2026-10-05
A federal watchdog found ACA Marketplace complaints about brokers more than quadrupled to 300,000. Open enrollment still has you emailing them your pay stubs.
Open Enrollment for 2027 Affordable Care Act Marketplace coverage opens Nov. 1, 2026 and runs through Jan. 15, 2027 — enroll by Dec. 15 to start coverage Jan. 1, per HealthCare.gov's own dates and deadlines page. A week before that window opened, a federal watchdog's numbers landed: a Government Accountability Office report released July 13, 2026 (GAO-26-108041) found that consumer complaints about unauthorized Marketplace enrollments and plan switches "grew more than fourfold" between 2023 and 2025 — from 66,548 to 299,604 — with at least 160,000 federal Marketplace applications in plan year 2024 showing likely unauthorized changes made by an agent or broker. Here's what encrypting your own income-verification documents before you send them to one of those agents actually fixes, and the one case tied to this exact scandal where it fixes nothing at all.
What the watchdog found, in its own numbers
GAO didn't just count complaints — it diagnosed why they're possible. Per the report, the Centers for Medicare & Medicaid Services' "processes to ensure consumer consent for agent or broker actions are weak," the agency "does not restrict access to consumer Marketplace records to the agent or broker already associated with a consumer's enrollment," and it doesn't inform consumers of every action taken on their account. CMS acted on that finding on Sept. 22, 2026, announcing it had canceled approximately 315,000 unauthorized enrollments covering more than 760,000 people, expected to return roughly $2.2 billion in advance premium tax credit payments, and imposed a temporary moratorium on new agent and broker registrations for the 2027 plan year.
Why a name, a birthdate, and a state are enough
What makes an individual agent's misuse possible at that scale predates this year's numbers. KFF Health News reported on April 2, 2024 that "armed with only a person's name, date of birth, and state, a licensed agent can access a policyholder's coverage through the federal exchange." Once inside, per Joshua Brooker — a broker who chairs a marketplace committee for the National Association of Benefits and Insurance Professionals — "those bad eggs now have access to all this private information about an individual, including household income, Social Security numbers, and dependents." The 2026 GAO report confirms the access problem Brooker described two years earlier was still unfixed when auditors looked.
The part the fraud story doesn't cover: your pay stub
None of that is about what you send an agent — it's about what an agent can already see once you're in their book of business. But Open Enrollment also runs the Marketplace's income-verification process at the same time: per HealthCare.gov's own verification page, if your reported income doesn't match IRS records, you get 90 days to confirm it, with a W-2, recent pay stubs, a tax return, or self-employment records among the accepted proof. HealthCare.gov describes exactly one official channel for that: log into your own Marketplace account and upload the file, or mail a photocopy. In practice, a lot of people doing this got help from an agent in the first place, and an agent's own instructions often skip that upload screen entirely — one licensed agency's client guide reads: "Scan (or take a high quality photo or screenshot of) your documentation and send to help@ihealthagents.com," listing pay stubs, bank statements, last year's tax return, and W-2s or 1099s as what to send. Nothing about that is itself a scam — a real agent still has to get the paperwork from somewhere — but it means the same pay stub the GAO and CMS findings are about now also exists as a plain email attachment sitting in that agent's personal inbox, a channel the Marketplace's own access controls never touch.
What encrypting that file actually fixes
NearSeal runs entirely in your browser — the pay stub, W-2, tax return, or bank statement you're sending never uploads anywhere to get encrypted. It's sealed on your own device, by default with AES-256-GCM and a passphrase-derived key (PBKDF2-SHA256 at 220 iterations), before it goes into an email at all. That removes the plaintext copy from the two places you actually control: the file sitting in your Downloads folder or Sent mail, and the attachment as it crosses the wire into whatever personal inbox your agent happens to use. For the passphrase to do any good once the file arrives, it has to travel a separate channel from the file itself — a text or a call to the agent you're already working with, not a reply in the same email thread.
The one case tied to this exact scandal that encryption can't touch
If the agent on the other end is one of the "bad eggs" GAO and CMS are describing — someone already using your Marketplace record to enroll you in a plan you didn't choose, or who will use the pay stub you just emailed the same way — encrypting that file before you send it changes nothing about what they do with it after they open it. You built the passphrase specifically to let them in; encryption protects a file from everyone except whoever holds that passphrase, and it has nothing to say about what an authorized, dishonest recipient does with the plaintext afterward. That's a consent and access-control failure, not an interception one, and GAO's own recommended fix is not cryptographic: a one-time passcode confirming you authorized each change, a control the report notes some state-based marketplaces already use. The actual defense here is logging into your Marketplace account yourself, at an address you typed in rather than one in an email, and checking for enrollments or plan changes you didn't request — exactly the review CMS has been urging since its Sept. 22 cancellations. Encrypting the file is for the income-verification half of this relationship that's left over once you trust who you're sending it to.
Two more honest limits, regardless of which path you're on
NearSeal's default container keeps the original filename in a plaintext header field — bound into the authenticated data so it can't be silently swapped for something else, but still readable without the passphrase. A file literally named "paystub-oct-for-broker.pdf" tells anyone who intercepts it exactly what's inside before they've broken anything; rename it to something unremarkable first, or use the opt-in age-encryption.org format, which carries no filename field at all. And there is no passphrase recovery of any kind — if you forget the passphrase before your agent has had a chance to open the file, the encrypted copy is permanently unreadable, including to you.
Where NearSeal fits
GAO's own findings are right that no amount of file encryption closes an account-access gap — once an agent can already view or switch your coverage with just your name, birthdate, and state, the fix has to be account-side verification, not cryptography. What that finding doesn't touch is the ordinary, legitimate second task Open Enrollment hands you at the very same time: proving your income to keep the subsidy you're entitled to, by sending a pay stub or a W-2 to the person helping you enroll. That's the gap NearSeal closes — not the account-switching fraud, and not what an honest agent does with the file after opening it, but the plaintext copy that otherwise sits in a personal inbox the whole way there.