Learn to Buy Health Insurance Calls

TCPA compliance for under 65 insurance call campaigns

So you're buying or selling U65 [health insurance calls](/under-65-u65-calls/best-time-of-year-to-buy-u65-health/), and somewhere in the back of your mind there's a voice asking "wait, is this actually legal?" Good. Keep listening to it.

I've been in lead gen and call marketing long enough to watch good agencies get buried by TCPA lawsuits they never saw coming. Not because they were doing anything wildly shady. Because they treated compliance like paperwork instead of the actual foundation of the business. Here's the thing: in the U65 and ACA space, compliance isn't optional decoration. It's the difference between a campaign that scales and one that ends with a demand letter.

What is the TCPA and why does it matter for U65 campaigns?

The Telephone Consumer Protection Act is a 1991 federal law restricting marketing calls and texts, especially ones using autodialers or prerecorded voices. The FCC enforces it, and private lawsuits are allowed too. Violations typically run $500 to $1,500 each, and U65 campaigns generate huge call volumes. That multiplies risk fast.

That per-violation number sounds small until you do the math. A single list of 3,000 numbers called without proper consent isn't one violation. It's potentially 3,000 of them. At even $500 a call, that's $1.5 million in statutory exposure from one bad list. I've seen agencies treat a purchased lead file like a golden ticket, only to find out later that the "consent" behind it was one vague checkbox buried on a comparison site nobody read carefully. That's not consent. That's a lawsuit waiting for a plaintiff's attorney to notice.

Short answer: the FCC's one-to-one consent rule, originally set to take effect in early 2025, would require a consumer to give separate consent to each individual marketing partner rather than one blanket consent covering dozens of lead buyers. It's facing legal challenges right now, so the rules are in flux. But the direction is clear.

For years, standard practice in lead gen was simple, and honestly a little sloppy. A consumer fills out a form on some insurance comparison site, agrees to be contacted by "our marketing partners," and that one click gets treated as consent for every buyer who eventually calls that lead, sometimes dozens of companies deep. The one-to-one rule says that's not good enough anymore. Each seller needs its own documented, specific consent tied to that consumer agreeing to be contacted by that particular company.

Here's why this matters so much for U65 and ACA calls. Lead aggregators in this space often resell the same lead to multiple buyers, sometimes 5 to 10 deep. Broad consent language like "partners," "affiliates," or "select advertisers" is exactly the kind of vague blanket consent the new rule targets. If the rule survives its legal challenges, and that's still an open question as of this writing, campaigns relying on old-style aggregator consent could find themselves suddenly non-compliant overnight. And even if enforcement gets delayed again, plaintiff's attorneys are already using the spirit of the rule to argue old consent wasn't specific enough under existing TCPA standards.

So even in legal limbo, the safe move is assuming stricter consent standards are coming. Build toward them now. Don't wait for a court to finalize it for you.

Do Not Call Registry rules still apply, and they're not going away

Numbers on the National Do Not Call Registry generally can't be called for marketing without prior express written consent. There's a narrow exception for established business relationships, usually good for about 18 months. But that exception is easy to misread and easier to lose track of.

I've talked to agencies who assumed an 18-month EBR window gave them blanket permission to keep dialing a lead pulled from an old CRM export. Doesn't work that way. The relationship has to be genuine, and the timeline matters. If a consumer's last interaction with your business was 20 months ago, that exception is gone. You're calling a DNC number cold. That's a real problem in Medicare and ACA campaigns specifically, because open enrollment creates annual bursts of old data getting recycled without anyone checking the dates.

Where most U65 campaigns actually get in trouble

Most TCPA exposure in this industry doesn't come from big obvious violations. It comes from three quiet, boring mistakes nobody catches until a lawsuit shows up.

Get the Full Buyer's Guide PDF

One document covering how to source and qualify Medicare, U65, and ACA calls without digging through every chapter online.

The first is purchased leads without verifiable consent. Third-party lead gen sites and aggregators are common in the U65 space, and some are run well, with clean, documented opt-ins. Plenty aren't. Buying a list without demanding the actual consent record, timestamp, IP address, exact disclosure language shown to the consumer, is asking for trouble down the line.

The second is consent scope mismatch. A consumer requests a quote from Company A, then Company B, an unrelated agent or carrier who bought that lead, calls them. Consent for one purpose doesn't automatically transfer to a different, unrelated seller. This is one of the most commonly missed points in the whole industry, and a favorite argument in TCPA class actions.

The third is dialer technology assumptions. Automated dialers and prerecorded or artificial voice messages face tougher consent requirements than a live agent manually dialing a number. The 2021 Supreme Court decision in Facebook v. Duguid narrowed the legal definition of an ATDS (automatic telephone dialing system), which gave some breathing room to certain predictive dialer setups. But narrowed doesn't mean eliminated. Plenty of dialer platforms still fall inside the stricter rules depending on how they store and generate numbers.

One-line takeaway: the real risk isn't the call itself. It's not knowing exactly where your consent came from.

The FTC's Telemarketing Sales Rule adds another layer

The TSR runs alongside the TCPA and isn't the same thing, though people mix them up constantly. FTC enforcement under the TSR can carry civil penalties stretching into the tens of thousands of dollars per violation, and it covers abandoned call rates, required disclosures, and do-not-call procedures separate from the FCC's rules. A campaign can be TCPA-compliant on paper and still trip over TSR requirements. Treating these as one unified checklist instead of two overlapping ones is a mistake I see constantly.

Enrollment season is when this all gets tested

ACA open enrollment (November 1 through January 15 in most states) and the various Medicare enrollment windows aren't just busy call seasons. They're also when TCPA litigation activity spikes hardest across the industry. Serial plaintiffs and litigation funders have specifically targeted health insurance and Medicare calls over the past several years, because the volume is high, the lists get reused fast, and mistakes are easy to make under pressure.

If you're buying calls or building a campaign for this window, this is exactly the moment to slow down on consent documentation, not speed up. I know that's counterintuitive when everyone else is racing for volume, but it's the season where sloppy compliance gets found fastest.

If you're sourcing inventory through a platform, working with a marketplace like Ringba X that gives you visibility into call routing and source data helps you actually verify where a call originated instead of taking a vendor's word for it. That traceability is worth more than people realize, until they need it in a legal dispute.

A quick word on buying calls the right way

If you're looking to buy calls for a U65 or ACA campaign, the consent question should come before the price question, not after. I've watched buyers get seduced by a cheap cost-per-call only to find out the traffic source was running blanket consent language that wouldn't survive a one-to-one standard, let alone a lawsuit. Ask vendors directly: where's the consent language, who's it specific to, can you show me the record. If they can't answer clearly, walk away.

Same goes if you're trying to buy health insurance calls at scale during open enrollment. Volume matters, sure. But a thousand cheap calls with shaky consent is worth less than three hundred verified ones. The math on litigation exposure makes that trade obvious once you've seen it play out.

FAQ

Does having a privacy policy on my website count as TCPA consent? No. A privacy policy explains data handling, not consent to receive marketing calls. You need explicit, documented consent language the consumer actively agreed to, ideally with a timestamp and the exact disclosure they saw.

If a lead vendor promises "TCPA compliant leads," is that enough to protect me? Not by itself. Get the actual consent record, not just a verbal or contractual promise. Courts have held buyers responsible even when a vendor claimed compliance, so documentation matters more than assurances.

Can I still call someone who submitted a quote request months ago? Depends on the consent language and how much time has passed. If it's tied to an established business relationship, that window is generally around 18 months, but vague or expired consent won't hold up, especially for DNC-listed numbers.

Does using a live agent instead of an autodialer solve my TCPA risk? It reduces some risk since ATDS and prerecorded message rules are stricter, but it doesn't eliminate consent requirements. You still need proper consent for the call itself, live agent or not.

How do I know if the one-to-one consent rule applies to my campaign right now? Given the ongoing legal challenges, enforcement timing is uncertain as of this writing. The safer move is building your consent processes as if the stricter standard is already in effect, rather than waiting for final court rulings to force your hand.

Frequently asked questions

What is the TCPA and why does it matter for U65 campaigns?

The Telephone Consumer Protection Act is a 1991 federal law restricting marketing calls and texts, particularly those using autodialers or prerecorded voices. Violations typically run $500 to $1,500 each, and U65 campaigns generate huge call volumes, which multiplies risk fast.

What is the one-to-one consent rule?

It's an FCC rule that would require a consumer to give separate consent to each individual marketing partner rather than one blanket consent covering dozens of lead buyers. It faces legal challenges, but the safe move is building toward stricter consent standards now.

Does the Do Not Call Registry still apply to U65 leads?

Yes. Numbers on the National Do Not Call Registry generally can't be called for marketing without prior express written consent, and the established business relationship exception only lasts about 18 months and is easy to misread.

Where do most U65 campaigns get in trouble with TCPA?

The three most common issues are purchased leads without verifiable consent, consent scope mismatch between the original request and the actual caller, and incorrect assumptions about dialer technology and ATDS rules.

How is the FTC's Telemarketing Sales Rule different from the TCPA?

The TSR runs alongside the TCPA but isn't the same thing. It covers abandoned call rates, required disclosures, and do-not-call procedures separate from FCC rules, and a campaign can be TCPA-compliant yet still violate the TSR.

Get the Full Buyer's Guide PDF

One document covering how to source and qualify Medicare, U65, and ACA calls without digging through every chapter online.