Spark maintains a formal set of compliance policies that govern how Spark, its employees, and its business partners — including downline agencies, agents, and vendors — operate. Below is a summary of three key policies, with links to the full documents.
Business Partner Code of Conduct
Version 2.0 · Effective June 30, 2026
This Code applies to all Business Partners of Spark Health Inc. and its subsidiaries — including downline agencies, agents, contractors, affiliates, consultants, suppliers, vendors, and distributors. It sets expectations for lawful and ethical conduct in any interaction with Spark, covering:
Compliance with CMS, HIPAA, FWA, anti-kickback, data privacy, and labor laws
Honest and fair dealings, including prohibitions on false or misleading statements and financial documentation
Anti-harassment and non-discrimination
Conflicts of interest and gift/hospitality limits
Reporting misconduct and protection from retaliation
Alcohol and drug use standards
Read the full policy here: Business Partner Code of Conduct_V2.0.pdf
Suspected violations, conflicts of interest, or questions can be reported to [email protected].
Compliance Program Policy
Control #: CMP-POL-001-P · Version 1.1 · Effective July 21, 2025
This policy establishes Spark's overall Compliance Program, built on the seven elements of an effective compliance program as defined by the HHS Office of Inspector General. It applies to all Spark employees, contractors, business partners, and third parties performing work on Spark's behalf, and covers:
The regulatory framework Spark operates under, including CMS requirements (42 CFR §§422.503, 423.504), HIPAA, and SOC 2
Compliance leadership and oversight, led by Spark's Compliance Officer and a Compliance Committee
Required annual training for all Associates and FDRs, including General Compliance, HIPAA, Conflict of Interest, and Fraud, Waste, and Abuse (FWA) Prevention
Multiple confidential and anonymous reporting channels, with a zero-tolerance stance on retaliation
Ongoing monitoring, auditing, and risk assessment, including oversight of the Compliance Agency Monitoring Program (CAMP)
Enforcement of standards and response to detected violations
This policy is reviewed at least annually. Individuals may report compliance concerns anonymously without fear of retaliation.
Read the full policy here: CMP-POL-001-P_Compliance Program Policy_V1.1 (1).pdf
Third-Party Marketing Organization (TPMO) Oversight Policy
Control #: CMP-POL-015-P · Version 2.0 · Effective July 17, 2026
This policy sets the rules for how Medicare Advantage, Part D, Medicare Supplement, and ancillary health products are sold and marketed by Spark and its downline agencies, agents, and lead vendors. It's grounded in CMS's Medicare Communications and Marketing Guidelines (MCMG), the CMS TPMO Final Rule, and 42 CFR §§422 and 423. Key areas covered include:
Scope of Appointment (SOA), needs assessments, and enrollment process requirements
Call recording, the TPMO disclaimer, and rules against unsolicited contact
Open Enrollment Period (OEP) marketing restrictions and anti-discrimination requirements
Limits on gifts and meals at marketing and sales events
Content requirements for marketing and communication materials, including required carrier/CMS submission
Lead vendor contracting, disclosure, and consent requirements
Monitoring and enforcement through Spark's Compliance Agency Monitoring Program (CAMP)
Important: Downline agencies may not circumvent this policy by operating through affiliated entities, subcontractors, alternative TPMO structures, or undisclosed marketing arrangements.
Questions about this policy can be directed to [email protected].
Read the full policy here: Third-Party Marketing Organization Oversight Policy_V2.0.pdf
Record Retention Policy
Control #: CMP-POL-004-P · Version 2.0 · Effective January 1, 2023
This policy establishes Spark's minimum requirements for retaining, maintaining, and disposing of business records, to ensure compliance with applicable federal and state regulations and support operational continuity. It applies to all Associates — employees, contractors, consultants, agents, temporary workers, and business partners — and covers records in any format across all departments and subsidiaries. Key areas covered include:
Medicare Advantage records — a 10-year minimum retention requirement covering enrollment/disenrollment records, training completion, exclusion screening evidence, FWA documentation, contracts, financial statements, and CMS audit-support records
A shortened 6-year retention schedule for certain Contract Year 2027 marketing and sales call recordings, with enrollment calls remaining subject to the standard 10-year requirement
General business records, including corporate records, contracts, financial records, tax returns, payroll, and personnel files, retained per the longest applicable federal, state, or litigation statute-of-limitations standard
Preservation of records under legal hold, audit, or investigation regardless of the standard retention schedule
Secure disposition standards for records that have met their retention period
Read the full policy here: CMP-POL-004-P_Record Retention Policy_V2.0 (1).pdf
