Every Medicare marketing and sales call you make has to be recorded, that part hasn’t changed. What changed is how long you’re on the hook for keeping it, and in what format. CMS’s Contract Year 2027 Medicare Advantage and Part D final rule rewrote the retention requirement at 42 CFR 422.2274(g)(2)(ii) and 423.2274(g)(2)(ii): marketing and sales call recordings now sit on a 6-year clock instead of the 10-year window most agencies had been building their storage policy around, and years four through six can be a transcript instead of the original audio file (Cornell LII, 42 CFR § 423.2274). It’s a smaller rule than the 48-hour SOA repeal that dominated agent group chats this spring, and it’s also one almost nobody outside a compliance department has actually read.
Key takeaways
- CMS's CY2027 final rule (91 FR 17384, published April 6, 2026, effective June 1, 2026) shortened TPMO marketing and sales call recording retention from a 10-year assumption to a specific 6-year requirement at 42 CFR 422.2274(g)(2)(ii) and 423.2274(g)(2)(ii).
- Years 1-3 of that 6-year window must stay in audio format. Years 4-6 can be audio or a complete, accurate transcript — your choice.
- Enrollment records are a separate track and still require 10 years, under 42 CFR 422.504(d) and 422.504(e)(1)(iv). Don't apply the shorter number to the wrong bucket of records.
- CMS's own civil monetary penalty table (45 CFR 102.3) sets a 2025 ceiling of $48,833 per violation for an MA organization that fails to comply with marketing restrictions or the rules implementing them — the category recording and retention failures fall into.
- The new rule applies to CY2027 marketing activity starting October 1, 2026 — two weeks before the 2026 AEP begins on October 15.
This is a different rule than the SOA change
If you're thinking of the CMS rule change everyone talked about this spring, that's the 48-hour Scope of Appointment repeal, covered in full in our CMS Drops the 48-Hour SOA Rule article. This one is about what happens to the recording after the call ends, not when you're allowed to make the call.
What actually changed, in plain terms
CMS’s Contract Year 2027 Medicare Advantage and Part D final rule, published in the Federal Register on April 6, 2026 as document 2026-06600 (91 FR 17384), took effect June 1, 2026 (Federal Register, document 2026-06600). Per the rule’s own text, “the new marketing and communications policies in this rule are applicable for all contract year 2027 marketing and communications, beginning October 1, 2026” — two weeks before the 2026 Annual Enrollment Period opens on October 15 (CMS, Medicare Open Enrollment partner resources).
The actual regulatory text at 42 CFR 423.2274(g)(2)(ii), and its identical MA counterpart at 422.2274(g)(2)(ii), now reads to the effect that TPMOs must record all marketing and sales calls, including the audio portion of calls made through web-based technology like Zoom, in their entirety, and retain them for a minimum of 6 years. For the first 3 years of that window, the recording has to stay in audio format. For years 4, 5, and 6, you can keep either the original audio or a complete and accurate transcript (Cornell LII, 42 CFR § 423.2274; 42 CFR § 422.2274).
That’s a genuinely new, specific number. Before this rule, most agencies treated marketing call recordings the same way they treated everything else in a Medicare Advantage file: keep it 10 years, because that’s the general recordkeeping standard under 42 CFR 422.504(d), which requires MA organizations to maintain books, records, documents, and other evidence of accounting and compliance practices for 10 years (Cornell LII, 42 CFR § 422.504). CMS never published a rule specifically shortening call recordings from 10 years to 6 as a stated before-and-after — what it did was carve out call recordings as their own category with their own, shorter number, distinct from the general 10-year rule that agencies had been applying to everything by default. The practical effect is the same either way: you now have a specific, shorter number to build a policy around, instead of defaulting to the longest number in the rulebook because nobody wrote you a shorter one.

| Record type | Retention period | Format rule | Citation |
|---|---|---|---|
| Marketing and sales call recordings | 6 years | Audio only, years 1-3. Audio or complete transcript, years 4-6. | 42 CFR 422.2274(g)(2)(ii) / 423.2274(g)(2)(ii) |
| Enrollment and disenrollment records | 10 years | No transcript substitution provision | 42 CFR 422.504(d), 422.504(e)(1)(iv) |
| General MA accounting and compliance records | 10 years | Not specified as audio-dependent | 42 CFR 422.504(d) |
Why one call recording rule got shorter while everything else stayed the same
CMS doesn’t explain every line of a 219-page final rule in its public fact sheet, and this one is no exception — the agency’s own summary of the CY2027 rule doesn’t call out the retention change by name. What the fact sheet does say is that this rule is part of a broader marketing rollback: CMS describes “removing restrictions on the time and manner by which beneficiaries can have conversations with licensed agents and brokers” as one of the rule’s changes (CMS, Fact Sheet: Contract Year 2027 Medicare Advantage and Part D Final Rule). The 48-hour SOA repeal, which we covered separately, is the headline version of that rollback. The shorter recording retention window reads as the same instinct applied to the back end of the process instead of the front end: fewer standing obligations on agents and TPMOs, not more.
That doesn’t mean the recording requirement itself got easier. It’s still full-call, still every marketing and sales conversation, still both directions of inbound and outbound. What got easier is the storage tail — six years of holding audio and paying for the infrastructure to store, encrypt, and retrieve it is a real and recurring cost, and CMS just cut that specific tail by 40%, with an explicit option to compress years four through six down to a text file once the format allows it. If you’ve been assuming 10 years because that’s what everyone told you two AEPs ago, you’ve been over-retaining audio you’re no longer required to keep in that format — which isn’t a violation, but it is spend you don’t have to carry.
What it costs to get the retention window wrong

CMS’s civil monetary penalty schedule, published under 45 CFR 102.3 and updated annually for inflation, sets a maximum of $48,833 per violation, as of the 2025 table, for a Medicare Advantage organization that fails to comply with marketing restrictions or the regulations and guidance that implement them, under the authority at 42 U.S.C. 1395w-27(g)(1) (Cornell LII, 45 CFR § 102.3). Recording and retention requirements live inside that same “marketing restrictions and implementing regulations” bucket, since they’re part of 422.2274, the section governing TPMO oversight under the marketing rules. That figure is a ceiling per violation, set by the penalty schedule itself, not a number tied to any specific enforcement action against a recording gap — CMS hasn’t published a case that isolates this exact fact pattern. What the schedule tells you is the scale CMS has authorized itself to use if a program audit turns up a documented gap: not a warning letter, a five-figure exposure per finding.
Nobody gets audited over one missing recording. They get audited, and then the missing recording is what turns a routine finding into a documented pattern.
Mike MooreThe other cost is quieter and shows up whether or not CMS ever asks for a specific file: storage you’re paying for past the point you’re required to. If your dialer, your CRM, or your compliance vendor has been keeping full audio for 10 years because that was the safe assumption before this rule, you’re carrying storage and encryption cost on years 7 through 10 that the current regulation doesn’t require in that format anymore. That’s not a violation in the other direction — over-retaining isn’t illegal — but it’s real, recurring spend that a policy update can trim once you’ve confirmed the shorter number applies to what you’re actually storing.
The manual way to build a compliant retention policy, step by step
None of this requires software you don’t already have. Here’s the checklist, run once and then checked quarterly.
Turn on recording everywhere a marketing or sales call happens
Every line: your cell, a softphone app, Zoom, RingCentral, whatever's inside your CRM or dialer. The rule doesn't care which tool made the call — it covers marketing, sales, and enrollment calls including the audio portion of web-based calls, inbound and outbound, full stop.
Tag every recording by type the moment it's saved
Marketing/sales, enrollment, or service-only. This is the single decision that determines which clock a given file is on — 6 years or 10 — so it has to happen at the point of filing, not months later when someone's trying to reconstruct it from memory.
Read the TPMO disclaimer before you discuss a single benefit
Covered in full below — the exact required language, and the fact that it now lives inside a recording that's retained for years, makes getting this line right non-negotiable rather than a formality.
Store audio in an encrypted, access-logged location for the first 3 years
A transcript doesn't satisfy this window, so don't build a workflow around one yet. Whatever you're using, confirm it logs who accessed a given recording and when — that log is what you'd hand a program auditor alongside the file itself.
At the 3-year mark, decide: keep the audio, or convert to a transcript
A "complete and accurate transcript" means the full call, not a summary — every statement, not a paraphrase of the highlights. If you convert, keep a record of when and how the transcript was generated, in case its accuracy is ever questioned.
Write the policy down
One page: what gets recorded, how it's tagged, where it's stored, who can access it, and the retention schedule by record type. A program auditor asking "how do you know you're compliant" wants to see this document, not just the underlying files.
Worked example: a solo agent's AEP call volume
Say you run 30 marketing and sales calls a week during a 12-week AEP push — 360 calls. Every one gets recorded and tagged. At the 3-year mark, roughly 360 audio files from that single AEP either stay as audio or convert to transcript for years 4 through 6. Multiply that by however many AEPs you're actively retaining, and you can see why the shorter window, and the option to compress to text after year 3, actually matters to a real storage bill — not just a compliance checkbox.
The disclaimer that’s now permanently on tape
Under 42 CFR 422.2267(e)(41), if you don’t represent every Medicare Advantage organization available in a beneficiary’s service area, you’re required to disclose language to this effect: “We do not offer every plan available in your area. Currently we represent [insert number] organizations which offer [insert number] products in your area. Please contact Medicare.gov or 1-800-MEDICARE to get information on all of your options.” If you do represent every plan in the area, the required version drops that first sentence and keeps the rest (Cornell LII, 42 CFR § 422.2267). The regulation requires this be conveyed verbally on sales calls before you discuss any plan benefits, electronically in email or online chat, prominently displayed on your website, and included in all print and broadcast marketing materials.
That disclaimer isn’t new. What’s new, functionally, is what happens to it once you say it: it’s now sitting inside a recording that CMS expects you to be able to produce for up to 6 years. Getting the wording wrong, skipping it, or saying it after you’ve already started walking through plan benefits used to be the kind of mistake that only mattered if someone complained. Now it’s provably on tape, retrievable, for six years. A CMS program audit doesn’t have to take your word for whether you read it correctly — the recording either has it in the right place or it doesn’t.
TPMO status isn't optional for independent agents
CMS defines a TPMO broadly enough to cover independent agents and brokers compensated to perform lead generation, marketing, sales, or enrollment-related functions as part of the chain of enrollment (42 CFR 422.2260). If you're marketing or selling Medicare Advantage or Part D coverage, the recording, retention, and disclaimer rules in this article apply to you directly, not just to the carrier you're appointed with.
The consent layer CMS never mentions: your state’s own recording law
CMS’s recording mandate tells you that you have to record the call. It says nothing about whether you’re legally allowed to, in your state, without saying something first — and that’s a separate question, governed by state wiretapping law, not CMS. Most states are “one-party consent,” meaning you, as a participant on the call, can record it without saying anything, because your own consent is enough. A meaningful minority require all-party consent instead, and getting this wrong isn’t a CMS compliance issue, it’s a criminal one.
California is one of them. Penal Code 632 makes it a crime to “intentionally and without the consent of all parties to a confidential communication” use a recording device to record it, with a first violation carrying a fine up to $2,500, up to a year in county jail, or both, and repeat violations rising to a $10,000 fine (FindLaw, California Penal Code § 632). Florida is another. Statute 934.03 prohibits intercepting a wire, oral, or electronic communication without the consent of all parties, subject to a specific consent exception at subsection 2(d), and treats violations as felonies or misdemeanors depending on the circumstances (Florida Legislature, Fla. Stat. § 934.03).
| State | Rule | First-offense exposure | Citation |
|---|---|---|---|
| California | All parties must consent before a confidential communication is recorded | Up to $2,500 fine, up to 1 year county jail, or both | Penal Code § 632 |
| Florida | All parties must consent to interception of a wire, oral, or electronic communication | Felony or misdemeanor depending on circumstances, per Fla. Stat. § 934.03(4) | Fla. Stat. § 934.03 |
The practical fix costs nothing: add a short, plain disclosure at the top of the call, “this call is being recorded for quality and compliance purposes,” before you get into the TPMO disclaimer or any plan discussion. In a one-party state, that line isn’t legally required but it’s good practice and doubles as proof of disclosure. In an all-party state, it’s the difference between a lawfully recorded, CMS-compliant call and a recording that’s simultaneously satisfying a federal retention mandate and violating a state criminal statute. Check your own state’s rule specifically — this article covers two examples, not all fifty, and state law is exactly the kind of detail that changes without a federal press release announcing it.
What happens once those transcripts leave the phone system
Here’s the part almost nobody’s thinking about yet. Once your dialer or CRM hands you a transcript instead of raw audio, years 4 through 6 under the new rule, or even a same-day transcript your softphone generates automatically, you now have a searchable, shareable text file of a real conversation with a real beneficiary. And the obvious next move for a lot of agents is going to be pasting that transcript into ChatGPT or a similar general-purpose AI tool to check whether the disclaimer landed in the right spot, summarize the call for a manager, or draft a QA note.
Don’t do that with a tool that hasn’t signed a Business Associate Agreement with you. A call transcript that names a real person and touches their Medicare status, health condition, or plan choice is exactly the kind of protected health information a general-purpose AI vendor without a BAA isn’t a safe destination for. This is also where the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted by NAIC membership in December 2023, becomes directly relevant: it sets the expectation that AI-supported decisions and actions comply with all applicable insurance laws and regulations, establishes governance expectations for how insurers use AI, and puts insurers on notice of the kind of documentation a state insurance department may request during an investigation or exam (NAIC, Insurance Topics: Artificial Intelligence). A workflow that runs client call transcripts through an unvetted AI tool with no oversight or record of what happened is exactly the gap that expectation is aimed at.
What not to paste into a general AI tool
Any call transcript or recording that ties a real person's name to a Medicare enrollment detail, a health condition, or a plan selection, sent to a destination without a signed BAA. That includes pasting a transcript into ChatGPT to "clean it up" or summarize it, uploading a recording to a general file-sharing AI assistant, or copying call notes with identifying details into a non-BAA scheduling or CRM add-on.
This is where Ambrose’s PHI Rail is built to solve exactly this problem — not by adding a call-recording feature, but by sitting between an agent and any AI destination. Per Ambrose’s own architecture documentation, PHI Rail runs a redact-then-rehydrate pipeline: when a prompt or file comes in, the system checks whether the destination is on the agency’s BAA allowlist. If it is, the data passes through unchanged. If it isn’t, PHI Rail calls its phi-gateway spoke to scrub identifiers and return a payload of typed aliases, PERSON_xxxx, EMAIL_xxxx, and so on, along with a hydration map, so the AI model sees a coded version of the conversation instead of the real names and details. When the model’s response comes back, phi_rehydrate splices the real identifiers back in before the answer reaches you (Ambrose docs, arch-phi-rail).
The phi-gateway spoke itself is listed in Ambrose’s current spoke catalog as a “PHI scrubber + re-hydrator” with a “safe” HIPAA posture, meaning it’s designed to run local-only rather than sending raw identifiers to an external model (Ambrose docs, Spokes catalog, fetched August 2026). Every scrub event gets logged, timestamp, source, and identifier counts, but never the actual values, through phi_audit_query, which is the kind of documentation trail a program auditor or a state exam would actually want to see. That catalog also lists agent-vault and client-vault, an agency’s private book-of-business store and a client-facing enrollment and policy store, both marked “safe” posture, as the tenant-scoped places that kind of material can actually live once it’s off the phone system.
| Part of the problem | What actually addresses it |
|---|---|
| Recording every marketing/sales call, correctly tagged | Your own dialer or softphone settings — no tool replaces this |
| Reading the TPMO disclaimer correctly, every time | A written script, checked against 422.2267(e)(41) — a discipline, not a product |
| Safely reviewing a transcript with AI once you have one | Ambrose's PHI Rail and the phi-gateway spoke |
| Keeping agency records tenant-isolated and access-logged | Ambrose's agent-vault and client-vault spokes |
To be direct about the boundary here: Ambrose doesn’t currently ship a dedicated call-recording or transcription spoke of its own — that’s not in its live spoke catalog as of this writing, and this article isn’t going to claim otherwise. What it does, confirmed and documented, is give you a safe way to put a transcript your phone system already generated in front of an AI model without that model — or whatever’s on the other end of it — ever seeing the beneficiary’s real name, number, or health details. If you’re already recording and retaining calls the way this rule requires, that’s the piece that keeps the next step, actually using those files for QA or coaching, from becoming its own HIPAA problem.
What you get by joining
One Ambrose seat, including the PHI Rail and the phi-gateway, agent-vault, and client-vault spokes, comes with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, founding rate locked in while the membership stays active. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, 30+ hours of recorded training, Meta Ads, AI, and marketing training built specifically for this industry, pre-built AI templates and bot deployments, and a free annual in-person member workshop. It’s also an explicit no-recruiting zone — you can ask a real compliance question about your call recording policy without ending up on someone’s downline pitch list.
Ambrose usage runs separately from the $97 seat
The membership includes one Ambrose seat; usage inside Ambrose runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise line item. See the full Spokes catalog for what else is available beyond what's covered here.
Compliance: what this touches, and what it doesn’t
If you market or sell Medicare Advantage or Part D coverage and get compensated to do it, you’re a TPMO under 42 CFR 422.2260, and the recording, retention, and disclaimer rules covered here apply to you directly, not just to the carrier or upline you work with. That includes the multi-plan disclaimer requirement at 422.2267(e)(41) covered above, and the recording retention window at 422.2274(g)(2)(ii) and 423.2274(g)(2)(ii). None of this article is legal advice, and CMS guidance and enforcement priorities shift — confirm your own agency’s specific obligations with CMS’s Medicare Communications and Marketing Guidelines, your upline’s compliance team, or qualified counsel before finalizing a retention policy.
If you’re using AI tools anywhere in your call-review, QA, or coaching workflow, the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers sets the expectation regulators increasingly apply: AI-supported decisions have to comply with applicable insurance law, insurers need governance around how the tools are used, and documentation has to be available if a state department of insurance asks for it (NAIC, Insurance Topics: Artificial Intelligence). Ambrose is HIPAA-aware by default, not HIPAA certified — there’s no such thing as HIPAA certification for a software platform, and any vendor claiming otherwise is worth a second look.
The close
Six years, audio for the first three, audio or a clean transcript for the last three, and enrollment records still on their own separate ten-year track. That’s the whole rule, and building a one-page policy around it costs nothing and takes an afternoon, whether you ever join anything or not. If you’d rather have someone double-check the policy with you, and see how PHI Rail keeps a transcript safe once you’re ready to put it in front of an AI tool, one Ambrose seat comes with a Tech Savvy membership, and the weekly build-with-you calls are where agents actually set this up on their own book: https://techsavvyinsurance.com/.
Before you rely on any figure in this article
Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. You are responsible for your own licensure and for complying with all applicable CMS, HIPAA, state, and carrier regulations, including your state's TPMO and recordkeeping rules. Regulations and enforcement priorities can change — confirm current requirements directly with CMS, your state Department of Insurance, or qualified legal counsel before relying on any figure here. AI-generated outputs may contain errors — always verify. Results may vary.
Frequently asked questions
Sources
- Cornell Law School, Legal Information Institute — 42 CFR § 423.2274 (TPMO oversight and recording retention, Part D) — law.cornell.edu
- Cornell Law School, Legal Information Institute — 42 CFR § 422.2274 (TPMO oversight and recording retention, MA) — law.cornell.edu
- Cornell Law School, Legal Information Institute — 42 CFR § 422.504 (MA organization contract, records retention) — law.cornell.edu
- Cornell Law School, Legal Information Institute — 42 CFR § 422.2267 (TPMO disclaimer requirements) — law.cornell.edu
- Cornell Law School, Legal Information Institute — 42 CFR § 422.2260 (TPMO definition) — law.cornell.edu
- Cornell Law School, Legal Information Institute — 45 CFR § 102.3 (civil monetary penalty inflation-adjustment table) — law.cornell.edu
- Federal Register — Medicare Program; CY2027 and Certain CY2026 Policy and Technical Changes (document 2026-06600 / 91 FR 17384), full text — federalregister.gov
- CMS — Fact Sheet: Contract Year 2027 Medicare Advantage and Part D Final Rule — cms.gov
- CMS — Medicare Open Enrollment partner resources (2026 AEP dates) — cms.gov
- NAIC — Insurance Topics: Artificial Intelligence (Model Bulletin background) — content.naic.org
- Ambrose docs — Architecture: PHI Rail — app.hiambrose.com
- Ambrose docs — Spokes (catalog) — app.hiambrose.com
- Ambrose docs — What is Ambrose — app.hiambrose.com
- FindLaw — California Penal Code § 632 (recording confidential communications) — codes.findlaw.com
- Florida Legislature — Fla. Stat. § 934.03 (interception and disclosure of wire, oral, or electronic communications) — leg.state.fl.us
Ready to put this into practice?
Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.
Join Tech Savvy — $97/month