Buy Insurance Calls

Common compliance pitfalls when buying health insurance calls

Buying calls sounds simple. Then the first demand letter shows up. I've sat in enough rooms with agency owners and lead buyers to tell you that most compliance disasters aren't caused by bad intent. They're caused by nobody reading the fine print on where the call actually came from, and what consent was collected for.

[Health insurance calls](/health-insurance-u65-calls/best-traffic-sources-for-aca-and-u65-health/), whether U65 or Medicare, sit under more regulatory weight than almost any other vertical in pay per call. The FTC, the FCC, CMS, and a growing list of state attorneys general all have their own opinions about how a call should be generated, recorded, and stored. The rules aren't hidden, either. Agencies just don't build workflows around them until something breaks.

This is the one that catches people most. A buyer assumes that because a lead vendor has "TCPA compliant" stamped on their pitch deck, the consent covers health insurance outreach. Often it doesn't.

Prior express written consent is generally product and purpose specific. Consent gathered for an auto insurance quote, or a home warranty offer, or even a general "insurance products" landing page, doesn't automatically transfer to health or Medicare-related contact. If a consumer clicked a box agreeing to be called about car insurance, that consent doesn't stretch to cover a Medicare Advantage pitch six weeks later. Courts have been unkind to agencies that tried to argue otherwise.

If you're buying calls from a network or lead gen partner, just ask them directly: what was the exact language on the opt-in, and what product category did it name? If they can't produce that documentation quickly, treat that as a red flag. Not a paperwork delay.

Here's the thing: the landing page copy matters as much as the checkbox itself. A vendor might show you a screenshot of a consent box, but if the surrounding page talks about "insurance savings" in general terms rather than naming health insurance specifically, that consent is thin. I've watched agencies get burned because they accepted a vendor's word instead of pulling the actual page history through the Wayback Machine or asking for a timestamped archive.

TCPA exposure is not theoretical

The Telephone Consumer Protection Act allows for statutory damages of $500 to $1,500 per violating call or text. Per call. Not per campaign, not per lead file. A single bad list of 10,000 numbers dialed without proper consent can turn into a seven-figure problem before your legal team even finishes reading the complaint.

This is why disclosures on the lead gen side matter so much, even though the buyer downstream is often the one holding the bag in practice. If you're an agency purchasing calls, you inherit risk from every step upstream: the publisher who ran the ad, the aggregator who routed the call, and the consent language buried on a landing page you've probably never seen.

I'd rather see agencies slow down and audit two or three vendors deeply than spread spend across a dozen sources with unknown consent practices. Volume isn't worth much if half of it is a liability waiting to mature.

In practice, most of the six and seven figure TCPA settlements I've seen discussed in industry circles didn't come from one obviously bad actor. They came from a chain of vendors each assuming the guy before them handled consent properly. Nobody checked. That's the pattern worth remembering: assume nothing, verify everything, and put it in writing with the vendor before the first dollar moves.

Medicare calls have their own rulebook

Are Medicare sales calls required to be recorded? Yes. CMS requires Medicare sales calls to be recorded in their entirety, covering the full sales pitch and enrollment process, not just the parts an agent chooses to capture. Partial recordings or "highlight" clips don't cut it.

This trips up buyers who assume a recording snippet proving TCPA consent is enough. It isn't, not for Medicare. CMS wants the whole conversation, start to finish, and expects agencies to retain that recording along with consent documentation for 10 years. That's a long runway compared to the 3 to 5 year retention windows most general business compliance policies default to. If your data retention system was built for a typical marketing department, it's probably not built for Medicare.

On top of recording rules, the Medicare Communications and Marketing Guidelines restrict unsolicited outbound calls to beneficiaries unless there's a prior business relationship or documented permission to contact. Stricter than general TCPA consent in a lot of ways. It's a separate layer agencies sometimes forget exists because they're so focused on the federal TCPA framework.

Free Email Course: Buying Insurance Calls

Learn how agents and agencies buy inbound calls that turn into sales, delivered in short lessons over email.

Storage costs add up here too. Full-length recordings at scale, kept for a decade, aren't free. A mid-size agency running 500 to 1,000 Medicare calls a week should budget for real cloud storage costs and a system that can actually retrieve a specific call from three years ago in under a day if CMS or a state regulator asks for it. "We have it somewhere" is not an answer that holds up in an audit.

U65 has its own separate exposure

Under 65 health insurance marketing doesn't fall under CMS rules at all, since those are specific to Medicare Advantage and Part D. Instead, U65 campaigns answer to the FTC's Telemarketing Sales Rule, alongside standard TCPA obligations. Agencies that buy both U65 and Medicare calls sometimes apply one compliance checklist to both, assuming the rules overlap more than they do.

They don't overlap cleanly. A vendor might be fully compliant on the U65 side and still exposed on Medicare recording requirements, or vice versa. Treat these as two separate compliance tracks. Not one.

There's also a cost angle worth mentioning. Compliant U65 calls, ones with clean consent trails and proper disclosures, typically run higher on a cost-per-call basis than the murky stuff floating around on cheaper networks. If you're seeing U65 calls priced at $8 to $12 when the market average sits closer to $20 to $35 for a qualified, TCPA-clean call, ask why. Cheap calls in this space are cheap for a reason, and that reason is usually compliance.

State laws add another layer

Federal rules are the floor, not the ceiling. Many states run their own "mini-TCPA" statutes. Florida and Oklahoma get cited often because their consent requirements are stricter and their penalty structures steeper than the federal baseline. A call that clears federal TCPA standards can still expose you legally in a state with tighter rules.

If your call volume touches Florida or Oklahoma consumers with any regularity, you need someone on your team, or your vendor's team, who actually knows those statutes. Generic TCPA compliance training usually skips this entirely. Washington and Maryland have also tightened their own telemarketing statutes in recent years, so if your buyer footprint touches those states too, don't assume the federal checklist covers you there either.

The Do Not Call list problem nobody schedules for

The National Do Not Call Registry requires scrubbing roughly every 31 days to stay compliant. Sounds like a small operational detail. That's exactly why agencies skip it. Nobody wants to own a recurring calendar task, so it falls through the cracks.

I've seen agencies run lead lists for two or three months without a rescrub because the responsibility sat between two departments and neither one claimed it. A 31-day scrub cycle isn't a suggestion, though. Build it into whatever system runs your call routing, and assign a specific person to own it every month. Not "whoever remembers."

The fines here aren't small either. Do Not Call violations can run up to $50,120 per call under current FTC penalty adjustments, a figure that gets updated periodically for inflation. That's a number worth putting on a whiteboard somewhere your team actually looks at it.

A quick gut check before you buy

Before signing with any call source, ask three things plainly. What product was the consent collected for? Is the recording full-length or partial? How long do they retain documentation? If a vendor hesitates on any of those, that hesitation is your answer.

If you're more interested in generating your own inbound health insurance calls instead of buying from third parties, that's a different conversation, and one I wrote a full book on. Check out The Pay Per Call Revolution for the mechanics of building your own compliant, inbound call pipeline instead of depending on someone else's lead hygiene. There's a companion workbook too that walks through it step by step.

FAQ

Does a signed TCPA consent form cover both auto and health insurance calls? Generally no. Consent is product and purpose specific, so a form written for auto insurance typically doesn't extend to health or Medicare outreach.

How long do I need to keep Medicare call recordings? CMS guidance points to a 10 year retention period for Medicare-related sales recordings and consent documentation, longer than most standard business retention policies.

Is a partial call recording enough for CMS Medicare requirements? No. CMS requires the entire call recorded, including the sales pitch and enrollment, not selected portions.

Do state laws matter if I'm already TCPA compliant federally? Yes. States like Florida and Oklahoma enforce their own mini-TCPA laws with stricter consent rules and higher penalties than federal law alone.

How often do I need to scrub against the Do Not Call Registry? Roughly every 31 days. Missing this window is one of the most common, and most preventable, compliance failures agencies run into.

Frequently asked questions

Does TCPA consent for one insurance product cover health insurance calls?

No. Prior express written consent is generally product and purpose specific, so consent gathered for auto insurance or general offers doesn't automatically cover health or Medicare-related contact.

What are the statutory damages for TCPA violations?

The TCPA allows for statutory damages of $500 to $1,500 per violating call or text, calculated per call rather than per campaign or lead file.

Are Medicare sales calls required to be recorded?

Yes. CMS requires Medicare sales calls to be recorded in their entirety, covering the full sales pitch and enrollment process, with retention of recordings and consent documentation for 10 years.

Do U65 and Medicare health insurance calls follow the same compliance rules?

No. U65 campaigns fall under the FTC's Telemarketing Sales Rule and standard TCPA obligations, while Medicare calls follow separate CMS recording and marketing guidelines, so they require two distinct compliance tracks.

How often must call lists be scrubbed against the Do Not Call Registry?

Lists must be scrubbed roughly every 31 days, and violations can run up to $50,120 per call under current FTC penalty adjustments.