Medicare call compliance: TCPA rules you can't ignore
So you bought a batch of Medicare leads last month and something felt off. Maybe it was the conversion rate. Maybe it was a cease and desist letter. If you've been in this business more than a year, you know the feeling.
I've been buying and selling calls since before "TCPA" was a word most agents even knew how to spell. And here's the thing: the rules haven't gotten easier. They've gotten sharper, more specific, and a lot more expensive to ignore.
This isn't legal advice. Talk to an actual attorney about your setup. But I want to walk you through what I've learned watching this space for years, because the mistakes I see agencies make are almost always the same five or six.
Why Medicare calls get sued more than almost anything else
Health insurance is one of the most litigated industries for TCPA class actions right now. Settlements range from low six figures for small campaigns up into the tens of millions for larger operators with high call volume and sloppy consent records.
Why Medicare specifically? A few reasons. The population being called skews older, and older consumers file more complaints with the FCC and FTC. Commissions are high, so lead gen volume is high, so the sheer number of calls being placed is enormous. And CMS layered its own marketing restrictions on top of federal TCPA law. Two regulatory systems, watching the same phone call.
CMS prohibits unsolicited outbound marketing calls to Medicare Advantage and Part D beneficiaries unless there's prior express consent or an existing business relationship. That's not a suggestion. It's the actual rule governing whether you can dial someone in the first place, separate from whatever TCPA says about consent and recordkeeping.
What counts as a violation, and what it costs
TCPA damages run $500 per violation. That jumps to $1,500 per call if a court decides the violation was willful or knowing. Do some quick math with me.
Say a campaign makes 10,000 calls without proper consent. Even at the base $500 rate, that's a theoretical exposure of $5 million. If a court finds the conduct willful, you're looking at $15 million.
Nobody expects to hit the statutory max on every call in a class action, and settlements typically land well under those full numbers. But that math is exactly why plaintiff's attorneys love this space. The exposure is enormous even on campaigns that felt routine to run.
Separately from TCPA, calls to numbers on the National Do Not Call Registry trigger their own penalties through the FTC and state attorneys general. That's a distinct enforcement track. You can comply with TCPA consent rules and still get hit for a DNC violation if you didn't scrub your list properly. I've seen agencies get blindsided by this exact gap, figuring one compliance check covered both problems. It doesn't.
The one-to-one consent rule you need to understand right now
The FCC's one-to-one consent rule, with enforcement targeted around January 2025, requires that a consumer's consent to be called is tied to one specific seller. Consent can't be shared or resold across a chain of lead buyers anymore, which upends how a lot of aggregator-based lead gen has worked for a decade.
Get the Full Buyer's Guide PDF
One document covering how to source and qualify Medicare, U65, and ACA calls without digging through every chapter online.
Here's the practical version. Under the old model, a consumer might fill out a form on some comparison site, and that single click generated "consent" sold to five, ten, sometimes twenty different buyers down the line. Everyone treated that one checkbox as blanket permission. The one-to-one rule kills that. Consent has to name the actual seller who's going to call. If you're buying calls or leads from a source that can't show you consent language tied specifically to your business, you're exposed. Not the lead vendor. You.
This is exactly why working with a platform that tracks call attribution and consent data properly matters so much right now. A service like Ringba X gives agencies call tracking and routing transparency that makes it a lot easier to document where a call came from and what consent was captured at the point of contact. When regulators or plaintiff's attorneys ask "show me the consent record," you want an actual answer. Not a shrug.
Cold calls are basically off the table
Medicare marketing rules generally don't allow cold calls to Medicare Advantage and Part D prospects at all. Agents have to work from beneficiary-initiated contact, a signed permission-to-contact form, or an approved, compliant lead source. That's a much higher bar than most people assume when they get into this business.
I talk to new agents all the time who think TCPA compliance means "just don't call people on the DNC list." That's step one of about six. The real standard for Medicare requires documented consent or an existing relationship. Full stop.
Robocalls need an even higher bar
If you're using an autodialer or prerecorded message to reach a cell phone, TCPA requires prior express written consent. That's stricter than the general "prior express consent" standard that can apply to live agent calls in some circumstances. Written consent generally means a clear disclosure, a specific signature or equivalent electronic action, and language naming the seller and the purpose of the calls.
Mixing live agents with any automated dialing tools means two separate compliance checks. Not one.
Consent doesn't transfer between product lines
This one trips up more agencies than almost anything else here. Consent collected for an ACA plan or an under-65 health plan does not automatically cover Medicare product calls. Regulators evaluate Medicare marketing rules and TCPA consent by product line, not by consumer. A lead who consented to be called about ACA marketplace plans hasn't consented to a Medicare Advantage pitch, even if they're now 65 and technically eligible.
Expanding from ACA sales into Medicare, or vice versa? Treat it as a completely separate compliance question. Don't assume your existing list gives you cover.
State law adds another layer
Federal TCPA is the floor, not the ceiling. States like Florida, Oklahoma, and Washington have their own mini-TCPA statutes with additional restrictions and damages, sometimes without the business relationship exemption that softens federal exposure. Recording disclosure rules vary by state too. Two-party consent states like California and Pennsylvania require you to notify every person on the call before you record it, which matters a lot if your Medicare sales process includes recorded verification calls.
A quick note on where you're sourcing calls
If you're looking to buy calls or specifically buy health insurance calls, ask your vendor directly how they document consent, whether it's tied to your business specifically under the one-to-one standard, and what their DNC scrubbing process looks like. If they can't answer clearly, that's your answer right there.
Takeaway: Medicare compliance isn't one rule. It's a stack of them, and the gaps between federal, state, and CMS requirements are exactly where lawsuits live.
FAQ
Can I call a Medicare lead who filled out a form for an ACA plan? No. Consent is evaluated by product line. A form filled out for under-65 or ACA marketing doesn't cover Medicare Advantage or Part D outreach, even from the same lead source.
Does scrubbing against the DNC list protect me from TCPA lawsuits? No. DNC compliance and TCPA consent requirements are separate legal frameworks. You need to satisfy both, not just one.
What's the real risk if I buy leads from a shared aggregator? Under the one-to-one consent rule, shared consent across multiple buyers generally won't hold up. If the consent language doesn't name your business specifically, you're likely exposed even though you didn't generate the lead yourself.
Do I need written consent for every Medicare call? Not every call, but any robocall or prerecorded message to a cell phone requires prior express written consent, a higher standard than what may apply to live agent calls in some situations. Check your specific method against current rules or talk to counsel.
Frequently asked questions
Can I call a Medicare lead who filled out a form for an ACA plan?
No. Consent is evaluated by product line, so a form filled out for under-65 or ACA marketing doesn't cover Medicare Advantage or Part D outreach, even from the same lead source.
Does scrubbing against the DNC list protect me from TCPA lawsuits?
No. DNC compliance and TCPA consent requirements are separate legal frameworks, and you need to satisfy both, not just one.
What's the real risk if I buy leads from a shared aggregator?
Under the one-to-one consent rule, shared consent across multiple buyers generally won't hold up, so if the consent language doesn't name your business specifically, you're likely exposed.
What is the one-to-one consent rule?
It requires that a consumer's consent to be called is tied to one specific seller, meaning consent can no longer be shared or resold across a chain of lead buyers.
Are cold calls allowed for Medicare Advantage and Part D marketing?
Generally no. Agents must work from beneficiary-initiated contact, a signed permission-to-contact form, or an approved, compliant lead source.
Get the Full Buyer's Guide PDF
One document covering how to source and qualify Medicare, U65, and ACA calls without digging through every chapter online.