Showing posts with label agent fraud. Show all posts
Showing posts with label agent fraud. Show all posts

Friday, October 11, 2024

CMS puts ACA agents and agencies on notice: Immediate suspension if fraud is suspected

Note: All xpostfactoid subscriptions are now through Substack alone (still free), though I will continue to cross-post on this site. If you're not subscribed, please visit xpostfactoid on Substack and sign up


Scout's honor won't cut it

Early this month, CMS released its annual proposal to update various rules governing the ACA marketplace, the Notice of Benefit and Payment Priorities (NBPP) for 2026. In one section, CMS proposes to clarify and perhaps expand upon its ability to swiftly suspend health insurance agents, agencies, and web-brokers (commercial enrollment platforms) suspected of fraud.

The proposed rule clarifies the conditions under which CMS will do what it is already doing under existing authority: Seek out and immediately suspend individuals* and entities whose enrollment records suggest a pattern of unauthorized enrollments and plan-switching and/or falsified income or eligibility information. Systemic failure to protect clients’ personally identifiable information is also grounds for immediate suspension.


Thanks for reading xpostfactoid! Subscribe for free:

In clarifying its authority and intent to act swiftly to shut down agent fraud, CMS acknowledges that such fraud has escalated in the past year:

Since the start of PY 2024 Open Enrollment, we have seen an increase in complaints from enrollees, applicants, and other individuals and entities to the Agent/Broker Help Desk regarding enrollments submitted without enrollee or applicant consent, enrollee or applicant eligibility applications submitted with incorrect information and without enrollee or applicant review or confirmation of the eligibility application information, and changes to enrollee or applicant eligibility applications made without enrollee or applicant consent.

The patterns of fraudulent behavior CMS states it will seek out closely mirror the allegations in the putative class action lawsuit filed (and amended here) against agencies TrueCoverage and Enhance Health and TrueCoverage’s captive web-brokers, BenefitAlign and Inshura, which CMS suspended this past August. (Inshura is simply TrueCoverage’s rebranding of the Enhanced Direct Enrollment platform BenefitAlign.) Indeed, the allegations of fraud patterns in the proposed rule read in part rather like an answer to the suit BenefitAlign filed to force CMS to lift its suspension (CMS’s fourth suspension of TrueCoverage, Inshura and/or BenefitAlign since 2018). Among the suit allegations echoed in the proposed rule changes:

Monitoring web-brokers (EDE platforms)

Past investigations using system monitoring data have borne results that show a connection between potentially noncompliant, fraudulent, or abusive behavior and the trends we monitor. For example, we monitor the number of unsuccessful person searches on approved Classic DE and EDE partner sites because, in our experience, there is often a correlation between a high volume of unsuccessful person searches and noncompliant, fraudulent, or abusive behavior. The person search feature is intended to help agents, brokers, and web-brokers find consumer applications to prevent duplicate enrollments, but in our experience, bad actors use this feature to find applications and make plan changes or NPN changes without consumer knowledge or consent, negatively impacting the consumer and compliant agents, brokers, and web-brokers.

(The recently-suspended BenefitAlign alleges in its suit that it processed 1.6 million enrollment applications in Open Enrollment for PY 2024.)

Monitoring agencies

Discovering agency-wide resources, such as company practices or directives, training manuals, or marketing material that suggests agency endorsement of or involvement in misconduct or noncompliant behavior or activities is another source of information we would use to determine whether to engage in a compliance review or take an enforcement action…

we have seen agency documentation instructing agents and brokers who work at the agency to fabricate enrollee or applicant incomes on eligibility applications submitted to the FFEs or SBE–FPs to ensure the enrollee or applicant has a zero-dollar policy….

Additionally, as part of these investigations and actions, we have reviewed agency procedures and directives instructing agents and brokers who work at the agency to not speak with the enrollee or applicant prior to enrolling them in a plan.

Monitoring agents

A non-exhaustive list of agent or broker data we monitor to identify behaviors or activities that may be indicative of misconduct or noncompliance with applicable HHS Exchange standards or requirements includes: (1) the number of Exchange transactions submitted to the FFEs or SBE–FPs to change enrollee or applicant eligibility application information or plan selections, (2) the volume of person search activities, (3) the number of submitted eligibility applications with missing Social Security Numbers (SSNs), (4) the number of enrollments submitted within a specified timeframe, and (5) the volume of submitted eligibility applications with NPN changes. We also review and consider complaints from enrollees, applicants, and other individuals or entities concerning agent and broker activities.

In elaborating its intent to respond to suspicious activity with immediate suspensions, CMS stresses that it already has the authority to do this. Part of the proposed rule is devoted to affirming CMS’s intent to focus not just on individual agents but also on agencies that employ many agents and exhibit a pattern of encouraging or mandating noncompliant behavior. CMS notes that some 640,000 enrollments record the National Producer Number (NPN) of an agency, rather than an individual agent. In cases where agency-level misconduct is suspected, CMS affirms its intent to direct enforcement action “at the lead agent(s) and any other agent, broker, or web-broker who is discovered to be involved in the misconduct or noncompliant activity.”

While CMS points toward a significant number of enrollments that show an agency’s NPN rather than an individual’s, agents who have had their clients poached complain that when rogue individual agents are identified, there is often nothing to tie them to an agency that may be training and directing them in bad practice. Hence, perhaps, CMS’s emphasis on analyzing EDE data (hello, BenefitAlign) and getting hold of actual agency training materials as well as on including applications with agency NPNs in its analysis.

With regard to imposing immediate suspensions of agents, agencies and web-brokers suspected of fraud or noncompliance, CMS stresses that it already has that authority. Its only proposed change to the existing provision granting that authority, CFR 45 § 155.220 (k)(3), is the addition italicized below:

HHS may immediately suspend the agent's or broker's ability to transact information with the Exchange if HHS discovers circumstances that pose unacceptable risk to the accuracy of the Exchange's eligibility determinations, Exchange operations, applicants, or enrollees, or Exchange information technology systems, including but not limited to risk related to noncompliance with the standards of conduct under paragraph (j)(2)(i), (ii), or (iii) of this section and the privacy and security standards under § 155.260, until the circumstances of the incident, breach, or noncompliance are remedied or sufficiently mitigated to HHS' satisfaction.  

The first part of the federal code alluded to, paragraph (j)(2)(i), (ii), or (iii) of CFR 45 §155.220, lays out the conditions generally violated by the agent fraud or sloppy practice that’s come into focus recently. These include requirements that the agent provide both the client and the marketplace with accurate information; document that the client has taken positive action to affirm that the information provided to the marketplace is accurate; provide contact information that verifiably belongs to the client; provide an income estimate calculated by the client; and document that the client has taken action to confirm consent for the agent to assist with the application.

As much of the fraud of the past year-plus was at least initially enabled by vague rules concerning the obtaining of client consent, the NBPP also proposes modifying a Model Consent Form created in 2023 as part of the 2024 NBPP. The update would “include a section for documentation of consumer review and confirmation of the accuracy of their Exchange eligibility application information.” Startlingly, CMS confesses, “Until we finalized new requirements related to consumer consent in the 2024 Payment Notice, there was no mandate to document the receipt of consent of the consumer or their authorized representative, or to maintain such documentation.” That was the loophole that the unauthorized plan-switching/unauthorized enrollment gravy train drove through. While the requirement was in place for Plan Year 2024, enforcement lagged behind.

The second section of CFR 45 alluded to above, §155.260, lays out the exchange’s responsibility to protect applicants’ personally identifiable information (PII) and the responsibility of non-exchange entities that gain access to PII to maintain the security of that information. CMS cited failure to protect PII (by sharing it with overseas subsidiaries) in suspending the EDE BenefitAlign.

CMS more or less explicitly states that the purpose of the proposed added language is to send a message:

Though we believe our current authority in § 155.220(k)(3) allows HHS to implement system suspensions broadly based on circumstances that pose unacceptable risk to Exchange operations or Exchange information technology systems, in light of the increasing complaints about unauthorized enrollments, we propose amendments to § 155.220(k)(3) to increase transparency concerning the reach and application of system suspensions and more accurately capture in regulation when HHS may invoke this authority. These proposed amendments would allow HHS to immediately respond to discovered risks to the accuracy of Exchange eligibility determinations, Exchange operations, applicants, or enrollees, or Exchange information technology systems. They would also provide agents and brokers with an increased understanding of our approach to implement system suspensions. The proposed amendments would also better encapsulate the original intent of the § 155.220(k)(3) suspension authority, which included protecting against unacceptable risk to consumer Exchange data.

Agents and agencies are thereby placed on notice: ‘We will shut you down if you can’t document that your clients have attested to the accuracy of information provided on the application and confirmed their permission for you to act on their behalf.’


* Suspension under the provision in question, CFR 45 §155.220 (k)(3), does not terminate an agent’s registration with the marketplace, and agents can submit evidence that the suspension is unwarranted, or that the flagged conduct has been remedied or mitigated to HHS’ satisfaction. Agents suspended under this provision can continue to assist clients with enrollment, either by phone or “side-by-side” on Healthcare.gov, but not independently on an EDE platform. Suspension under other provisions, §155.220 (f) or (g), in contrast, suspend or terminate the agent’s exchange agreement.

Thanks for reading xpostfactoid! Subscribe for free:

Photo by Bryce Carithers 


Thursday, August 22, 2024

What's driving CMS's sudden clamp-down on agent fraud?

 Note: All xpostfactoid subscriptions are now through Substack alone (still free), though I will continue to cross-post on this site. If you're not subscribed, please visit xpostfactoid on Substack and sign up.

Unauthorized plan-switching in the ACA marketplace, whereby health insurance agents access an existing enrollee’s account, list themselves as the agent of record (AOR), and switch the enrollee into a different plan without the enrollee’s knowledge or consent (or with nominal, uncomprehending consent), obviously hurts enrollees who try to use their health insurance and find that they’re no longer enrolled because they’ve been switched to a different (often inferior) plan.

The poaching also hurts other agents, who in many cases find their clients poached en masse, often by large call centers engaged in wholesale fraud. Agents and their trade organizations, such Health Agents for America (HAFA) and the National Association of Benefits and Insurance Professionals (NAPIB) have long complained that CMS has not acted vigorously enough to quell the fraud. That changed rather suddenly last month, when CMS dropped a hammer — or a series of hammers — on agents’ access to enrollees’ accounts. Why?


Thanks for reading xpostfactoid! Subscribe for free:

First, as quickly as possible, some background on the unauthorized plan-switching scandal, news of which Julie Appleby of Kaiser Health News first broke in April (that story is an excellent introduction; see also this from me on gray-area fraud). While agents’ licenses impose professional obligations, and agents must put their name and identifying number on an account to get paid by insurers, unauthorized plan-switching in the 32 states that use the federal exchange, HealthCare.gov, has been mechanically easy for agents via federally approved commercial Enhanced Direct Enrollment (EDE) platforms, which streamline the enrollment process and provide agents with various CRM tools. More than three quarters of enrollments in HealthCare.gov states are agent-assisted, and more than 80% of broker-assisted enrollments are via EDE (none of the 19 state-based marketplaces have as yet enabled EDE enrollment; most have their own agent portals which function similarly). Until last month, agents could locate and act on any existing account armed only with the enrollee’s name, date of birth, and state of enrollment. While agents are legally obligated to obtain and document client consent before acting on an account, that requirement was until recently loosely enforced. Agents engaged in plan-switching obtain their leads through often-unscrupulous ads, which misrepresent premium subsidies as cash that can be used for other expenses. Those ads are often sold to multiple agencies, which then compete for the same respondents to the misleading incentives.

Unauthorized plan-switching and new enrollments received major stimulus from the enhancements to marketplace premium subsidies created by the American Rescue Plan and implemented in March 2021, which rendered benchmark silver plans free to enrollees with incomes up to 150% of the Federal Poverty Level (FPL). Plan-switching received further stimulus from a rule implemented in early 2022 that provided applicants in states using the federal exchange with income below 150% FPL (the threshold for free silver coverage) with access to a Special Enrollment Period (SEP) in any month of the year — that is, they can enroll year-round, and change plans monthly. (16 of the 19 state-based marketplaces (SBMs) have implemented this SEP as well.)

In a very real sense, there is no off-season in HealthCare.gov states, though Open Enrollment Period (OEP) only runs from Nov. 1 to Jan. 15.In HealthCare.gov states, 55% of all enrollees in 2024 (just shy of 9 million) claimed incomes below 150% FPL. The vast majority of them — 87% — were in the 10 states that have refused to enact the ACA Medicaid expansion (they include behemoths Florida and Texas). In those states, eligibility for marketplace premium subsidies begins at 100% FPL, compared to 138% FPL in expansion states, where people with income below that threshold are eligible for Medicaid. Nearly all of these enrollees qualify for free benchmark silver coverage, and millions more with higher incomes qualify for free bronze coverage. The dramatic ACA enrollment growth of the past three years is concentrated in those states — as is the agent fraud.

In July, CMS changed gears

As fraud escalated through 2023 and 2024, agents and their trade groups have urged CMS to take preventive measures. Most of the SBMs require some form of two-factor authorization from the client before an agent can act on an existing account that has a prior AOR, or no AOR. CMS has rather gloried in the near-100% enrollment growth in enrollments in the federal exchange from 2021-2024. Much of that growth is attributable to increased agent engagement: the ranks of agents registered with the federal marketplace increased from 49,000 in 2018 to 83,000 in 2024. The growth is concentrated among low-income enrollees who often can be hard to reach and may have difficulty with two-factor authorization. CMS seemed reluctant to implement measures similar to those deployed by SBMs, where enrollment growth has been much slower. In May, Ronnell Nolan, president and CEO of HAFA, told KHN’s Julie Appleby about CMS, “We’ve given them a whole host of ideas…They say, ‘Be careful what you wish for.’”

Then, on July 19, CMS gave agents perhaps more than they had wished for, announcing System Changes to Stop Unauthorized Agent and Broker Marketplace Activity. From that point forward, agents seeking to act on an existing account with a different AOR or with no AOR would have to conduct a three-way call with the client and the marketplace center “or to direct the consumer to submit the change themselves through HealthCare.gov or via an approved Classic Direct Enrollment or Enhanced Direct Enrollment partner website with a consumer pathway.”

To unpack the latter option as implemented (briefly —see below) by HealthSherpa, the dominant EDE: An agent could make changes on a new client’s existing account but, prior to execution, would receive an error message to be forwarded to the client, with a link that the client could click on to complete and execute the application.

On message boards, agents commenting on the three-way calls worried that the lines would seriously back up during the upcoming Open Enrollment Period, but most who did the calls reported that they went pretty smoothly (although, in accord with existing policy, the call center agents are obligated to read through the entire application before enabling a change). HealthSherpa’s faster workaround appeared to be working with minimal friction.

But then, on August 2, CMS paused the HealthSherpa procedure , apparently worried that some agents might be faking the address or phone number to which the link was sent. HealthSherpa has submitted a request to CMS to reactivate the procedure with ID proofing instead of 2-factor authentication. I.D. proofing in the marketplace is based on information provided by Experian. To complete changes to an application made by an agent newly attaching to the account, an enrollee would have to provide her Social Security number and other personally identifiable information, then answer a series of questions, such as whether they ever lived at a given address.

HealthSherpa’s Adam Van Fossen pointed out to me that i.d. proofing requires a credit history, which many low-income people, particularly immigrants, don’t have. Requiring i.d. proofing introduces more friction than two-factor authorization, which CMS had previously seemed reluctant to introduce. 2FA appears to be effective in the SBMs, where agent fraud does not appear to be an acute problem — though that is partly because all of the 19 SBM markets (18 states and DC) have expanded Medicaid, which vastly reduces the target market of low-income enrollees eligible for zero-premium coverage (who are less likely to notice unauthorized plan switches, as they do not pay their insurers monthly). Van Fossen said that the two-factor process HealthSherpa deployed was not generating widespread fraud (e.g., by agents attributing a phone number of their own to the client), and that the company was putting further controls into place before CMS shut the process down.

CMS also seems to be expressing a new leeriness about agent-assisted enrollment generally, after years of cheerleading growing agent engagement (beginning in the private market-friendly Trump administration but very much continued by Biden’s team. In an Aug. 13 email bulletin asking recipients to “help CMS spread the word about marketplace fraud prevention” promotes this message to consumers: “For free, non-biased personal help, call the Marketplace Call Center at 1-800-318-2596… Marketplace Call Center representatives don’t get any incentives for signing you up” (my emphasis).

CMS has also started to ramp up suspensions of agents suspected of fraud or bad practice — though HAFA’s Ronnell Nolan complained as recently as late July that the 200 agents CMS had reported suspending as of July 19 was a “very low” total.

Something or someone seems to have lit a fire under CMS. Who and why?

One might infer that political pressure kicked in. Republicans have seized on the reports of widespread agent fraud (which hit mainstream news this past April) to deploy arguments against extending the life of the premium subsidy enhancements, currently funded only through 2025 (widespread free coverage, they argue, has stimulated widespread fraud). On the Democratic side, Senate Finance Committee Chair Ron Wyden and five colleagues have introduced legislation that would impose stiff fines on agents for submitting incorrect information, subjecting them to criminal liability for outright fraud, and “establish a consent verification process for new enrollments and coverage changes that includes notifying individuals when there has been a change in their enrollment, agent of record, or tax subsidy.”

In a high-stakes election season, shutting down fraud seems to have trumped juicing enrollment as a priority. Perhaps the pressure has emanated from the White House, or from the Harris campaign. Speculation, but the change in CMS’s approach does seem abrupt.


Thursday, June 13, 2024

Red flags in agent-assisted enrollment stats in the ACA marketplace

 Note: All xpostfactoid subscriptions are now through Substack alone (still free), though I will continue to cross-post on this site. If you're not subscribed, please visit xpostfactoid on Substack and sign up.

CMS to marketplace agents, May 24, 2023


A May 2023 CMS presentation to health insurance agents and brokers selling ACA marketplace plans opens on a celebratory note. Enrollment in the Open Enrollment Period for 2023 was up 19% year-over-year in the 33 states using the federal exchange, HealthCare.gov. CMS implicitly credited brokers for much of the surge, noting:

The Plan Year (PY) 2023 Open Enrollment Period (OEP) was the strongest year yet for agents and brokers assisting consumers through the Marketplace.

CMS noted that agents* assisted 6.8 million active enrollments in HealthCare.gov in PY 2023, which comes to 70% of the active enrollment total (“active enrollment” excludes 2.5 million auto-re-enrollments, for which agents or other assisters are not credited). CMS further noted that 74,100 agents were registered with HealthCare.gov in PY 2023.