CMS compliance rules for buying Medicare inbound calls
Look, if you're buying Medicare Advantage or Part D calls right now, you're sitting on more liability than most agencies realize. I've watched buyers get burned not because they did something wrong on the call itself, but because the vendor upstream cut a corner three steps before the phone ever rang. CMS doesn't care whose fault it was. It cares that the rule got broken.
Medicare call buying looks like a straightforward media transaction on paper. Pay for a call, get a lead, close a sale. In practice, it's a regulated activity with paper trails, disclosure timing rules, and retention obligations stretching back a decade. Get sloppy with any of it and you're not just risking a bad call. You're risking your whole book of business.
Why compliance matters more for buyers than most people think
Buying a call doesn't transfer risk away from you. It stacks new risk on top of whatever the vendor already created. CMS treats the agency that ultimately enrolls the beneficiary as accountable for the entire chain that got them there. Including the parts you never touched.
This is where a lot of buyers coming from other verticals, final expense, ACA, that sort of thing, get tripped up. In those spaces, a bad lead is just a wasted dollar. In Medicare, a bad lead can be a compliance violation with your name on it, even if you bought it from a vendor who swore up and down everything was documented. CMS has made clear through the Medicare Communications and Marketing Guidelines that downstream responsibility doesn't stop at the point of sale. If your vendor's SOA process was broken, or their disclosure language was off, that failure becomes yours the moment you act on the call.
I've sat across the table from agency owners who figured a signed vendor contract with a compliance clause was enough protection. It's not. CMS audits the outcome, not the paperwork. You need actual proof of what happened on that call, not someone else's promise that it was handled.
Scope of Appointment and the 48-hour rule
What is Scope of Appointment and when does it need to happen? SOA is a required disclosure documenting what specific Medicare products will be discussed before a sales conversation happens. CMS generally requires it be completed at least 48 hours beforehand, with narrow exceptions for walk-ins and calls landing in the last four days of a valid election period.
For inbound call buying, this creates a real operational headache. A beneficiary calls in, they're interested, they want to talk now. If your agent jumps straight into plan benefits without a documented SOA already on file, there's a violation sitting right there in the recording. The exceptions exist for exactly this scenario, but they're narrow, and CMS expects proof the exception applied, not just a claim after the fact.
Buying inbound call volume from a third party? Ask them point blank how SOA gets captured before the transfer happens. A vague answer is your answer.
TPMO disclosure requirements
What do TPMOs need to disclose and when? Any third-party marketing organization involved in generating or handling the call, lead generators and call buyers included, must disclose their TPMO status within the first minute of the call. This became a hard requirement under the CY2023 Medicare Advantage and Part D Final Rule.
Sixty seconds isn't much time. That's exactly why this rule catches so many operations flat-footed. The disclosure has to happen early, it has to be recorded, and it has to happen whether the call came from a licensed agent, a staffed call center, or an affiliated marketing partner three layers removed from your brand. CMS doesn't grant a pass because the call ran through someone else's phone system. Buy the call, use it to enroll a beneficiary, and the missing disclosure is now your problem.
Sounds minor, until you're the one explaining to an auditor why forty calls in your sample month are missing it entirely.
Free Email Course: Buying Insurance Calls
Learn how agents and agencies buy inbound calls that turn into sales, delivered in short lessons over email.
Recorded call retention: the ten-year problem
Most buyers underestimate this one. It just doesn't feel urgent day to day. CMS Marketing Guidelines require recorded calls involving Medicare Advantage and Part D enrollment discussions be kept for a minimum of 10 years. Not two years. Not five. Ten.
That means your storage infrastructure, your vendor agreements, and your own internal systems all need to survive a decade without gaps. Vendors go out of business. Servers get decommissioned. Storage providers quietly change retention defaults. None of that is CMS's problem. It's yours. Because when an audit request lands for a call from six years ago, "the vendor we used back then doesn't exist anymore" doesn't fly.
Buying calls at any real volume means you need your own retention system. Not just reliance on whoever generated the call originally.
Language that can trigger penalties fast
CMS prohibits language implying government affiliation, phrases like "Medicare-endorsed" or anything close. This shows up constantly in marketing copy, IVR scripts, even agent talk tracks, from people who don't realize how touchy CMS is about this specific wording.
Violations here aren't a warning letter. Civil monetary penalties can run from a few thousand dollars into the tens of thousands per incident, depending on severity and whether it's a pattern or a one-off. Buying calls generated off marketing creative you didn't write? Get eyes on that creative. You inherited it the moment you paid for the call.
TCPA consent is a separate obligation, not a substitute
CMS compliance and TCPA consent are two different legal frameworks, and satisfying one doesn't satisfy the other. Lead sources need express written consent under TCPA independent of whatever CMS marketing rules require, and call buyers can face liability under both at once if either is missing.
I've seen buyers assume that passing CMS-style disclosure requirements meant the consent side was automatically covered. It's not. Ask your vendor for actual proof of consent capture, not a verbal assurance. Insurers like Humana, UnitedHealthcare, and Aetna have tightened internal requirements for TPMO partners since 2022 for exactly this reason, enforcement around both frameworks has picked up hard.
Want to stop depending on vendors for compliance headaches altogether and build your own inbound call volume instead? That's a different conversation, one I cover in my book, The Pay Per Call Revolution, along with a companion workbook that walks through the setup step by step.
Bottom line: buying calls doesn't buy you distance from compliance. It buys you exposure to someone else's mistakes too.
FAQ
Do I need to keep recordings if I'm just buying the call, not generating it? Yes. Retention obligations apply no matter who generated the call. Use it to enroll a beneficiary, and you need to produce it for up to 10 years.
What happens if my vendor didn't get SOA documented before transferring the call? That's a violation you now share. CMS holds the agency that completes the enrollment responsible for the full chain, not just its own piece of it.
Can I rely on a vendor's contract language saying they handle compliance? No. A contract clause doesn't satisfy an audit. You need actual documentation, recordings, and consent records, not a promise buried in an agreement.
Is TPMO disclosure required even for smaller, informal call sources? Yes. The rule applies to any third party involved, regardless of size, whether they're a licensed agent, call center, or marketing affiliate.
Does TCPA consent count as CMS compliance too? No. Separate frameworks, separate requirements. You can be fully compliant on one and still exposed on the other.
Frequently asked questions
Do I need to keep recordings if I'm just buying the call, not generating it?
Yes. Retention obligations apply no matter who generated the call. Use it to enroll a beneficiary, and you need to produce it for up to 10 years.
What happens if my vendor didn't get SOA documented before transferring the call?
That's a violation you now share. CMS holds the agency that completes the enrollment responsible for the full chain, not just its own piece of it.
Can I rely on a vendor's contract language saying they handle compliance?
No. A contract clause doesn't satisfy an audit. You need actual documentation, recordings, and consent records, not a promise buried in an agreement.
Is TPMO disclosure required even for smaller, informal call sources?
Yes. The rule applies to any third party involved, regardless of size, whether they're a licensed agent, call center, or marketing affiliate.
Does TCPA consent count as CMS compliance too?
No. Separate frameworks, separate requirements. You can be fully compliant on one and still exposed on the other.