CMS's ACA Marketplace sends zero fraud alerts; states send some
Summary
Confirmed complaints about unauthorized health-plan enrollments and switches on HealthCare.gov grew more than fourfold from 2023 through 2025, according to CMS data GAO reviewed -- and GAO's own investigative work found at least 160,000 federal Marketplace applications in plan year 2024 had likely unauthorized changes. GAO's July 13, 2026 report found CMS's federal Marketplace doesn't verify consumer consent before an agent or broker acts, doesn't restrict record access to the agent already tied to a consumer's account, and sends no notification at all when a person search, enrollment change, or agent-of-record change happens on a consumer's account. All three state-based Marketplaces GAO examined -- California, Georgia, and New Mexico -- send at least one of those notifications, and New Mexico's BeWell sends all three, using one-time passcodes CMS doesn't require. CMS implemented weaker consent procedures in 2024 that GAO found don't prevent unauthorized actions because they aren't always used. GAO made two recommendations; HHS concurred and is considering stronger controls, possibly by open enrollment for plan year 2027.
Consent that isn't verified, records anyone can see
's federal Marketplace doesn't verify that an agent or broker actually obtained consumer consent⧉ before carrying out enrollment activities, doesn't restrict access to a consumer's Marketplace record to the agent already on file, and doesn't inform consumers of all agent or broker actions taken on their accounts. In 2024, added procedures meant to strengthen consent -- but found they don't prevent unauthorized actions because they aren't consistently used, and takes only limited steps to confirm who's actually consenting.
Zero notifications, versus states that send at least one
compared the federal Marketplace against three state-based ones -- California, Georgia, and New Mexico⧉. All three require a one-time passcode (or, in California's case, a passcode or three-way call) before an agent or broker can act on a consumer's enrollment; the federal Marketplace requires none. On notifications specifically, the federal Marketplace sends none of the three types tracked -- person searches, new enrollments or changes, agent-of-record changes. Georgia sends one. California sends two. New Mexico's BeWell sends all three.
View data as table
| BeWell New Mexico | 3 |
|---|---|
| Covered California | 2 |
| Georgia Access | 1 |
| Federal Marketplace | 0 |
CMS's fix is still just an idea
told it's exploring options for stronger controls⧉ in time for the open enrollment period for plan year 2027 -- but hadn't decided on anything as of this report. made two recommendations: build stronger consent, access, and notification controls (including a one-time passcode), and periodically review whether those controls still work. concurred with both and described steps it's considering; lists both as open.
The takeaway
- Unauthorized-enrollment complaints more than quadrupled in two years. Confirmed complaints grew 4x-plus from 2023 to 2025, and separately found at least 160,000 likely-unauthorized applications in plan year 2024 alone.
- The federal Marketplace sends zero of the three consumer alerts state Marketplaces send. No notification of person searches, enrollment changes, or agent-of-record changes -- while California, Georgia, and New Mexico each send at least one, and New Mexico sends all three.
- 's 2024 fix doesn't actually stop unauthorized activity, and the real fix is still undecided. The new consent procedures aren't consistently used; is only 'exploring options' for 2027, and 's two recommendations remain open despite 's concurrence.
All findings are from -26-108297, "Health Insurance Marketplaces: Needs Stronger Controls to Prevent Unauthorized Actions by Agents and Brokers," published and publicly released July 13, 2026 -- read directly in full (33 pages), not just the Highlights summary. 's site also catalogs this same testimony/report under a second product number, -26-108041, with identical findings; this piece cites -26-108297 alone rather than treating the two catalog entries as independent sources. The 160,000-application figure was first reported by in December 2025 from preliminary, ongoing investigative work and is reiterated here.
Sources(1) ▾
- U.S. Government Accountability Office, Health Insurance Marketplaces: CMS Needs Stronger Controls to Prevent Unauthorized Actions by Agents and Brokers (2026-07-13) — -26-108297, published and publicly released July 13, 2026. Read the full 33-page PDF directly (extracted with pdftotext -layout) -- the state-Marketplace comparison table and exact recommendation text are only in the full report, not the Highlights summary. Note: 's site also independently catalogs this same testimony/report content under a second product number, -26-108041 (identical Highlights text, same recommendations, same contacts, a 32-page rather than 33-page full-report variant) -- direct text comparison confirms these are the same underlying work reachable via two catalog URLs, not two distinct products, so this piece cites -26-108297 alone as the canonical source rather than treating both as independent evidence. Direct gao.gov PDF asset access intermittently returns HTTP 403 and the Wayback lookup endpoint was rate-limited (HTTP 429) at capture time; the Artemis-sealed copy of the product page serves as the one-click capture. gao.gov · original document
Comments
Always open. Logged-in readers can annotate paragraphs in place.
Confirmed complaints about unauthorized health-plan enrollments and switches on the federal Marketplace grew more than fourfold from 2023 through 2025⧉, according to data reviewed. Separately, 's own investigative work found at least 160,000 federal Marketplace applications in plan year 2024⧉ had likely unauthorized changes. 's July 13, 2026 report explains why: the controls meant to stop it are weak.