FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #81
FTC WARNS

Scammers buy top search-engine ad slots and use lookalike web addresses and official-looking logos to pass themselves off as Healthcare.gov or Medicare.gov during Open Enrollment.

HIGH CONFIDENCEPublished 2026-09-28
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

The Federal Trade Commission says health insurance scams run year-round but pick up during Open Enrollment for Medicare and the Marketplace. According to the FTC, scammers and dishonest businesses sometimes pay to appear at the top of search results, using web addresses that look similar to government addresses along with keywords and official-looking logos so you think you are at the real Healthcare.gov or Medicare.gov. The FTC says that if you use the link or phone number in one of those ads, you might end up paying for a scammy plan that is not health insurance, or expose yourself to medical identity theft. The advisory points readers to Medicare.gov or 800-633-4227 for Medicare, and HealthCare.gov or 800-318-2596 to compare plans, check coverage or see if they qualify for savings. Never reach a health plan through a search ad: type the site name in yourself, scroll past anything labelled "Ad" or "Sponsored", and check the address ends in .gov before you enter a single detail. If a page or caller has already taken money or personal details, report it at ReportFraud.ftc.gov and to your state attorney general, and report Medicare-related scams at Medicare.gov or 800-633-4227. We do not know how many people have lost money to this, how much, or which specific sites and phone numbers are involved — the advisory names no fraudulent operator and gives no figures. LIVEFRAUD ALERTS is independent and not affiliated with the FTC, Medicare, HealthCare.gov or any agency named here; brand names appear only because an official source named them as impersonation targets.
THE RULE
A paid search result can cost you a plan premium for coverage that is not insurance, plus your medical identity.

What we don’t know

The bench — who voted

3 INDEPENDENT AI MODELS REVIEWED THIS. 2 OF 3 — ONE MODEL DISSENTED. READ WHY.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · MODERATE
Several factual specifics in the finding are attributed to the FTC but appear nowhere in the single evidence row: that the scams 'run year-round but pick up during Open Enrollment', and the helpline numbers 800-633-4227 and 800-318-2596. These may well be accurate and publicly known, but on the evidence supplied they are unsourced attributions.
DISSENT, PRESERVEDThe finding deserves credit for stating its own limits plainly: it names no operator, no loss figures, and says so. That self-limiting framing is the reason this holds rather than overstates.
DISSENT, PRESERVEDI would argue for a grade above moderate for the Medicare-eligible audience specifically. Government-site impersonation combined with medical identity theft is high-consequence and hard to unwind, and the target population skews older. My moderate grade reflects the low sophistication required to avoid the harm, not the severity if it lands.
GROQopenai/gpt-oss-120b · HIGH
The finding adds that health‑insurance scams "pick up during Open Enrollment" which is not stated in the cited FTC advisory; the source only provides preventative guidance ahead of enrollment, not evidence of a seasonal increase.
OPENROUTERopenrouter/free · HIGH
The finding states that the FTC says health insurance scams run year-round but pick up during Open Enrollment; this is not present in the evidence row.
DISSENT, PRESERVEDThe core claim that scammers buy top search ad slots and use lookalike domains and logos to impersonate Healthcare.gov and Medicare.gov is supported by the evidence row. However, the finding adds numerous details not present in the evidence, making it overstated.

Reviewed by 3 independent models: 1 found it carried by the evidence, 2 did not.

▼ Protocol & challenge record
Objection (high): The advice sentence "check the address ends in .gov" is the single most load-bearing instruction in the piece and it is imprecise in a way that can get a reader phished. Impersonators routinely register domains like medicare.gov-enroll.com, healthcare-gov.com or healthcaregov.info; every one of those 'contains .gov' and two of them arguably 'end in .gov' to a casual eye reading left to right. The correct instruction is that the registrable domain itself must terminate in .gov immediately before the first single slash — i.e. the last dot-segment of the host. The FTC's own wording ('look for the .gov ending') is equally sloppy, but a consumer alert republisher who repeats the flaw inherits it. Rewrite to something operable: 'the part just before the first slash must end in .gov — medicare.gov/ is real, medicare.gov-plans.com is not.'
Resolved: Replace 'check the address ends in .gov' with a test the reader can actually apply: 'read the address up to the first single slash — that part must end in .gov. medicare.gov/plan-compare is real; medicare.gov-plans.com and healthcare-gov.net are not.'
Objection (high): Unsourced absolutism in the advice line. The FTC says scroll past paid ads and type the address yourself; it does not say 'Never reach a health plan through a search ad.' That is the draft's own invention, carries no row_id, and is factually overbroad — licensed brokers, state exchanges, SHIP-affiliated counselors and insurers all buy search ads lawfully. The source itself distinguishes 'scammers' from 'dishonest businesses' and says they 'sometimes' pay for top placement. Converting 'sometimes some advertisers are bad' into 'never use an ad' is a source-to-claim stretch, and it is the kind of overclaim that costs credibility when a reader clicks a perfectly legitimate sponsored result.
Resolved: Rewrite to the sourced instruction: 'Don't reach a health plan through a search ad you weren't looking for. Type Medicare.gov or HealthCare.gov in yourself, scroll past anything labelled "Ad" or "Sponsored", and check the domain before entering any detail.' Drops the unsupported 'never' while keeping the behaviour the FTC recommends.
Objection (medium): The headline claim drops the source's hedges. FTC: 'scammers and dishonest businesses sometimes pay to appear at the top.' Draft claim: 'Scammers buy top search-engine ad slots and use lookalike web addresses and official-looking logos to pass themselves off as...' — stated as settled, ongoing, general practice with no 'sometimes' and with 'dishonest businesses' silently folded into 'scammers.' The finding paragraph restores the hedge; the claim line, which is what most readers see, does not.
Resolved: Restore the source's hedge in the claim line: 'The FTC warns that scammers and dishonest businesses sometimes pay for top search-ad placement, using lookalike web addresses and official-looking logos to pass themselves off as Healthcare.gov or Medicare.gov.' Attribution plus 'sometimes' costs six words and removes the overclaim.
Objection (medium): No date is attributed anywhere in reader-facing text. The advisory is dated 2026-09-29 and is explicitly framed as guidance 'ahead of' Open Enrollment. The finding says scams 'pick up during Open Enrollment' without saying which enrollment period, which year, or when the FTC said it. Medicare OEP (Oct 15–Dec 7) and Marketplace OEP (roughly Nov 1–Jan 15) are fixed windows; an undated alert reads as evergreen and will silently rot. Add 'In a September 2026 consumer alert, the FTC said...' The currency of the underlying source should also be sanity-checked against today's date before publication — a 2026-dated URL should not be shipped if the harvest ran earlier.
Resolved: Date-stamp the attribution in the first finding sentence ('In a consumer alert published 29 September 2026, the FTC said...') and add the enrollment windows only if a source supports them — otherwise leave them out and let the date carry the currency signal.
Objection (medium): Internal inconsistency in targeting governance. The draft drops two audience items on the stated ground that naming who is at risk is a claim about people needing a source (§11 Rule 2) — then offers 'ATTENTION: VETERANS' as a callout option. Nothing in the harvested row mentions veterans, TRICARE, VA or military health benefits at all. 'ATTENTION: EVERYONE' is also unsourced as a risk statement, though it is at least non-discriminating. Only the older-adult/Medicare framing has support (the row carries topic tags 'Scams Against Older Adults' and 'Medicare Impersonators' and names Medicare enrollment). Either the rule applies to the option list or it does not.
Resolved: Strike 'ATTENTION: VETERANS' from callout_options. It has zero support in the harvested row and contradicts the rule the draft just applied to drop two other audience items.
Objection (medium): Material omission of the source's own help routes. The FTC alert names three free, non-commercial places to get plan help: State Health Insurance Assistance Program (SHIP), Senior Medicare Patrol, and HealthCare.gov's 'Find Local Help.' The draft cuts all three while keeping the fear content and the reporting content. That inverts the alert's utility-to-alarm ratio — the reader is told not to trust search ads but not told where the free counseling is, which increases the chance they go back to searching.
Resolved: Add one sentence, fully sourced to the same row: 'The FTC also points to free help — State Health Insurance Assistance Programs and the Senior Medicare Patrol for Medicare, and the "Find Local Help" tool on HealthCare.gov for ACA plans.'
Objection (medium): 'High' confidence is doing work the evidence cannot support. There is exactly one row. It is preventative guidance, not incident documentation: no case counts, no loss totals, no named operator, no dated incident, no ad platform identified. High confidence is defensible for 'the FTC published this advice'; it is not defensible for 'scammers are currently buying top ad slots impersonating these two sites,' which is what the claim line asserts. Either downgrade to medium or narrow the claim to an attributed-statement claim. Note also that real corroboration plausibly exists (prior FTC enforcement in the health-plan lead-generation space) but none was harvested — the confidence_reasons correctly say 'no independent corroboration' and then the rating ignores that.
Not resolved — preserved on the record.
Objection (low): Risk line extrapolates. Source: 'paying for a scammy plan that's not health insurance.' Draft: 'can cost you a plan premium.' The source never says the loss takes the form of a premium, nor that it recurs. 'Cost you money for coverage that isn't insurance' is the supported version.
Resolved: Change risk_line to 'A paid search result can cost you money for coverage that isn't insurance, plus your medical identity.'
Objection (low): Directive option 'Send this to any impersonator you know' is incoherent and should not be in the option set at all — it reads as either a generator artifact or a joke, and if selected it would ship as nonsense over the byline.
Resolved: Strike 'Send this to any impersonator you know' from directive_options.
Objection (low): Alternative explanation not acknowledged. A top-of-page sponsored result for 'healthcare.gov' is more often a licensed-but-aggressive lead-generation or brokerage operation harvesting contact details for resale than an outright criminal impersonator. The consumer harm differs (spam call deluge and mis-sold limited-benefit products vs. outright theft), and the FTC's phrase 'dishonest businesses' points at exactly that middle category. The draft collapses the spectrum into 'scammers,' which makes the alert less accurate and less useful for recognising what the reader is actually looking at.
Not resolved — preserved on the record.
Preserved dissent
ON THE RECORDI do not accept 'high' confidence on this packet. One official row, preventative in nature, with no incident, no operator, no figure, no date of occurrence and no corroboration, supports a high-confidence statement that the FTC published advice — not a high-confidence statement about what scammers are doing right now. The confidence_reasons themselves concede 'no independent corroboration' and 'scale is undescribed,' and then the rating overrides that concession. Mark it medium or narrow the claim.
ON THE RECORDThe instruction 'check the address ends in .gov' is worse than no instruction, because it manufactures false confidence. A reader taught this test will clear medicare.gov-plans.com. The FTC wrote it badly; repeating it verbatim is a choice. If this ships unamended I want it on the record that the primary protective instruction in this alert is defeated by the most common impersonation domain pattern in existence.
ON THE RECORD'Never reach a health plan through a search ad' is not in the source and is not true. It is the draft's own absolutism dressed as guidance, and it is exactly the kind of line that gets a publication called alarmist by the agency it is citing.
ON THE RECORDOffering 'ATTENTION: VETERANS' while simultaneously dropping a 'shopping' callout for want of a source is not a close call. It is the same rule applied in two directions in the same document. Pick one.

The sources

Official sourceWhat to know ahead of Open Enrollment to avoid health insurance scams2026-09-29
The FTC says bad actors pay for top search placement and use lookalike web addresses, keywords and official-looking logos to imitate Healthcare.gov and Medicare.gov, and that using the ad's link or phone number can lead to paying for a scammy plan or to medical identity theft.
Authority: official. Retrieved 2026-09-28.
Limitation: Advisory is preventative guidance ahead of Open Enrollment; it gives no case counts, loss totals, named operators or dates of specific incidents.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/-0ybTjU

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 5 material sentence(s) map to FTC.
  • ✗ anthropic raised 4 objection(s); anthropic recorded dissent; groq returned "overstated"; openrouter returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-09-29.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.