Skip to main content
Compliance

Compliance Guide

A reference guide for ContractorBridge agents covering CMS, TCPA, HIPAA, data privacy, and state insurance regulatory requirements.

Last Updated: June 26, 2026 · This guide is for informational purposes only and does not constitute legal advice.

Important: This guide is a general reference only. Regulatory requirements change frequently. Agents are solely responsible for maintaining their own compliance. ContractorBridge strongly recommends consulting a licensed compliance attorney or your carrier's compliance department for guidance specific to your situation.

CMS Compliance

Centers for Medicare & Medicaid Services regulations govern how agents market, sell, and enroll beneficiaries in Medicare Advantage and Part D plans.

Key Requirements

  • Annual AHIP or carrier-equivalent certification
  • Scope of Appointment (SOA) documentation for all Medicare sales meetings
  • Prohibition on unsolicited contact with Medicare beneficiaries
  • Adherence to CMS marketing guidelines and approved materials
  • Recording of sales calls where required by carrier
  • 10-year record retention for Medicare-related transactions
  • Compliance with the Medicare Communications and Marketing Guidelines (MCMG)

TCPA Compliance

The Telephone Consumer Protection Act restricts telemarketing calls, auto-dialed calls, prerecorded messages, and text messages.

Key Requirements

  • Written prior express consent required before auto-dialed or prerecorded calls
  • Maintain and honor Do-Not-Call (DNC) lists — federal and state
  • Identify yourself and your company at the start of every call
  • Provide opt-out mechanisms in all text message campaigns
  • Time-of-day restrictions: calls permitted 8 AM–9 PM local time only
  • Document consent records with timestamps and source
  • FCC 2024 one-to-one consent rule compliance for lead generation

HIPAA Compliance

The Health Insurance Portability and Accountability Act protects the privacy and security of Protected Health Information (PHI).

Key Requirements

  • Execute Business Associate Agreements (BAAs) where required
  • Minimum necessary standard: access only the PHI needed for the task
  • Safeguard PHI in all forms — electronic, paper, and verbal
  • Report breaches of unsecured PHI within required timeframes
  • Annual HIPAA training for all staff handling PHI
  • Maintain written privacy and security policies

Data Privacy

State and federal data privacy laws govern how consumer data is collected, used, shared, and protected.

Key Requirements

  • Provide clear privacy notices at or before point of data collection
  • Honor consumer rights: access, correction, deletion, portability
  • State-specific requirements: CCPA (California), SHIELD Act (New York), and others
  • Data minimization: collect only what is necessary
  • Vendor due diligence: ensure third-party data processors maintain adequate protections
  • Incident response plan for data breaches with state notification timelines

State Insurance Regulations

Each state department of insurance imposes licensing, appointment, and conduct requirements on agents and agencies.

Key Requirements

  • Maintain active license in every state where you solicit or sell
  • Complete continuing education (CE) requirements by state deadline
  • Carrier appointment required before soliciting in most states
  • Errors & Omissions (E&O) insurance — minimum limits vary by state
  • Prompt disclosure of material changes (address, criminal history, license actions)
  • Anti-rebating and anti-twisting compliance

Get Your Free Compliance Review

When you contract through ContractorBridge, we include a complimentary compliance review covering CMS, TCPA, HIPAA, data privacy, and state-specific requirements.

Start Contracting — It's Free