Route Medicare Advantage, Medigap, Part D, ACA, dental, and vision leads to licensed agents and carriers under strict federal and state rules. Encrypted data handling, TCPA consent evidence on every lead, state licensure filters, and per-carrier caps on one engine.
Real-Time
Routing decision
AES-256-GCM
Encryption at rest
Row-level
Tenant isolation
Audit logged
Every access
The Reality
Health insurance and Medicare carry a stack of federal and state rules that most generic routers were never designed to handle.
Healthcare leads can include sensitive health information. Health-data privacy rules and rules for outreach can apply. Medicare Advantage and Part D marketing also has CMS requirements. See the Medicare Communications and Marketing Guidelines. Your team needs to check which rules apply to the data and outreach you plan.
Healthcare intake needs controls for sensitive data, consent evidence, product-specific limits, and licensed service areas. On January 24, 2025, the Eleventh Circuit vacated the one-to-one and logically-and-topically-associated consent restrictions in Part III.D of FCC 23-107. Those vacated restrictions are not a current federal one-to-one requirement. Existing TCPA obligations still apply to the relevant calls and texts. Set up each program from its actual requirements. A routing platform does not decide whether an outreach program meets them.
Lead Router was built for operators who sell into this environment. The same routing engine that handles auto, solar, and home services comes with the compliance controls healthcare needs, and the controls are designed so the compliance team and the revenue team see the same record.

How Lead Router Solves It
The compliance controls that make Medicare, ACA, and ancillary health work inside one routing engine.
Lead payloads are encrypted at rest with AES-256-GCM and moved in transit over TLS 1.2 or higher. Tenant rows are isolated at the query layer so one client cannot read another client's data. Every read, write, and export is audit logged with actor, action, and timestamp, and role-based access controls scope who can see sensitive health-related lead data.
The verbatim consent language shown on the form, the consent timestamp, the submitting IP, and the user agent are stored with the lead, alongside TrustedForm certificate URLs and Jornaya LeadiD tokens when your intake captures them. That record goes out with every sale and stays intact on export, so a carrier audit or a demand letter is answered from the lead itself.
Contracts can gate on agent state licensure so a Medicare Advantage lead in Florida only routes to carriers and agents licensed in Florida. Product filters split Medicare Advantage, Medicare Supplement, Part D, ACA on-exchange, ACA off-exchange, dental, vision, and supplemental so a dental-only buyer never pays for an MA lead.
Daily, weekly, and monthly caps track by carrier, by product, by state, and by agent. A United Medicare Advantage contract can cap at 200 Florida leads per day while a Humana Part D contract caps at 75 Texas leads per week. Caps cut off the contract automatically and the lead fails over to the next eligible buyer in the waterfall.
Medicare and health insurance calling rules vary by state and by federal guidance, so every contract has its own schedule: a time zone plus day-of-week and hour windows. The routing engine skips any contract whose window is closed. A live-transfer buyer is not handed a lead outside the hours you set for them. Form-lead buyers on their own schedule can still take the lead for next-day outreach.
Set up delivery to a carrier or aggregator endpoint you are approved to use. Map the intake fields that each destination requires, then test the response before sending live leads. Your team checks the carrier requirements and the rules for the program.
Inside Lead Router

Where It Fits
Health and health-adjacent product lines, with the filters and field schemas each one requires.
Delivery Targets
Lead Router delivers to whatever endpoint a carrier or aggregator exposes for lead intake.
Delivery happens over HTTPS POST, generic webhook, email, or Google Sheets. Field mapping is set per contract, so each destination gets the format it expects. Medicare-specific fields (Medicare Beneficiary Identifier intent, Part A effective date, Part B effective date, plan year, and scope-of-appointment confirmation) are mapped per buyer. Health and Medicare teams route leads into carrier and aggregator intake endpoints. Carriers like UnitedHealthcare, Humana, and Aetna and the major Medicare and ACA aggregators accept standard lead posts. You keep one intake form, and the router translates it for each destination.
TrustedForm certificate URLs and Jornaya LeadiD tokens are captured at form submit and forwarded on the outbound post so the buyer receives the consent-certificate URL with every sale. The posting log records the exact payload, the HTTP response, and the timestamp for every delivery, which is the record auditors ask for first.
Live transfer is available on the same engine. Ping-post picks the winning buyer, the call bridge fires, and the same MA, ACA, or dental filters that apply to a form post apply to the call as well. See the ping-post and lead distribution pages for how the routing mechanics work across channels.
Compliance Posture
The architecture and policy docs are public so buyers, partners, and auditors can read them before asking.
Lead Router is built security-first. Data at rest uses AES-256-GCM, data in transit uses TLS 1.2 or higher, tenant data is isolated at the query layer, role-based access controls scope who can see sensitive health-related lead data, and every read, write, and export is audit logged.
Lead Router keeps the consent text, timestamps, and certificate references supplied by the intake. It can also capture consent directly when you set that up. Operators remain responsible for obtaining valid consent for their outreach and configuring delivery of the relevant evidence. See consent capture and evidence workflows.
Frequently Asked
The questions healthcare operators ask before signing on.
AES-256-GCM encryption at rest, TLS 1.2 or higher in transit, row-level tenant isolation, role-based access controls, and full audit logging of every access. One client cannot read another client's data, and every read, write, and export is recorded with actor, action, and timestamp.
Yes. Set contract filters for the fields your Medicare program needs, such as plan year, service area, or scope-of-appointment confirmation. Map the fields to each buyer’s posting spec and set its caps. Your team must confirm licensing, consent, and CMS requirements before sending traffic.
Yes. Scope-of-appointment data is captured through custom fields on the intake form and stored with the lead record. The scope confirmation, the products the consumer agreed to discuss, and the timestamp are forwarded to every downstream carrier that requires the data. A buyer whose contract requires scope cannot win a lead that does not carry a valid scope record.
Calling windows are set per contract. Each contract has a schedule: a time zone plus day-of-week and hour windows. The routing engine checks it on every decision and skips any contract whose window is closed. A live-transfer buyer is not handed a lead outside the hours you set for them. The lead can still go to form-lead buyers whose own window is open. Because the schedule sits on the contract, you can tune it by product, by carrier, and by state.
Route Healthcare Cleanly
Encrypted data handling, TCPA consent evidence on every lead, state licensure filters, per-carrier caps, and multi-channel distribution on one engine.