Article

Medicare Advantage Enrollment Caps: The 2027 Rule for Agents

← All articles
An empty modern insurance agency workspace shot from behind, a wide desk with an ultrawide monitor showing a Medicare Advantage enrollment application marked denied with a capacity limit reason code, a second monitor showing a calendar counting down AEP days, green and blue Aurora tones, no people visible

Your client picked a plan, you submitted the application on day three of AEP, and four days later it bounces back denied — not for a data error, not for a missing signature, but because the plan hit its enrollment cap before your app got processed. That’s legal. It’s been legal for years under 42 CFR 422.60(b). What’s new for 2027 is that CMS just told every MA organization to start naming this reason on the actual denial notice, instead of it showing up as a mystery rejection an agent has to chase down mid-AEP. One Ambrose seat — the AI platform included with a Tech Savvy membership — can point its Brain at the federal plan data that flags the risk signals before you build an appointment around one plan; the cap number itself still isn’t public anywhere, and that’s the whole problem this article walks through.

Key takeaways

  • 42 CFR 422.60(b) lets an MA organization stop accepting new enrollees once CMS determines a plan has hit its enrollment capacity, processing applications received before that determination in chronological order (eCFR.gov, 42 CFR 422.60).
  • The capacity number itself is set at bid submission — due to CMS no later than the first Monday in June — under 42 CFR 422.254(c)(4), and nothing in that rule requires it to be published anywhere agents can check in advance (eCFR.gov, 42 CFR 422.254).
  • CMS's August 25, 2026 CY2027 guidance revised the capacity-limit discussion in the enrollment manual and added capacity-related denial reasons to MA Exhibit 7, the model denial notice (CMS.gov, HPMS Memo).
  • AEP is a fixed, 54-day window — October 15 through December 7 (CMS.gov) — so every day lost chasing down an ambiguous denial is a day not spent re-submitting to a plan that's still open.
  • Ambrose's Brain fronts 25+ federal and healthcare data MCPs including CMS's own data (Ambrose docs, Architecture) — useful for checking a plan's risk signals before the appointment, though it can't surface a capacity number CMS never publishes.

What actually happens when a plan is full

Here’s the version of this that catches an agent off guard, not the theoretical one. You’ve got a client locked in on a Medicare Advantage plan with a strong star rating and a provider network that includes her cardiologist. You run the Scope of Appointment, you submit the enrollment application through the carrier’s agent portal on October 18th — day four of AEP — and on October 22nd it comes back denied. No data error. No missing signature. The reason code, if the carrier’s notice spells it out clearly, says something like “enrollment capacity reached.” If it doesn’t spell it out clearly — which has been common enough that CMS just built a fix for it, covered below — you spend an afternoon on the phone with the carrier’s broker line trying to figure out whether this is a real denial or a paperwork problem you can fix.

Either way, your client is now six days into AEP with no plan selected, the plan she wanted and prepared for is closed to her specifically, and you’re rebuilding a recommendation from scratch during the exact stretch of the calendar where every other appointment on your book is also competing for your time.

This isn't a carrier mistake or a compliance violation

A capacity-based denial is a legal, CMS-permitted outcome under existing Medicare Advantage regulations. Nobody did anything wrong. What makes it costly is that the cap itself is invisible to you until the application already bounced — which is exactly the gap the manual method later in this article is built to manage.

Why it happens: two regulations, one gap between them

This isn’t a new authority CMS invented for 2027. It’s the interaction of two long-standing Medicare Advantage regulations, and CMS just made the visible part of that interaction sharper.

42 CFR 422.254(c)(4) is where the cap gets set. Every MA organization’s annual bid submission to CMS — due “not later than the first Monday in June” for the following plan year (eCFR.gov, 42 CFR 422.254) — must include “the projected number of enrollees in each MA local area used in calculation of the bid amount, and the enrollment capacity, if any, for the plan” (eCFR.gov, 42 CFR 422.254). MA MSA plans carry a nearly identical, separate requirement under 422.254(e)(1). That means the capacity decision for a plan’s 2027 enrollment happened back in June 2026, based on the organization’s network and staffing projections at the time — months before AEP, and months before you had any conversation with a client about that plan.

42 CFR 422.60(b) is where the cap gets enforced. “If CMS determines that an MA plan offered by an MA organization has a capacity limit, and the number of MA eligible individuals who elect to enroll in that plan exceeds the limit, the MA organization offering the plan may limit enrollment in the plan under this part, but only if it provides priority in acceptance” — first to people who elected before CMS’s determination, processed “in chronological order by date of receipt,” then to everyone else on a nondiscriminatory basis (eCFR.gov, 42 CFR 422.60). There’s a third piece worth knowing: CMS states it “considers enrollment limit requests for an MA plan service area, or a portion of the plan service area, only if the health and safety of beneficiaries is at risk, such as if the provider network is not available to serve the enrollees in all or a portion of the service area” (eCFR.gov, 42 CFR 422.60) — a separate, mid-cycle mechanism tied to actual network adequacy problems, not the standard bid-time cap.

The two regulations that create this gap
Regulation What it governs When it happens
42 CFR 422.254(c)(4) MA organization discloses a plan's enrollment capacity, if any, in its bid to CMS First Monday in June, the year before the plan year
42 CFR 422.60(b) CMS determines a plan hit capacity; the organization limits enrollment, priority by chronological order of receipt Any time enrollment volume exceeds the disclosed cap — including mid-AEP
42 CFR 422.60(b)(3) Separate mid-cycle limit request tied to network adequacy risk in a service area Only when beneficiary health/safety is genuinely at risk

Source: eCFR.gov, current text of 42 CFR 422.254 and 422.60, fetched September 2026.

The gap between those two rules is exactly nine or ten months, and it’s a one-way information flow: the organization tells CMS the number in June, CMS enforces it whenever it gets hit, and neither regulation requires anyone to tell an agent the number before an application gets submitted.

What actually changed for 2027

CMS didn’t rewrite either regulation for CY2027. What changed is the operational guidance that tells MA organizations and plans how to apply it — and that’s exactly the layer agents feel. On August 25, 2026, CMS’s Medicare Enrollment & Appeals Group released the CY2027 Medicare Advantage and Part D Enrollment and Disenrollment Guidance via HPMS memo, replacing the prior version of the guidance manual effective January 1, 2027 (CMS.gov, HPMS Memo, Aug. 25, 2026). Two changes matter here directly:

  • Section 30 and Section 50 of the guidance manual were revised specifically on “the discussion of enrollment capacity limits” and “enrollment capacity limit guidance” (CMS.gov, HPMS Memo, Aug. 25, 2026) — more operational detail for MA organizations on how to actually apply 422.60(b) in practice.
  • MA Exhibit 7, the Model Notice for MA Organization Denial of Enrollment, gained new denial reasons “related to enrollment capacity limits and plans closed for new enrollments” (CMS.gov, HPMS Memo, Aug. 25, 2026). Before this, an agent chasing down why an application bounced had to rely on the carrier’s own phrasing. Starting with 2027 applications, there’s a standardized reason on the model form itself.

That last point is the practical headline for agents: this is CMS formalizing a denial category on its own standardized paperwork, which strongly signals it expects this reason to show up on enough denial notices to be worth standardizing. It’s not evidence of a wave of new caps — CMS doesn’t publish how many plans have set one, and neither does anyone else we could verify — but it is CMS treating this as common enough to name clearly rather than leave to carrier discretion.

Infographic titled The 2027 Enrollment Capacity Timeline, showing a horizontal timeline bar with four labeled markers: first Monday in June 2026, bid submission and capacity disclosure to CMS; August 25 2026, CMS releases CY2027 enrollment and disenrollment guidance with revised capacity limit sections; October 15 2026, AEP opens; December 7 2026, AEP closes; January 1 2027, guidance and plan year take effect, green and blue Aurora color palette, source line reading CMS.gov and eCFR.gov 2026

The capacity decision is locked in five months before AEP even opens — and it's disclosed to CMS, not to agents.

What it actually costs when a denial lands mid-AEP

There’s no published dollar figure for what a capacity denial costs an agent, and we’re not going to invent one — no carrier, CMS, or research firm publishes a per-incident cost for this specific denial reason, so any number here would fail the sourcing bar this site holds itself to. What we can source is the calendar, and the calendar is what actually drives the cost.

AEP runs “October 15 - December 7” every year, per CMS’s own Medicare Open Enrollment materials (CMS.gov, Medicare Open Enrollment Partner Resources) — a fixed 54-day window, counting both endpoints. That window doesn’t extend because a denial ate a week of it. Run the math on when a denial lands and what’s left:

Days of AEP left after a capacity denial, by when it lands

Calculated from CMS's own AEP dates (Oct. 15–Dec. 7) — illustrative date math, not a separately reported figure.

Denied Oct 22 (day 8)
46 days left
Denied Nov 14 (day 31)
23 days left
Denied Nov 28 (day 45)
9 days left
Denied Dec 4 (day 51)
3 days left

Source: CMS.gov, Medicare Open Enrollment Partner Resources (AEP Oct. 15–Dec. 7); days-remaining figures calculated for illustration.

An early denial is an inconvenience. A late one, especially anything landing in the final week, can leave a client with no enrolled plan on January 1st unless you move immediately to a backup and the client is reachable and ready to decide fast. That’s the actual cost: not a dollar figure, a shrinking window with a hard federal deadline on the other end of it.

54 days
length of the fixed AEP window, October 15 through December 7
CMS.gov, Medicare Open Enrollment Partner Resources
First Mon. in June
bid submission deadline where a plan's capacity limit for next year gets set
eCFR.gov, 42 CFR 422.254(a)(1)
Aug. 25, 2026
date CMS released the CY2027 guidance revising capacity-limit sections and Exhibit 7
CMS.gov, HPMS Memo

Stat card graphic showing three sourced figures in large readable text: fifty four days, the fixed AEP enrollment window; first Monday in June, the MA bid submission deadline where enrollment capacity gets set; and August 25 2026, the date CMS released the revised CY2027 enrollment capacity guidance, each stat labeled with its CMS.gov or eCFR.gov source, green and blue Aurora color palette

Three sourced dates that define the window an agent actually has to work with.

The full manual method: protecting a client without any tool

None of this requires software. It requires knowing the mechanism well enough to plan around it, and building two habits into every AEP appointment. Here’s the complete process, free of charge, same as every method on this site.

Never build an appointment around exactly one plan

Walk in with a primary recommendation and a genuinely viable second option the client also understands and would accept. If the primary bounces for any reason — capacity, a data mismatch, anything — you have a same-day pivot instead of a from-scratch rebuild.

Watch for the risk signals a capacity cap tends to travel with

A plan brand new to the county this year, a plan with a meaningfully smaller network than last year's version, or a plan riding a big star-rating jump into a marketing push are the kinds of plans an organization is more likely to have bid a conservative capacity number for. None of this is a guarantee — CMS doesn't publish the number, so this is pattern recognition, not a lookup.

Submit early in AEP for anything you suspect is popular

42 CFR 422.60(b)(2)(i) processes people who elected before CMS's capacity determination in chronological order by date of receipt (eCFR.gov, 42 CFR 422.60). Being early in the queue is the only lever an agent actually has — there's no override, no appeal that beats the calendar, just being one of the earlier applications on file.

Read the actual denial reason on the notice, don't assume

Starting with 2027 applications, the model denial notice (MA Exhibit 7) is supposed to carry a specific reason tied to enrollment capacity or plan closure, not a generic denial (CMS.gov, HPMS Memo, Aug. 25, 2026). Confirm it's actually a capacity denial before spending time troubleshooting a data error that isn't there.

Move to the backup the same day, not the same week

Every day inside AEP's fixed 54-day window is a day that doesn't come back. Call the client back immediately, walk through the second option you already prepared in step 1, and get a new application submitted before the queue for the backup plan gets any longer too.

Document the denial reason and the date you responded

If a client later asks why their plan changed twice, a dated note showing the original submission date, the specific denial reason from the notice, and the date you resubmitted is the full explanation — and it protects you if anyone ever questions the timeline.

This scales down to a solo agent fine

You don't need a team process for this — you need the habit of never walking into an AEP appointment with only one plan in your head, and checking the actual reason code the day a denial comes back instead of assuming the worst or the most convenient explanation.

Everything above works whether you ever join anything or not. Go run it on your next AEP appointment, or let Ambrose help you check the risk signals faster.

Where the manual method breaks down at scale

Steps 1 and 2 above — never build around one plan, watch for risk signals — take real judgment and real familiarity with the local market. That’s fine for a handful of appointments a week. It gets harder fast during AEP, when you might be running a dozen appointments a day, each one needing its own primary-and-backup plan comparison built from scratch, on top of everything else AEP already demands of your calendar.

The risk-signal check specifically — is this plan new to the county, did its network shrink, did its star rating jump — means pulling CMS plan data for every plan you’re considering, for every appointment, during the busiest six weeks of your year. Doing that by hand from CMS’s own landscape files, plan finder, and star ratings pages, one plan at a time, is exactly the kind of research that gets skipped when the calendar is full — which is precisely when skipping it costs the most.

How Ambrose’s Brain and Routines fit into this

Ambrose OS, the platform included with a Tech Savvy membership, can’t tell you a plan’s enrollment capacity number — nobody’s tool can, because CMS doesn’t publish it. Be precise about that instead of overselling it. What it can do, confirmed in the current docs, is take the research burden out of step 2 above.

The Brain is described in Ambrose’s own glossary as “an internal service that fronts 25+ federal/healthcare data MCPs (CMS, NADAC, FDA, Federal Register, FEMA, …)” (Ambrose docs, Glossary), the same description confirmed on the Architecture page (Ambrose docs, Architecture). Instead of pulling CMS plan data by hand for every appointment, a question routed at the Brain can check a plan’s federal-source attributes — the kind of check that turns “is this plan new to the county, and did its network change” from a research task into a single question, without changing what CMS actually discloses.

Routines run a target — an agent or a team — on a five-field cron schedule, with an output sink of Slack, email, a GHL note, or a log-only record (Ambrose docs, Routines). A daily AEP-season Routine can’t see a denial the moment it happens inside a carrier’s own system, but paired with the ghl spoke — which has read access across “Contacts, conversations, call logs, pipelines, opportunities, workflows, calendars, social posts, Voice AI agents, tasks, notes, and custom fields” in GoHighLevel (Ambrose docs, spoke-ghl) — a Routine can scan your pipeline daily for any application sitting in a “submitted” stage for more than 48 hours without moving, and flag it to Slack so a stalled or bounced app gets a human look fast instead of surfacing when the client calls asking what happened.

Manual method vs. the Ambrose pieces that assemble it
Manual step Ambrose equivalent
Research a plan's county history, network size, star-rating trend by hand Ask the Brain, which fronts CMS data among its 25+ federal/healthcare MCPs
Remember to check pipeline for stalled applications every day during AEP A daily Routine on a cron schedule does the check automatically
Notice a stalled GHL opportunity manually ghl spoke reads pipeline/opportunity stage and age directly
Post the flagged list somewhere the team will see it Routine output sink posts to Slack, a GHL note, or email
Find the actual capacity number before the appointment Not possible — CMS doesn't publish it, and no tool can surface a number that doesn't exist publicly

This flags risk and stalls. It doesn't predict a denial

Nothing here — the Brain, a Routine, the ghl spoke — can tell you in advance that a specific application will be denied for capacity. It narrows which plans deserve a backup plan built in advance, and it catches a stalled application faster than waiting for a confused client to call. That's the honest scope of what's confirmed and buildable today.

Edge cases worth knowing before AEP

Special Needs Plans layer on their own enrollment restriction. Dual eligible special needs plans “must limit enrollments to those individuals who meet the eligibility requirements established in the state Medicaid agency contract” under 422.60(a)(3) (eCFR.gov, 42 CFR 422.60) — a categorical eligibility restriction, separate from and in addition to any capacity limit the plan might also carry. A D-SNP denial can be either one; check the actual reason before assuming.

MA MSA plans carry a separate, near-identical capacity disclosure rule. Under 422.254(e)(1), organizations offering MA Medical Savings Account plans must submit “the enrollment capacity (if any) for the plan” as part of a distinct information set from the standard coordinated-care plan bid data (eCFR.gov, 42 CFR 422.254) — worth knowing if any part of your book touches MSA plans, which behave differently from standard MA in several other ways too.

A mid-cycle network-adequacy limit is a different animal from a bid-time cap. 422.60(b)(3)‘s health-and-safety-based enrollment limit request is CMS-initiated in response to an actual network capacity problem in a service area, not a number the organization simply disclosed in June (eCFR.gov, 42 CFR 422.60). It’s rarer, and it’s a signal that something is genuinely wrong with that plan’s network in that area — worth flagging to a client differently than an ordinary capacity denial.

This article covers Medicare Advantage capacity mechanics only

It doesn't cover Special Election Periods, the 48-hour Scope of Appointment change, or D-SNP alignment rules in depth — see our 48-hour SOA rule change guide and AEP book re-shop guide for those.

Compliance: the disclaimer, the AI rule, and the data

The TPMO disclaimer still applies to every one of these conversations. Under 42 CFR 422.2267(e)(41), a third-party marketing organization that doesn’t sell for every MA organization in the service area must use this exact standardized statement: “We do not offer every plan available in your area. Currently we represent [insert number of organizations] organizations which offer [insert number of plans] products in your area. Please contact Medicare.gov or 1-800-MEDICARE to get information on all of your options” (eCFR.gov, 42 CFR 422.2267). It has to appear across email, websites, printed materials, and be stated within the first minute of a sales call — a capacity denial and a backup-plan pivot don’t exempt you from restating it on the follow-up call.

If AI helps you check risk signals or draft the backup-plan outreach, the NAIC’s AI Model Bulletin applies. Adopted at the NAIC’s 2023 Fall National Meeting, it calls for insurers to create and implement “a written AIS Program, commensurate with an assessment of the risk” and sets expectations for third-party AI vendor oversight and testing/validation protocols (NAIC, Members Approve Model Bulletin). States adopt it individually, so confirm your own state’s current status — but the expectation of a written policy, not just a tool subscription, is the standard regulators are working from.

Don't paste a client's application data into a general AI tool

A denied application, a Medicare Beneficiary Identifier, and the reason code together are exactly the kind of record a general-purpose AI tool's terms almost never cover under a BAA. Ambrose's PHI Rail runs a redact-then-rehydrate pipeline — it checks whether the destination has BAA status, and if not, scrubs identifiers into typed aliases like PERSON_xxxx before anything leaves, then splices the real values back into the response (Ambrose docs, Architecture / PHI Rail). That's HIPAA-aware by default, not HIPAA certified, and AI outputs can still contain errors — verify anything it tells you about a specific application before you act on it.

What you get by joining

One Ambrose seat, including the Brain, Routines, and ghl spoke this article describes, comes with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, founding rate locked in while the membership stays active. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, 30+ hours of recorded training, Meta Ads and marketing training built for this industry, pre-built AI templates and bot deployments, and a free annual in-person member workshop — plus an explicit no-recruiting rule, so you can ask a real question about an AEP denial without ending up on someone’s downline pitch list.

Ambrose usage is separate from the $97 seat

The membership includes one Ambrose seat; usage inside Ambrose runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise. See the full Spokes catalog for what else is available beyond the Brain, Routines, and ghl.

The close

Everything above — the primary-and-backup habit, the risk signals, reading the actual denial reason, submitting early — works whether you ever join anything or not. That’s the point of writing it out completely: a capacity denial shouldn’t cost your client three days of AEP because nobody had checked the reason code yet. This is the kind of thing we work through on a Tuesday call, with a Routine’s Slack output flagging a stalled application before the client even notices. $97 a month, cancel anytime, and nobody will pitch you a downline: https://techsavvyinsurance.com/.

Before you rely on anything in this article

Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. You are responsible for your own licensure and for complying with all applicable CMS, HIPAA, state, and carrier rules, including Medicare marketing, TPMO, and Scope of Appointment requirements. AI-generated outputs may contain errors — always verify. Results may vary.

Frequently asked questions

Yes. Under 42 CFR 422.60(b), if CMS determines that an MA plan has a capacity limit and the number of people who elect to enroll exceeds it, the MA organization offering the plan may limit enrollment, as long as it processes valid elections in the order they were received before CMS's determination, then continues without discriminating on health-related factors (eCFR.gov, 42 CFR 422.60). It's not common, and it's not new law, but CMS just made it far more visible for 2027 than it's ever been.
It's the regulation governing how an MA organization processes elections once CMS has determined a plan is at capacity: applications submitted before the capacity determination get priority, processed in chronological order by date of receipt, and only after that does the organization apply nondiscriminatory rules to whoever is left (eCFR.gov, 42 CFR 422.60). CMS also states it will only consider enrollment limit requests tied to a service area, or part of one, when beneficiary health and safety is genuinely at risk — for example, a network that can't actually serve everyone in that area.
The MA organization sets it, and discloses it to CMS as part of its annual bid submission. 42 CFR 422.254(c)(4) requires every bid to include "the projected number of enrollees in each MA local area used in calculation of the bid amount, and the enrollment capacity, if any, for the plan" (eCFR.gov, 42 CFR 422.254). Bids are due to CMS no later than the first Monday in June for the following plan year, months before AEP opens.
CMS's August 25, 2026 HPMS memo releasing the CY2027 Medicare Advantage and Part D Enrollment and Disenrollment Guidance explicitly revised the discussion of enrollment capacity limits in two sections of the guidance manual, and — separately — added denial reasons tied to enrollment capacity limits and plans closed for new enrollment to MA Exhibit 7, the model notice organizations use to tell an applicant why they were denied (CMS.gov, HPMS Memo, Aug. 25, 2026). The underlying authority isn't new; the standardized, named denial reason on the model form is.
Not from a public CMS source we could find. The bid data required under 422.254(c)(4), including the capacity figure, goes to CMS as part of the organization's confidential bid submission — nothing in that regulation requires the number to be published anywhere an agent can look it up before an appointment (eCFR.gov, 42 CFR 422.254). That gap is exactly why this article's manual method leans on risk signals instead of a lookup table that doesn't exist.
Check the denial notice for the specific reason first — under the updated MA Exhibit 7 model notice, a capacity-related denial should say so, not just "denied" (CMS.gov, HPMS Memo, Aug. 25, 2026). Then move to your backup plan immediately: AEP runs on a fixed calendar (October 15 through December 7), so every day spent re-diagnosing a denial is a day not spent re-submitting to a plan that's still open. Confirm the client isn't left uncovered on January 1 by re-checking their options the same day, not the same week.
This specific mechanism, 42 CFR 422.60(b) and 422.254(c)(4), is part 422 — the Medicare Advantage program regulations. Medigap is medically underwritten or guaranteed-issue depending on state law and timing, a different framework entirely, and isn't covered by this article. MA Medical Savings Account (MSA) plans have their own separate capacity disclosure requirement under 422.254(e)(1).
No, and we're not going to claim it can — that number isn't public, so no tool can surface it, Ambrose included. What Ambrose's Brain can do, confirmed in the docs, is answer questions against 25+ federal and healthcare data MCPs including CMS's own data (Ambrose docs, Architecture), which is useful for checking the risk signals in this article — a plan new to the county, a shrunken network, a big star-rating jump — before you build a client's application around a single plan.

Sources

  1. CMS.gov — Medicare Open Enrollment Partner Resources (AEP dates) — cms.gov
  2. eCFR.gov — 42 CFR 422.254, Submission of bids — ecfr.gov
  3. eCFR.gov — 42 CFR 422.60, Election process — ecfr.gov
  4. eCFR.gov — 42 CFR 422.2267(e)(41), TPMO disclaimer — ecfr.gov
  5. CMS.gov — HPMS Memo, CY2027 MA and Part D Enrollment and Disenrollment Guidance (Aug. 25, 2026) — cms.gov
  6. CMS.gov — Contract Year 2027 Medicare Advantage & Part D Final Rule fact sheet — cms.gov
  7. NAIC — Members Approve Model Bulletin on Use of AI by Insurers — content.naic.org
  8. Ambrose docs — Architecture (the Brain) — app.hiambrose.com
  9. Ambrose docs — Glossary — app.hiambrose.com
  10. Ambrose docs — Routines — app.hiambrose.com
  11. Ambrose docs — ghl spoke — app.hiambrose.com
  12. Ambrose docs — Architecture (PHI Rail) — app.hiambrose.com

Ready to put this into practice?

Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.

Join Tech Savvy — $97/month