Skip to main content

The Money Overview

A genuine message from Medicare will never offer a new card or ask you to click a link

Beneficiaries who receive an unexpected call, text, or email promising a new Medicare card or directing them to click a link are almost certainly dealing with a scam. The federal program does not initiate contact to request personal information, offer replacement cards, or verify account details through surprise messages. With CMS recently notifying individuals about a data incident involving Medicare.gov account-creation letters, the risk of confusion between real government correspondence and fraudulent outreach has grown sharper for the millions of Americans enrolled in the program.

Why scam timing around Medicare notices creates real danger

Fraudulent Medicare contacts do not arrive at random. Scammers design their outreach to coincide with periods when beneficiaries expect to hear from the government, such as open enrollment or after CMS sends official letters. CMS issued a press release confirming it had notified individuals potentially impacted by a data incident involving Medicare.gov account-creation letters that recipients did not initiate. That kind of legitimate government mailing creates a window of uncertainty. A beneficiary who just received a real CMS letter is far more likely to engage with a follow-up phone call or text that appears to come from Medicare, even if the second contact is fake.

The hypothesis that phishing campaigns spike alongside official CMS notifications is plausible but not yet confirmed by public call-center data. No primary dataset from 1-800-MEDICARE currently quantifies inbound verification calls tied to specific notification mailings. The pattern, however, fits what federal and state agencies describe: scammers exploit moments of legitimate government activity to make their scripts more convincing.

Federal and state agencies agree on what Medicare will never do

Multiple federal agencies have drawn the same bright line. Medicare will never call beneficiaries uninvited to ask for or check Medicare numbers, according to official card guidance. The program will only call and ask for personal information after a beneficiary has already contacted Medicare or reported fraud, as the agency’s own fraud information page confirms. The Federal Trade Commission has separately stated that Medicare will never unexpectedly call, email, text, or message on social media to ask for Medicare, Social Security, or bank account numbers.

During the card-number transition, CMS published a printed scam alert explicitly telling beneficiaries they did not need to take any action to receive the updated card and that no one representing Medicare would ever ask for personal information to issue it. The FTC documented common scam scripts in which callers claim a beneficiary must provide personal details or pay a fee to get a new card. The HHS Office of Inspector General has flagged the same pattern, noting that scammers target individuals through phone, email, and social media to steal money or personal, medical, and financial information.

State-level warnings reinforce the federal position. The Georgia Attorney General’s consumer protection division warns that caller ID may display “Medicare” even when the call is a scam. The District of Columbia’s Department of Insurance, Securities and Banking has warned that scammers send unsolicited emails, texts, and social media messages urging people to click a link or call a number to confirm eligibility. Both offices emphasize that beneficiaries should treat any uninvited request for Medicare, Social Security, or banking details as a red flag, regardless of what the caller ID or email address appears to show.

Gaps in enforcement data and what beneficiaries should do first

Despite the consistent warnings, significant gaps remain in the public record. No comprehensive, publicly available dataset links specific CMS notification campaigns to changes in scam reports or call volumes. Federal agencies publish consumer alerts and enforcement actions, but those snapshots do not quantify how many people were targeted during particular mailings or how many attempted scams went unreported. State regulators likewise tend to highlight individual cases or emerging tactics rather than providing granular statistics that could confirm suspected spikes in fraud.

Those blind spots put more weight on individual decision-making. Because beneficiaries cannot rely on real-time scam statistics, they have to assume that any unsolicited outreach about Medicare benefits, cards, or account issues may be fraudulent. The safest default is to hang up, delete, or ignore and then verify independently using trusted contact information.

Experts consistently recommend a simple sequence when something seems off. First, do not provide or confirm any personal, medical, or financial details in response to an unexpected contact, even if the caller already knows part of your information. Second, avoid clicking links or opening attachments in unsolicited emails or texts that reference Medicare accounts or cards. Third, if you are worried that a message might be legitimate, use a phone number or website you look up yourself-such as the number on the back of your Medicare card or the official Medicare.gov site-rather than anything provided in the suspicious communication.

Beneficiaries who suspect they have shared information with a scammer should act quickly. That includes contacting their bank or credit card issuer, monitoring Medicare Summary Notices for unfamiliar charges, and reporting the incident to Medicare and other relevant authorities. Even when enforcement data is incomplete, those reports help agencies spot new patterns, issue timely warnings, and, in some cases, shut down fraudulent operations before they reach more people.


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.