Clicking the first result when you search for Medicare or a health plan can drop you onto a scammer’s site

Senior man doctor working with laptop computer professional senior mature healthcare expert searchin

People searching online for Medicare enrollment or health insurance quotes are landing on sites designed to harvest their personal data, and federal regulators are treating the problem as an industry-wide pattern rather than a string of one-off scams. The Federal Trade Commission sent warning letters to healthcare plan marketers and lead generators in December 2024 over deceptive ads that mimic official enrollment channels. Separately, Assurance IQ and MediaAlpha agreed to pay a total of $145 million to settle FTC charges that they misled consumers seeking health insurance. The Centers for Medicare and Medicaid Services has also notified beneficiaries that fraudulent Medicare.gov accounts were created between 2023 and 2025 using valid personal information.

How search results funnel Medicare beneficiaries to impostor sites

The core risk is simple: a consumer types “Medicare” or “health plan” into a search engine, clicks the top result, and ends up on a page that looks official but exists to collect Social Security numbers, dates of birth, or Medicare IDs. The FTC has documented how paid and organic search listings use false incentives and misleading branding to pull people away from legitimate enrollment portals. In a consumer alert on addiction-treatment searches, the agency described how sponsored results can impersonate trusted providers and divert callers to unrelated operations. The same mechanics apply to health-plan shopping, where the stakes include both financial loss and medical identity theft.

Once scammers obtain a Medicare number, they can bill the program for services never provided or open new accounts in the beneficiary’s name. The HHS Office of Inspector General warns that stolen Medicare identifiers can fuel both identity theft and improper billing, and its guidance on medical identity theft urges people to review Medicare Summary Notices, question unknown charges, and report suspicious activity quickly. Victims are directed to contact Medicare through official channels and to treat any unexpected calls or emails requesting additional information as potential red flags.

FTC enforcement and the $145 million settlement

Federal action against deceptive health-plan marketing has accelerated. In December 2024, the FTC sent formal warning letters to healthcare plan marketers and lead generators, citing repeated use of misleading ads and false incentives designed to capture consumer data during open enrollment periods. Regulators said these tactics may violate the FTC Act’s ban on deceptive practices, the Telemarketing Sales Rule’s requirements for truthful disclosures, and the agency’s Impersonation Rule, which targets entities that pose as government agencies or well-known brands.

The largest financial consequence so far came when Assurance IQ and MediaAlpha agreed to pay $145 million to resolve charges that they misled people shopping for coverage. According to the FTC, the companies operated a lead-generation pipeline that steered consumers through confusing online forms and marketing funnels, obscuring who would receive their information and what products were actually being sold. The settlement signals that regulators are willing to pursue significant penalties against intermediaries that build and monetize these funnels, not just the insurers that ultimately sell policies.

Although the enforcement actions target specific firms, the FTC has framed the underlying conduct as systemic. Warning letters and settlements emphasize that marketers cannot bury consent in fine print, misrepresent affiliations with Medicare, or suggest that consumers must provide detailed personal data simply to check eligibility. By treating deceptive lead generation as an industry problem, regulators are pushing brokers and advertising networks to overhaul how they acquire and share consumer information.

CMS alerts about fraudulent Medicare accounts

Regulatory concern is not limited to advertising. The Centers for Medicare and Medicaid Services recently disclosed a data incident in which bad actors created or accessed online beneficiary profiles using authentic personal details. In its announcement, CMS said it was notifying individuals whose information may have been exposed and offering resources to help them monitor for misuse. The agency’s notice on potentially impacted individuals underscores that even when Medicare’s core systems remain secure, fraudsters can exploit consumer data gathered elsewhere to open unauthorized accounts.

These fraudulent profiles can be used to change contact information, request replacement cards, or facilitate false billing. CMS urged beneficiaries to review their Medicare statements, look for unfamiliar providers or services, and contact Medicare immediately if they see anything they do not recognize. The agency also reminded people that official representatives will not pressure them to share full Social Security numbers, bank details, or passwords over the phone or via unsolicited email.

How beneficiaries can protect themselves

Experts say Medicare beneficiaries can reduce their exposure by starting at trusted entry points rather than search engines. Typing Medicare.gov directly into a browser, calling 1-800-MEDICARE, or working with a known local counselor can help avoid impostor sites that rank highly in search results. Consumers should be wary of ads that promise “free” benefits unrelated to their current coverage, countdown timers that claim enrollment is closing within hours, or forms that demand sensitive data before showing any plan options.

Security advocates also recommend treating a Medicare number like a credit card: share it only with providers you know, keep copies of statements, and dispute charges that do not match services received. If someone suspects their information has been misused, they can report it through Medicare, contact the HHS Office of Inspector General, and place fraud alerts with credit bureaus. While regulators move against deceptive marketers and data misuse, beneficiaries who recognize the warning signs of impostor sites and fraudulent accounts remain the first line of defense.