Skip to content
Compliance

Buying Insurance Leads in 2026: The $145M FTC Warning

The FTC just fined two lead-gen firms $145 million for deceptive robocalls tied to consumer leads. Here is what it means for insurance agents who buy leads.

Mike Moore 21 min read
Mike Moore, founder of TheAffordableAI, frowning skeptically at a laptop screen displaying a dashboard with a red warning triangle and the words Lead Source Unverified above a row of small phone icons, with a stack of printed lead sheets on the desk and a faint emerald voice waveform glowing on a second monitor, representing an insurance agent scrutinizing a purchased lead vendor's consent

A federal settlement announced on August 7, 2025 put a real number on a question insurance agents have been guessing at for years: what happens when a lead vendor’s “the consumer consented” turns out not to hold up? Per the FTC’s own press release, Assurance IQ, LLC and MediaAlpha, Inc. agreed to pay a combined $145 million, $100 million and $45 million respectively, to settle charges that they misled consumers shopping for health insurance and, in the agency’s words, “flooded” people, including many already on the National Do Not Call Registry, with robocalls and telemarketing calls tied to leads MediaAlpha generated and sold. If your agency buys leads from a vendor you did not build yourself, this is the article that walks through what that settlement actually says, why the liability for a bad lead does not automatically stay with the company that sold it to you, and how to check a vendor’s consent chain before you pay for the next batch.

This is not an argument against buying leads. Plenty of vendors run a defensible, well-documented process, and third-party leads remain a normal way to fill a pipeline. It is an argument against buying leads the way most of the industry has been buying them for a decade: on trust, with no record of what the consumer actually agreed to, from a vendor who could not produce that record if you asked. The FTC’s settlement is what happens when nobody asks.

The short version

  • The FTC settled with Assurance IQ and MediaAlpha for a combined $145 million on August 7, 2025, over deceptive health-insurance marketing and robocalls tied to purchased consumer leads, per the FTC's own press release.
  • MediaAlpha sold roughly 119 million consumer leads in 2024 alone, according to the FTC's complaint, which is the scale at which one lead-generation company was operating before the settlement.
  • TCPA consent obligations attach to the call, not to the sale of the lead. Under FCC 13-54, the DISH Network declaratory ruling, a business can be held vicariously liable for a third party's calling conduct under agency law, even without dialing the phone itself.
  • Insurance and healthcare were the second-largest category of FCC robocall complaints in 2025, at 11 percent of more than 125,000 complaints, per the FCC's own March 2026 consumer alert.
  • None of this changes what the law requires on any call you place: consent, disclosure, a working opt-out, and for Medicare business, the CMS TPMO disclaimer and recording-retention rules. Using AI to call faster does not transfer that liability away from the licensed agent.

What the FTC Actually Settled, and Why the Problem Runs Wider Than MediaAlpha

Assurance IQ sold short-term medical and limited-benefit plans directly. The FTC’s complaint says the company misrepresented what those plans actually covered, capped benefits without disclosing the caps clearly, misstated provider network access, and, per the FTC’s press release, “unfairly charged consumers without first getting their express informed consent.” MediaAlpha did not sell insurance at all; it ran the lead-generation machinery that fed prospects to Assurance IQ and other partners. According to the FTC, MediaAlpha built landing pages under domains like “ObamacarePlans.com” designed to look connected to a government program, used paid actors to promote that impression, and, in 2024 alone, sold approximately 119 million consumer leads, a figure that comes directly from the FTC’s own press release describing its complaint.

Read that last number again. One lead-generation company, in one year, sold 119 million leads. That is not a rounding error in a niche industry. That is the scale at which “collect an email and a phone number on a landing page, resell it downstream” operates across the entire consumer-insurance shopping category, health insurance specifically but not exclusively. An individual agency buying 200 leads a month from a vendor is a tiny customer of a machine built to move numbers like that.

$145M

Combined FTC settlement, Assurance IQ and MediaAlpha

Source: FTC press release, Aug. 7, 2025

119M

Consumer leads MediaAlpha sold in 2024, per the FTC's complaint

Source: FTC press release, Aug. 7, 2025

21

Companies sent FTC warning letters over health-plan lead ads

Source: FTC press release, Dec. 10, 2024

11%

Of FCC robocall complaints that were insurance or healthcare scams in 2025

Source: FCC consumer alert, released March 6, 2026

This was not an isolated incident, either, and it was not sudden. Roughly eight months before the settlement, on December 10, 2024, FTC staff sent warning letters to 21 companies that market or generate leads for health insurance plans, specifically calling out misrepresented plan benefits, false claims that a limited plan was “major or comprehensive medical health insurance,” inaccurate cost claims, and phantom incentive offers, per the FTC’s own press release announcing those letters. Samuel Levine, then Director of the FTC’s Bureau of Consumer Protection, put it plainly in that release: “It is critical for consumers’ health and financial well-being that marketers of health plans be honest about the plans they and their partners are offering.” The warning letters came during open enrollment season, the exact window when insurance agencies are buying the most volume from exactly this kind of vendor.

Here’s the mechanism, and it’s worth being precise about the vocabulary because the terms get used loosely in this industry.

A lead aggregator is a company that collects consumer information, typically through an ad-driven landing page asking for a name, phone number, and a few qualifying questions, then sells that contact to one or more downstream buyers. Ping-post is the real-time version of that sale: the aggregator “pings” its network of buyers with a stripped-down version of the lead (state, product interest, maybe age range) the instant it’s captured, buyers bid or accept in a live auction that runs in a fraction of a second, and the full contact record “posts” to whichever buyer wins. A lead sold this way can hit multiple buyers’ phones within seconds of the consumer clicking submit.

Consent, in this system, usually means one checkbox on a landing page, often pre-checked or written in dense legal language nobody reads, that theoretically authorizes contact from “our partners,” a category that can include dozens or hundreds of unnamed companies the consumer has never heard of. Whether that checkbox constitutes valid prior express written consent under the TCPA for a specific business calling weeks or months later is a live legal question, not a settled one, and it is exactly the question the FTC’s complaint against MediaAlpha puts real money behind.

Consent doesn't transfer with the sale

Buying a lead does not buy consent the way buying a car buys the title to it. Under 47 U.S.C. Section 227, prior express consent has to actually exist for the specific kind of contact being made, and a court or the FTC can look past what a lead vendor claims on paper to what a consumer actually agreed to, when, and in what language. A vendor telling you "this lead is TCPA compliant" is a sales claim, not a legal fact, and it is not a fact you can verify unless the vendor can show you the underlying record.

This is where TCPA vicarious liability comes in, and it’s the part most agents have never heard explained. On May 9, 2013, the FCC released a declaratory ruling, FCC 13-54, in a proceeding brought jointly by DISH Network, LLC, the United States, and four states, addressing exactly this question: can a business be held liable under the TCPA for calls a third party made on its behalf, even if the business itself never dialed the phone? The FCC’s answer was yes, under certain conditions. The ruling holds that while a seller of goods or services does not generally “initiate” a call placed through a third-party telemarketer within the meaning of the TCPA, that seller can still be held vicariously liable under federal common law principles of agency for the third party’s violations. The FCC was explicit that this liability follows real agency-law relationships, not simply any call made to benefit the seller, but the underlying principle, that responsibility for a bad call does not stay neatly contained to whoever dialed it, is exactly the logic that should worry an agency buying leads from a vendor whose consent practices it has never actually checked.

Infographic titled Two Paths to a Warm Transfer. Left path, Buy a Third-Party Lead: consumer sees an ad, clicks a landing page and checks a box, an aggregator resells the same lead to multiple buyers, you buy it with consent unverified, ending in a red box reading Risk: you inherit someone else's consent chain. Right path, Call Your Own Database: a past client or old lead already on file, consent and timestamp already documented, a managed AI caller dials your own list, warm transfer to a licensed agent, ending in a green box reading You control the consent record.

None of this means every purchased lead is a landmine. It means the safety of a purchased lead depends entirely on facts you usually cannot see from the buyer’s side of the transaction: what exact language the consumer saw, whether that language named your business or your category clearly, how many other buyers got the same lead, and whether the vendor can actually produce a timestamped record of any of it rather than just asserting it exists.

The direct cost sits with the two companies the FTC named. But the pattern underneath it, ad-driven volume, thin consent, resale to multiple buyers, describes a meaningful share of the health-insurance lead industry, and the enforcement activity around it has been building for over a year, not appearing out of nowhere in August 2025.

The lead-generation enforcement timeline, health insurance vertical
Date Action Detail
December 10, 2024 FTC staff warning letters 21 companies marketing or generating leads for health plans warned over misrepresented benefits, coverage type, cost, and false incentives
August 7, 2025 FTC v. Assurance IQ / MediaAlpha settlement $145 million combined ($100M Assurance IQ, $45M MediaAlpha); MediaAlpha sold roughly 119 million leads in 2024 per the FTC's complaint
March 6, 2026 FCC consumer alert Insurance/healthcare confirmed as the 2nd-largest robocall complaint category for 2025, 11% of 125,000+ complaints

Sources: FTC press releases (Dec. 10, 2024; Aug. 7, 2025); FCC consumer alert (released Mar. 6, 2026). See sources list.

Zoom out to where insurance sits in the broader robocall complaint picture and the pattern gets clearer still. The FCC’s own March 2026 consumer alert states it received more than 125,000 unwanted call complaints in 2025, and breaks out the top five scam categories by share: debt relief and loan assistance led at 27 percent, insurance and healthcare came second at 11 percent, ahead of government imposter scams (7 percent), credit and credit card scams (4 percent), and Google listing scams (2 percent).

Insurance and healthcare is the FCC's #2 robocall complaint category

Share of FCC robocall scam complaints by category, 2025 (over 125,000 total complaints).

Debt relief / loan assistance 27%
Insurance / healthcare 11%
Government imposter 7%
Credit / credit cards 4%
Google listing 2%

Source: Federal Communications Commission, consumer alert released March 6, 2026, covering 2025 complaint data. Percentages are the FCC's stated shares of total robocall scam complaints, not an insurance-specific report.

Stat card titled The Lead-Generation Enforcement Timeline, showing four figures: 21 companies sent FTC warning letters over health-plan lead ads in December 2024; 145 million dollars, the FTC settlement with Assurance IQ and MediaAlpha in August 2025; 119 million consumer leads sold by MediaAlpha in 2024 per the FTC complaint; and 11 percent of FCC robocall complaints that were insurance or healthcare scams in 2025, sourced to FTC.gov and FCC.gov press releases 2024 to 2026

That 11 percent figure is not proof that any specific vendor you buy from is doing anything wrong. It’s context: insurance is a category where enough of this volume is bad enough, often enough, that federal regulators track it as a distinct, named problem, second only to debt relief scams. When your agency’s outbound calling looks, from a carrier’s or a regulator’s perspective, statistically similar to the volume driving those complaints, and a purchased-lead-heavy calling pattern can look exactly like that, you inherit some of the scrutiny that comes with the category, whether or not your specific calls are the problem.

The invoice price was never the whole cost

A purchased lead's sticker price, whether that's a few dollars for an aged shared lead or well over a hundred for a fresh exclusive one, has never included the cost of an unverifiable consent chain. That cost doesn't show up until something goes wrong: a complaint, a demand letter, a class action, or an agency's own number getting flagged from calling a list that never should have been called in the first place. The $145 million settlement is that hidden cost made visible, at a scale most agencies will never personally see, but the mechanism that produced it operates at every scale.

What Still Applies No Matter Where the Lead Came From

Before the vetting checklist, it’s worth separating what a vendor’s consent record can fix from what it can never fix. Buying leads from a well-documented vendor solves the evidence problem, whether you can show consent existed. It does not touch the underlying legal requirements every call carries regardless of source.

Calling obligations that apply to every lead, purchased or your own
Requirement What it means Legal basis
Prior express consent Required before an automated, artificial-voice, or prerecorded call, or a text message, to a wireless number 47 U.S.C. § 227 (TCPA)
National DNC Registry scrub Numbers on the Registry can't be called for telemarketing absent an established exception FTC Telemarketing Sales Rule, 16 CFR 310.4
Calling-time restriction Outbound telemarketing calls limited to 8 a.m. to 9 p.m. at the called party's local time FTC TSR, 16 CFR 310.4(c)
Clear disclosure and working opt-out Caller must identify itself and honor stop or removal requests immediately FTC TSR guidance

Sources: Cornell Law School Legal Information Institute, 47 U.S.C. § 227; FTC, Complying with the Telemarketing Sales Rule. A vetted lead vendor helps you prove consent existed; it does not substitute for any row in this table, and Medicare business carries CMS's additional TPMO disclosure and recording-retention rules on top of it.

How to Vet an Insurance Lead Vendor Before You Buy

This is the part worth giving away completely, because an agency that does this work itself doesn’t need anyone’s help to keep buying leads safely.

  1. Ask to see the exact consent language, not a description of it. A vendor should be able to show you the actual checkbox text or disclosure the consumer saw at the moment they opted in, not a summary like “fully TCPA compliant.” If a vendor can’t produce the literal wording, they likely can’t produce the record behind it either.
  2. Ask whether the lead is exclusive or shared, and get it in writing. A shared lead sold to five buyers off one consent event is a fundamentally different risk profile than an exclusive lead sold once, and pricing alone won’t tell you which one you’re getting.
  3. Ask for the timestamp and capture method. A legitimate vendor logs when consent was captured, from what page or form, and often what IP address or device signaled the submission. This is the kind of record that turns “the consumer agreed” from a claim into evidence.
  4. Check whether the landing page identifies your business, or a category you fall into, by name. Consent to be contacted by “our marketing partners” in the abstract is weaker than consent to be contacted about “quotes from licensed local insurance agents,” and weakest of all when the page implies a government program the consumer never actually agreed to be marketed by.
  5. Watch for domain names and branding that borrow government or nonprofit credibility. The FTC’s complaint against MediaAlpha specifically calls out domains like “ObamacarePlans.com” designed to look official. A vendor using that playbook is running exactly the model the FTC just spent $145 million signaling it will pursue.
  6. Cross-check the vendor’s own compliance page against what they actually deliver. A polished “compliance” page is easy to publish. A sample consent record for an actual lead you bought, checked against the timestamp on your CRM, is much harder to fake.
  7. Keep your own record of every purchased lead’s source, price, and vendor-provided consent evidence. If a complaint ever surfaces, “we bought it from a vendor who told us it was fine” is a weak defense. A dated file showing what you actually checked before dialing is a much stronger one.
Red flags in a lead vendor

What an unverifiable consent chain looks like

  • "Fully compliant" claimed, no consent record produced on request
  • Vendor won't say whether a lead was exclusive or shared
  • Landing page domain implies a government program or affiliation
  • Consent checkbox references vague "partners," no named category
  • No timestamp, IP, or capture-method data available for a specific lead
What a defensible vendor provides

What holds up if a consumer complains

  • Exact consent language shown at the moment of opt-in, on request
  • Clear exclusive vs. shared status, disclosed before purchase
  • A named business category or specific disclosure in the consent flow
  • Timestamp, capture method, and source page logged per lead
  • A track record without a public FTC or FCC enforcement history

If you’re already working with a vendor who checks every one of these boxes, this article shouldn’t change anything about how you buy leads. If you can’t answer most of these questions about your current vendor right now, that’s worth finding out before your next invoice, not after a complaint.

Where Your Own Database Fits Into This

Every one of the risks above shares a root cause: you’re relying on someone else’s record of someone else’s consent event. There’s an entire category of leads that doesn’t have this problem at all, the ones already sitting in your own CRM. A past client. A quote request from eight months ago that never closed. Someone who called your office directly and asked for a callback. For every one of those, you already have your own timestamped record of how that contact came to be a lead, because you were there when it happened.

Your own list is a consent record, not just a call list

An aged lead you already own, or a past client whose file shows when and how they engaged with your agency, is a fundamentally different asset than a purchased lead: the consent chain is one link long, and you're the one holding the link. Calling it still requires the same underlying obligations, consent for the specific contact type, disclosure, an opt-out, but you're not trusting a stranger's word for whether that consent exists.

That’s not a new idea; agencies have talked about “database reactivation” for years without necessarily connecting it to this specific risk. But the $145 million settlement is a concrete reason to weigh working the leads you already have, harder and more systematically, against buying fresh volume from a vendor you haven’t fully vetted.

Where a Managed AI Caller Fits, and Where It Doesn’t

To be precise about what TheAffordableAI actually is: a managed AI voice caller for insurance lead follow-up, outbound and inbound, with warm transfers, auto-booking, number warmup, and native HighLevel CRM sync. It is not a lead-generation company, does not sell consumer leads, and has no role in the consent chain behind any lead you already own or buy elsewhere. What it changes is what happens after you decide who to call.

If your agency is sitting on an aged database, past leads, expired quotes, former clients due for a policy review, working that list with your own documented consent is one of the lower-risk ways to fill calling volume, and it doesn’t require hiring a dedicated dialer team to do it at scale. Every plan includes number warmup and spam defense so those outbound calls have a better chance of landing, warm transfers so a real conversation reaches a licensed agent while the prospect is still on the line, and HighLevel sync so the call record, transcript, and disposition land on the same contact file your consent documentation already lives on.

Calls your own database, not a purchased one

Built to work the leads and past contacts already in your CRM, where the consent record is yours, not a vendor's claim.

Warm transfers and auto-booking

A qualified lead reaches a licensed agent live, or gets booked against real calendar availability if nobody's free.

Number warmup and spam defense, standing

A routine on every plan, not a one-time setup step, aimed at keeping your outbound caller ID from getting mislabeled.

No contracts either way

Single Account runs $200/mo plus a $500 one-time setup at $0.20/min, down to $0.15 at bulk. Agency runs $500/mo plus a $1,000 setup at $0.18/min, down to $0.16 at bulk. Cancel anytime.

Where this doesn’t help: if your agency’s entire pipeline depends on fresh, purchased, third-party leads and you have no meaningful database of your own to call instead, an AI caller doesn’t fix the underlying consent-chain problem, because the problem lives upstream of the call, at the point where the lead was generated and sold. In that case, the fix is vendor vetting, exactly the checklist above, not a faster or cheaper way to dial the same unverified numbers. If you want to hear what a compliant call actually sounds like before deciding anything, there’s a live demo on the homepage; putting your number in gets you one real call.

A Worked Example: Two Ways to Fill 500 Calling Slots a Month

Take an agency that wants to place roughly 500 outbound calls a month and is deciding how to fill that volume. This is illustrative arithmetic to make the tradeoff concrete, not a sourced industry benchmark, so substitute your own numbers before drawing a conclusion for your agency.

Path one: buy 500 fresh leads a month from a vendor you haven’t fully vetted. At a mid-range fresh lead price, the direct spend is real money before a single call happens, and every one of those 500 numbers carries whatever consent risk sits behind that vendor’s landing pages. If the vendor’s consent practices don’t hold up, the exposure applies across the full batch, and you have no way to know which specific leads are the problem until something goes wrong.

Path two: call 500 contacts from your own aged database instead, at TheAffordableAI’s Single Account rate of $0.20 a minute, dropping to $0.15 at bulk. On a three-minute average qualifying call, 500 calls runs roughly $300 to $400 in per-minute cost, plus the $200 monthly platform fee, against zero incremental lead-purchase spend, because the contacts were already yours. The consent question for each of those 500 contacts has one answer you can actually point to: your own CRM record of how and when they became a lead.

Neither path is free, and neither is automatically the right call for every agency; a database that’s too small or too stale to produce 500 real contacts a month still needs fresh volume from somewhere. But the comparison is worth running with your own numbers before assuming purchased volume is the only way to hit a calling target, especially for the portion of your pipeline sitting in old files nobody’s called back.

What You Actually Get

Concretely: a documented reason to trust, or not trust, every lead your agency dials, instead of a vendor’s word taken on faith. A framework for asking the four or five questions that separate a defensible lead purchase from an exposed one. And, if you choose to work it, a way to reach the leads you already own without adding a new vendor or a new consent question to the mix at all.

What you don’t get from any of this: a promise that vetting a vendor, or calling your own database, eliminates legal risk entirely. It doesn’t. Consent obligations, disclosure requirements, and opt-out rules still apply to every call regardless of where the lead came from, and using AI to place the call doesn’t shift that responsibility away from the licensed agent of record. What changes is whether you can actually show your work if someone ever asks you to.

A lead vendor's sales pitch and a lead vendor's consent record are two different documents. The FTC's $145 million settlement is what it costs when an agency, or a regulator, only ever sees the first one.

Mike Moore

Where This Doesn’t Apply

If your agency already runs a documented vendor-vetting process, checks consent language before buying, and knows which of its leads are exclusive versus shared, this article isn’t telling you to rip anything up. The settlement targets a specific, identifiable business model, ad-driven volume with unverifiable consent resold to many buyers, and a vendor that doesn’t operate that way isn’t the vendor the FTC is describing.

And if your bottleneck genuinely isn’t lead quality or consent risk but simple follow-up speed, how fast a fresh lead gets a real conversation, that’s a separate problem with a separate fix, and piling vendor-vetting concerns onto a speed problem won’t solve either one. Our companion piece on speed to lead covers that ground directly, and the FCC’s one-to-one consent rule guide covers the separate, and now-vacated, rulemaking fight over how many buyers one consent event could legally support.

Compliance disclaimer

Prior express consent is required under the TCPA, 47 U.S.C. Section 227, before placing automated or marketing calls or texts to a cell phone, and that obligation belongs to whoever is responsible for the call under agency-law principles, which can include a business relying on a third party's lead generation or telemarketing, per the FCC's declaratory ruling in FCC 13-54. Buying a lead from a third-party vendor does not by itself establish that valid consent exists, and vetting a vendor's practices does not eliminate legal risk. Medicare marketing carries CMS's additional rules, including the TPMO disclaimer and call-recording retention requirements. Using an AI calling platform does not transfer compliance liability away from the licensed agent or agency responsible for a lead. This article reflects a review of the cited FTC and FCC documents as of the date published and is general information, not legal advice for your specific situation.

Most agencies that buy leads have never asked a vendor to produce the actual consent record behind one. That’s not a moral failing; it’s how the industry has operated for years, and most of the time nothing goes wrong. The FTC’s $145 million settlement is a reminder that “most of the time” isn’t a compliance strategy, and that the questions in the checklist above take one phone call to a vendor to answer.

Work the leads you already own

Hear how a managed AI caller handles your own database, warm transfers, and CRM sync on a live demo call from the homepage. No vendor consent chain to check, because the leads are already yours.

Frequently asked

What did the FTC actually settle with Assurance IQ and MediaAlpha, and why does it matter to a small agency?

On August 7, 2025, the FTC announced that Assurance IQ, LLC agreed to pay $100 million and MediaAlpha, Inc. agreed to pay $45 million, a combined $145 million, to settle charges that they misled consumers shopping for health insurance and, per the FTC's own press release, 'flooded' consumers, including many on the National Do Not Call Registry, with robocalls and telemarketing calls built on leads MediaAlpha generated. It matters to a small agency because the underlying complaint was never really about the size of these two companies. It was about a lead-generation business model, ad-driven landing pages, checkbox consent, leads resold to multiple buyers, that a huge share of the insurance lead industry runs on, including some of the vendors any individual agency buys from.

Can an insurance agent get in trouble for calling a lead a vendor sold them, even if the agent did nothing wrong?

Yes, potentially, because prior express consent belongs to the call, not to the transaction that produced the lead. Under 47 U.S.C. Section 227, the party responsible for having valid consent before an automated or marketing call to a cell phone is generally the one making or authorizing the call, not the lead broker who sold the phone number. If the consent a vendor claims to have obtained was never real, valid, or specific to your business, a call you place using that lead can be a TCPA violation regardless of how carefully you personally behaved on the call.

What is TCPA vicarious liability, and how does it apply to a purchased lead?

It is the legal doctrine, laid out by the FCC in its May 2013 declaratory ruling in the DISH Network proceeding (FCC 13-54), that a seller can be held liable under the TCPA for a third party's calling conduct under federal common law principles of agency, even though the seller itself did not dial the phone. The ruling was about a company using an outside telemarketer to sell its product, but the underlying logic extends naturally to a licensed agent whose business benefits from a call a lead vendor's network placed, or from a call the agent places using a lead that vendor's consent language does not actually support.

How can an agent tell if a lead vendor's consent is legitimate before buying?

Ask the vendor to show you, not just tell you, the exact consent language a consumer saw, the timestamp, the IP address or device signal captured at opt-in, and how many other buyers that specific lead was sold to. A vendor that cannot produce this on request, that uses a landing page with a name implying a government program, or that cannot say clearly whether a lead is exclusive or shared is a vendor whose consent chain you cannot verify, which under the FTC's and FCC's stated framework is the exact condition that creates risk for whoever ends up dialing the number.

Does this settlement mean agents should stop buying leads altogether?

No, and nothing in the FTC's settlement or in this article says that. Plenty of lead vendors run a legitimate, well-documented consent process, and buying leads remains a normal, legal way to build a pipeline. What changed is the cost of not checking. A settlement this size is the FTC putting a concrete number on what happens when a lead-generation operation's consent practices do not hold up, and that is a reason to vet a vendor before paying for volume, not a reason to abandon lead buying as a channel.

What is the practical difference between a shared lead and an exclusive lead when it comes to risk?

A shared lead was sold to multiple buyers off the same consumer interaction, meaning several different businesses are all relying on the same underlying consent event to justify calling that person. An exclusive lead was sold once. Neither structure is automatically compliant or automatically risky, but a shared lead multiplies how many parties are depending on one consent event being valid, and it multiplies how many separate calls that consumer receives from businesses they may not remember agreeing to hear from, which is exactly the pattern the FTC's MediaAlpha complaint describes at scale.

Does calling my own aged database instead of buying new leads avoid this risk entirely?

It removes the third-party consent-chain risk specifically, because you already have your own record of how and when that person became a lead, whether that is a past client, a quote that never closed, or someone who filled out your own form. It does not remove every compliance obligation. Prior express consent for automated calls or texts, a clear disclosure, a working opt-out, and, for Medicare business, the CMS TPMO disclaimer and call-recording retention rules still apply to a call placed to your own database. What changes is that you control the record proving consent existed, instead of trusting a vendor's word for it.

Does using an AI calling platform change any of this liability?

No. Whether a human or an AI voice agent places the call, the underlying consent, disclosure, and opt-out obligations under the TCPA and, for Medicare, CMS's marketing rules, do not move. Using AI to place a call faster or at greater volume does not transfer liability away from the licensed agent or agency responsible for that lead, and it does not retroactively create consent that a purchased lead's consent chain never actually had.

Sources

  1. Federal Trade Commission — Assurance IQ and MediaAlpha to Pay a Total of $145 Million to Settle FTC Charges They Misled Consumers Seeking Health Insurance (press release, August 7, 2025)
  2. Federal Trade Commission — FTC Staff Sends Warning Letters to Healthcare Plan Marketers and Lead Generators (press release, December 10, 2024)
  3. Federal Communications Commission — In the Matter of the Joint Petition Filed by DISH Network, LLC, et al., Declaratory Ruling, FCC 13-54 (adopted April 17, 2013, released May 9, 2013)
  4. Federal Communications Commission — Consumer Alert: FCC Recognizes National Consumer Protection Week, 2025 top-five robocall scam categories (released March 6, 2026)
  5. Federal Trade Commission — Complying with the Telemarketing Sales Rule (business guidance)
  6. Cornell Law School Legal Information Institute — 47 U.S.C. Section 227, Telephone Consumer Protection Act
  7. TheAffordableAI — Pricing

Put this on your own phone line

See the AI dial, qualify, and warm-transfer a live call in under a minute. No contract, no dev work.

← All articles