The ACA Broker Moratorium: What Agents Need to Know — Tech Savvy Insurance
Article

The ACA Broker Moratorium: What Agents Need to Know

← All articles
A dark, empty insurance agency workspace at dusk shot from behind a desk toward a wide curved monitor showing a faint glowing outline map of the United States with a red padlock icon over part of it, a second monitor beside it showing a stack of translucent document icons with a red circular seal on the top page, teal and blue ambient lighting, no people visible, no legible text

CMS paused new agent and broker registration for the Federally-facilitated Exchanges on September 22, 2026, and at the same time made it easier to terminate the Exchange agreement of an agent who already has one — the ACA broker moratorium runs through February 1, 2027, applies only to the 30 states on HealthCare.gov, and takes effect about five weeks before OEP 2027 opens on November 1. If you’re a compliant ACA agent with a clean book, none of that is a hypothetical. It’s a live question of whether you can prove, in under five minutes, that every enrollment you wrote this year had real consumer consent behind it.

Key takeaways

  • CMS's interim final rule (Federal Register Doc. 2026-19493) paused new agent/broker registration for the Federally-facilitated Exchanges effective September 22, 2026, through February 1, 2027 — it applies only to agents without an active Plan Year 2026 Exchange agreement, and it does not touch the 21 State-Based Exchanges.
  • CMS's September 2026 press release reports roughly 315,000 unauthorized PY2026 enrollments cancelled, affecting more than 760,000 individuals, about $2.2 billion in subsidies recovered, termination notices issued for over 200 non-compliant agents/brokers since January 2026, and 569 notices of intent to terminate issued over the summer.
  • A separate rule, CMS-9884-F, revised 45 CFR 155.220(g)(2) so HHS can terminate an agent's Exchange agreement for cause on a "preponderance of the evidence" — defined at 45 CFR 155.20 as proof that a fact is "more likely true than not" — a lower bar than requiring near-certainty.
  • GAO (GAO-26-108297, July 13, 2026) found consumer complaints of unauthorized enrollments and plan switches grew more than fourfold from 2023 through 2025, and that at least 160,000 federal Marketplace applications in plan year 2024 had likely unauthorized changes — the pattern CMS says it's now responding to.
  • CMS requires agents to document consumer consent and keep it for a minimum of 10 years, producible on request. A compliant agent's real exposure right now isn't having done anything wrong — it's not being able to retrieve that proof fast when asked.

A dark, empty insurance agency workspace at dusk shot from behind a desk toward a wide curved monitor showing a faint glowing outline map of the United States with a red padlock icon over part of it, a second monitor beside it showing a stack of translucent document icons with a red circular seal on the top page, teal and blue ambient lighting, no people visible, no legible text

The registration freeze on the left screen and the document stack on the right are two separate CMS actions — one blocks new agents, the other makes it easier to remove existing ones.

The pain: you did everything right and you still can’t prove it fast

Here’s the version of this that actually keeps an agent up at night. You ran a clean Scope of Appointment call, you read the attestations, the client said yes, you wrote a good enrollment. Eight months later a data-matching flag, a random audit sample, or a complaint against someone else at your agency puts your name in a CMS review queue. Someone asks you to produce the consent record for that specific enrollment, today. Can you find it in under five minutes? For most independent agents, the honest answer is no — the SOA is in one system, the recorded call is in another, the actual application is in HealthCare.gov’s own portal, and the client’s file in your CRM has a note that says “enrolled” and nothing else.

This is guidance, not legal or compliance advice

Tech Savvy Insurance is a training and software community, not a law firm, an insurance company, or an insurance agency, and nothing here is insurance, legal, tax, or compliance advice. This article describes what CMS, GAO, and the Federal Register have published, as of the dates cited. Confirm your own compliance posture, your obligations under your Exchange agreement, and your specific state's rules with your own FMO, carrier compliance department, or legal counsel before acting on anything here.

That gap didn’t matter much when CMS’s enforcement posture was slow and case-by-case. It matters now, because September 2026 brought two changes at once: a channel-wide registration freeze, and a lower legal bar for pulling an individual agent’s Exchange agreement. Neither one was written to catch a compliant agent. Both of them will, if that agent can’t produce the paper trail fast enough.

What CMS actually announced in September 2026

On September 22, 2026, CMS imposed a temporary moratorium pausing new agent and broker registration for the Federally-facilitated Exchanges, codified through an interim final rule published in the Federal Register the next day. The rule’s own text is specific about who it hits: CMS is “immediately imposing a temporary moratorium to pause the registration of agents and brokers that do not have Plan Year 2026 Exchange agreements with the Federally-facilitated Exchanges and are seeking to enter into agreements with CMS to assist consumers with enrollment through the Federally-facilitated Exchanges for Plan Year 2027” (Federal Register, Doc. 2026-19493, 91 FR 60317). If you already hold a PY2026 Exchange agreement and simply need to keep working under it, the moratorium doesn’t touch you directly — it blocks new registrations and re-registrations, not existing, active agreements.

The rule sits alongside a broader enforcement push CMS described the same week in a press release titled “CMS Cracks Down on Fraud, Waste, and Abuse in the Federal Health Insurance Marketplace.” The numbers in it are the reason this story is bigger than one procedural rule:

~315,000
Unauthorized PY2026 enrollments cancelled, affecting more than 760,000 individuals
CMS, press release, September 2026
$2.2B
Subsidies recovered from cancelled unauthorized enrollments
CMS, press release, September 2026
569
Notices of intent to terminate issued over summer 2026 for applications missing required info like SSNs
CMS, press release, September 2026

Add to that: CMS has issued termination notices for over 200 non-compliant agents and brokers since January 2026, per the same release. CMS Administrator Dr. Mehmet Oz put the agency’s framing plainly: “Every dollar lost to fraud is a dollar taken from hardworking taxpayers.” That’s the backdrop the moratorium landed in — not an isolated procedural tweak, but one piece of a channel-wide response to a fraud pattern CMS says it has already found and started pulling apart.

Flat editorial infographic on a dark navy background titled ACA Marketplace Crackdown: By The Numbers, showing three large stat blocks: 315,000 unauthorized PY2026 enrollments cancelled, $2.2B in subsidies recovered, and 569 notices of intent to terminate issued, sourced to CMS's September 2026 press release

Three figures, one primary source: CMS's own September 2026 press release on the Marketplace fraud crackdown.

Why it happened: what GAO actually found

CMS didn’t build this enforcement posture in a vacuum. On July 13, 2026, GAO published GAO-26-108297, “Health Insurance Marketplaces: CMS Needs Stronger Controls to Prevent Unauthorized Actions by Agents and Brokers,” and the findings explain the timing. GAO reported that “the number of consumer complaints of unauthorized enrollments and plan switches grew more than fourfold from 2023 through 2025,” and separately, that “at least 160,000 federal Marketplace applications in plan year 2024 had likely unauthorized changes” (GAO, GAO-26-108297, July 13, 2026).

Consumer complaints of unauthorized Marketplace enrollments and plan switches

GAO reports complaint volume grew more than fourfold from 2023 through 2025 — exact annual counts aren't broken out in the report, so the bars show the reported relative growth, not absolute figures.

2023
1x (baseline)
2025
4x+ baseline

Source: GAO, GAO-26-108297, Health Insurance Marketplaces: CMS Needs Stronger Controls to Prevent Unauthorized Actions by Agents and Brokers, July 13, 2026.

GAO’s recommended fix is worth naming because it previews where CMS may go next: stronger controls including “use of a one-time passcode and limits to the amount of consumer details agents and brokers who are not the agent of record can see,” noting that California, Georgia, and New Mexico already require one-time passcodes to verify consumer consent to agent or broker actions on their own state-based Exchanges (GAO, GAO-26-108297). If a passcode-based consent verification requirement eventually reaches the Federally-facilitated Exchange, the agents best positioned for it will be the ones who already have a habit of timestamped, retrievable consent records — which is exactly the manual system later in this article.

Complaints about unauthorized enrollments and plan switches didn't grow a little. GAO says they grew more than fourfold in two years. CMS's response wasn't written for the agent who did the SOA correctly — it was written for the pattern behind that number, and it doesn't distinguish the two on first pass.

Mike Moore

The moratorium’s exact scope: who it actually hits

This is the part most agents get wrong in a hurry, in both directions — some assume it applies to them when it doesn’t, and some assume they’re in the clear when they’re one lapsed registration away from being affected.

Who the September 2026 registration moratorium affects
Situation Affected by the moratorium?
You hold an active PY2026 Exchange agreement with the FFM and want to keep working under it No — the moratorium blocks new/re-registration, not an existing active agreement
You never registered with the FFM, or your PY2026 agreement lapsed, and you want to register for PY2027 Yes — registration is paused until February 1, 2027
You're licensed and registered in a State-Based Exchange (e.g. California, Colorado, Connecticut, New York, Washington) No — the rule states explicitly that it "does not affect registrations on the State-based Exchanges (SBEs)"
You're a web-broker operating your own direct enrollment platform The moratorium's own text frames it as a registration pause for agents and brokers seeking FFM/SBE-FP agreements; confirm your specific web-broker agreement status directly with CMS or your FMO rather than assuming either way

The Federally-facilitated Exchanges the rule covers are the 30 states that use HealthCare.gov for plan year 2026, per CMS’s own Marketplace 2026 Open Enrollment Period Report: National Snapshot. The remaining 21 jurisdictions run their own State-Based Exchange platforms, named in that same CMS report (California, Colorado, Connecticut, and others). If you’re licensed only in an SBE state, this specific rule does not reach your registration — full stop. It’s still worth reading the rest of this article, because the lowered evidentiary standard for Exchange agreement termination comes from a different rule and isn’t scoped the same narrow way.

Letting your PY2026 agreement lapse now is the mistake to avoid

If your PY2026 Exchange agreement is still active, the moratorium isn't your immediate problem. The agents it actually blocks are the ones who let a registration expire or never completed one, and then try to register or re-register between now and February 1, 2027. Check your own agreement status directly rather than assuming it's still current.

”Preponderance of the evidence”: what the lower bar actually means

This is the change that matters most for an agent who’s already registered and doesn’t think the moratorium touches them. A separate rule, CMS-9884-F — a final rule titled “Marketplace Integrity and Affordability,” published in the Federal Register on June 25, 2025 — is described by CMS’s own summary as a rule that “establishes the evidentiary standard HHS uses to assess an agent’s, broker’s, or web-broker’s potential noncompliance” (Federal Register, Doc. 2025-11606, 90 FR 27074).

That rule revised 45 CFR 155.220(g)(2), the regulation governing termination for cause. The current text, verified live against eCFR this session, reads: “An agent, broker, or web-broker may be determined noncompliant under paragraph (g)(1) of this section if HHS finds by a preponderance of the evidence that the agent, broker, or web-broker violated” a standard under that section or a term of their Exchange agreement (eCFR, 45 CFR 155.220(g)(2), current as of September 23, 2026). A separate provision, 45 CFR 155.20, defines the standard itself: “Preponderance of the evidence means proof by evidence that, compared with evidence opposing it, leads to the conclusion that the fact at issue is more likely true than not” (eCFR, 45 CFR 155.20, current as of September 23, 2026).

Translate that out of regulatory language: HHS doesn’t need proof beyond a reasonable doubt, and it doesn’t need clear and convincing evidence. It needs evidence that tips the scale past 50 percent that you did the thing alleged. That’s a materially easier bar to clear than a stricter evidentiary standard would be, and it applies to every agent and broker holding an FFM Exchange agreement, not just the ones in a registration queue.

What most agents assume

"I've never done anything wrong, so there's no real risk to my Exchange agreement even if CMS is cracking down on bad actors."

What the preponderance standard actually means

HHS can terminate your agreement on evidence that merely tips the scale past 50/50 — not on certainty. A thin or unretrievable paper trail on your side doesn't have to be proof of wrongdoing to leave you exposed; it can simply be the absence of the evidence that would have tipped the scale back toward you.

We don’t have a confirmed, citable source describing the exact word-for-word evidentiary language that applied before CMS-9884-F, so we’re not going to guess at it or imply a specific prior standard we can’t point to. What we can say, sourced directly: this rule is the one CMS itself describes as establishing the standard now in place, and the standard it established is preponderance of the evidence, defined exactly as quoted above.

What it costs: the mechanism, not a guess

We’re not going to hand you a made-up dollar figure for what losing an Exchange agreement costs an individual agent — nobody has published a sourced number for that, and inventing one would be exactly the kind of unverifiable claim this site doesn’t run. What’s sourced and worth sitting with instead is the mechanism.

An Exchange agreement isn’t one client’s file. It’s the credential that lets you touch Marketplace enrollment and service work for every ACA client you have, through the standard Classic Direct Enrollment or Enhanced Direct Enrollment pathways. If HHS terminates it — on a preponderance-of-the-evidence finding, mid-OEP, with the moratorium blocking a straightforward re-registration until February 1, 2027 — an agent whose book is majority ACA isn’t looking at one lost sale. They’re looking at every renewal, every plan change, every new enrollment on that book going through someone else, for as long as the termination and any related registration bar stays in place. That’s the real stakes of this story for a compliant agent: not a fine, not a warning letter, but the mechanism by which an entire line of business stops.

Set against that: CMS’s own figures on what it’s already done. Termination notices issued for over 200 non-compliant agents and brokers since January 2026. 569 notices of intent to terminate issued over the summer for applications missing required information like Social Security numbers. Those aren’t hypothetical enforcement actions — they already happened, this year, to real agents, on the same regulatory machinery now sitting at a lower evidentiary bar.

The manual fix: build a retrievable proof system this week

None of what follows requires software, a vendor, or a membership. It requires an afternoon and a willingness to change how you close out every enrollment from today forward, plus a pass through your recent book to backfill what you can.

Verify and record identity at the moment of contact

Before you do anything with a consumer's Marketplace application, confirm who you're talking to and note how you confirmed it — full name, and the method (government ID on a video call, a verified phone number already on file, whatever your process actually is). Write it down as part of the enrollment record, not as a separate memory you're trusting yourself to have later.

Capture the exact consent language you used, every time

Per CMS's own FAQ, you need documented consent before collecting or using consumer PII for a quote, before a person search on an approved DE/EDE platform, before actively helping with an application, before enrolling someone in a QHP, before updating an existing application, and before checking status on financial assistance eligibility (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, June 12, 2024). Save the actual script or form you used, not a paraphrase of it, attached to that specific enrollment.

Timestamp what plan was selected and why

A dated note — even three sentences — explaining why this plan, at this metal level, with this carrier, was the one the client chose. This is the record that shows a plan selection was the consumer's informed choice, not something that happened to them.

Document that the attestations were actually explained

CMS requires you to document that you explained the attestations at the end of the eligibility application to the consumer and got a positive confirmation they understood them — a recorded call covering this, or a written note stating "the attestations at the end of the application were explained to me," both satisfy it (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, June 12, 2024). Skipping this step is one of the most common gaps, because it feels redundant with the consent step. It isn't; CMS treats them as two separate documentation requirements.

Keep a copy the client can also access

A record that only lives in your head, your personal inbox, or a system your agency doesn't control isn't retrievable in five minutes when you're not the one being asked. Give the client (or keep in a shared, agency-level system) a copy of what was selected and when, so the proof doesn't depend entirely on one person's memory or one person's laptop.

File it so any single enrollment is retrievable in under five minutes

One folder or record per client, containing the identity note, the consent language used, the plan-selection rationale, and the attestation-review note, named consistently (client name + enrollment date). The test is simple: if CMS asked about a specific enrollment from four months ago right now, could you open the exact file in under five minutes? If the honest answer is no, the filing system is the gap, not your compliance.

Retention: 10 years, not "as long as I remember to keep it"

CMS states plainly that consumer consent documentation "must be maintained for a minimum of 10 years and produced to CMS upon request in response to monitoring, audit, and enforcement activities" (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, June 12, 2024). Build your filing system assuming a decade of retention from day one, not as something you'll figure out later.

Flat vector checklist infographic on a dark navy background titled What To Keep On File For Every Enrollment, listing five items with green checkmarks: Identity verification, Dated consent record, Plan selection notes, Attestation review record, and Client-accessible copy

Five items, one file per client. The test that matters: can you open the right one in under five minutes if CMS asks about it today?

The pre-OEP self-audit: do this before November 1

Pull your last 20 Marketplace enrollments. For each one, check: do you have a dated consent record on file? Do you have a note showing the attestations were explained and confirmed? Can you find the plan-selection rationale? Is there a copy the client could also produce if asked? If you hit a gap on any of the 20, that’s the exact gap to fix agency-wide before OEP 2027 opens on November 1 — not a reason to panic about the specific file, but a clear signal about where your process is thin.

CMS doesn’t prescribe a single required format. Per its own FAQ: “CMS regulations do not prescribe the manner in which agents, brokers, and web-brokers must document consumer consent,” and acceptable formats include “a recorded phone call, text message, email, electronic document with digital signature” (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, June 12, 2024). What matters is that the documentation actually demonstrates consent was given, for the specific action taken, by the specific consumer or their authorized representative.

Actions that require documented consumer consent, per CMS's Consumer Consent & Application Review Requirements FAQ
# Action requiring documented consent
1Collecting or using consumer PII to provide a quote or estimate on Marketplace coverage
2Conducting a person search for eligibility applications on an approved Classic DE or EDE website
3Actively helping a consumer complete an eligibility application on their behalf
4Actively enrolling a consumer in a Marketplace qualified health plan (QHP)
5Making updates to a consumer's eligibility application throughout the year via DE/EDE
6Checking the status of a consumer's coverage or eligibility application, including financial assistance eligibility

One consent can cover more than one of these if it was written broadly enough and hasn’t been rescinded or expired — CMS allows an initial consent to authorize later status checks throughout the year without a fresh form each time, including agency-wide if the original documentation said so (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, June 12, 2024). But any time you take an action a prior consent doesn’t cover — updating a plan selection, for instance — a fresh, documented consent is required for that specific action.

A timeline: how we got from GAO’s report to the moratorium

2025–2026 CMS agent/broker enforcement timeline
Date Action Source
June 25, 2025 CMS-9884-F final rule published, establishing the preponderance-of-the-evidence standard for terminating an agent's, broker's, or web-broker's Exchange agreement for cause Federal Register, Doc. 2025-11606
July 13, 2026 GAO publishes GAO-26-108297, finding complaints of unauthorized enrollments/switches grew more than fourfold from 2023–2025, and at least 160,000 PY2024 applications had likely unauthorized changes GAO-26-108297
Summer 2026 CMS issues 569 notices of intent to terminate to agents/brokers whose 2026 applications lacked required information such as SSNs CMS, press release, September 2026
September 22, 2026 Temporary moratorium on new FFM agent/broker registration becomes effective Federal Register, Doc. 2026-19493
September 23, 2026 CMS publishes its fraud crackdown press release: ~315,000 enrollments cancelled, $2.2B recovered, 200+ agents terminated since January CMS, press release, September 2026
November 1, 2026 2027 Open Enrollment Period opens on HealthCare.gov, running through January 15, 2027 HealthCare.gov, Dates & Deadlines
February 1, 2027 Registration moratorium ends, unless CMS extends, modifies, or lifts it before then Federal Register, Doc. 2026-19493

Where Ambrose fits, and where it doesn’t

Nothing below makes you compliant. Building the actual documentation — the consent record, the plan-selection note, the client-accessible copy, all of it retained for the 10-year window CMS requires — is work you or your agency does; no platform automates that governance decision for you, Ambrose included. What Ambrose’s own documentation confirms, fetched fresh this session, is narrower and still genuinely useful for the exact retrievability problem this article is about.

The client-vault spoke is documented as a “client-facing enrollment + policy store,” with a HIPAA posture marked “safe” (Ambrose docs, Spokes). Instead of a consent recording in one system, a CRM note in another, and the actual application sitting in a third, an agency’s own tenant keeps each client’s enrollment record in one retrievable place.

The PHI Rail’s audit log gives that retrieval a paper trail of its own: every scrub event is logged — “timestamp, source, identifier counts — never the actual values” — and it’s queryable through phi_audit_query (Ambrose docs, Architecture: PHI Rail). That’s a real, timestamped record of what ran and when, without the actual identifiers sitting exposed in the log itself.

And Routines — a scheduled prompt attached to an agent or team, on cron syntax, with results sent to Slack, email, a GoHighLevel note, or a log (Ambrose docs, Routines) — is the feature an agency could use to build its own version of the self-audit above: a weekly sweep of the last week’s enrollments, checking for missing consent documentation or incomplete attestation notes, posted to the team’s Slack channel every Monday morning. That’s not a shipped “compliance audit” product; it’s a routine you configure yourself, using the Routines feature exactly as documented, aimed at exactly the gap this article describes.

Building the retrievability system by hand vs. what Ambrose's documented features already do
Task Doing it by hand Running through Ambrose
Keeping one enrollment record per client in one place Spread across email, a CRM note, and a filing cabinet or shared drive The client-vault spoke stores it as a client-facing enrollment + policy record, agency-scoped
Proving what ran and when, without exposing raw identifiers Screenshots and memory, if anything PHI Rail logs every scrub event with timestamp, source, and identifier counts — queryable via phi_audit_query
Running a recurring documentation check on the book Relies on someone remembering to do it, usually right before an audit A Routine, scheduled on cron syntax, posts the results to Slack automatically

Name the mechanism, not "AI compliance"

The specific, checkable things here are the client-vault spoke's storage model, the PHI Rail's queryable audit log, and the Routines feature's scheduling and output sinks — all per Ambrose's own documentation, fetched this session. None of it is a certification, and none of it writes your documentation for you.

Everything in the manual section above works whether you ever look at Ambrose or not — verify identity, capture the consent language, timestamp the plan rationale, document the attestation review, keep a client-accessible copy, file it so any one record is retrievable in five minutes. Ambrose’s seat is worth mentioning here specifically because the gap it closes — records scattered across three systems, no queryable log of what happened, no recurring check to catch the ones that slipped through — is exactly the kind of gap that turns “I did this correctly” into “I can’t prove it fast enough” when CMS asks.

This is the kind of thing we build on a Tuesday call with Ambrose open on the screen — setting up client-vault for a real book, watching a scrub event actually land in the PHI Rail’s audit log, and writing the Monday-morning Routine that flags incomplete files before OEP does. $97 a month, cancel anytime, and nobody’s going to pitch you a downline while you’re doing it.

What you get by joining

One Ambrose seat, including client-vault, comes with the $97/month Tech Savvy Insurance membership — billed monthly, cancel anytime, with the founding rate locked in while the membership stays continuously active. Ambrose usage runs on its own credit ledger, separate from the membership fee, so cost stays visible instead of becoming a surprise. Alongside the seat: weekly Zoom calls with open Q&A and build-with-you sessions, more than 30 hours of recorded training updated monthly, Meta Ads and AI marketing training built for health and life agents, pre-built AI templates and bot deployments, and a free annual in-person member workshop — in an explicit no-recruiting zone, so you can ask a real compliance question without getting DM’d about a downline an hour later.

Build your proof-of-consent system before OEP 2027

Verify identity, capture the consent language, timestamp the plan rationale, document the attestation review, and file every record so it's retrievable in five minutes — the six-step method above is the whole thing, no membership required. If you'd rather build it with client-vault and the PHI Rail's audit log open on a screen-share, one Ambrose seat comes with the Tech Savvy membership.

Join Tech Savvy — $97/month

Related reading: our guide on reshopping your ACA book before Open Enrollment, what to check before the ACA subsidy cliff hits a client’s household income, our breakdown of vetting insurance lead vendors if unauthorized enrollments in your funnel trace back to a lead source, and our look at insurance referral fee rules for the adjacent compliance landscape agents are navigating this year.

The close

CMS didn’t write the September 2026 moratorium or the preponderance-of-the-evidence standard to catch an agent who ran a clean SOA and wrote a clean enrollment. It wrote them in response to a real, sourced pattern: complaints up more than fourfold in two years, at least 160,000 likely-unauthorized applications in a single plan year, hundreds of thousands of people affected, billions in subsidies paid out on enrollments nobody actually authorized. The problem for a compliant agent is that the response is channel-wide and the evidentiary bar for an individual termination is now lower, which means the agents best protected aren’t necessarily the ones who did the most right — they’re the ones who can prove it fastest. Build that proof system before OEP 2027 opens on November 1, not after CMS asks for it.

Before you rely on any figure in this article

Tech Savvy Insurance is a training and software community, not an insurance company, agency, or law firm, and does not provide insurance, legal, tax, or compliance advice. Results may vary. You are responsible for confirming your own Exchange agreement status, your state's specific rules, and your compliance obligations with your own FMO, carrier, and legal counsel — none of which this article can substitute for. Regulatory status changes over time; confirm current status directly with CMS before relying on any date or figure above. AI-generated outputs, including anything drafted by an AI tool for your own compliance documentation, may contain errors: always verify.

Frequently asked questions

It's a temporary pause on new agent and broker registration for the Federally-facilitated Exchanges, imposed through an interim final rule CMS published in the Federal Register on September 23, 2026, effective September 22, 2026. Per the rule itself, CMS is "immediately imposing a temporary moratorium to pause the registration of agents and brokers that do not have Plan Year 2026 Exchange agreements with the Federally-facilitated Exchanges and are seeking to enter into agreements with CMS to assist consumers with enrollment through the Federally-facilitated Exchanges for Plan Year 2027" (Federal Register, Doc. 2026-19493, 91 FR 60317). If you already hold an active PY2026 Exchange agreement, the moratorium does not affect your ability to keep working; it only blocks brand-new registrations and re-registrations for agents and brokers who let their agreement lapse or never had one.
No. The rule says explicitly that "this temporary moratorium does not affect registrations on the State-based Exchanges (SBEs)" (Federal Register, Doc. 2026-19493). It applies only to the Federally-facilitated Exchanges — the 30 states that use HealthCare.gov for plan year 2026, per CMS's own Marketplace 2026 Open Enrollment Period Report. If you're licensed and registered in one of the 21 state-based Exchange jurisdictions CMS lists for 2026 (California, Colorado, Connecticut, and others with their own platform), this specific moratorium doesn't reach your registration at all. It's still worth reading the rest of this article, because the lowered evidentiary standard for terminating an Exchange agreement for cause comes from a separate rule, CMS-9884-F, and that one isn't limited to FFM states the same way.
It's the formal agreement an agent or broker signs with CMS to assist consumers with Marketplace enrollment through the Federally-facilitated Exchange — the credential that lets you use the Marketplace's Classic Direct Enrollment or Enhanced Direct Enrollment pathways to help a client apply for or change ACA coverage. Losing it doesn't just end one transaction; it ends your ability to touch any client's Marketplace application through those pathways at all, which for an agent whose book is majority ACA effectively ends that line of the business until a new agreement, if ever granted, is back in place. We don't have a sourced dollar figure for what that costs an individual agent and we're not going to invent one — the mechanism is what matters: no agreement means no further Marketplace enrollment or service work on existing Marketplace clients through the standard agent pathways.
CMS-9884-F, a final rule published in the Federal Register on June 25, 2025, revised 45 CFR 155.220(g)(2) so that HHS may terminate an agent's, broker's, or web-broker's Exchange agreement for cause if it "finds by a preponderance of the evidence" that the agent violated a standard or a term of the agreement (eCFR, 45 CFR 155.220(g)(2), current as of September 23, 2026; Federal Register, Doc. 2025-11606, 90 FR 27074). Separately, 45 CFR 155.20 defines that standard as "proof by evidence that, compared with evidence opposing it, leads to the conclusion that the fact at issue is more likely true than not" (eCFR, 45 CFR 155.20, current as of September 23, 2026). In plain terms: HHS doesn't need overwhelming proof, just evidence that tips the scale past 50/50 that you did what's alleged. We don't have a confirmed, citable source for the specific word-for-word standard that applied before this rule, so we're not going to characterize it beyond what CMS's own rule summary says: the rule "establishes the evidentiary standard HHS uses to assess an agent's, broker's, or web-broker's potential noncompliance," meaning this is the standard as newly codified, not a minor tweak to language that was already this explicit.
A minimum of 10 years, and you have to produce it to CMS on request. Per CMS's own FAQ on consumer consent and application review requirements: "the documentation of consumer consent must be maintained for a minimum of 10 years and produced to CMS upon request in response to monitoring, audit, and enforcement activities" (CMS, Frequently Asked Questions: Consumer Consent & Application Review Requirements, published June 12, 2024). That applies to the consent documentation itself; CMS lists six specific actions that each require their own documented consent unless a prior, still-valid consent already covers the action, which we walk through in the body of this article.
The moratorium and the preponderance-of-the-evidence standard are specific to the ACA Marketplace's Exchange agreement framework under 45 CFR Part 155, so if you never touch ACA enrollments, those two provisions don't reach you directly. But if you're a dual-market agent who sells both ACA and Medicare Advantage or Part D, which a large share of the health-agent population is, the underlying pattern is worth noticing on the Medicare side too: CMS's own CY2026 Agent and Broker Training & Testing Guidelines require organizations to ensure TPMOs "record all marketing, sales, and enrollment calls, including the audio portion of calls via web-based technology, in their entirety," per 42 CFR 422.2274(g)(2)(ii) and 423.2274(g)(2)(ii) (CMS, CY2026 Agent and Broker Training & Testing Guidelines). Same underlying idea as the ACA consent rules: CMS wants a retrievable record proving what happened, and it's building the enforcement apparatus to check for one on both sides of your book.
No, and we're not going to pretend otherwise. Building and maintaining the actual documentation — the consent record, the application-review record, the retrievable client file — is work you or your agency has to do and be able to produce on request; nothing turns that into a finished compliance program automatically. What Ambrose's own documentation does confirm, fetched this session: the client-vault spoke is described as a "client-facing enrollment + policy store" with a "safe" HIPAA posture (Ambrose docs, Spokes), the PHI Rail logs every scrub event with "timestamp, source, identifier counts — never the actual values," queryable through phi_audit_query (Ambrose docs, Architecture: PHI Rail), and Routines let you schedule a prompt against an agent or team with output sent to Slack, email, a GoHighLevel note, or a log (Ambrose docs, Routines). Those are real pieces of a documentation system you could build. They are not a substitute for confirming your own compliance posture with your FMO, your carrier, or your own counsel.
February 1, 2027, unless CMS extends, modifies, or lifts it before then. The rule states plainly that affected agents and brokers "will not be able to complete registration with the Federally-facilitated Exchanges for Plan Year 2027 until the moratorium ends on February 1, 2027" (Federal Register, Doc. 2026-19493). That date sits just over two weeks after the 2027 Open Enrollment Period closes on January 15, 2027 (HealthCare.gov, Dates & Deadlines), which means an agent shut out by the moratorium is shut out for the entire 2027 OEP on the FFM side, not just part of it.

Sources

  1. CMS — CMS Cracks Down on Fraud, Waste, and Abuse in the Federal Health Insurance Marketplace (press release) — cms.gov
  2. GAO — Health Insurance Marketplaces: CMS Needs Stronger Controls to Prevent Unauthorized Actions by Agents and Brokers (GAO-26-108297, July 13, 2026) — gao.gov
  3. Federal Register — Patient Protection and Affordable Care Act; Temporary Moratoria on Certain Agent and Broker Registration To Participate in the Exchanges (Doc. 2026-19493, Sept. 23, 2026) — federalregister.gov
  4. Federal Register — Patient Protection and Affordable Care Act; Marketplace Integrity and Affordability, CMS-9884-F final rule (Doc. 2025-11606, June 25, 2025) — federalregister.gov
  5. eCFR — 45 CFR 155.220, Standards for termination for cause from the Federally-facilitated Exchange — ecfr.gov
  6. eCFR — 45 CFR 155.20, Definitions (preponderance of the evidence) — ecfr.gov
  7. CMS — Marketplace 2026 Open Enrollment Period Report: National Snapshot — cms.gov
  8. CMS — Frequently Asked Questions: Consumer Consent & Application Review Requirements (published June 12, 2024) — cms.gov
  9. CMS — CY2026 Agent and Broker Training & Testing Guidelines — cms.gov
  10. HealthCare.gov — Dates & Deadlines (2027 Open Enrollment Period) — healthcare.gov
  11. Ambrose docs — Spokes (catalog) — app.hiambrose.com
  12. Ambrose docs — Architecture: PHI Rail — app.hiambrose.com
  13. Ambrose docs — Routines — app.hiambrose.com

Ready to put this into practice?

Join a private community of Health & Life insurance professionals using AI, Meta Ads, and automation to grow — without draining their bank account.

Join Tech Savvy — $97/month