Skip to content

Updated Jul 2026

Permission to Contact, explained

If you sell Medicare products, you already know the rule of thumb: you don’t contact a beneficiary about coverage unless they’ve agreed to it. The harder question is what “agreed” looks like on paper. A spreadsheet of phone numbers tells you who you can dial. It doesn’t tell you who said yes, what they said yes to, or when they said it. If anyone ever asks why you called a particular person, a list of numbers has no answer.

That’s the gap the Permission to Contact (PTC) form exists to close. It’s not a lead form. Your capture form collects a name, an email, and a phone number. The PTC form records specific, detailed permission to be contacted about Medicare products, signed by the person giving it.

What a signed record establishes

Each signature captures the pieces you’d need to reconstruct the permission later: who signed, which of your brands collected it, the date they signed, the contact channels they allowed (phone, text, email, or mail), the coverage types the signature applies to, and the date the permission runs out.

The form itself constrains what that permission can be. It has to stay carrier-neutral, because naming a carrier would limit the permission to that carrier’s products. Any organization you share signed permissions with must be named as a specific legal entity, not a category like “our marketing partners.” And the disclaimer the signer reads states, verbatim, how many organizations you represent and how many products you offer in your service area. The scope of the consent is spelled out before anyone signs, which is exactly what makes the record worth keeping.

People can sign more than once. A renewal doesn’t overwrite the old signature. Every signature a person has ever given stays in their history with its own dates, channels, and coverage, and the export includes one row per signature. The record grows. It doesn’t get rewritten.

Why consents expire

A signed permission is valid for 12 months from the date it’s signed. Permission is a statement about a moment in time, and a year on, the person’s situation, or yours, may have changed.

After 12 months the record’s status changes to Expired, and the person needs to sign again before you rely on it. Expiry doesn’t erase anything. The old signature stays in their history. It stops being something you can act on, and starts being something you can only point back to.

How lineage works for your contacts

Consent is one half of the story. The other half is being able to show how a person got onto your list in the first place. When someone signs up through a capture link you inserted into a specific post, their contact record keeps that post as their source, and it stores the exact consent wording they agreed to at the time. A signup from your bare form link is recorded as direct instead. Either way, you can trace a contact back to the moment and the wording of their signup rather than reconstructing it from memory.

Where the boundary sits

PostSignoff stores and organizes the consent record. It doesn’t decide whether your outreach fits inside what someone consented to. Placing a call, sending a text, keeping the conversation within the coverage types on the signature: all of that is yours to get right.

Two limits are worth knowing before you depend on the feature. There’s no in-app action to revoke a signed permission, so handling a revocation request is a process you run outside the app. And activating the form is not a legal review. The settings page carries this warning every time you open it:

This form has not been reviewed by counsel or approved by your carriers. Do not enable it until both are complete.

The form gives you the record. What the record is worth in front of a regulator or a carrier is a question for your counsel, not for this page.