Skip to main content

Agent authorization

An overview of CMS' agent authorization requirement

Siga las instrucciones aquí para traducir esta página a otro idioma usando Chrome.


Beginning October 12, 2026, the Centers for Medicare & Medicaid Services (CMS) will require all agent-driven Affordable Care Act (ACA) enrollments to include an agent authorization step.

HealthSherpa allows agents to begin collecting authorizations for plan year 2027 even before the Open Enrollment Period (OEP) begins.

In this article we'll cover:


Agent authorization at a glance

Agent authorization is a consumer's confirmation that a specific agent is permitted to access their Marketplace application. Beginning October 12, 2026, CMS will require this authorization for all agent-driven enrollments.

How the process works:

  • The agent sends a consumer an authorization request by text or email.

  • The consumer receives the request.

  • The consumer confirms they want to grant authorization.

    • CMS requires identity verification for applications flagged as high risk before authorization can be granted.

  • Authorization is completed.

Agent authorization relies on the agent’s Federally Facilitated Marketplace (FFM) username and is required once per plan year, per agent, per Enhanced Direct Enrollment (EDE) platform.

Authorization is not required each time an authorized agent interacts with a consumer's application. However, only one authorization can be active at a time, and a new authorization replaces any previous authorization.

Agent authorization, consent, and CMS' Invalid Action error

Agent authorization and CMS consent requirements apply at different points in the enrollment journey and serve different purposes. CMS' Invalid Action error is separate from both, and CMS will begin phasing it out on October 12, 2026.

Agent authorization & consent

Agent authorization, Consumer Consent, and Eligibility Application Review are three separate requirements.

Agents need agent authorization annually to access a consumer's Marketplace application. Agent authorization does not meet CMS consent requirements or replace the need to capture consent.

Consent is made up of two separate parts that are collected and documented at different points in the enrollment journey. These parts are called Consumer Consent and Eligibility Application Review.

Agents will still need to obtain and document consumer consent & eligibility application review when providing assistance.

Agent authorization & CMS' Invalid Action error

Agent authorization and CMS' Invalid Action error occur at different points in the application and rely on different identifiers.

Agent authorization takes place before an agent can begin or access an application. It relies on FFM username, and is required once per plan year, per agent, per EDE platform.

Agent authorization has no impact on the NPN associated with a consumer's existing enrollment.

CMS' Invalid Action error occurs at the end of an application and is based on the National Producer Number (NPN) currently associated with the enrollment. CMS will sunset the Invalid Action error beginning October 12, 2026.


2027 Authorizations tab

Located within the Clients page of the HealthSherpa account, the 2027 Authorizations tab provides a single place to view and manage authorizations across your book of business.

From the 2027 Authorizations tab, agents can:

  • Initiate authorization requests

  • View & track authorization statuses

  • Search for consumers

Columns & statuses

  • Client: The primary applicant’s name.

  • Plan year: Plan year associated with the authorization.

  • Authorization status: The status of the authorization.

    • Not authorized: An authorization request has either not yet been sent to the consumer, or authorization has been removed.

      • Not started: An authorization request has not yet been sent to the consumer.

      • Client declined: The consumer declined the authorization request.

      • Authorized to another agent: authorization has been granted to another agent.

    • Pending authorization: An authorization request has been sent to the consumer, but has not yet been completed.

      • Request sent: The consumer has not yet clicked the link within the authorization request.

      • Link clicked: The application has been flagged as high risk by CMS, and the consumer is attempting to verify their identity.

      • ID verification issue: The application has been flagged as high risk by CMS, and the consumer has experienced at least one issue while attempting to verify their identity.

    • Authorized: Authorization is active.

  • Last updated: The most recent date and time the authorization request was updated by the agent or the consumer.

  • Contact info: The contact information associated with the consumer's application. When available, the order of information displayed is primary phone number, secondary phone number, then email address.

  • Action: Includes the option to get authorization or resend a request for authorization.


Initiating authorization requests

Agents can choose to email or text an authorization request to the contact information associated with the consumer's application. Authorization requests can be resent to a consumer up to three times per day.

Plan year 2026

Beginning October 12, 2026, agent authorization will be required for plan year 2026 applications.

When a consumer is already listed on the agent's Clients page, authorization status for plan year 2026 is visible from the All clients tab of the Clients page.

Grandfathered clients

Grandfathering automatically authorizes the writing agent (i.e. FFM username) who last serviced the client's plan year 2026 application. Agents who use more than one HealthSherpa account will find the grandfathered application only in the account where it was last serviced, or claimed.

Grandfathering will only take place when the application is not high risk or the consumer has verified their identity on HealthSherpa in the past.

Grandfathering applies to plan year 2026 only and does not carry over to plan year 2027.

Agents can continue servicing grandfathered clients with their plan year 2026 application without interruption. Agents will not need to take additional steps to obtain authorization when assisting grandfathered clients with their plan year 2026 application.

When assisting a consumer who is not grandfathered, agents will be prompted to collect agent authorization. Agents can do this by selecting Get authorization or by conducting a search & claim.

When a consumer is not already listed on the agent's Clients page, agents will be prompted to collect agent authorization during search & claim.

If the consumer is new to the Marketplace, the agent will be prompted to obtain authorization once contact information has been entered.

Regardless of a client's grandfathered status, authorization for plan year 2026 does not apply to plan year 2027 applications. Agents will need to collect a new authorization for each consumer every plan year, prior to accessing their application.

Plan year 2027

HealthSherpa allows agents to begin collecting authorizations for plan year 2027 even before the Open Enrollment Period (OEP) begins.

From the 2027 Authorizations tab on the Clients page, an agent can initiate authorization requests to a single consumer or multiple consumers at once.

Initiate a request to a single consumer

To initiate an authorization request to a single consumer, select Get authorization from the Action column.

Choose whether to send the authorization request by text or email.

Customizing the request

The email subject line and body can be customized as needed. To customize the email prior to sending, select the pencil icon.

Select Send to generate the customized authorization request, or back to return to the previous screen.

Select [Text/Email] to generate an authorization request.

After sending an authorization request, agents will see an authorization status box.

From the authorization status box, agents can wait for the client to complete the request, resend the request, refresh the status of the request, or choose to send the request using email or text instead - whichever method was not used initially. Sending the request using email or text instead will cancel the current, pending request.

Close the authorization status box to return to the 2027 Authorizations tab.

Initiating requests to multiple consumers at once

When initiating authorization requests to more than one consumer at a time, each consumer will receive their own secure authorization request.

The Bulk authorize option can be used to email or text up to 5,000 consumers at a time. To narrow the list of recipients, use the filters or select the checkbox next to a consumer's name to identify consumers who should receive a request.

Once desired consumers are selected, choose Bulk authorize.

Choose whether to send the authorization requests by text or email. The email subject line and body can be customized as needed.

Select Send preview to send yourself a test email or text. Preview emails will be sent to the email address associated with the HealthSherpa account, and preview texts will be sent to the phone number listed on the agent's Marketing page.

Select Send to generate the authorization requests. Agents will be returned to the 2027 Authorizations tab where a success message will appear.

Ask the consumer to open the authorization request from their own device. Review the consumer experience when completing an agent authorization request to learn more.


Tracking & reporting

Agents can view and track the progress of authorization requests for consumers using the Clients and Leads pages.

The Clients page displays consumers who have submitted an enrollment. The Leads page displays consumers who started plan shopping or started an application but have not yet completed an enrollment submission.

  • Plan year 2026 clients: Go to the Clients page and select the All clients tab.

  • Plan year 2027 clients: Go to the Clients page and select the 2027 Authorizations tab.

  • Leads: Go to the Leads page and select the All leads tab.

Agents and agencies can also export agent authorization data for clients.


Frequently asked questions

What can an agent see if they do not have agent authorization?

For plan year 2026, agents can view & service grandfathered clients without interruption.

For non-grandfathered plan year 2026 applications & plan year 2027 applications already in the Clients page, the agent has a view only record until they obtain agent authorization. This is similar to the view available when an application does not have an active EDE sync.

What if a consumer's contact information no longer matches what is listed on their application?

If a consumer's phone number and email address no longer matches the contact information listed on their application, or they no longer have access to the contact information listed on their application:

  • Plan year 2026: With consent, edit the consumer's application, then resubmit the application.

  • Plan year 2027: Consumers will need to choose one of the following options:

    • Submit their own enrollment using a consumer-driven pathway such as using an agent's marketing link

    • Submit their own enrollment by calling the Marketplace directly at 1-800-318-2596.

    • Visit HealthCare.gov to update their phone number and/or email address under the ‘Communication preferences’ section of their account. For this option, consumers must:

      • Create an account on HealthCare.gov (including identity proofing)

      • Utilize 'Find My Application' to associate their account with their application

      • Select the 'Communications preferences' section of the application and update their contact information.

Can an agent create a new application if a consumer's contact information is outdated?

No. Agents should not create a new application to avoid outdated contact information. CMS may cancel applications they determine are duplicative.

Will the Marketplace Call Center remove an agent's NPN if a consumer calls the Marketplace?

According to CMS, the Marketplace Call Center will only remove an existing National Producer Number (NPN) from an application in two situations:

  • The consumer asks for the NPN to be removed, or says they are no longer working with an agent or broker.

  • The consumer is updating their application but does not provide a verifiable Social Security Number (SSN) or immigration documentation. In this case, the consumer can choose to submit the application without the NPN, and the application will go through the standard Data Matching Issue (DMI) process.

In all other cases, the existing NPN stays on the application. Review CMS' Marketplace Call Center tip sheet to learn more.

Does authorization need to be repeated for every consumer each year?

Yes. Authorization is completed once per plan year, per agent, per Enhanced Direct Enrollment (EDE) platform.

Does plan year 2026 authorization roll over to plan year 2027?

No. Agent authorization is valid for a single plan year and does not roll over to the next plan year. Authorization for plan year 2026, including authorization granted through grandfathering, does not apply to plan year 2027 applications. Agents will need to collect a new authorization for each consumer every plan year.

What is an Enhanced Direct Enrollment (EDE) platform?

Enhanced Direct Enrollment (EDE) is a CMS-approved technology that creates a secure backend connection to the Marketplace. An EDE platform is an enrollment platform approved to use that connection, which allows agents to complete the full Marketplace enrollment process directly on the platform rather than on HealthCare.gov. HealthSherpa is an EDE platform.

Does authorization transfer to other EDE platforms?

No. Authorization is specific to the EDE platform where it is completed, so authorization completed through HealthSherpa is valid only through HealthSherpa and does not transfer to other EDE platforms.

If a consumer is moved to a different EDE platform, the consumer will need to complete that platform's authorization process.

Does an agent's authorization transfer between all of an agent's HealthSherpa accounts?

No. Agents may have multiple HealthSherpa accounts, but each account functions separately for authorization purposes. Authorization completed in one account is not valid in another.

Will all consumers be required to verify their identity?

No. Consumers will only be required to verify their identity during the agent authorization process if CMS flags the application as high risk, or an application moves from low risk to high risk during the enrollment journey.

How does CMS determine whether an application is high risk?

Before authorization can be granted, CMS may require additional identity verification for certain higher-risk applications. Applications flagged as high risk by CMS include:

  • New to the Marketplace or state

  • Enrollment is already active, and has a net monthly premium of $30 or less

  • Consumer is working with a different or new agent

Identity verification could also be required if an application moves from low risk to high risk during the enrollment journey.

How do consumers verify their identity when required?

Several identity verification pathways are available on HealthSherpa, and consumers are able to complete agent authorization and consumer ID verification in one simple step.

Do consumers have to repeat identity verification each year?

No. Consumers who have verified their identity using HealthSherpa will not need to repeat verification on HealthSherpa unless their contact information changes.

Does identity verification transfer to other EDE platforms?

No. Identity verification completed through HealthSherpa is valid only through HealthSherpa and does not transfer to other EDE platforms.

If a consumer is moved to a different EDE platform, the consumer will need to complete that platform's identity verification process as required.

What does net premium mean?

Net premium is the premium amount a consumer pays after advance premium tax credit (APTC) has been applied. In contrast, gross premium is the full premium amount before APTC is applied.

Does agent authorization affect commissions or Agent of Record (AOR) status?

No. Agent authorization concerns access to a consumer's application on HealthSherpa. Agent authorization does not affect the AOR associated with the enrollment, the National Producer Number (NPN) associated with the enrollment, or carrier commission relationships.

Do agents have to get authorization if their NPN is already associated with the enrollment?

If authorization is not already active, yes. Agent authorization does not rely on NPN, and has no impact on the NPN associated with a consumer's existing enrollment.

Does agent authorization impact applications done using an agent's marketing link?

No. Applications done using an agent's marketing link are consumer-driven enrollments. Agent authorization applies to agent-driven enrollments.

Is agent authorization required for off-exchange applications?

No. Agent authorization is required for FFM application only.

Can another agent, or agency administrator send an authorization request on behalf of an agent?

No. Authorization requests can only be sent by the agent requesting authorization.

How does agent authorization work with shared book & full book access?

Agencies using these features can expect them to provide view only access. Each agent who wants to service or interact with a consumer's application needs agent authorization to do so. Only one authorization can be active at a time, and a new authorization replaces any previous authorization..

Can agents complete enrollment submissions by contacting the Marketplace Call Center?

Beginning OEP for plan year 2027, the Marketplace Call Center will no longer support changes requested by an agent, except in complex cases. For more information from CMS, review question 11 here.

How can agents update the Agent of Record (AOR) if the Marketplace Call Center no longer supports agent-requested changes?

Agents can update the AOR, and the National Producer Number (NPN) associated with the enrollment, by completing an enrollment submission on HealthSherpa.

During the Open Enrollment Period (OEP), agents can actively renew the consumer's coverage.

Outside of OEP, agents can resubmit the consumer's enrollment. Application changes and Special Enrollment Period (SEP) eligibility are not required, but agents must resubmit the application and complete the plan confirmation step. The carrier receives the AOR update only after the enrollment submission is complete.

Does agent authorization impact NPN override?

No. National Producer Number (NPN) override functionality will still be available within HealthSherpa.

Is agent authorization required for applications submitted using the Enrollee Assistance Program (EAP)?

Yes. Agents using the EAP Shared-Service Model (SSM) need agent authorization when completing enrollment submissions, and follow the same initiation steps outlined in this article.

In the EAP Full-Service Model (FSM), agent authorization is also required, and HealthSherpa manages the process.

Will agents be able to send authorization requests to consumers who share the same phone number or email address?

Enhanced Direct Enrollment (EDE) partners are required to have protections in place that limit the reuse of contact information and restrict the use of temporary phone numbers. As a result, a request may not be able to be sent to a phone number or email address that has already been used, and requests sent to temporary or disposable numbers may be blocked. Agents are also not able to substitute their own contact information for the consumer's.

How can agents increase response rates to authorization requests?

Consumers are more likely to respond to an authorization request that is personal, clear, and easy to verify. Agents can customize the email subject line and body before sending. When customizing the request, agents can:

  • Write in their own voice and remind the consumer who they are. Consumers are more likely to respond to a message from their agent than to one that reads like an automated notice. For example: "Hi, this is [agent name], and I helped you with your current health insurance coverage."

  • Explain the request in plain language. State what the consumer needs to do and how it helps them, and avoid industry terms the consumer may not recognize. For example: "Please complete this form so I can make sure your information is up to date and you receive the savings you qualify for."

  • Tell the consumer where the link goes. For example: "You'll be taken to HealthSherpa, the platform I use to manage your health insurance application, to complete this request."

  • Give the consumer a way to confirm the request is legitimate. This can reassure consumers who are unsure whether the message is genuine. For example: "Have questions about this request? Call my office at [phone number]."


Additional resources

For help using HealthSherpa or for other assistance, contact Agent Support. Agent Support is available by phone at (888) 684-1373, by email at Support@HealthSherpa.com, or by chat directly from your account.

Attachment icon
Did this answer your question?