Skip to content
Hugin
A silver pen tethered to a thin bead chain, lying on a dark steel counter.

Journal

When someone else can click 'I agree' in your name, the record stops proving that you agreed. This week's federal records show who finds out last: the person named on it, often from a tax form.

8 min read

Original editorial artwork generated for Hugin.

On August 31 federal officials canceled about 315,000 HealthCare.gov marketplace policies covering more than 760,000 people. The rule that followed describes them this way: enrolled through an agent or broker, no verified citizenship or immigration documents, no claims, and nobody the insurer could reach. On September 24 a federal judge sentenced a man whose scheme filed more than 500 pandemic unemployment claims in 27 states under at least 375 stolen identities, and the FTC asked whether the ad tools that platforms sell help impersonators find people. These records share one shape. Someone acted in another's name without them, and the paperwork could not tell the difference. CMS says a victim may first learn of it from a Form 1095-A at tax time, and the Labor Department says the same of the 1099-G. Fixes keep arriving long after the harm, because the evidence that justifies them arrives late. The defense is to read your own records at the source before someone else's paperwork does. A checklist for before November 1 follows.

consentidentity-thefthealth-insuranceimpersonation-scamsconsumer-protectionopen-enrollment

On August 31, federal officials canceled about 315,000 policies in the health insurance marketplace behind HealthCare.gov, covering more than 760,000 people. In a rule published September 23, the Centers for Medicare & Medicaid Services described those people mostly by absences. They were enrolled with agent or broker assistance, without verified citizenship or immigration documentation, and were people "for whom issuers were unable to identify claims or establish consumer contact."

Read that twice. The enrollment went in through an intermediary. It came out, in part, because nobody could reach the person it named. Neither the rule nor the fact sheet describes a moment when that person said yes, or no.

On September 24, a federal judge in Pennsylvania sentenced a man to ten years in prison for a scheme that filed more than 500 pandemic unemployment applications in 27 states under at least 375 stolen identities, all current or former employees of one company. The same day, the Federal Trade Commission asked whether the ad tools that platforms sell are helping impersonators reach people.

Three records, one shape. Someone acted in another's name, without them, and the system could not tell the difference.

Consent became a field someone else fills in

On paper, consent is an act: your signature, in your hand. In an electronic system run through an intermediary, it is a value submitted with the application, and the system accepts it from whoever is at the keyboard. CMS says this about its own application, describing data points it tracks because they correlate with unauthorized enrollment:

Each of the above factors represent a point in the enrollment application that is self-attested or unverified, which creates an opening for agents and brokers to submit or alter enrollment data without a genuine, informed decision from the consumer.

Then look at who submits it. Brokers, the rule explains, "typically earn a per-member-per-month commission" for each active enrollment. The party recording your consent is paid when the answer is yes. That is not an accusation against brokers as a class; the rule pins the pattern on a subset of them. A consent field filled in by someone paid per yes proves that they wanted a yes.

The portable rule: whenever someone else records your consent, ask three questions. Who submitted it? Who is paid when it says yes? Where can you read the record yourself, without going through them?

You find out from a tax form

CMS says a person enrolled without their knowledge "may only learn of this coverage upon receipt of a Form 1095-A from the Marketplace at tax time". The Labor Department says nearly the same about a different form: many victims "only find out when they get something in the mail, like a notice from a state unemployment agency or a state-issued 1099-G tax form reporting unemployment benefits that they never requested or received."

Two agencies, two programs, one sentence. The system knows first. The person named knows last, and the first notice arrives months later with a bill in it.

The bill is real. The CMS rule works through a case: a victim who never corrects the 1095-A, ineligible for a year of the average subsidy, could owe "more than $8,000." SBA, which announced on September 14 that it had suspended 870,000 pandemic borrowers tied to an estimated $39 billion in suspected fraud, says unpaid demand letters can bring collection fees of up to 28 percent and offset against tax refunds and Social Security. A loan taken out in your name stays yours on paper until you prove otherwise, and SBA warns that an identity theft report "alone does not initiate SBA's process of preventing financial harm."

Sometimes the only record you see is written by the intermediary. The CFTC's complaint against Cash FX, filed September 24, alleges that it promised trading by professionals, bots and artificial intelligence, traded with "less than one percent of the pool participant funds that it received for that purpose", and sent "false account statements". A statement produced by the party acting for you is testimony, not a record.

Why the fix keeps arriving after the harm

CMS has been closing this door in stages. On July 19, 2024, it began blocking brokers from changing an enrollment unless they were already associated with it. In October 2024 it reported 90,863 complaints of plans changed without consent, and 183,553 of enrollments made without consent, in that year's first eight months. The new rule counts more than 624,000 confirmed complaints from 2023 through 2025. Now CMS promises electronic consumer authorization before Open Enrollment, and the rule says its additional preventive controls "will not be fully operational before that period begins". It is candid about the pattern: many of its enforcement efforts "operate only after an agent or broker is already registered and conducting transactions."

The FTC's clock runs longer. It opened its impersonation rulemaking with an advance notice in December 2021 and finalized the rule in March 2024. Along the way it proposed covering suppliers who knew, or had reason to know, their goods or services would be used to impersonate, then set that aside in December 2024. This week it started over, with another advance notice and no rule text. Its own diagnosis explains why platforms lag: because many victims blame the impersonated business or the scammer, "digital platforms face little to no market discipline to correct the problem".

The lag is not carelessness. It is built into how harm gets counted. A rule needs evidence; the evidence is complaints; a complaint needs a victim who has noticed, and by the CMS and Labor Department accounts above, victims often notice only when a letter or tax form arrives. So the record that justifies a fix runs months behind the harm, while the party best placed to stop it at the door is paid at the door.

The change CMS has measured put the person back into the transaction. After the July 2024 block, CMS reported that "the overall number of plan changes associated with an agent or broker has decreased by nearly 70%." That is CMS grading itself, but the mechanism is right: a step only the named person can take.

Before November 1

  • Read your own HealthCare.gov record now. Log in yourself, not through a link someone sends you, check that the application and plan on file are the ones you chose, and turn on the login security codes HealthCare.gov offers. If anything is wrong, call the Marketplace Call Center at 1-800-318-2596 (TTY 1-855-889-4325), open around the clock except holidays. If its representatives confirm the change was made without your knowledge, CMS says they can work with your insurer and the IRS to cancel the plan, re-enroll you, repay inaccurate costs and correct your tax forms.
  • Tuesday, September 29, 1 p.m. Eastern (10 a.m. in Arizona). The FTC hosts a public roundtable, with CMS panelists, on health-insurance scams around Open Enrollment. Joining details are on the FTC's event page.
  • November 1. Open Enrollment opens; December 15 is the last day to enroll or change plans for coverage starting January 1. If an authorization request arrives for an application you did not start, do not approve it. Call.
  • Report impersonators and scam ads at ReportFraud.ftc.gov and identity theft at IdentityTheft.gov.
  • At the IRS and Social Security, sign in to your IRS online account, check the authorizations section, and get an Identity Protection PIN, which the IRS says is generally available there from mid-January through mid-November. Then open a my Social Security account and review your earnings history.
  • If a state 1099-G shows unemployment you never received, report it to the state where it happened, through the Labor Department's state directory, and leave that income off your return.
  • If SBA writes about a pandemic loan you never took, send SBA a photo ID, an Identity Theft Report and SBA's Declaration of Identity Theft: PPPidtheftinquiries@sba.gov for PPP loans, IDTheftRecords@sba.gov for COVID EIDL loans.
  • Before anyone trades money for you, check their registration at cftc.gov/check.
  • November 21. Comments close on the CMS rule, docket CMS-2026-3202 at Regulations.gov. The FTC notice's 60-day clock has not started: as of September 27, it had not printed in the Federal Register.

Your name will be on the paperwork either way. What you can still choose is whether you are the first person to read it or the last.

Source links