Compliance Guide
A reference guide for ContractorBridge agents covering CMS, TCPA, HIPAA, data privacy, and state insurance regulatory requirements.
Last Updated: June 26, 2026 · This guide is for informational purposes only and does not constitute legal advice.
Important: This guide is a general reference only. Regulatory requirements change frequently. Agents are solely responsible for maintaining their own compliance. ContractorBridge strongly recommends consulting a licensed compliance attorney or your carrier's compliance department for guidance specific to your situation.
CMS Compliance
Centers for Medicare & Medicaid Services regulations govern how agents market, sell, and enroll beneficiaries in Medicare Advantage and Part D plans.
Key Requirements
- Annual AHIP or carrier-equivalent certification
- Scope of Appointment (SOA) documentation for all Medicare sales meetings
- Prohibition on unsolicited contact with Medicare beneficiaries
- Adherence to CMS marketing guidelines and approved materials
- Recording of sales calls where required by carrier
- 10-year record retention for Medicare-related transactions
- Compliance with the Medicare Communications and Marketing Guidelines (MCMG)
TCPA Compliance
The Telephone Consumer Protection Act restricts telemarketing calls, auto-dialed calls, prerecorded messages, and text messages.
Key Requirements
- Written prior express consent required before auto-dialed or prerecorded calls
- Maintain and honor Do-Not-Call (DNC) lists — federal and state
- Identify yourself and your company at the start of every call
- Provide opt-out mechanisms in all text message campaigns
- Time-of-day restrictions: calls permitted 8 AM–9 PM local time only
- Document consent records with timestamps and source
- FCC 2024 one-to-one consent rule compliance for lead generation
HIPAA Compliance
The Health Insurance Portability and Accountability Act protects the privacy and security of Protected Health Information (PHI).
Key Requirements
- Execute Business Associate Agreements (BAAs) where required
- Minimum necessary standard: access only the PHI needed for the task
- Safeguard PHI in all forms — electronic, paper, and verbal
- Report breaches of unsecured PHI within required timeframes
- Annual HIPAA training for all staff handling PHI
- Maintain written privacy and security policies
Data Privacy
State and federal data privacy laws govern how consumer data is collected, used, shared, and protected.
Key Requirements
- Provide clear privacy notices at or before point of data collection
- Honor consumer rights: access, correction, deletion, portability
- State-specific requirements: CCPA (California), SHIELD Act (New York), and others
- Data minimization: collect only what is necessary
- Vendor due diligence: ensure third-party data processors maintain adequate protections
- Incident response plan for data breaches with state notification timelines
State Insurance Regulations
Each state department of insurance imposes licensing, appointment, and conduct requirements on agents and agencies.
Key Requirements
- Maintain active license in every state where you solicit or sell
- Complete continuing education (CE) requirements by state deadline
- Carrier appointment required before soliciting in most states
- Errors & Omissions (E&O) insurance — minimum limits vary by state
- Prompt disclosure of material changes (address, criminal history, license actions)
- Anti-rebating and anti-twisting compliance
Get Your Free Compliance Review
When you contract through ContractorBridge, we include a complimentary compliance review covering CMS, TCPA, HIPAA, data privacy, and state-specific requirements.
Start Contracting — It's Free