You vet a carrier before you contract with them. You vet a CRM before you pay for a year of it. Most agents don’t vet a lead vendor at all — they hand over a credit card, a batch of names and numbers shows up, and the only question anyone asks is whether the leads converted. In August 2025, the FTC put a number on what happens when nobody asks the earlier question: it fined two health insurance lead generators, MediaAlpha and Assurance IQ, a combined $145 million for misleading the exact consumers whose contact information ended up in agents’ CRMs (FTC, Aug. 7, 2025). This article is about the four-question check you can run on any vendor before you buy from them, what it actually costs to skip it, and where CMS’s own rules on this — not the FCC rule you’ve probably read is dead — still very much apply.
Key takeaways
- The FTC fined MediaAlpha and Assurance IQ a combined $145 million on August 7, 2025 for misleading health insurance shoppers; MediaAlpha alone sold roughly 119 million consumer leads in 2024 (FTC press release, Aug. 7, 2025).
- CMS finalized its own "one-to-one consent" requirement for TPMOs sharing Medicare beneficiary data on April 4, 2024 — a separate rule from the FCC's version, which was vacated in court and never took effect (CMS, CY2025 MA/Part D Final Rule fact sheet).
- The TCPA attaches liability to whoever calls or texts, not to whoever sold the lead — WebRecon counted 2,810 TCPA lawsuits filed in federal court in 2025, and statutory damages run $500 to $1,500 per violation under 47 U.S.C. § 227(b)(3).
- A four-question vendor check, consent language, a third-party consent certificate, exclusivity, and enforcement history, catches most of what the FTC's complaint described, and it costs nothing to run before you buy.
- Ambrose's lead-hunter spoke is a genuine, documented alternative for the B2B slice of a pipeline (public business data only, no consumer PHI) — not a replacement for consumer Medicare or ACA lead buying, and this article says so plainly rather than overselling it.
This is about buying leads, not texting the ones you already have
If your question is what you're allowed to text or call a lead you already own, that's covered separately in our TCPA Rules for Insurance Agents in 2026. This article is about the transaction before that one: what you're actually buying when you pay a vendor for a batch of names, and how to check it before the money leaves your account.
What actually happened to MediaAlpha, and why it’s your problem too
On August 7, 2025, the FTC announced that MediaAlpha, Inc. and its subsidiary QuoteLab, LLC, along with Assurance IQ, LLC, would pay a combined $145 million to resolve charges tied to how they generated and sold health insurance leads (FTC, Aug. 7, 2025). MediaAlpha’s share of that judgment was $45 million. Per the FTC’s own account, the company sold approximately 119 million consumer leads in 2024 alone — a scale that makes the specific tactics described in the settlement worth reading closely, because they weren’t a one-off scam. They were the production line.
The FTC’s complaint and its own summary of the case describe a specific pattern: websites with names like ObamacarePlans.com and GovernmentHealthInsurance.com, built to imply a government affiliation that didn’t exist; paid actors, including a doctor, appearing in scripted segments presented as independent endorsements; and marketing claiming consumers could get comprehensive coverage for “$1 a day” when the plans actually being sold routinely fell short of that promise (FTC Business Blog, Aug. 2025). Both companies were charged with violating the FTC Act and the Telemarketing Sales Rule; MediaAlpha specifically was also charged under the FTC’s Rule on Impersonation of Government and Businesses.
If you never bought a lead from MediaAlpha, the settlement can still feel like someone else’s problem. It isn’t, and here’s the mechanism that makes it yours: a lead you buy from any vendor arrives in your CRM as a name, a phone number, an email, and usually a line that says something like “TCPA compliant” or “opted in.” You have no way to independently verify that claim from the record itself. The FTC’s complaint is one of the only public documents that shows, in detail, what that claim can actually mean in practice at scale — a landing page built to look like a government site, a consent checkbox buried under a “$1 a day” claim nobody could deliver on. The mechanics aren’t unique to one company. They describe how a meaningful share of the digital health insurance lead market has generated volume, and a batch of leads sitting in your CRM right now gives you no way to tell which mechanics produced it.

Why this keeps happening: the economics run against quality
None of this requires anyone at a lead-gen company to be malicious on purpose, in the same way that a carrier’s commission-statement error doesn’t require bad faith. It requires an economic structure that rewards volume over verification, and the online lead market has exactly that structure.
Vendors get paid on volume, not on consent quality. A lead generator’s revenue is a function of how many leads it can produce and sell, not how airtight the consent behind each one is. Verifying consent slows down production. Skipping the verification step, or writing consent language vague enough to cover almost anything, doesn’t.
Leads get resold, and each resale is a chance for the original consent to get diluted. A single form submission on a landing page can be sold once, exclusively, to one buyer — or it can be auctioned to multiple buyers simultaneously through an aggregator, with each buyer believing they’re the only one who paid for it. The person who filled out the form typically has no idea how many companies are about to call them, and every one of those companies is relying on the same original, possibly deceptive, consent event.
The consent language and the sales pitch are often the same page. When a landing page promises “$1 a day” coverage and buries a TCPA disclosure in six-point gray text underneath it, the FTC’s argument is that the disclosure doesn’t actually inform anyone of anything, because the surrounding page was built to make sure they never read it. A checkbox someone clicks without reading isn’t meaningfully different, from a consumer’s perspective, from no checkbox at all — even though it looks identical to a buyer downstream reviewing a “compliant” field in a spreadsheet.
By the time it reaches you, all of that history is invisible. Your CRM shows a name, a number, a source label, and maybe a timestamp. It doesn’t show you the landing page the person actually saw, the exact disclosure language above the checkbox, or how many other buyers received the same lead. You’re buying the outcome of a process you can’t see.
What it actually costs, in numbers you can check

Run the numbers the way they’d actually hit your agency. A TCPA violation carries statutory damages of $500 per violation, or up to $1,500 per violation if a court finds it willful, under 47 U.S.C. § 227(b)(3). That’s per call or text, not per lawsuit, and TCPA suits are routinely filed as class actions, which is how a single bad lead list can turn into a five- or six-figure exposure instead of a $500 nuisance. None of that requires you to have known the lead’s consent was fabricated. It requires only that you called or texted someone who, it turns out, never actually agreed to hear from you — and the vendor’s representation to you at the point of sale isn’t a defense in that lawsuit, even if it might give you a separate claim against the vendor afterward.
TCPA lawsuits filed in federal court, 2024 vs. 2025
Filings tracked monthly by WebRecon across all industries; insurance lead-buying is a recurring driver of this docket.
Source: WebRecon, December 2025 litigation statistics and year in review. The 2025 figure is exact; the 2024 figure is derived from WebRecon's reported +0.8% year-over-year change.
Then there’s the cost that never shows up in a lawsuit at all: wasted spend on leads that were never real prospects in the first place. A lead captured through a deceptive “$1 a day” promise isn’t shopping for what you sell — they’re responding to a claim your actual plan can’t match, and the conversation starts from a place of mismatched expectations before you’ve said a word. That cost doesn’t have a court record attached to it, which is exactly why it’s easy to keep paying it indefinitely without noticing.
A "TCPA compliant" checkbox in a spreadadsheet tells you the vendor typed that phrase. It doesn't tell you what the person actually agreed to, or how many other buyers got the same lead.
Mike MooreThe rule you’ve heard is dead, and the one that’s still very much alive
Two different “one-to-one consent” rules get confused constantly in this industry, and the confusion is exactly what makes agents let their guard down at the wrong moment.
The FCC’s version is dead. In late 2023, the FCC adopted a TCPA rule that would have required a separate consent per seller — one consent, one company — rather than a single blanket consent covering multiple unrelated telemarketers. The Eleventh Circuit vacated that rule in Insurance Marketing Coalition Limited v. FCC, No. 24-10277, decided January 24, 2025, ruling the FCC exceeded its statutory authority. It never took effect. Our companion piece, TCPA Rules for Insurance Agents in 2026, walks through that ruling and what’s still live under the general TCPA in detail.
CMS’s version is not dead — it’s a completely separate rule, and it’s in force right now. In the Contract Year 2025 Medicare Advantage and Part D Final Rule (CMS-4205-F), finalized April 4, 2024, CMS codified its own requirement: personal beneficiary data collected by a TPMO for marketing or enrolling someone in a Medicare Advantage or Part D plan may only be shared with another TPMO when the individual gave prior express written consent, through “a transparent, and prominently placed, disclosure,” separately for each TPMO that receives the data — CMS’s own regulatory version of one-to-one consent (CMS, CY2025 MA/Part D Final Rule fact sheet). That requirement applies beginning with the Fall 2024 Annual Enrollment Period, covering CY2025 and future contract years. It has nothing to do with the FCC’s vacated rule and was never touched by that court decision.
| Rule | Who it governs | Current status |
|---|---|---|
| FCC's TCPA one-to-one consent rule | Any TCPA robocall or robotext, all industries | Vacated, Jan. 24, 2025 — never took effect |
| CMS's TPMO one-to-one consent rule | TPMOs sharing Medicare beneficiary data with each other | In force since Fall 2024 AEP — finalized April 4, 2024 |
Practically, if you buy Medicare leads from a vendor who acquired that data from a second company, and that second company’s consent covered only itself, the transfer to your vendor and then to you needed its own, separate written consent under the CMS rule. A vendor who tells you “one-to-one consent doesn’t apply anymore” isn’t lying about the FCC’s rule. They may be quietly wrong about CMS’s, which is the one that actually governs how your Medicare leads got to you in the first place.
TPMO status isn't optional for you either
CMS defines a TPMO broadly enough to include independent agents and brokers who are compensated to perform lead generation, marketing, or enrollment-related functions in the chain leading to a Medicare enrollment. Buying and working a lead puts you inside that definition. The obligations described in this section don't stop at the vendor who sold you the data — they follow the lead into your own hands.
How to vet a lead vendor, done completely, before you spend a dollar
This is the part we’re not holding back. Four questions, run before you buy, catch most of what the FTC’s complaint against MediaAlpha described. None of it requires software or a membership.
Ask for the exact consent language, and read the page it ran on
Don't accept "TCPA compliant" as an answer. Ask the vendor to show you the actual disclosure text and, if it's a digital lead, the landing page it appeared on. Read it the way a regulator would: is the consent language prominent, or buried under an unrelated offer? Does the page itself make a claim, like guaranteed low pricing, your plan can't actually match? A vendor unwilling to show you the page is telling you something on its own.
Ask whether they use a third-party consent certificate, and get it with every lead
Services like TrustedForm (from ActiveProspect) and Jornaya generate an independent, timestamped record of a consent event — what the consumer saw, when, and what they clicked — separate from the vendor's own claim. A vendor already using one of these will hand you the certificate without hesitation. It's a genuine piece of evidence if a lead's consent is ever challenged, not just a compliance talking point.
Ask whether the lead was sold exclusively to you or shared
A "shared" or "aggregator" lead was sold to multiple buyers off the same consent event, which means the person is about to hear from several companies who each believe they're the only one calling. That's not automatically a compliance problem, but it is a quality and cost problem worth knowing about before you pay the same price as an exclusive lead.
Check the vendor's own enforcement history before you check anything else
Search the vendor's company name against the FTC's legal library (ftc.gov/legal-library), your state Department of Insurance's enforcement actions, and your state attorney general's press releases. This takes ten minutes and it's the single highest-value step on this list — a company already named in an enforcement action has told you, in public record, exactly how it operates.
Run this before AEP, not during it
The 2026 Annual Enrollment Period runs October 15 through December 7, 2026 (CMS, Medicare Open Enrollment partner resources) — the highest-volume lead-buying window of the year for Medicare agents. Vetting a vendor in the middle of AEP, once you're already committed to a spend plan and a call schedule, is the wrong time to find out their consent chain doesn't hold up. Run these four questions in September, before the budget is already spent.
For Medicare-specific leads, add one more check, because CMS layers its own requirement on top of the general TCPA picture: confirm in writing that any beneficiary data your vendor is passing to you was collected with prior express written consent naming your organization specifically, not a blanket consent that covered some other TPMO earlier in the chain. That’s the CMS one-to-one rule from the section above, applied at the point of purchase.
What to do once a purchased lead is already sitting in your CRM
Vetting the vendor up front is the real fix. But leads you’ve already bought, from vendors you vetted imperfectly or not at all, are still sitting in your system, and a few habits limit the downside without requiring you to throw the list out.
Keep a dated record of where every batch of leads came from and what the vendor represented about consent at the time of purchase — an email or a saved page is enough. If a complaint or a lawsuit ever surfaces, that record is the difference between “we relied on a specific written representation from our vendor” and having nothing at all. Before you call or text anyone from a purchased batch, especially a large one bought quickly ahead of AEP, spot-check a handful of records against what you’d expect a real, engaged prospect to look like: a working phone number, a name that matches public records, a timestamp that lines up with when you were told the lead was generated. And treat any purchased list the same way you’d treat a carrier statement full of real client data: it’s full of personal information about real people, and it deserves the same handling discipline, not less, just because you paid for it in bulk.
Where Ambrose actually fits, and where it honestly doesn’t
Ambrose OS, the platform included with a Tech Savvy membership, is not a tool that verifies a vendor’s consent chain for you, and this article isn’t going to claim it is. What it does have, per its own documentation, is a genuine alternative for part of the problem, and a genuine safety rail for another part.
The alternative is the lead-hunter spoke. Per Ambrose’s own docs, it runs three tools — hunter_gmaps_scrape for pulling prospect information from Google Maps business listings, hunter_email_guess for generating likely work email addresses from a name and a domain, and hunter_verify for confirming a candidate email is actually deliverable — and it’s built to be “HIPAA-free,” operating exclusively on public business data with no client or consumer PHI ever crossing the wire (Ambrose docs, spoke-lead-hunter, fetched August 2026). That scope is deliberately narrow, and it’s worth being precise about what it does and doesn’t replace: it’s not a way to source consumer Medicare or ACA leads instead of buying them. It’s a way to build your own first-party pipeline for local business outreach — small-group and voluntary benefits prospecting, business owners you’d partner with for final expense or Med Supp referrals — where you’re finding the business yourself instead of trusting a vendor’s consent chain for that part of your book.
| Part of the problem | What actually addresses it |
|---|---|
| Verifying a vendor's consent chain before you buy | The four-question manual check above — no tool replaces this |
| Reducing reliance on vendor-sourced consumer leads for B2B/group prospecting | Ambrose's lead-hunter spoke — public business data only |
| Handling a purchased lead file safely once AI tools touch it | Ambrose's phi-gateway spoke and the PHI Rail |
The safety rail is the phi-gateway spoke. Per Ambrose’s documentation, it scrubs protected health information from any payload headed to a non-BAA destination using a layered detection approach, matching against your own vault contacts, regex patterns, Presidio named-entity recognition, and insurance-specific term detection, and it can re-hydrate the real values afterward through a locally stored encrypted vault for destinations that are covered by a BAA (Ambrose docs, spoke-phi-gateway, fetched August 2026). If you’re using any AI tool to clean, dedupe, or summarize a purchased lead list, and that list has anything tying a name to a Medicare or health condition detail, this is the layer that keeps that detail from leaving your control by accident. It’s the same PHI Rail architecture we cover in our guide to insurance commission reconciliation, applied here to lead data instead of commission statements.
What you get by joining
One Ambrose seat, including the lead-hunter and phi-gateway spokes, comes with a Tech Savvy Insurance membership: $97 a month, billed monthly, cancel anytime, founding rate locked in while the membership stays active. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, 30+ hours of recorded training, Meta Ads, AI, and marketing training built specifically for this industry, pre-built AI templates and bot deployments, and a free annual in-person member workshop. It’s also an explicit no-recruiting zone — you can ask a real question about a lead vendor that’s making you nervous without ending up on someone’s downline pitch list, which is a genuine point of difference from most agent Facebook groups.
Ambrose usage runs separately from the $97 seat
The membership includes one Ambrose seat; usage inside Ambrose runs through its own credit ledger with spend caps, so cost stays visible instead of showing up as a surprise line item. See the full Spokes catalog for what else is available beyond lead-hunter and phi-gateway.
Compliance: what this touches, and what it doesn’t
If any lead you buy is used to market or enroll someone in a Medicare Advantage or Part D plan, you are operating inside CMS’s TPMO framework whether or not you think of yourself that way. That includes the TPMO disclaimer requirement: when you don’t represent every plan available in a beneficiary’s service area, CMS’s Medicare Communications and Marketing Guidelines require a disclosure along the lines of “we do not offer every plan available in your area,” naming how many organizations and plans you do represent, and directing the consumer to Medicare.gov, 1-800-MEDICARE, or their state’s SHIP for the full picture, across websites, ads, call scripts, and marketing emails (CMS, Medicare Communications and Marketing Guidelines; PSM Brokerage’s Feb. 25, 2026 compliance summary, citing MCMG Section 50.1). This is separate from, and in addition to, the one-to-one consent requirement for TPMO-to-TPMO data transfers covered above.
If you’re using AI tools anywhere in your lead-vetting or lead-management workflow, whether that’s summarizing a vendor’s terms, cleaning a lead file, or drafting outreach, the NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted December 2023, sets the expectation regulators increasingly apply: a written policy on how the tool is used, human oversight before anyone acts on its output, documentation you can produce if asked, and accountability that follows through to any vendor whose AI tool you rely on (NAIC, Insurance Topics: Artificial Intelligence). Ambrose is HIPAA-aware by default, not HIPAA certified — there’s no such thing as HIPAA certification for a software platform, and any vendor claiming otherwise is a red flag worth noting the same way you’d note one in a lead vendor’s pitch.
The close
The four-question check, consent language, a consent certificate, exclusivity, enforcement history, works whether you ever join anything or not. Run it on every vendor you’re considering before AEP spend ramps up this fall, and you’ll catch most of what the FTC’s complaint against MediaAlpha described, before it’s your name on a lead file instead of theirs. If you’d rather build the B2B slice of your pipeline yourself, with Ambrose’s lead-hunter spoke doing the public-data prospecting and phi-gateway keeping anything sensitive out of the wrong hands, one seat comes with a Tech Savvy membership, and the weekly build-with-you calls are where agents actually set this up on their own book: https://techsavvyinsurance.com/.
Before you rely on any figure in this article
Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. You are responsible for your own licensure and for complying with all applicable CMS, FTC, TCPA, HIPAA, state, and carrier regulations, including your state's telemarketing and TPMO rules. Regulations, settlements, and vendor practices can change — confirm current requirements directly with CMS, your state Department of Insurance, or qualified legal counsel before relying on any figure here. AI-generated outputs may contain errors — always verify. Results may vary.
Frequently asked questions
Sources
- FTC — Assurance IQ and MediaAlpha to Pay a Total of $145 Million to Settle FTC Charges (press release, Aug. 7, 2025) — ftc.gov
- FTC Business Blog — If you're deceiving consumers, the FTC means business: exploring the recent settlement with MediaAlpha (Aug. 2025) — ftc.gov
- CMS — Contract Year 2025 Medicare Advantage and Part D Final Rule (CMS-4205-F) fact sheet — cms.gov
- CMS — Medicare Communications and Marketing Guidelines (guidance document index) — cms.gov
- PSM Brokerage — TPMO Disclaimer Requirements for Insurance Agents (updated Feb. 25, 2026) — psmbrokerage.com
- ActiveProspect — Consent for TPMOs: CMS Medicare issues new rules — activeprospect.com
- WebRecon — December 2025 litigation statistics and year in review — webrecon.com
- Cornell Law School, Legal Information Institute — 47 U.S.C. § 227 — law.cornell.edu
- Insurance Marketing Coalition Limited v. FCC, No. 24-10277 (11th Cir., decided Jan. 24, 2025) — media.ca11.uscourts.gov
- NAIC — Insurance Topics: Artificial Intelligence (Model Bulletin background) — content.naic.org
- CMS — Medicare Open Enrollment partner resources (2026 AEP dates) — cms.gov
- Ambrose docs — spoke-lead-hunter — app.hiambrose.com
- Ambrose docs — spoke-phi-gateway — app.hiambrose.com
- Ambrose docs — What is Ambrose — app.hiambrose.com
- Ambrose docs — Spokes (catalog) — app.hiambrose.com
Ready to put this into practice?
Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.
Join Tech Savvy — $97/month