Broker’s Broker
Compliance Toolkit
Check this before you market, call, text, or email a prospect. Search below or browse by topic.
Scope of Appointment (SOA) Medicare
Required before most individual, one-on-one Medicare Advantage or Part D sales meetings.
What it is
A Scope of Appointment (SOA) is a documented agreement between an agent and a Medicare-eligible consumer that specifies which Medicare product types (e.g., Medicare Advantage, Part D prescription drug plans, Medicare Supplement) will be discussed during a scheduled one-on-one sales appointment. It exists to prevent agents from steering a conversation into products the consumer didn’t agree to discuss, and to create a paper trail of consumer consent.
When it’s required
- Before any individual (one-on-one) marketing/sales appointment (in person, by phone, or via video) that will discuss Medicare Advantage or Medicare Part D plans.
- Generally expected to be collected in advance of the appointment (commonly cited as at least 48 hours prior when practical), with limited exceptions for walk-ins or unscheduled same-day meetings where a documented in-person SOA may be completed immediately before the discussion begins.
- Not typically required for pure Medicare Supplement (Medigap)-only conversations or for public/formal marketing events where no individual sales presentation occurs. Confirm this against current-year rules and your specific carrier’s requirements, since carrier policies are sometimes stricter than the baseline regulatory requirement.
How to properly document one
- Use a compliant SOA form (paper, electronic signature, or recorded verbal SOA via a compliant recorded phone process). Never rely on a verbal, undocumented “yes.”
- Capture the consumer’s name, the product types they’ve agreed to discuss, and the date the SOA was obtained. This must be dated before the appointment, not backfilled afterward.
- If the appointment expands to a product type not originally listed (e.g., the consumer asks about a product type mid-meeting that wasn’t on the original SOA), a new/updated SOA covering that product type generally must be completed before discussing it, often on a subsequent day for in-person, or immediately if using a compliant recorded process.
- Retain the completed SOA in the consumer’s file for the retention period required by CMS and your carrier (commonly cited as a multi-year retention window; confirm the exact current requirement).
- Never pre-check or pre-select product types on behalf of the consumer. The consumer (or their authorized representative) must indicate their own choices.
Sample SOA Form: Field Checklist
Carrier portals and CRM/SOA tools you use through Broker’s Broker or your upline may generate a compliant SOA automatically. When in doubt, use the carrier’s official SOA tool rather than a homemade form.
Call Recording & Retention
Medicare sales calls generally must be recorded in their entirety and retained.
The general rule (conceptual; confirm current CMS requirement)
Telephonic marketing and sales calls with Medicare-eligible consumers (including calls that lead to enrollment in a Medicare Advantage or Part D plan) are generally expected to be recorded in their entirety, from greeting through disposition, when conducted by or on behalf of a carrier or its downstream agents/agencies. This is intended to protect consumers from misrepresentation and to give carriers/CMS an audit trail.
- Recording generally applies to the full call, not just the enrollment portion. Partial recordings are typically not considered compliant.
- Retention periods are commonly cited in multi-year terms (many carriers require 10 years, consistent with typical CMS recordkeeping expectations); verify the exact current-year retention requirement with each carrier, since this can vary by contract.
- Recordings and documentation must generally be retrievable on request (by the carrier or CMS) within a short turnaround window.
- Some carriers require use of their approved dialer/recording platform rather than a personal phone or unapproved app. Using non-approved tools to conduct Medicare sales calls is a common compliance violation.
What must typically be said at the start of the call
Opening call disclosures (general pattern; confirm carrier script)
Marketing Do’s and Don’ts
Channel-by-channel guidance for phone, text, email, and social media outreach to Medicare-eligible and ACA prospects.
✔ Do
- Confirm you have a valid SOA before an individual MA/Part D sales conversation.
- Use carrier-approved dialers/recording tools for Medicare calls.
- Identify yourself, your agency, and the purpose of the call at the outset.
- Honor “do not call” and opt-out requests immediately and document them.
✘ Don’t
- Don’t cold-call Medicare beneficiaries who have not given permission to be contacted (unsolicited outbound MA/Part D calls are generally prohibited).
- Don’t discuss product types outside the scope agreed to in the SOA.
- Don’t use scare tactics, high-pressure closes, or misleading claims about government affiliation.
✔ Do
- Obtain clear, documented prior express written consent before texting marketing content, including the specific phone number and consent date.
- Include a simple opt-out method (e.g., “Reply STOP to unsubscribe”) in every message.
- Keep a record of consent capture (source, timestamp, opt-in language shown).
✘ Don’t
- Don’t text marketing messages to numbers scraped from public sources or purchased lists without documented consent.
- Don’t use autodialed/automated texting platforms without confirming TCPA-compliant consent is on file for each recipient.
- Don’t ignore STOP requests or continue texting after an opt-out.
✔ Do
- Include a working unsubscribe link and honor requests promptly (CAN-SPAM expects this within a short window, commonly cited as 10 business days).
- Use accurate “From” names/addresses and non-deceptive subject lines.
- Include your agency’s physical mailing address in marketing emails.
✘ Don’t
- Don’t use deceptive subject lines implying the email is from Medicare, the government, or a consumer’s current carrier.
- Don’t send marketing email to purchased/harvested lists without a lawful basis and proper disclosures.
- Don’t use unapproved marketing copy. Run new email templates through your agency/carrier compliance review first.
✔ Do
- Use only carrier-approved or agency-approved marketing materials and images.
- Clearly identify yourself as a licensed insurance agent, not a government entity.
- Route inquiries generated through social ads into a compliant intake/SOA process before any individual sales discussion.
✘ Don’t
- Don’t post unapproved comparisons, guarantees, or superlative claims (“best plan,” “guaranteed savings”) without substantiation and compliance sign-off.
- Don’t use CMS, Medicare, or federal government logos/imagery in a way that implies endorsement.
- Don’t collect personal or health information through social media comments/DMs as a substitute for a compliant lead form.
TCPA Basics for Outbound Calling & Texting
The Telephone Consumer Protection Act governs how you can call or text prospects who haven’t asked to hear from you.
Consent requirements
- Calls or texts made using an autodialer or prerecorded/artificial voice generally require prior express written consent from the consumer. A simple verbal “yes” is usually not sufficient for autodialed/text marketing.
- Consent should be specific: it should reference the phone number, the type of communications (calls and/or texts), and ideally the agent/agency or lead source.
- Consent obtained through a third-party lead vendor should be documented and traceable: keep records of the lead source, the consent language the consumer saw, and the timestamp.
- Consent can generally be revoked by the consumer at any time, through any reasonable method (a text reply, verbal statement on a call, email, etc.). Once revoked, stop contacting that number for marketing purposes.
Do-Not-Call list awareness
- Check outbound call/text lists against the National Do Not Call (DNC) Registry and maintain your own internal do-not-call list of consumers who have opted out directly.
- Being an “established business relationship” with a consumer may create limited exceptions under some rules, but exceptions are narrow, time-limited, and don’t override a consumer’s direct opt-out request. Don’t rely on this without compliance confirmation.
- State-level mini-TCPA and do-not-call laws can be stricter than federal rules. Confirm requirements in every state where you solicit business.
- Violations of TCPA can carry statutory damages per call/text and are frequently the subject of class action litigation. This is a high-risk area to get wrong.