Table of Contents

Key Takeaways

  • Agents need the appropriate state licenses, required carrier appointments/contracts, and a valid NPN, along with any applicable product-specific certifications, before selling.
  • Compliance requirements vary by line of business, with Medicare, ACA/Marketplace, and group benefits each having their own rules and obligations.
  • An agency management system (AMS) can centralize compliance records, automate reminders, and keep documentation connected to the right client.

Compliance is more important than ever for agents and brokers serving Marketplace clients. Even small compliance issues can have serious consequences for your clients and your business.

Between January and August 2024, CMS received 183,553 complaints of unauthorized Marketplace enrollments. By October 2024, CMS had suspended 850 agents’ and brokers' Marketplace Agreements for suspected fraudulent or abusive conduct related to unauthorized enrollments or plan switches. Staying compliant helps protect your clients and your ability to keep serving them.

What Does Compliance Mean for Your Agency?

Health insurance compliance covers the federal, state, carrier, and industry requirements that shape how agents sell, service, market, and document health insurance. For your team, that means paying attention to the details behind every task. Tasks like:

  • Making a call
  • Collecting a signature
  • Recommending a plan
  • Storing client information

In this blog, we’ll cover the key health insurance compliance requirements your agency needs to know to protect your clients and your license.

Pro Tip: Insurance compliance requirements vary by state, product, carrier, and the type of business your agency sells. Always verify current requirements with the applicable state insurance department (DOI), CMS, carrier, or legal/compliance professional.

What Are the Core Health Insurance Compliance Requirements?

Before your agency can sell insurance, you need to meet the requirements in every state where your team does business. If your team works across state lines, that includes keeping up with nonresident licensing in each state. Requirements can vary by state, so it is important to know the details.

1. What Licensing, Appointments, & Continuing Education Do Health Insurance Agents Need?

Here is a breakdown of the key requirements your team should track:

Requirement What It Covers How Often What to Track
State Licensing Agents must have an active license in each state where they sell. Nonresident licenses may also be required. Varies by state. Most renew every 2 years. License numbers, licensed states, and expiration dates.
National Producer Number (NPN) The National Association of Insurance Commissioners (NAIC) assigns each agent a unique NPN through the NIPR licensing application process. It is required for Marketplace registration, agent validation, and commissions processing. One-time assignment. No renewal. NPNs for each agent. Verify accuracy on every application and carrier appointment.
Carrier Appointments & Contracting Requirements vary by state and carrier. Some states require an appointment before an agent can sell for a carrier. Some carriers also require product certifications. Varies by state and carrier. Some certifications must be renewed each year. Carriers require annual renewal. Appointment status and contracting completion dates by carrier.
Medicare Certifications & Training Agents selling Medicare products must complete annual Medicare training and testing. Carriers may also require training for the specific plans they sell. Annually, before selling for the applicable plan year. Completion dates and renewal deadlines by selling season.
Marketplace Registration & Training Agents helping consumers through the Federally Facilitated Marketplace must complete CMS registration and training. Annually, by plan year. Registration status and training completion by plan year.
Continuing Education (CE) Most states require a set number of CE hours to keep a license active. Requirements vary by state. Varies by state. Many states require CE every 1–2 years. Hours completed, renewal deadlines, and renewal cycle timing by state.

Pro tip: Designate one person to manage the compliance calendar and track important deadlines across the team. A CRM can also help keep renewal dates, licenses, certifications, and other compliance tasks organized and on schedule.

2. How Does HIPAA Affect Health Insurance Agents & Client Data?

Your team may handle sensitive information, including personally identifiable information (PII) and, depending on your role and relationships, protected health information (PHI).

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting individually identifiable health information. That means having the right privacy, security, and access controls in place. And keeping them there consistently.

That starts with having clear internal processes for:

  • Access controls: Limit PHI access to employees who need it.
  • Secure storage: Protecting PHI starts with secure storage. Keep digital records in access-controlled systems and physical records in secure locations to prevent unauthorized access, loss, or theft.
  • Vendor agreements: Make sure vendors handling PHI have appropriate Business Associate Agreements (BAA) when required.
  • Breach response: Have a plan for what to do if information is exposed.
  • Employee training: Train your team members who handle PHI on their responsibilities.
  • Risk management: Regularly assess how your agency stores, accesses, and shares sensitive information.

Your clients share some of their most personal information with your agency. Protecting that information requires consistent attention and clear internal processes.

3. What Are the Medicare Scope of Appointment Requirements?

If your agency sells Medicare Advantage or Part D plans, one of the most important documents to manage is the Scope of Appointment (SOA).

An SOA is a signed form that documents what Medicare products a client has agreed to discuss during an appointment. Collecting an SOA is only required when the appointment involves Medicare Advantage or Part D plans. If neither product will be discussed, the SOA is not required.

The SOA requirements are changing for 2027. Beginning October 1, 2026, CMS has removed the 48-hour waiting period between completion of an SOA and a personal marketing appointment. The SOA requirement itself remains in place.

A few best practices:

  • Collect the SOA before the appointment.
  • Confirm the form reflects the products your client agreed to discuss.
  • Retain completed SOAs.
  • Keep records for canceled appointments and no-shows.
  • Store the completed form where your team can easily find it.

Your agency also needs to keep compliance in mind when communicating with clients by phone. Medicare marketing and sales calls are subject to CMS call-recording requirements. Agencies should understand which calls must be recorded, how recordings must be stored, and how quickly they can be retrieved if requested. 

The best place to store those recordings is directly in the client's record. If questions ever come up about a conversation, having everything tied to one place saves a lot of time and reduces stress for your team.

Need to Communicate About a Scope of Appointment? 

Keep your Medicare appointment communications clear and documented with our free SOA communication templates.

Get the SOA Templates

4. What Are the ACA Consent to Contact Requirements?

If your agency helps clients enroll through the Federal Marketplace, there are two documentation requirements your team needs to follow every time:

  1. Consent to Contact
  2. Attestations

Consent to Contact gives your agency permission to assist, while the Attestation confirms that the client has reviewed and verified the information they’ve submitted.

Documentation must include, at minimum:

  • A description of the scope, purpose, and duration of consent
  • Date consent was given
  • Consumer or authorized representative's name
  • Name of the agent, broker, or agency receiving consent
  • A process for consumers to withdraw their consent

Attestation documentation needs to include:

  • The date the information was reviewed
  • The client's name or their authorized representative
  • An explanation of the attestation
  • The name of the agents involved

A couple of other notes:

  • Attestations must also be collected before submitting the application.
  • Consent may be documented through written, electronic, or verbal methods, but verbal consent must be documented in a record that meets CMS requirements.

Getting clear consent and documenting it properly helps protect your clients and your agency.

5. What Compliance Requirements Apply to Group Benefits & ERISA?

If your agency works with group health plans, there are additional compliance requirements your team needs to understand. Employers are ultimately responsible for compliance, but your agency can help make those requirements easier to understand and follow. Note: Assisting clients with compliance could support your agency’s overall retention goals.

Assisting with compliance can include:

  • Presenting plan options accurately
  • Documenting recommendations & communications
  • Supporting employer enrollment timelines
  • Maintaining organized client records
  • Understanding applicable compensation disclosure requirements

If your team works with ERISA-covered group health plans, you need to understand compensation disclosure requirements. The Consolidated Appropriations Act (CAA) requires brokers and consultants to disclose their compensation when they receive $1,000 or more for services related to an ERISA-covered health plan.

Depending on the situation, disclosures can include:

  • Services provided
  • Who is providing the services
  • Direct compensation
  • Indirect compensation
  • Transaction-based compensation
  • Compensation related to contract termination or prepaid amounts

The key is to understand which requirements apply to your agency and establish a consistent process for documenting them.

6. What Do Health Insurance Agencies Need to Know About Advertising & Marketing Compliance?

Marketing compliance is just as important as compliance in your day-to-day client work. Every piece of marketing your agency puts out needs to meet CMS and carrier guidelines. That includes emails, mailers, social posts, digital ads, and scripts used during sales calls.

Here are a few best practices to keep your marketing compliant:

  • Get carrier approval before content runs. Treat every new piece of ad copy as "needs review" by default. Scripts, mailers, ads, and social posts should go to your carrier compliance team before they go anywhere near a client or prospect.
  • Use approved language and required disclaimers. This protects your agency and makes sure your clients are getting accurate, trustworthy information.
  • Follow Medicare’s cross-selling requirements. During Medicare Advantage or Part D sales appointments, agents cannot sell non-health-related products, such as life insurance or annuities.
  • Stay current on CMS updates. Marketing rules shift from year to year, so it’s important to stay up to date with the current rules and regulations.

Building a review process and sticking to it consistently is the best way to stay compliant when marketing.

What Data Security Practices Should Health Insurance Agencies Follow?

Protecting client data means having the right people, systems, and processes in place. Client data can be vulnerable to security threats, which makes protecting it a priority for every agency.

At a minimum, your agency should have:

  • Multi-factor authentication (MFA): Require users to verify their identity in more than one way before accessing systems, adding a critical layer of protection if passwords are ever compromised.
  • Encryption: Ensure that data is unreadable to anyone who shouldn't have it, whether it's stored on a device or being sent across the internet.
  • Password management: Help your team create and manage strong, unique passwords without having to remember them or reuse credentials across platforms.
  • Employee security training: Regular training keeps everyone up to date on current threats and best practices for your agency.
  • Phishing awareness: Phishing attacks are one of the most common ways agencies get compromised. Make sure your team knows how to spot suspicious emails before clicking or responding.
  • Data backup: Ensure your agency can recover quickly if data is lost, corrupted, or held in a ransomware attack.
  • Access Controls: Use role-based permissions to limit access to client data, and regularly review those permissions when team members change roles or leave the agency.
  • Secure disposal of client information: Properly destroy physical documents and wipe devices before disposing of them.

The goal is to create multiple layers of protection that help keep your agency and your clients’ information secure.

What Daily Habits Keep Your Agency Audit-Ready?

These habits can help your agency stay organized and maintain compliance year-round.

  1. Create a compliance checklist. List who's responsible for each task, what needs to be collected, when it's due, and where it's stored.
  2. Use standard scripts and templates for SOAs, ACA Consent to Contact, Attestations, and other recurring compliance communications. This keeps the process consistent across producers.
  3. Store compliance records with the client record, not scattered across email, shared drives, and spreadsheets. This makes records easier to find during an audit.
  4. Complete required training before enrollment windows open, and document completion dates.
  5. Run internal audits periodically. Check for missing SOAs, missing ACA compliance records, expired licenses, incomplete client records, missing call recordings, outdated training, and incomplete compensation disclosures.
  6. Track regulatory and carrier updates and assign someone to review changes and identify any actions your agency needs to take.

Adding small habits like these to your daily routine will make compliance easier for your team to handle.

See where your compliance stands.

Download the free Health Agent Compliance Checklist to find out exactly what your agency needs to track, document, and maintain all year long.

How Can an Agency Management System Help With Health Insurance Compliance?

Manual compliance management, spreadsheets, shared drives, and disconnected tools leave too much room for error. Documents get lost. Deadlines get missed. And when someone finally asks for a record, your team ends up searching across multiple systems to find it.

An agency management system (AMS) can help bring these workflows into one place, making it easier to organize documents, monitor deadlines, and retrieve records. Technology can support your compliance process, but your agency remains responsible for adherence.

With AMS+, an AgencyBloc Solution, your agency can:

  • Send SOA, Consent to Contact, & Attestation forms electronically
  • Store signed documents on the client record
  • Record & store calls
  • Automate compliance reminders
  • Connect policies, clients, producers, & documentation
  • Make records easier to retrieve during an audit

When your processes are organized and your records are centralized, compliance starts being a part of how your agency runs every day.

Curious how AMS+ fits into your agency's process?

Schedule a Demo

FAQ

How long do I need to keep compliance documents?

Retention requirements vary by document and applicable rules. Medicare SOAs and ACA records can have long retention requirements, so your agency should verify current CMS and carrier requirements and build those timelines into your recordkeeping process.

Digitizing compliance documents in your AMS can make this process easier by keeping records organized and accessible in one place.

What's the difference between ACA Consent to Contact and an Attestation?

Consent to Contact gives an agent permission to help a consumer with Marketplace business, while an Attestation confirms the consumer has reviewed and verified their information before submission.

Can compliance documents be collected verbally?

Some requirements may permit verbal collection, but verbal consent still needs to be documented and retained appropriately. Electronic collection can make compliance easier to manage because it creates a consistent record.

Am I responsible for compliance if I use third-party tools?

Working with a third-party vendor does not remove your agency's responsibility to follow applicable requirements or maintain proper documentation. Make sure you understand how vendors handle client data and have the appropriate agreements and security measures in place.

What happens if my agency isn't compliant?

The consequences vary depending on the severity of the violation and can include fines, corrective action, loss of selling privileges, termination of carrier contracts, or loss of your license.

Does using an agency management system make my agency compliant?

An agency management system can help organize records, automate reminders, and standardize workflows, but it does not replace your agency's responsibility to understand and follow applicable federal, state, carrier, and contractual requirements.

Posted by Shannon Beck on Wednesday, September 16, 2026 in Electronic Compliance Management

  1. data management
  2. productivity

About The Author

Shannon Beck

Shannon is the Marketing Specialist at AgencyBloc. She creates and curates engaging, helpful content across blogs, social media, and other digital platforms for health, benefits, and senior insurance agencies looking to grow. Favorite quote: "If you can dream it, you can do it." &m ... read more