U65 Health Lead Fraud: How to Buy Verified Leads (2026)

U65 Health Lead Fraud: How to Buy Verified Leads — Elevarus

Share This Post

If you buy health insurance leads, you know the feeling. A batch looks clean on the spreadsheet. Then it turns into a day of dead numbers, people who never heard of your offer, and a few who thought they were signing up for free money. That is not bad luck. Health insurance is one of the FTC’s stated lead-gen priorities, and that is exactly where the junk piles up. This guide is the buyer’s view of that one vertical. Why U65 and private-health leads get faked so often. What the junk actually looks like here. And what to demand from a lead source so you buy verified instead of getting burned again. It is a spoke off our ad fraud in lead generation pillar; here we go deep on the health slice alone.

TL;DR

  • The FTC has named health-insurance lead gen a priority. The enforcement record is the clearest map of where the junk lives: $145M from Assurance IQ and MediaAlpha, $2.5M plus a robocall ban from Fluent.
  • It is a fraud magnet because the payout per health lead is high and the buyers are easy to confuse. Bad actors pull in real people with deceptive offers, then sell the contact details as interest that was never there.
  • U65 is not ACA. U65 is off-exchange private coverage, such as short-term and indemnity plans. ACA is on-exchange marketplace coverage. A source that blends them hands you a mismatch before you even get to fraud.
  • The junk here has a signature. Incentivized and co-registration “give-back” clickers. Aged and resold health data. Bot-filled forms with fake identities. And wrong-intent leads who wanted a reward, not a plan.
  • You buy verified by demanding it. Real-time verification at capture. Consent provenance. Source transparency. No incentivized traffic. And a replacement policy for unreachable leads.

Quick answers:

Why U65 and private-health leads get faked more

Two forces make this vertical a magnet for fake leads, and they feed each other.

The first is money. A qualified health lead is worth a lot. When the payout is that high, faking a lead stops being petty fraud and becomes a business model. The second is the consumer. Health coverage is confusing, costly, and stressful, which makes it easy to hook someone with a deceptive offer.

Put those together and you get the move that defines this vertical. A bad actor pulls in a real person with something that sounds like free coverage. It harvests their contact details. Then it sells them as insurance interest the person never had.

You do not have to take that on faith. The FTC has put it in dollars. On August 7, 2025, the agency announced a $145 million settlement with Assurance IQ and MediaAlpha over misleading consumers who were shopping for health insurance. MediaAlpha sold about 119 million consumer leads in 2024. It pulled that traffic in with government-sounding domains such as ObamacarePlans.com and a made-up “Health Insurance Give Back Program”. Those consumers were then hit with robocalls, including numbers on the Do Not Call Registry.

The FTC was blunt about why it cares. “Coherently and systematically addressing unlawful lead generation is a priority for the FTC,” said Christopher Mufarrige, who runs the agency’s Bureau of Consumer Protection. “That’s especially so in connection to health insurance.” That is the vertical you are buying in.

The FTC Health-Lead Enforcement Record
$145M
Assurance IQ / MediaAlpha
Announced Aug 7, 2025
MediaAlpha sold about 119 million consumer leads in 2024. It pulled that traffic in with government-sounding domains such as ObamacarePlans.com and a made-up Health Insurance Give Back Program. The split was $100M against Assurance and $45M against MediaAlpha.

$2.5M
Fluent, LLC + robocall ban
Operation Stop Scam Calls, 2023
The FTC said Fluent ran a consent farm. It used fake job offers and a $1,000 gift card to pull people in, then sold more than 620 million telemarketing leads from Jan 2018 to Dec 2019. It was ordered to delete the data.

180+
Operation Stop Scam Calls
2023 sweep, 100+ partners
48 federal and 54 state agencies brought more than 180 actions. The FTC said plainly that third-party lead generation for robocalls is illegal under the Telemarketing Sales Rule.

Why this lands on U65 and ACA buyers
Every one of these cases turns on the same thing. Real people were pulled in by a deceptive offer, then sold as insurance leads. That is the traffic that ends up in a private-health or ACA buyer’s pipeline.

Figures from the FTC’s August 7, 2025 settlement announcement and its July 2023 Operation Stop Scam Calls release.

It is not a one-off. Two years earlier, as part of Operation Stop Scam Calls, the FTC said Fluent, LLC ran a “consent farm”. Fluent lured people with fake rewards, such as a job interview with UPS or a $1,000 Walmart gift card, then treated a single click as consent to be called by hundreds of third parties. From January 2018 to December 2019 it sold more than 620 million telemarketing leads. Fluent paid a $2.5 million civil penalty, was ordered to delete the data it had collected, and was banned from robocalls. In that same sweep, 48 federal and 54 state agencies brought more than 180 actions, and the FTC stated plainly that third-party lead generation for robocalls is illegal under the Telemarketing Sales Rule. For the full cast of fraud actors behind these cases, the pillar maps who is actually behind the fake leads. Here the point is narrower. The enforcement record is the clearest map you have of where health-lead junk sits.

First, keep U65 and ACA straight

Before we talk about junk, one distinction trips up buyers, and bad sources exploit it on purpose. U65 is not ACA.

U65 is short for under-65. It means off-exchange private coverage: the short-term medical and indemnity products sold outside the government marketplace. ACA means on-exchange coverage bought through the marketplace, the plans people mean when they say Obamacare. They pull different people with different needs, so they are different lead products.

This matters for fraud. A favorite trick is to run an ACA-flavored or “free coverage” hook, because that pulls the most clicks, then sell the contacts as “U65 leads”. Notice that the MediaAlpha case turned on a domain built to sound like the government marketplace. A source that cannot tell you which product a lead was made for, or that markets one thing to produce another, is handing you a targeting mismatch on top of whatever fraud rides along. Insist on clarity here first. It is the cheapest quality filter you have.

What the junk looks like in this vertical

Fraud in health leads is not mostly bots typing gibberish. The dangerous stuff looks real. Here is the signature to watch for. Each type maps to a fraud actor the pillar breaks down in full.

Incentivized and co-registration “give-back” clickers. This is the big one for health. A real person is chasing a gift card, a sweepstakes entry, or a “$1 a day” style offer. Somewhere in that flow they check a box for a health quote. The name, phone, and email are all real, which is exactly why the contact sails past bot filters and form checks. What is missing is intent. They wanted the reward, not a plan. In a high-payout vertical, this is the main source of real-looking, zero-intent leads, and the pillar explains why a co-registration lead is so low quality.

Aged and resold health data. Someone’s real details get captured once, sometimes legitimately. Then they are resold across advertisers for months or years, to farm the same cost-per-lead payout again and again. That person may have looked into coverage once, long ago, and have no need now. The record is real. The timing is dead.

Bot-filled forms with fake identities. The automated layer has got good. Bots fill lead forms with stolen or invented identities, specifically so they look like conversions. That is worse than obvious junk, because it feeds your ad platform a false quality signal. We cover how bots really do fill out lead forms in the pillar. In health, the payout makes this worth automating at scale.

Wrong-intent “free money” leads. The close cousin of the incentivized clicker. A real, reachable person who truly believes they signed up for free or nearly free money, because that is what the ad promised. They will answer the phone. They will also be confused and annoyed that you want to talk about a private health plan, because that was never what they thought they were getting.

The through-line is that most of these are real people or real data. That is why the easy defenses miss them, and why the easy defenses fail is worth reading in the pillar. reCAPTCHA, form validation, and call-duration rules all test something near intent. None of them test whether a real, reachable person actually wanted coverage.

How verification fixes it at the conversion event

If the junk here is mostly real people with no intent, and real data with no life left in it, the fix has to happen at the one point where you can prove a live person is present: the moment of capture.

That is what real-time OTP verification does. A one-time passcode fires at submission. The person has to receive a code on the number they just typed and send it back, right then, before the lead is accepted. That one step turns “a phone number was typed into a field” into “a real person with live access to that number was here and cooperated”.

Bots cannot clear it, because spoofing a fingerprint fakes the browser, not possession of a phone. Recycled and dead numbers cannot clear it, because the code goes to a phone nobody is holding. And the incentivized survey-filler, chasing someone else’s reward, mostly will not bother with a live step for a health quote they never wanted. For U65 that means you get a reachable, in-market person instead of a give-back-program clicker. The pillar shows exactly how verification defeats each fraud vector.

Two honest notes, because overselling this is its own kind of dishonesty. First, OTP is lead verification, not call tracking. It filters the lead at the conversion event. It is not a way to measure what happens on a call afterward, and it is not a widget you install and forget. Elevarus runs it as an operator, verifying leads inside real U65 and health funnels rather than selling a verification product. Second, verification proves a person is real, reachable, and consenting. It does not prove they need coverage or are ready to buy. Someone who is genuinely just looking will pass and still be a soft lead. Verification raises the floor so your qualifying work runs on real humans. It does not replace that work. The pillar is candid about the honest limits of what verification can and cannot catch. This is the same signal discipline behind our Performance Max spam-leads guide: verify at capture, then feed only the honest outcomes back into bidding.

The buyer’s checklist: what to demand from a lead source

You do not need to become a fraud analyst to buy clean. You need to make five demands, and walk away from any source that cannot meet them. This is the practical core of buying verified.

The Buyer’s Verified-Lead Checklist
Five things to demand from any U65 or private-health lead source before you spend a dollar:

Real-time verification at capture
An OTP step at the moment the form is sent, proving a real person had live access to the number they typed. Not a source certificate emailed after the sale. Not a formatting check.

Consent provenance on every record
The timestamp, the IP address, the exact form URL and version, and the consent language the person actually saw. The full record, not a summary.

Source transparency
The real domains and creatives the traffic came from. No government-sounding domains. The FTC’s MediaAlpha case turned on ObamacarePlans.com.

No incentivized or co-registration traffic
A written guarantee that leads do not come from survey routers, sweepstakes, or gift-card offers. That is the category the FTC’s consent-farm cases were built on.

A replacement policy for unreachable leads
If a verified number does not reach a real person, it gets credited or replaced. A source that stands behind reachability is a source that measured it.

The rule: if a source cannot show you real-time verification and clean provenance, you are buying someone else’s traffic problem. Demand these five before you spend, not after the first bad batch.
Operator guidance, built on the FTC enforcement pattern above: misleading domains, made-up offers, and incentivized consent farms.
  1. Real-time verification at capture. Ask it straight: is there an OTP or real-time step at the moment of capture? Not a “verified source” certificate emailed after the sale. Not a formatting check. An actual live proof that a person had access to the number. If the answer is no, the leads are not verified in any real sense, however clean the file looks.
  2. Consent provenance on every record. Ask for the timestamp, the IP address, the form URL and version, and the exact consent wording each person saw. This is standard lead-provenance paperwork, and a source that has it will hand it over. A source that cannot produce it does not know where its leads came from, which is its own answer.
  3. Source transparency. Get the real domains and creatives the traffic came from. The MediaAlpha case turned on a misleading, government-sounding domain, so this is not a paranoid ask. It is the exact failure the FTC prosecuted. No ObamacarePlans.com-style domains, and no made-up give-back-program offers.
  4. No incentivized or co-registration traffic. Get it in writing that leads do not come from survey routers, sweepstakes, or gift-card offers. That is the category the consent-farm cases were built on, and it is the biggest single source of real-looking, zero-intent health leads.
  5. A replacement policy for unreachable leads. If a verified number does not reach a real person, it should be credited or replaced. A source willing to stand behind reachability is a source that measured reachability, and that tells you more than any pitch deck.

Notice what this checklist leaves out. No magic fraud score. No vendor logo. No promise that the leads are “100% verified”. Those are marketing. Real-time verification plus a clean consent record is the thing itself.

The operator’s bottom line

The FTC calls health-insurance lead gen a priority for a reason. High payout, confused buyers, and a decade of bad actors who learned to package real people as interest that was never there. You cannot filter your way out of that after the fact. You buy your way out of it. Demand verification at capture and a clean consent record before you spend, and keep your U65 and ACA pipelines honest about which product each lead was made for.

That is what Elevarus does as an operator. We run verified U65 and private-health funnels, verify the lead at the conversion event, and only work reachable, in-market people. If you want to see how the economics work in your vertical, the U65 private health and ACA pages lay it out, and how our lead generation model works covers the whole approach. Or just book a free call and we will look at your current lead source with you.

Frequently Asked Questions

Why are health insurance leads so often fake?

Because the payout per lead is high and the buyers are easy to confuse. When one health lead is worth a lot, there is real money in faking one. The easiest way to fake one is to pull in a real person with a deceptive offer, then sell their details as interest they never had. The FTC’s record shows it. In the Assurance IQ and MediaAlpha case announced in August 2025, the agency said about 119 million consumer leads were sold in 2024 through misleading domains and a made-up Health Insurance Give Back Program. The two firms settled for $145 million. We map the full fraud landscape in the ad-fraud pillar.

What is the difference between U65 and ACA leads?

They are two different products. Never treat them as one list. U65 is short for under-65. It means off-exchange private coverage, such as short-term medical and indemnity plans, sold outside the government marketplace. ACA means on-exchange plans bought through the marketplace, the ones people call Obamacare. Someone shopping off-exchange private coverage is not the same buyer as someone shopping an on-exchange subsidy plan. So a source that blends them, or runs an ACA-sounding offer to make what it calls U65 leads, hands you a targeting mismatch before you even get to fraud. Insist that a source can tell you which product each lead was made for.

How do I know if a health insurance lead is verified?

Verified means one specific thing, and it is not a certificate emailed after the sale. A verified lead is one where a real-time step proved a real person had live access to the number. Usually that is a one-time passcode sent at the moment of capture. Ask the source three questions. Is there an OTP step at the point of capture? Can you see the consent record for each lead, with the timestamp, the IP, the form version, and the exact consent wording shown? Is there a replacement policy for numbers that turn out to be unreachable? If the answer to the first one is no, the lead is not verified in any real sense, however clean the file looks.

That depends on facts a lawyer would need to review. But the enforcement direction is clear, and it is worth knowing as a buyer. In Operation Stop Scam Calls the FTC went after lead generators, not just the telemarketers who bought from them. The agency stated that third-party lead generation for robocalls is illegal under the Telemarketing Sales Rule. Incentivized and co-registration traffic, where someone hands over their details to chase a gift card, is exactly the sourcing those cases looked at. So the practical takeaway is simple. Incentivized health leads carry quality risk and regulatory risk. Get a written guarantee that your source does not use them.

What is a co-registration health lead?

It is a lead collected as a side offer while someone is doing something else, usually a survey or a sweepstakes. Halfway through claiming a gift card, they see a prompt like “check this box for a health insurance quote”. They check it because it is one more click toward the reward, not because they want coverage. The contact details are completely real. A real name, a real phone, a real email. That is exactly why they slip past bot filters and form checks. What is missing is intent. In a high-payout vertical like private health, this is a primary source of real-looking, zero-intent leads. The pillar covers why these are the hardest fraud type to filter.

Does OTP verification catch every bad health lead?

No. Any source that promises it does is overselling. Real-time OTP proves three things. The number is real and in service. The person filling the form had live access to it. And they cared enough to finish an extra step. That strips out the cheap fraud layer: bots, dead and recycled numbers, and most survey-fillers who will not finish a verification for someone else’s offer. What it does not prove is that the person needs coverage or is ready to buy. Someone who is genuinely just looking will pass and still be a soft lead. Verification raises the floor so your qualifying work runs on real humans. It does not replace that work.

Sources



Work with Elevarus

Are You Ready to Grow With a Proven Lead Generation & Performance Marketing Agency?

Get a free, no-pressure strategy call with our lead-generation team. We'll map the fastest path to more qualified leads for your business.

Book a free call →

Ready to put this into action?

Picture of <a href="https://elevarus.com/shane-mcintyre/">SHANE MCINTYRE</a>

Founder and CEO of Elevarus, specializing in paid media, lead generation, pay-per-call, and customer acquisition.