Earlier quoted context omitted.
This. SMS 2FA has been considered insecure by NIST since 2016 [1] and it's a major pain when travelling and swapping sim cards. [1] https://www.theregister.com/2016/07/24/nist_says_sms_no_good...
I was thinking this with my health insurance website (which uses SMS 2FA), and I realized the problem is you can't expect your average Joe to know how to manage a TOTP 2FA correctly. SMS might not be the most secure, but it's probably better than 1FA, and absolutely everyone can use it. Enter your number, receive text, boom.
Controversial opinion: If you are given all these options and you cannot/refuse to use them, you shouldn't manage your insurrance trough the web. Either you are wholly computer-illiterate, deeply misinformed or you are not educated enough to use it safely.
Of course, the main issue is that companies only give SMS 2FA as an option, or only one other, like the App method, which forces users without phones to fall back to SMS. Worst part is that especially financial institutions are guilty of this.