NearSeal

2026-10-03

Medicare Open Enrollment starts Oct. 15. The FTC says never give your Medicare number to a caller — nobody warns you about the email.

Medicare Open Enrollment opens Oct. 15 and runs through Dec. 7, and the FTC's own May 28, 2026 alert puts a number on what rides along with it: Medicare fraud, waste, and abuse costs taxpayers "about $60 billion every year," and one of the specific schemes the agency names is a caller who gets you to "confirm your Medicare number — which they then use to commit hospice fraud." The agency's fix for that exact scenario is blunt: "Never share your Medicare number with someone who calls unexpectedly." That's solid advice for a phone call. It says nothing about the photo of your Medicare card you're about to email an insurance broker, a SHIP counselor, or the adult child helping you compare plans this year — the completely legitimate thing Open Enrollment actually asks of most people.

Why this number was already treated as sensitive, by law

The FTC isn't improvising a new worry. Your Medicare card hasn't carried your Social Security number since 2018, for exactly this reason. Per CMS's own Sept. 14, 2017 press release, the agency mailed new cards to approximately 58 million beneficiaries starting in April 2018, replacing the old SSN-based Health Insurance Claim Number with a new, randomly assigned Medicare Beneficiary Identifier (MBI). CMS Administrator Seema Verma described the goal plainly: "to help prevent fraud, combat identify [sic] theft, and safeguard taxpayer dollars." By the statutory deadline of April 2019, the swap was complete nationwide. The government spent a year mailing out replacement plastic to tens of millions of people specifically so this number would stop doubling as a Social Security number. That's an unusually direct admission, from the same agency that issues the card, that the number printed on it is identity-theft-grade data — not a harmless account number like a library card.

What the FTC is actually warning about this Open Enrollment

The agency's Sept. 30, 2025 alert lays out the seasonal pattern: scammers "get more active" every year once Open Enrollment (Oct. 15–Dec. 7) opens, often posing as Medicare itself and claiming you need a "new" or "updated" card, then asking for your Medicare, bank account, or credit card number — even though real Medicare cards are free and mailed automatically. The same alert warns that "caller ID can be faked," so a call that appears to come from Medicare proves nothing, and it points people toward their State Health Insurance Assistance Program (SHIP) for free, unbiased help comparing plans instead of acting on an unsolicited call. The May 2026 alert adds the dollar figure and the specific fraud a stolen number feeds: with "about $60 billion" lost to Medicare fraud, waste, and abuse annually, a scammer who talks you into "confirming" your Medicare number can use it to bill Medicare for hospice services you never received. Both alerts are entirely about one channel: an unsolicited phone call. Neither one mentions email, text, or file attachments, because that isn't the scam pattern they're describing.

Same Medicare number, two very different paths Medicare Beneficiary Identifier (MBI) the number printed on your Medicare card Unsolicited call: "confirm your number" Caller ID can be faked (FTC, Sept. 2025) Used to bill hospice fraud (FTC, May 2026) part of ~$60B/yr in Medicare fraud FTC's fix: hang up, call 1-800-MEDICARE yourself — no file involved here Comparing plans: broker, SHIP, family A routine, legitimate Open Enrollment step Card photo/PDF emailed or texted — a plain attachment, not a phone call Not covered by the FTC's phone-call warnings — encrypting the file helps here Same MBI, same card — the phone channel and the email channel each need their own defense Verify who's calling. Encrypt what you send.
The FTC's Medicare scam warnings cover the phone call. They say nothing about the Medicare card photo that goes out by email every Open Enrollment for an entirely legitimate reason.

The legitimate copy nobody's warning you about

Comparing Medicare Advantage or Part D plans well enough to actually save money usually means getting help — from a licensed broker, a SHIP counselor, or an adult child who's agreed to sit down with the paperwork. In practice, helping almost always starts with having the Medicare card and sometimes a Social Security benefit-verification letter in hand, and the fastest way to hand that over to someone who isn't in the room is a photo or a scanned PDF, sent by email or text. None of that is a scam, and none of it is unusual — it's the ordinary mechanics of Open Enrollment working as intended. But it's also the one piece of this picture the FTC's own alerts never touch, because their advice is built entirely around an unsolicited phone call. An email attachment sitting in a broker's inbox, or in your own Sent folder, isn't protected by "hang up and call 1-800-MEDICARE" — there's no call to hang up on. It's protected by whatever happens to the file itself.

What encrypting that file actually fixes

NearSeal runs entirely in your browser — the Medicare card photo or benefit letter never uploads anywhere to get encrypted. It's sealed on your own device, by default with AES-256-GCM and a passphrase-derived key (PBKDF2-SHA256 at 220 iterations), before it goes into an email or a text at all. That removes the plaintext copy from the two places you actually control: the file sitting in your Downloads folder or Sent mail, and the attachment as it crosses the wire into whatever inbox a broker or SHIP office happens to use. For the passphrase to do any good once the file arrives, it has to travel a separate channel from the file itself — a text or a call to the broker or family member you're already working with, not a reply in the same email thread.

The one case encryption can't touch

This only works if the person on the other end is who they say they are. If the "broker" who called you is actually the scammer the FTC is describing — someone who invented a reason to contact you so they could collect your Medicare number in the first place — encrypting the file and then reading them the passphrase over the phone accomplishes nothing. You've simply handed over the same plaintext, one extra step later, to the person the encryption was supposed to keep it from. Encryption authenticates nothing about who's on the other end of the conversation; it only protects a file from everyone except whoever holds the passphrase, and in that scenario, the attacker already holds it. The FTC's own advice is the real defense there, and it's not a cryptographic one: don't act on an unsolicited call, hang up, and call 1-800-MEDICARE or your SHIP office using a number you looked up yourself. Verify who you're actually working with first. Encrypting the file is for the legitimate half of Open Enrollment that's left once you have.

Two more honest limits, regardless of which path you're on

NearSeal's default container keeps the original filename in a plaintext header field — bound into the authenticated data so it can't be silently swapped for something else, but still readable without the passphrase. A file literally named "medicare-card-mom.pdf" tells anyone who intercepts it exactly what's inside before they've broken anything; rename it to something unremarkable first, or use the opt-in age-encryption.org format, which carries no filename field at all. And there is no passphrase recovery of any kind — if you forget the passphrase before the broker or your family member has had a chance to open the file, the encrypted copy is permanently unreadable, including to you.

Where NearSeal fits

The FTC's Open Enrollment warnings describe a real, dated, and specific threat — and they're right that no amount of file encryption stops a scammer who gets you on the phone in the first place, because verifying who you're talking to is the only thing that helps there. What those warnings don't describe is the ordinary, legitimate second half of the same number's journey: the card photo that goes out by email so a real broker, a real SHIP counselor, or your own adult child can actually help you compare plans. That's the gap NearSeal closes — not the phone scam, and not what a broker does with the file after opening it, but the plaintext copy that otherwise sits in a Sent folder and crosses an ordinary, unencrypted inbox the whole way there.

Sponsored
← NearSeal

This page shows ads only if you consent.