Buy Insurance Calls

TCPA rules every insurance agent buying calls must know

Look, if you're buying insurance calls and you haven't read the TCPA at least once, you're running your agency on borrowed time. I've sat in enough rooms with agency owners, lead vendors, and compliance attorneys to hear the same thing every time: the agents who get burned aren't doing anything exotic. They just assumed someone else handled the paperwork.

The Telephone Consumer Protection Act became law in 1991. The FCC enforces it. But here's the part that trips people up: private lawsuits are allowed too. There's a regulator to worry about, sure. But there's also a whole cottage industry of plaintiff's attorneys who specialize in nothing else, scanning call records and consent trails looking for a payday.

What is the TCPA and why does it matter for call buyers?

The TCPA is a federal law restricting how businesses contact consumers by phone. That covers autodialed calls, prerecorded messages, and calls to numbers on the Do Not Call Registry. For agents buying calls, it matters because you can be held liable for compliance failures even when a third-party vendor generated the lead.

That's the part that catches agencies off guard every single year. Buying a lead from a vendor doesn't transfer legal responsibility to that vendor. If the call turns out non-compliant, whoever placed or benefited from it, meaning you, can still get named in a suit. The vendor's misrepresentation about consent doesn't shield you. Courts have made this pretty clear over the last decade. You bought the call. You own the risk.

The math on statutory damages

TCPA exposure isn't calculated like normal business risk. Statutory damages run $500 to $1,500 per violation, and "willful or knowing" violations get the higher number. Now stretch that across a lead list of 3,000 numbers pulled from a sketchy source with fabricated consent records. That's not a fine anymore. That's a number that can close an agency.

I've watched agencies treat a $2 or $3 per lead discount as a win, without asking a single question about how consent was captured. Backwards, honestly. The cheapest lead source usually carries the most legal exposure, because corners get cut somewhere, and it's almost always in the consent documentation.

The FCC's 2023 rule, often called "one-to-one consent," requires that a consumer's consent be tied to a single, specifically identified seller, not shared across a pool of buyers. The original effective date was January 27, 2025, though legal challenges have pushed the timeline around. Verify current status before assuming it's fully in force.

This rule exists because of how lead generation used to work. A consumer fills out a form on some comparison site, checks one box, and suddenly fifteen companies claim they have consent to call. One-to-one consent kills that model. The consent now has to name you specifically, not a category of "insurance partners" buried in fine print. If you're buying shared leads today, ask your vendor point blank how they're handling this. Get it in writing.

Do Not Call Registry rules still apply

Calling a number on the National Do Not Call Registry generally requires prior express written consent, unless the established business relationship exception applies. That exception typically covers inquiries or existing customers for about 18 months. Not indefinitely. It's narrower than most agents assume.

People ask constantly whether an old lead is still fair game. If it's been 19 months since that consumer's inquiry and they're on the DNC list, the answer is no. You need fresh consent. Agencies that batch-dial aged leads without checking dates against the registry are sitting on liability they don't even know exists yet.

Free Email Course: Buying Insurance Calls

Learn how agents and agencies buy inbound calls that turn into sales, delivered in short lessons over email.

Medicare calls carry extra rules on top of TCPA

Medicare marketing has its own layer of restriction through CMS, entirely separate from TCPA. CMS limits unsolicited outbound calls to beneficiaries who haven't given permission to be contacted, and the rules around scope of appointment and permission to contact run stricter than general insurance marketing.

If you sell Medicare Advantage or Medicare Supplement and buy calls, you're stacking two compliance systems on top of each other. A call that's fine under TCPA can still violate CMS marketing rules. Agents who only think about TCPA and ignore CMS are missing half the picture. CMS violations can put your carrier contracts and AHIP certification at risk. Not just your wallet.

The dialer question: ATDS and prerecorded calls

Autodialed calls and prerecorded messages face a higher consent bar than a live agent manually dialing a number. This shapes how call centers configure their dialers, since a system classified as an automatic telephone dialing system triggers stricter rules than manual dialing does.

It's a technical detail. But it ends up mattering a lot in litigation. Vendors sometimes claim their dialer isn't an ATDS to sidestep consent requirements, and that claim doesn't always hold up. If you're working with a call center or dialer platform, ask directly how the system is classified and what consent standard it's built around. Don't take their word for it. Get the technical documentation.

If a TCPA complaint lands on your desk, your consent documentation is what saves you or sinks you. Timestamped opt-in records naming the specific seller, capturing the date, and showing the exact consent language presented to the consumer are usually what decides these cases. Hold onto them for several years. Don't delete them after the sale closes.

I've seen agencies win cases purely because they had clean, timestamped consent records sitting in a folder somewhere. I've also seen others lose because a vendor promised "we have consent on file" and never produced anything when asked. Get the records yourself, at the time of purchase, every time. Don't rely on a vendor's word after the fact.

State law adds another wrinkle. Florida and Oklahoma both run mini-TCPA statutes with stricter consent and calling-time rules than federal law. If you're buying calls across multiple states, you can't just comply with the federal floor and call it done. Check what each state requires, because "compliant nationally" doesn't always mean compliant locally.

If you're tired of the whole compliance headache that comes with buying leads from someone else and want to generate your own inbound calls instead, that's a different conversation. One I wrote a whole book about, actually. Check out The Pay Per Call Revolution, along with the companion workbook that walks through the process step by step.

FAQ

Can I just rely on my lead vendor's consent guarantee? No. You can still be held liable even if the vendor misrepresented consent. Get your own documentation, not just a promise.

How long should I keep consent records? Several years is standard practice among agencies that have been through litigation. Keep timestamped records naming the specific seller for every lead you buy.

Does the established business relationship exception protect me long term? Only for about 18 months from the inquiry or last transaction, and only for numbers on the Do Not Call Registry. After that, you need fresh consent.

Are Medicare leads held to the same standard as other insurance leads? No. CMS marketing rules add restrictions on top of TCPA, including limits on unsolicited outbound calls to beneficiaries who haven't given permission to be contacted.

What's the biggest mistake agents make with purchased call leads? Assuming compliance transferred with the purchase. It didn't. You're the calling party, and that's where liability lands.

Frequently asked questions

Can I just rely on my lead vendor's consent guarantee?

No. You can still be held liable even if the vendor misrepresented consent. Get your own documentation, not just a promise.

How long should I keep consent records?

Several years is standard practice among agencies that have been through litigation. Keep timestamped records naming the specific seller for every lead you buy.

Does the established business relationship exception protect me long term?

Only for about 18 months from the inquiry or last transaction, and only for numbers on the Do Not Call Registry. After that, you need fresh consent.

Are Medicare leads held to the same standard as other insurance leads?

No. CMS marketing rules add restrictions on top of TCPA, including limits on unsolicited outbound calls to beneficiaries who haven't given permission to be contacted.

What's the biggest mistake agents make with purchased call leads?

Assuming compliance transferred with the purchase. It didn't. You're the calling party, and that's where liability lands.