Categories
Uncategorized

HIPAA and Your Medicare CRM: The Questions to Actually Ask

If you sell Medicare, you handle protected health information every working day — diagnoses, medications, providers. Most agents assume their CRM handles the HIPAA side. Here is how to check rather than assume.

What you are actually holding

A Medicare client record is not a sales contact. It contains, at minimum, the medications someone takes, the doctors they see, and frequently enough to infer what is wrong with them. Under HIPAA that is protected health information, and as a business associate handling it you carry obligations that do not disappear because you are a one-person agency.

The practical risk is not usually a hacker. It is a laptop in a car, a spreadsheet emailed to a personal address, a shared password, or a former assistant who still has access.

Five questions to ask your CRM vendor

1. Will you sign a Business Associate Agreement?

This is the first question and it is disqualifying. If a vendor storing PHI on your behalf will not sign a BAA, the conversation is over. Ask for it in writing before you migrate anything.

2. Which certifications do you actually hold, and who audits them?

“HIPAA compliant” is a claim anyone can print on a website. What you want are named attestations with an auditor behind them — SOC 2 Type 2 in particular, because Type 2 tests whether the controls actually operated over a period rather than existed on paper on one day.

Ask for the list. A vendor that takes this seriously will have a compliance page; ours is the Trust Center.

3. Is data encrypted at rest as well as in transit?

Nearly everyone encrypts in transit — that is just HTTPS. At rest is the one worth confirming, because that is what protects you when the failure is physical or internal.

4. What does access control look like?

Specifically: can you enforce multi-factor authentication, can you set permissions so a downline agent sees only their own book, and can you revoke access immediately when someone leaves? The last one is the one that catches agencies out.

5. What is the audit trail?

If someone asks who viewed a client record and when, can the system tell you? For a small agency this feels like overkill right up until the day you need it.

The questions to ask yourself

Vendor compliance does not make you compliant. The gaps are usually on the agent’s side:

  • Where does client data live outside the CRM? Spreadsheets on a desktop, PDFs in an email inbox, photos of forms on a phone. Every copy is a separate exposure and none of them are covered by your vendor’s certifications.
  • Who has access, and is that list current? Include former staff, VAs, and anyone who has ever used your login.
  • How do you send documents to clients? An unencrypted email attachment containing a medication list is a disclosure.
  • What happens if a device is lost? If the answer involves data stored locally rather than accessed through a browser, that is worth changing.
  • How long do you keep records, and where? Retention obligations do not end when a client leaves.

Why the platform underneath matters

An independent agency cannot fund an enterprise security programme — penetration testing, continuous monitoring, formal incident response, third-party audits. Nobody expects it to.

What you can do is put your data somewhere that already funds one. HowardCRM runs on the Salesforce platform, which means it inherits Salesforce’s security posture: bank-level encryption, multi-factor authentication, and a compliance programme covering HIPAA and SOC 2 Type 2 among a long list of others. That is not marketing language on our part; it is the reason the product was built on Salesforce rather than from scratch.

The practical version: the security question becomes “have I configured this properly” rather than “is this safe at all”.

A short self-audit

  • Do you have a signed BAA with every vendor touching client data?
  • Is MFA on for every user, without exception?
  • Is there any client PHI in a spreadsheet, an inbox or a phone right now?
  • Could you produce a list of everyone with access in five minutes?
  • Do you know what you would do in the first hour after a breach?

Most agents fail at least two of these. It is worth fixing the ones you fail before AEP, not during it.

See how HowardCRM handles this

Built on Salesforce, HIPAA and SOC 2 Type 2, with your book of business in one place instead of five. Read the full certification list on the Trust Center, or ask us the awkward questions directly.

Read the Trust Center
Book a walkthrough

This article is general guidance, not legal advice. Confirm your own obligations with a qualified compliance professional.

Categories
Uncategorized

AEP Prep Checklist for Medicare Agents: What to Do Before 15 October

AEP runs 15 October to 7 December. Marketing for the following plan year opens on 1 October. Which means the work that decides how your season goes is the work you do in the six weeks before any of that starts.

Six weeks out: clean the data

Everything downstream depends on this and almost nobody does it properly.

  • Phone numbers. Pull a list of every client with no mobile number or an obviously stale one. You cannot text an SOA to a number you do not have.
  • Email addresses. Same exercise. This is your cheapest channel in October.
  • Duplicate records. Households where the same person exists twice will cost you twice in October — two calls, two SOAs, one annoyed client.
  • Plan and effective dates. If your policy records are not current, every report you run in November is wrong.

If you cannot produce these lists from your system in a few minutes, that is itself the finding, and it is worth fixing before the season rather than during it.

Five weeks out: segment the book

You will not review everyone. Decide now who you are reviewing and in what order, rather than working alphabetically in November.

Segment Why it moves first
PDP clients on plans with premium or formulary changes Highest chance of a genuinely better option, highest chance of a complaint if you miss it
Clients on a plan being discontinued Non-optional. These people must be contacted.
MA clients with a provider network change The most common reason a happy client becomes an unhappy one
Clients with high prescription spend Where the dollar difference is largest, so where the review is most valued
Med Supp clients approaching a birthday-rule window Time-boxed opportunity that expires

The first two are obligations. The rest are where the season is won.

Four weeks out: fix the Scope of Appointment workflow

The fixed 48-hour SOA waiting period is being removed, with the new workflow beginning on 1 October — the same day marketing opens. Same-day appointments become possible, which changes what your calendar can hold.

That only helps if you can actually collect an SOA in minutes. Test it now: can you send one by text, get it signed, and have it filed against the client record without leaving your system? If not, this is the single highest-value thing to fix before October. We wrote about the change in more detail in this article.

Three weeks out: build the reports you will need

Build them now, while you have time to get them wrong. The ones you will reach for:

  • Every client on plan X (for when a carrier makes an announcement)
  • Whole PDP book, sorted by current premium
  • Med Supp book by birth month
  • Clients not yet contacted this season — the report you will live in from mid-November
  • Enrollments submitted, by status, so nothing sits unconfirmed

The last one matters more than agents expect. Applications that quietly fail to process are the most expensive thing that happens in December.

Two weeks out: the outreach sequence

Before 1 October you cannot market the next plan year, but you can:

  • Draft the emails and texts so they are ready to send on the first
  • Confirm your compliance language with each carrier
  • Set the appointment calendar and decide how many slots per day you can genuinely hold
  • Tell your existing clients when you will be in touch — a service message, not a marketing one

One week out: dry run

Take one client and run the entire process end to end: outreach, SOA, appointment, plan comparison with drug and provider lookup, enrollment, confirmation, record. Time it. Whatever it takes, multiply by the number of reviews you are planning and see whether the arithmetic works.

If it does not, you have a week to change something. In November you will not.

During AEP: one report a day

Pick one number and look at it every morning — usually “clients reviewed” against “clients to review”. Agents lose AEP by working hard on whoever calls rather than working through the list they built in September.

Going into AEP with a system that can answer questions

HowardCRM was built by a working agent for exactly this eight-week window: custom reporting across your whole book, SOA sent and stored in-system, drug and provider lookup where the client record is. $300 a year, 30-day free trial, and we load your data for you.

Book a walkthrough
See the features

Categories
Uncategorized

The 48-Hour Scope of Appointment Rule Is Going Away: What Changes on 1 October

The fixed 48-hour wait between recording a Scope of Appointment and holding the appointment is being removed. The regulation took effect on 1 June 2026 and the new marketing workflow operationally begins on 1 October 2026 — two weeks before AEP opens. Here is what it changes, and what it does not.

What the rule was

Under the rule as it has stood, an agent had to agree and record a beneficiary’s Scope of Appointment at least 48 hours before a scheduled personal marketing appointment. Two exceptions applied: SOAs completed during the last four days of a valid election period, and unscheduled in-person meetings initiated by the beneficiary — the walk-in exception.

In practice this meant an agent could not take a call on Tuesday morning and sit down with that person on Tuesday afternoon. It cost a lot of appointments, particularly during AEP when the calendar is the constraint.

What changes

The fixed waiting period is eliminated. From 1 October 2026, the Scope of Appointment must still be agreed and recorded with the beneficiary before the appointment, but with no mandated gap. Same-day is permitted, provided the SOA is complete before any plan-specific discussion begins.

For in-person personal marketing appointments, the SOA must be in writing.

What does not change

This is the part worth being careful about, because “the 48-hour rule is gone” is being repeated in a way that sounds like the SOA is gone. It is not.

  • The SOA is still mandatory. It must exist before you discuss specific plans — benefits, premiums, networks, formularies or enrollment options.
  • Written SOA still required for in-person appointments.
  • Scope still binds the conversation. If the SOA covers MA-PD and the client wants to talk Med Supp, you still need scope for that.
  • Your carrier and FMO rules still apply. Several carriers impose requirements stricter than CMS’s floor. Removing a CMS timing requirement does not remove a carrier one. Check before you change your process.

Why the timing matters this year

1 October is the date agents may begin marketing the following plan year, and AEP itself runs 15 October to 7 December. The new workflow therefore starts on exactly the day the season starts. Whatever you change, you are changing it live.

Two practical consequences:

  • Same-day appointments become bookable. If your process assumed a two-day lead time, your capacity model for AEP just changed. That is a real throughput gain, but only if your SOA collection is fast enough to keep up.
  • Documentation gets more load, not less. More appointments in the same window means more SOAs recorded per week, and every one still has to be retrievable if you are asked for it.

What to check in your own process before 1 October

  • Can you send an SOA by text and have it signed while you are still on the phone? If it involves emailing a PDF and hoping, same-day appointments will not work in practice.
  • When an SOA comes back signed, where does it go? If the answer is an inbox or a folder, you have a retrieval problem waiting for you in an audit.
  • Can you produce every SOA for a given client, in order, in under a minute?
  • Have you confirmed the position with each carrier you write, in writing?
  • Does anyone else on your team need retraining before the season starts?

Where a CRM actually helps here

The compliance failure mode for Medicare agents is almost never “I did not get an SOA.” It is “I got one and I cannot find it.” Documentation that lives in an inbox, a phone’s photo roll and a filing cabinet is documentation you cannot produce on demand.

HowardCRM sends, receives and stores Scope of Appointment and enrollment forms against the client record, and can deliver them by text as well as email. That is the specific capability the new same-day workflow depends on: fast enough to collect during the call, and structured enough that the record is where you would look for it a year later.

Get your SOA workflow ready before 1 October

If your Scope of Appointment process is currently a PDF and an inbox, that will not survive a same-day AEP calendar. Call and we will show you the alternative.

Book a walkthrough
Call +1 (619) 391-1776

This article summarises publicly reported changes to CMS marketing requirements and is not legal or compliance advice. Confirm the current position with your FMO, your carriers and the CMS Medicare Communications and Marketing Guidelines before changing your process.

Categories
Uncategorized

How to Choose a Medicare CRM: A Buyer’s Guide for Agents

Every Medicare CRM demo looks good. The differences that matter only show up in October, when you are trying to move four hundred people in eight weeks. Here is what to actually test before you commit.

Start with the question nobody asks in a demo

Most CRM evaluations turn into feature bingo. You get a list, the vendor ticks the boxes, and everyone feels productive. The problem is that almost every Medicare CRM can tick the same boxes. Contact management, policy tracking, a mobile app, some dashboards — that is table stakes.

The question worth asking is narrower: can this system answer a question about my book of business that I cannot currently answer?

Concrete version. A carrier pulls a plan in your state in September. How long does it take you to produce a list of every affected client, with their phone numbers, sorted by renewal date? If the answer is “I’d export to Excel and work it out”, you do not have a CRM. You have a database with a nice front end.

The eight things to test

1. Enrollment freedom

Some CRMs in this market are supplied by an FMO and quietly assume you will write business through that FMO. That is fine until you want to write a plan through a different upline. Ask directly: can I quote and enroll any carrier, any plan, regardless of who my FMO is? Get the answer before you migrate your data, not after.

2. Scope of Appointment, end to end

SOA is the single most common compliance failure point for Medicare agents, and it is entirely avoidable. Test the full loop in the demo: send an SOA by text and by email, have it signed, and then find it again attached to the client record. If any part of that involves a separate tool or a PDF in an inbox, that is where your documentation will go missing.

3. Reporting you can build yourself

This is the biggest genuine difference between systems, and the hardest to see in a demo, because vendors show you their prettiest pre-built dashboard.

Ask to build a report live, during the call. Something specific: every Med Supp client turning 65 in the next 90 days; every PDP client on a plan whose premium is rising; every household with more than one policy. If the answer is “we can build that for you”, you will be waiting on a support ticket every time you have an idea.

4. Drug and provider lookup where the client record is

Checking a formulary or whether a cardiologist is in network is not a technical feature, it is 60% of a Medicare appointment. If it happens in a separate browser tab, you are copying information across by hand while a client watches. Look for provider lookup and a pre-populated drug search inside the CRM, working the way Medicare.gov’s does.

5. Blue Button access

Blue Button lets a client authorise you to pull their actual Medicare claims and prescription history. The difference between “what do you take?” and knowing what was actually filled last year is the difference between a plan recommendation and a guess. Not every CRM in this market supports it.

6. Security, honestly assessed

You are handling protected health information. Ask what the CRM’s compliance posture actually is — not “is it secure” but which certifications and attestations it holds, and who audits them. HIPAA and SOC 2 Type 2 are the baseline. A CRM built on a major enterprise platform inherits that platform’s security programme; a bespoke tool built by a small vendor is carrying it alone.

If the vendor cannot produce a compliance page, that is your answer.

7. What migration actually costs

The stated price is rarely the real cost of switching. Ask who does the data upload, what it costs, how long it takes, and what happens to your historical policy records. A vendor that migrates your data for free is telling you they expect you to stay; one that charges for it is telling you something else.

8. The annual number, not the monthly one

Per-user-per-month pricing is designed to look small. Multiply it out. Then ask what is not included: commission tracking, texting, call recording, additional seats, premium support. Build the twelve-month total for the way you actually work, then compare.

Where each type of system fits

If you are… What usually matters most
A solo agent under 200 clients Speed of setup and low annual cost. Deep reporting is nice but not yet the bottleneck.
A solo agent over 400 clients Reporting and AEP throughput. This is the point where spreadsheets stop working and a real query engine starts paying for itself.
A small agency with downline Enrollment freedom across uplines, shared visibility, and compliance documentation that survives an audit.
Writing ACA as well as Medicare Whether the system handles both lines properly, or bolts ACA on as an afterthought.

The honest trade-off with platform-based CRMs

Medicare CRMs broadly split into two camps: purpose-built lightweight tools, and systems built on an enterprise platform such as Salesforce.

The lightweight tools are faster to learn. You will be productive in an afternoon. The ceiling is lower — when you want the system to answer a question its designers did not anticipate, it usually cannot.

Platform-based systems are the reverse. There is more to learn, and anyone who tells you otherwise is selling. What you get for that is a reporting engine that will answer nearly anything, an enterprise security programme you could never fund yourself, and a system that does not hit a ceiling as your book grows.

Which is right depends entirely on where you are. If you are managing 80 clients and want something simple, buy something simple. If you are managing several hundred and losing time in AEP because you cannot interrogate your own data, the extra learning curve pays for itself in one season.

A short checklist to take into your next demo

  • Build a custom report live, on the call, that the vendor has not prepared
  • Send an SOA by text, sign it, and find it again on the client record
  • Ask which carriers and uplines you are restricted to — and get it in writing
  • Ask for the compliance certifications by name
  • Ask who migrates your data, how long it takes, and what it costs
  • Calculate the twelve-month total including everything you would actually turn on
  • Ask what happened to a customer who left, and how they got their data out

Run that checklist against HowardCRM

Built on Salesforce by a working health insurance agent, $300 a year, 30-day free trial, and we upload your existing book at no cost so the trial is a real test.

Book a walkthrough
See the features