, Not Routine Oversight
The Comau case did not begin with a scheduled audit. It began with an insider. Dennis Wegner, a former BCBSM account manager, identified patterns of overpayment and alerted the employer, setting in motion the litigation and, ultimately, the expert engagement that produced the unsealed report.
This is the operating reality of self-funded plan oversight in 2026: in many of the largest carrier disputes that have reached public courts, the trigger was not an audit, a regulatory inquiry, or a fiduciary monitoring process. It was an individual former employee deciding to speak.
That is not a fiduciary monitoring strategy. It is a dependency on chance. A reasonable, prudent process for monitoring a service provider, as required by ERISA §404(a)(1)(B), cannot rest on the willingness of a stranger to risk their career on the plan’s behalf.
200+ Lawsuits, Almost No Public Findings, and What That Means for Every Other Plan
The Comau report describes a specific carrier administering a specific plan. The temptation is to read it as a one-off. The structural evidence cuts the other way:
Volume of litigation suggests pattern, not anomaly. More than 200 cases filed against a single carrier since 2011 are inconsistent with a 99%+ payment-accuracy operating environment. The cases include BCBSM disputes with TPAs, providers, and plan sponsors, and span the full claim-administration lifecycle.
Recent rulings extend audit rights and TPA accountability. In Tiara Yachts v. BCBSM, the Sixth Circuit has been pressed on the scope of a TPA’s ERISA fiduciary obligations, a separate but related front in the same fight over data access and accountability.
Settlement and confidentiality block industry learning. Because the overwhelming majority of these cases settle under NDA, the industry receives almost no information about what audits find, what remedies are negotiated, or what changes carriers make. Each plan sponsor must effectively start from zero.
The data architecture issues are systemic, not client-specific. Rolled-up facility financials, incomplete payee fields, and approved-amount inconsistencies are properties of how a carrier built its claims system, not properties of how it administered one specific employer’s plan. If those issues exist for Comau, they exist for every other employer on the same platform.
The honest reading of the Comau report is not “this is what BCBSM did wrong.” The honest reading is “this is what an independent expert finds when permitted to look.” Most plan fiduciaries have never permitted that look because their contracts do not allow it, their carriers will not facilitate it, or they have not realized it is part of their job to demand it.
What Fiduciaries Should Do With This Information
The Comau report is not a litigation document. It is a fiduciary monitoring document. Treat it as evidence about what reasonable monitoring of a health plan service provider must include. Five actions follow directly:
Independently verify financial reporting. Settlement reports, performance guarantee reports, and stop-loss filings all depend on the underlying claims data reconciling cleanly. Most do not. Confirm the math before it drives a budget decision.
Demand line-level facility claims data. If 38% of your facility claims are reported as rolled-up financial entries, no audit is possible at any cost. Make line-level data a contractual requirement, not a courtesy.
Audit the “approved amount” field. This is the single field that drives member cost-sharing, Transparency in Coverage filings, and most downstream reporting. If it is not internally consistent inside the carrier’s system, every downstream number is suspect.
Use contract renewal as the leverage point. Audit rights, data access rights, and gag-clause attestations are most negotiable at renewal. Once the contract is signed, those rights shrink dramatically.
Build independent oversight before you need it. The plans that learn what their carrier is doing tend to do so after a problem has become a lawsuit. The plans that document fiduciary prudence build the oversight first, in the ordinary course, with a documented monitoring process, independent claims analysis, and contract language reviewed against ERISA standards.
Frequently Asked Questions
What is the Comau v. BCBSM case about? Comau LLC, a self-funded employer, sued Blue Cross Blue Shield of Michigan, alleging ERISA fiduciary breach and contract violations related to BCBSM’s administration of the Comau health plan. The case is filed in the Eastern District of Michigan as Case 2:19-cv-12623. The expert report prepared by VerSan Consulting, unsealed by court order, documented systemic data and payment integrity issues that became central to the litigation.
Why are independent carrier claims reviews so rare? Standard ASO and TPA contracts limit which data fields can be audited, by whom, at what cost, and under what confidentiality terms. Disputes that do produce findings typically settle under non-disclosure agreements. This combination means most audit findings never become public, and most plan sponsors never see an independent review of their own administration.
Does the CAA require my carrier to give me claims data? Yes. Section 201 of the Consolidated Appropriations Act prohibits gag clauses that restrict a plan sponsor’s access to de-identified claims and provider cost information, and plan sponsors must annually attest to compliance through the DOL gag-clause attestation process. In practice, enforcement has been uneven, and many contracts continue to operate in ways that limit meaningful access. Fiduciaries should verify access themselves, rather than relying on the carrier’s self-attestation.
What is the statute of limitations on ERISA fiduciary breach claims? ERISA Section 413 (29 U.S.C. 1113) generally sets a six-year limitations period from the date of the breach, shortened to three years from the date the plaintiff gains actual knowledge of the breach. In cases of fraud or concealment, suit may be brought within six years of the date the breach is discovered. Because concealment of claims-administration problems can delay discovery, the practical lesson for fiduciaries is the same: documented, proactive oversight establishes when the plan actually knew what it knew, rather than leaving that question to be reconstructed years later in litigation.
How should plan fiduciaries respond if they cannot get the data needed to review? Document the request, document the carrier’s response, and treat the data-access barrier itself as a fiduciary issue. Under ERISA’s prudent expert standard, a fiduciary who cannot obtain the information needed to monitor a service provider must either negotiate access or change service providers. “The carrier wouldn’t give us the data” is not, on its own, a defense. It is part of the breach pattern courts now look for.
The Bottom Line
The Comau v. BCBSM expert report is in the public record due to an accident of litigation timing and a court ruling. Almost everything else, like it, sits behind contracts, confidentiality terms, and settlement walls. The findings within it, including unreconciled financial reporting, inconsistent approved amounts, rolled-up facility claims, missing payee data, and basic editing failures, are not the result of a single bad contract. They are properties of a system that was never built with fiduciary oversight as a design requirement.
A plan fiduciary who has not independently verified what is happening inside their carrier’s claims system is not monitoring a service provider. They are trusting a representation. After Comau, that trust is harder to defend.




Comments