Buy Insurance Calls

How to document consumer consent for inbound calls

Look, most agencies get consent wrong not because they're careless, but because they're guessing. They assume an inbound call is automatically clean. It isn't. Consent is a paper trail, and if you can't produce that trail on demand, you don't actually have consent that'll hold up in court. You have a story you're telling yourself.

I've spent years watching call data move through dialers, buffers, and CRMs. The agencies that survive audits treat consent documentation like a product feature, not an afterthought. This is a how-to, so let's get into the mechanics.

Does answering an inbound call give you permission to market to that consumer going forward? No. Inbound consent generally covers the call happening right now, not future outbound marketing. Treating it as blanket permission is one of the most common mistakes in the industry.

Here's the thing: a consumer who calls a number they saw on a Medicare Advantage ad has consented to that interaction. They have not consented to being added to a dialer list three weeks later for a final expense pitch. Agents assume the door stays open once it's been opened. Regulators don't see it that way. Neither do plaintiff's attorneys working TCPA cases.

The Telephone Consumer Protection Act requires "prior express written consent" for marketing calls or texts made using automated dialing systems or prerecorded messages. Statutory damages run $500 to $1,500 per violation, and they add up fast when you're talking about a list of a few thousand numbers. A single bad campaign can turn into six-figure exposure before anyone notices there's a problem.

The FCC's one-to-one consent rule, which took effect in 2025, made this worse for anyone relying on shared lead consent. Before the change, one consent captured on a lead form could get shared across multiple marketing partners, sometimes a dozen or more buyers working off the same click. That loophole's closed now. Consent has to be tied to one seller, obtained with clear and conspicuous disclosure, and logically related to what the consumer expected. If you're buying or generating leads and still treating consent as transferable across your downstream partners, you're operating on a rule that no longer exists.

What actually counts as documentation

A phone call by itself is not documentation. Regulators and courts want a record tying a specific consumer, a specific phone number, a specific date and time, and the exact disclosure language used, all in one place, timestamped and retrievable.

That's the standard used in FTC and FCC enforcement actions. It's a low bar in theory but a high bar in practice, mostly because agencies don't build systems to capture it consistently. At minimum you need the consumer's phone number and the date and time of the call or web submission, the exact disclosure language presented to them word for word, confirmation of the action taken (a checkbox click, a verbal "yes" on a recorded line, a signed form), which product or line of business the consent applies to, and who owns that record and how long it's kept.

Notice that last point. Consent isn't generic. A consumer agreeing to be contacted about auto insurance quotes hasn't agreed to Medicare Advantage calls. Lumping product lines together under one consent record is exactly the kind of shortcut that gets flagged in an audit.

If you record inbound calls for quality or compliance purposes, you need a second layer of consent that has nothing to do with TCPA. States like California and Florida require both parties to be notified a call is being recorded, and that notification generally has to happen at or near the start of the call.

Free Email Course: Buying Insurance Calls

Learn how agents and agencies buy inbound calls that turn into sales, delivered in short lessons over email.

This trips up agencies laser focused on TCPA who forget state wiretap and recording laws are a completely separate lane. A disclosure like "this call may be recorded for quality and training purposes" up top handles it in most states, but confirm your dialer or call tracking platform is actually inserting that disclosure before the recording starts, not after. I've reviewed call flows where the recording notice played mid-call, well after the consumer had already answered questions. That's not a technical detail. That's a live legal problem.

Medicare and the SOA requirement

If you're selling Medicare Advantage or Part D, CMS requires a documented Scope of Appointment, generally completed at least 48 hours before the sales meeting, with limited exceptions for walk-ins or end-of-enrollment-period situations. This is separate from TCPA consent and separate from state recording laws. It's its own animal, and CMS auditors treat it that way.

The SOA has to specify which products will be discussed. If a consumer agrees to talk Part D and the agent pivots into a Medicare Advantage pitch without an updated SOA, that's a documented violation waiting to be found in a secret shopper call or a CMS audit. Keep SOA records separate from your general consent files, dated, and tied to the specific appointment they cover.

State insurance department requirements layered on top

NAIC model regulations and individual state insurance departments frequently require agents to document consumer consent separately from telecom-level TCPA consent. This shows up most in final expense and Medicare-related sales, where vulnerable populations get extra scrutiny. A state examiner won't care that your dialer has a TCPA timestamp if you can't also produce the insurance-related consent your state requires, like acknowledgment of a licensed agent's identity or confirmation the consumer understood they were talking to a sales rep, not a government entity.

This is why I tell agencies to build consent documentation in layers, not as one blanket record. TCPA consent, state recording consent, CMS SOA documentation, and state insurance consent are four different things that happen to occur, often, in the same phone call. Treat them separately in your recordkeeping even when they're captured in one conversation.

Retention: how long is long enough

Hold call recordings and consent records for a minimum of two to five years depending on your state and carrier requirements. TCPA claims generally carry a four-year statute of limitations, so anything shorter leaves you exposed on claims filed near the end of that window. If you're contracted with multiple carriers, check each one's retention requirement separately. They don't always match state minimums, and the longer requirement wins.

If you're generating your own inbound call volume rather than buying it from a network, and you want to build compliant funnels from the ground up instead of inheriting someone else's consent problems, I wrote The Pay Per Call Revolution for exactly that. There's a companion workbook that walks through building the campaign and the compliance layer side by side. That's where most of these mistakes actually get made, in my experience.

FAQ

Does a consumer calling my 1-800 number count as consent for future marketing calls? No. It generally covers that specific call and inquiry. Future outbound marketing needs its own documented consent, tied to the specific product line involved.

How long do I need to keep consent records if I only sell in one state? Follow whichever is longer, your state's requirement or your carrier's contract terms. Plan on at least two to five years given the four-year TCPA statute of limitations.

Is a checkbox on a website enough consent under the new one-to-one rule? Only if it's tied to a single identified seller with clear, conspicuous disclosure of what the consumer's agreeing to and who'll contact them. Shared or bundled consent across multiple buyers no longer qualifies.

Do I need a Scope of Appointment for every Medicare call, even inbound ones? Generally yes, if you plan to discuss Medicare Advantage or Part D products, unless it falls under a limited CMS exception like a walk-in appointment or specific enrollment period circumstance.

What's the single most common documentation mistake you see? Treating one consent record as if it covers everything, recording notice, TCPA marketing consent, and insurance-specific disclosure, when regulators expect each one documented on its own.

Frequently asked questions

Does a consumer calling my 1-800 number count as consent for future marketing calls?

No. It generally covers that specific call and inquiry. Future outbound marketing needs its own documented consent, tied to the specific product line involved.

How long do I need to keep consent records if I only sell in one state?

Follow whichever is longer, your state's requirement or your carrier's contract terms. Plan on at least two to five years given the four-year TCPA statute of limitations.

Is a checkbox on a website enough consent under the new one-to-one rule?

Only if it's tied to a single identified seller with clear, conspicuous disclosure of what the consumer is agreeing to and who will contact them. Shared or bundled consent across multiple buyers no longer qualifies.

Do I need a Scope of Appointment for every Medicare call, even inbound ones?

Generally yes, if you plan to discuss Medicare Advantage or Part D, with limited exceptions for walk-ins or end-of-enrollment-period situations.