Rules

What can plans and practices send under TCPA and CMS Medicare Advantage rules?

Medicare Advantage outreach rules split into two layers: CMS marketing rules that govern what plans may send, and TCPA consent that governs how they may send it.

What to take away

  • Medicare Advantage outreach rules come from two places: the CMS Medicare Communications and Marketing Guidelines and the TCPA, and both apply to the same text message.
  • Plans must file marketing materials with CMS before distribution, and the filing clock starts before the first text, not after.
  • TCPA prior express written consent must name the sender, cover autodialed or prerecorded calls and texts, and include a clear opt-out.
  • Call recording rules depend on state consent law, so a single national script will fail in two-party consent states.
  • Vendors touching member data need a BAA, and plans remain liable for what those vendors send.
  • Keep dated consent records, filed material IDs, call recordings, and opt-out logs for CMS and TCPA review.

The CMS Medicare Communications and Marketing Guidelines in plain terms

CMS splits everything a plan says to a member into two buckets: communications and marketing. Communications cover plan operations, like a formulary change or a provider termination notice. Marketing covers anything meant to draw a beneficiary toward a plan or a supplemental product. The bucket decides the review path, the filing requirement, and the disclaimers.

The Managed Care Marketing | CMS page is the anchor for these rules and links to the current guidance. It applies to Medicare Advantage, Medicare Advantage Prescription Drug plans, stand-alone Part D, and Medicaid managed care. If your outreach touches any of those products, the guidelines apply.

Several words are effectively banned in marketing material. CMS prohibits the use of "free," "no cost," and similar phrasing unless the benefit is truly without condition. It also bars claims that a plan is endorsed by Medicare or by the federal government. Those restrictions apply to texts, scripts, direct mail, and social posts.

Marketing material also has to carry required disclaimers, including the plan name and a statement that the plan contracts with Medicare. The disclaimer cannot be buried in a link or a landing page.

For a text message, that means the message itself has to carry the required elements or the recipient has to be able to reach them without a login.

CMS updates the guidelines through transmittals and sub-regulatory guidance, not only through formal rulemaking. The Transmittals | CMS library is where operational changes appear first. A plan that only reads the annual rule can miss a mid-year change to call scripts or disclaimers.

For anyone running senior outreach across several product lines, a single healthcare marketing compliance guide that maps CMS, TCPA, and HIPAA together saves repeated legal review. The rules overlap, and a message that passes one test can fail another.

Communications versus marketing: a quick table

Element Communications Marketing
Purpose Plan operations, benefits administration Draw a beneficiary to enroll or stay
Filing with CMS Generally not filed Filed before distribution
Disclaimers Limited Required, including plan name and Medicare contract statement
Language limits Few No "free" or "no cost" unless unconditional
Example Annual notice of change Enrollment text with a call to action

What plans must file before a single text goes out

Materials filing before send is the rule most often missed by lean marketing teams. CMS requires plans to submit marketing materials to the appropriate CMS regional office or through the Health Plan Management System before the material is used. The review window is not a formality; distribution before filing is a compliance finding.

The filing package includes the material itself, the intended audience, the distribution channel, and the dates it will run. Text messages count. So do scripts used by agents and call centers, because a script is a marketing material when it pitches a plan.

CMS reviews filed material for required elements, prohibited terms, and accuracy. If a plan changes a message after filing, the change may need a new filing. A minor edit to a text message can turn a cleared material into an unfiled one.

Steps to file and send without gaps:

  1. Classify the message as communications or marketing and document the reason.
  2. Build the material with required disclaimers and approved language.
  3. Submit to CMS through the plan's filing channel and log the submission date.
  4. Wait for the review outcome or the applicable review period before release.
  5. Send only the filed version, and refile if the copy changes.

Federal Register notices are where larger changes to marketing rules surface before they bind. The Federal Register :: Money topic collects CMS payment and program notices, and plan compliance teams watch it for marketing rule changes that affect filing timelines.

A practical casl healthcare email marketing compliance checklist helps here. It forces the filing date, the material ID, and the reviewer name into one record, which is exactly what CMS asks for during an audit.

TCPA consent: prior express written consent and its limits

TCPA prior express written consent is a higher bar than most plans assume. It applies to autodialed calls, prerecorded calls, and text messages sent with an autodialer to cell phones. A signature, electronic or written, plus clear disclosure of the sender and the opt-out, is the core of it.

The consent has to identify the entity that will call or text. A generic "our marketing partners" clause is not enough. It also has to state that the consumer is not required to consent as a condition of any purchase, and that consent can be revoked at any time.

The Stop Unwanted Robocalls and Texts | Federal Communications Commission page lays out the federal baseline. The FCC treats a text message as a call for TCPA purposes, so the same consent standard applies to SMS and MMS.

Consent obtained for one plan does not automatically cover another. A beneficiary who agreed to hear from a Medicare Advantage plan has not agreed to hear from a dental supplemental product or a third-party agency. Each sender needs its own consent, or the consent language has to name all of them.

Business-to-business exemptions do not rescue member outreach. Beneficiaries are consumers, and the calls and texts go to personal cell phones. There is no B2B carve-out for a text to a member's mobile number.

Consent also has a shelf life in practice. The TCPA does not set a fixed expiration, but the FTC and courts look at whether the consent is still reasonable given the time passed and the relationship. A consent collected three years ago for a different plan year invites a challenge.

The consent and opt-out rules for patient texting overlap with these TCPA standards, and the two should be documented in one place. A single consent record that satisfies both is easier to defend than two partial ones.

Call recording rules and two-party consent states

Call recording requirements are a state law problem layered on top of federal rules. Federal law allows one-party consent, meaning the person recording can consent for everyone. Several states require all parties to consent, and those states include California, Illinois, Massachusetts, and Washington.

That list matters for plans with national dialing. A call center in Texas recording a member in California has to meet California's two-party standard, not Texas's one-party rule. The strictest state on the line usually controls.

The same logic applies to a plan that records every call by default. A default recording practice that is lawful in Florida can be unlawful in Illinois. Connecticut, Pennsylvania, and Nevada have also been treated as all-party states in various contexts, so the map is not stable.

Practical controls for a national program:

  1. Determine the member's state from the dialing record before the call connects.
  2. Play a recorded disclosure at the start of the call that names the plan and states the call is recorded.
  3. Require an affirmative response before recording begins, or stop recording if the member objects.
  4. Log the disclosure, the response, and the timestamp.
  5. Store recordings under the same retention schedule as consent records.

For teams comparing tools, call tracking systems vary widely in whether they capture the disclosure and the response in the same record. A system that records audio but not consent gives you half a defense.

State privacy laws add a second layer. California's CMIA and Washington's My Health My Data Act reach health information that HIPAA may not cover, and both have consent and notice requirements that touch recorded calls about benefits or conditions.

Quiet hours, opt-outs, and revocation handling

Quiet hours under the TCPA restrict calls to between 8 a.m. and 9 p.m. in the recipient's time zone. Texts are treated like calls, so a text at 6 a.m. Pacific to a member in California violates the window even if the sender is on Eastern time.

Plans get this wrong when they batch sends by campaign rather than by time zone. A single national send at 9 a.m. Eastern reaches California members at 6 a.m. The fix is to schedule by recipient time zone, not by headquarters time.

Opt-out rules require a clear and conspicuous way to stop messages. For texts, "reply STOP" is the standard, and the plan must honor it promptly. CMS also requires that marketing material tell beneficiaries how to opt out of future marketing.

Revocation handling is broader than the word STOP. A member who says "stop texting me" in a reply, or tells an agent on a call, has revoked consent. The revocation has to flow to every system that can send a message, including vendor platforms.

A practical workflow:

  1. Capture opt-outs from every channel: SMS reply, call, email, and in-person request.
  2. Push the opt-out to a central suppression list within one business day.
  3. Sync the suppression list to every vendor and dialer before the next campaign.
  4. Confirm the opt-out to the member where the channel allows it.
  5. Retain the opt-out record with a timestamp.

An opt-out that lives only in the texting platform is a finding waiting to happen. If the call center does not see it, the next campaign will call a member who already said stop.

Where CMS rules are stricter than the TCPA floor

The TCPA sets a floor. CMS rules often sit above it. Consent that satisfies the TCPA may still fail CMS requirements for marketing to Medicare beneficiaries.

CMS restricts unsolicited contact with beneficiaries more tightly than the TCPA does. It limits when plans may call, what agents may say, and how they may use the Medicare name. A call that is legal under the TCPA can still be a CMS marketing violation.

CMS also requires that marketing materials be filed, which the TCPA does not. And CMS requires specific disclaimers that have no TCPA equivalent. A text can have perfect consent and still fail CMS.

Enrollment-related outreach faces additional timing rules. CMS limits contact around the Annual Enrollment Period and the Open Enrollment Period, and it restricts the use of certain events and prizes. These are marketing rules, not consent rules, and they apply regardless of what the member agreed to.

The two regimes also differ on who is liable. Under the TCPA, the sender and the party on whose behalf the message is sent can both be liable. Under CMS, the plan is responsible for the conduct of its agents and downstream vendors.

For teams that track recurring issues, the hipaa compliant patient texting questions that surface most often are about this gap. People assume TCPA consent covers CMS, and it does not.

Vendor and BAA obligations for plan outreach

BAA obligations for plan vendors follow from HIPAA. Any vendor that creates, receives, maintains, or transmits protected health information on behalf of a plan or practice needs a Business Associate Agreement. That includes texting platforms, call centers, analytics tools, and CRM providers.

A BAA is not a substitute for TCPA consent. It governs the handling of health information, not the permission to contact. A vendor with a signed BAA can still send a text the plan had no consent to send.

Vendors that send on the plan's behalf also inherit CMS filing obligations in practice. If a vendor writes the script or the text copy, that copy is marketing material and has to be filed before use. The plan cannot outsource the filing duty.

Contract terms to check:

  • The BAA covers the specific data the vendor touches.
  • The vendor agrees to follow CMS filing and disclaimer rules.
  • The vendor maintains consent records and provides them on request.
  • The vendor honors opt-outs across all its platforms.
  • The vendor permits plan audits and retains records for the required period.
  • The vendor discloses subcontractors that handle member data.
  • The contract states who is responsible for TCPA compliance.

Subcontractors matter. A texting vendor that routes messages through a third-party aggregator has created another party that touches the data. The plan's BAA chain has to reach that party, or the plan carries the risk.

The FTC also watches health product claims, and its Health Products Compliance Guidance applies to any plan or practice marketing a health-related product. A claim about a benefit or a health outcome has to be supported, whether it appears in a text, a call script, or a landing page.

Audit trails plans should keep for CMS review

An audit trail is the difference between a plan that can prove compliance and one that can only assert it. CMS reviews look for dated records, not recollections.

Keep the filed material and the CMS submission record together. The record should show what was filed, when, and what version was approved. If the copy changed, keep both versions and the refiling.

Keep consent records with the exact language the member agreed to. A screenshot of the consent form, the timestamp, the IP address, and the source page are the standard package. For paper consent, keep the signed form.

Keep call recordings and the disclosure log. The recording shows what was said; the log shows that the recording was permitted. In a two-party consent state, the log is the defense.

Keep opt-out records with timestamps and the channel used. If a member opted out by replying STOP, the platform log should show the reply and the suppression action.

Keep vendor BAAs and the vendor's consent and opt-out reports. If CMS asks how a vendor handled member data, the plan needs the vendor's records, not just its own.

Retention periods vary by record type and by state. A general rule is to keep marketing, consent, and opt-out records for at least the period CMS can review, plus the state statute of limitations for TCPA claims. When in doubt, keep longer.

Common questions

Does TCPA consent cover CMS marketing rules? No. TCPA consent governs permission to contact. CMS rules govern what the contact may say, when it may happen, and whether it was filed. A message can have valid consent and still violate CMS marketing rules.

Can a plan text a member without prior express written consent? For autodialed or prerecorded marketing texts, no. The TCPA requires prior express written consent for marketing calls and texts to cell phones. A plan that texts without it risks statutory damages per message.

Do we need to file every text message with CMS? Marketing texts must be filed before distribution. Operational communications generally do not need filing. The classification depends on the purpose and the call to action, so document the reason for each message.

Can we record calls to members in California and Illinois? Only with all-party consent. California, Illinois, Massachusetts, and Washington require every party on the call to agree. Play a disclosure and get an affirmative response before recording, or do not record.

What happens if a member replies STOP? The plan must stop marketing texts to that number and suppress it across every system and vendor. The opt-out should be logged with a timestamp and shared with any platform that can send a message.

Who is liable if a vendor sends the text? The plan and the vendor can both be liable under the TCPA, and CMS holds the plan responsible for its vendors. A BAA and a contract clause do not shift CMS liability away from the plan.

More in Rules

Rules

What does a HIPAA business associate agreement cover for a US healthcare marketing agency?

A HIPAA business associate agreement binds your marketing agency to specific clauses, breach timelines, and PHI safeguards. Here is what to check.

Rules

HIPAA and patient outreach, what appointment reminders and review requests can say

HIPAA patient outreach rules: what appointment reminders and review requests can say under the Privacy Rule, and when marketing authorization is required.

Rules

How California, Washington, and Florida differ on patient consent for outreach texts

Patient consent rules by state diverge sharply: California CMIA, Washington My Health My Data, and Florida statutes each add duties beyond the TCPA federal floor.

Latest from Guides Desk

Operations

Cross-border patient outreach, serving Canadian patients at US hospitals

Cross-border patient outreach for Canadian patients at US hospitals: PHIPA and PIPEDA differences, insurance verification, referral letters, consent.

Operations

How US hospitals run multilingual patient outreach under Section 1557

Multilingual patient outreach under Section 1557: what OCR taglines, notices, CMS rules and Miami, LA and Houston staffing really require of hospitals.