G
Sign up free
Free Compliance Resource

CMS, HIPAA & Federal Marketing Guardrails

A free reference center for Medicare Advantage, Part D, insurance sales, and digital marketing compliance. Use this alongside - not instead of - your licensed compliance review.

Compliance-aware AI

GSS Growth Tool is built for regulated industries.

Every AI-generated asset ships with disclosure prompts, consent capture, and state-aware language toggles. Our Compliance Guardian reviews copy for CMS, HIPAA, TCPA, and FINRA-style risks before you publish.

Sales & Marketing Guardrails

Scope of Appointment (SOA)

Document and secure the Scope of Appointment at least 48 hours before an individual sales appointment whenever possible. GSS CRM can automate SOA capture and timestamped consent records.

TPMO Disclaimers

Clearly state whether the agent, broker, or Third-Party Marketing Organization (TPMO) offers all plans available in an area or only a subset. This disclaimer must be prominent on public websites and electronic materials.

Call Recording

All marketing, sales, and enrollment calls must be recorded in their entirety. Retain call logs, recordings, and SOAs securely for the required retention period.

Approved Materials

Promotional content must follow the Medicare Communications and Marketing Guidelines (MCMG). Use only carrier- or CMS-approved language, and route short ads to a fully compliant landing page.

Legal & Operational Rules

Record Retention

Store call logs, recordings, and SOAs securely. Retention periods vary by data category - many records must be kept for 10 years (or 6 years under specific adjustments).

Enrollment Periods

Applications are restricted to valid windows such as the Annual Enrollment Period (AEP), Open Enrollment Period (OEP), and qualifying Special Enrollment Periods (SEPs).

Prohibited Tactics

High-pressure selling, misleading claims, and implying direct government affiliation are banned. Do not use official logos, Medicare cards, or deceptive naming conventions.

Privacy & Data Protection

HIPAA & PII Compliance

Personally Identifiable Information (PII) and Protected Health Information (PHI) require end-to-end encryption and secure storage. GSS Growth Tool encrypts data at rest and in transit.

Consent to Contact

Obtain express written permission before cold-calling, texting, or emailing a consumer. Consent must be documented, timestamped, and revocable.

Breach Notification

Security breaches involving consumer PII must be reported to federal authorities rapidly - often within 24 hours - depending on the scope and data involved.

Website & Landing Page Guardrails

Digital first impressions are still marketing

HPMS Pre-Approval

Any page displaying specific plan names, premiums, or benefits must be submitted and approved through the Health Plan Management System (HPMS) before going live.

TPMO Disclaimer

The updated Third-Party Marketing Organization disclaimer must be displayed prominently and electronically on public websites and landing pages.

Ancillary Documents

Sites must link directly to the plan's exact Summary of Benefits, multi-language inserts, and formal non-discrimination notices.

Data Transparency

If you collect consumer information, explicitly disclose how lead data is used or shared. GSS forms include consent capture and privacy links by default.

Paid Ads & Social Media Rules

Short ads still need full disclosures

Character-Limit Workarounds

Character limits on platforms like Google or X (Twitter) do not exempt you from required disclosures. Short ads must route consumers to a fully compliant, linked landing page containing the full disclaimers.

Ban on Government Affiliation

Visuals or text cannot feature official government logos, Medicare cards, or deceptive naming conventions that imply direct government endorsement.

Public PHI Prohibitions

Agents cannot request health information via public social media comments or direct messages, nor reference client scenarios without express written consent.

No Unsolicited Digital Contact

Initiating direct, unsolicited sales pitches over social media messaging platforms is considered an illegal marketing tactic under CMS guidance.

Email & SMS Compliance

Prior Express Written Consent

For SMS and text-based marketing, secure prior express written consent that complies with both the Telephone Consumer Protection Act (TCPA) and CMS guidelines before sending a text.

One-Click Opt-Out

Marketing emails require a highly visible, automated opt-out mechanism that honors unsubscribe requests within 10 business days.

Encryption Standards

Emails containing any collected personal details or health metrics must rely on end-to-end, HIPAA-compliant encryption.

Important disclaimer

This page is an educational reference, not legal advice. CMS, HIPAA, TCPA, and state insurance rules change frequently. Always have your licensed compliance officer, legal counsel, or carrier review final marketing materials, scripts, and workflows before use.

Agent responsibility for legal forms

Agents must use their required legal company- or carrier-specific Scope of Appointment (SOA), List of Items (LOI), and Prior Express Written Consent (PEWC) forms outside of this app. GSS Growth Tool does not issue, file, or take responsibility for these regulated documents. Each contracted agent is solely responsible for obtaining, completing, storing, and handling all required forms and records in compliance with applicable laws, carrier rules, and CMS guidance.

Calling and texting: scrub every list before you dial. Use the built-in DNC Scrub Center to suppress numbers across your workspace, and share the public Do Not Call request form with any consumer who asks to opt out. You are still responsible for your own FTC registry subscription, state lists, and written consent records.

Want compliance built into every campaign?

Upgrade to Growth or Enterprise to unlock the Compliance Guardian, automated SOA capture, consent tracking, and carrier-ready disclosure templates.