1.HIPAA
When CallBlade handles protected health information on behalf of a covered entity or business associate, CallBlade does so under a Business Associate Agreement and applies administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including access controls, encryption, workforce training, and minimum-necessary access.
2.Medicare marketing (CMS)
For campaigns involving Medicare Advantage or Part D plans, CallBlade and its clients comply with the Centers for Medicare & Medicaid Services marketing and communications requirements for Third-Party Marketing Organizations (TPMOs), including:
- delivering the required TPMO disclaimer within the first minute of sales calls, in the required form;
- recording sales, marketing, and enrollment calls in their entirety, and retaining those recordings for ten (10) years;
- not using unsolicited outbound calls to Medicare beneficiaries except as permitted by CMS rules;
- using only client-approved, compliant scripts; and
- supporting client and plan sponsor oversight, audits, and TPMO reporting.
3.Client responsibility
Licensing, carrier appointments, plan sponsor requirements, Scope of Appointment rules, and marketing material approvals remain the responsibility of the client and its licensed agents.
