18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- The Gramm-Leach-Bliley Act (GLBA) requires an initial and annual privacy notice and lets consumers opt out of sharing nonpublic personal information with nonaffiliated third parties.
- The Fair Credit Reporting Act (FCRA) governs consumer/credit reports; an adverse action based on a report requires notice and the reporting agency's identity.
- Insurance fraud is a knowing material misrepresentation to obtain a benefit; soft fraud (padding) and hard fraud (staged losses) both qualify and are usually felonies.
- Many states require a fraud-warning statement on applications and claim forms and mandate insurer fraud reporting through SIUs.
- Federal anti-money-laundering and OFAC rules apply mainly to cash-value products, but P&C producers still cannot transact with sanctioned parties.
Privacy: The Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) of 1999 protects nonpublic personal information (NPI) held by financial institutions, including insurers and producers. Core duties:
- Deliver an initial privacy notice at the start of the relationship and an annual notice describing information-sharing practices.
- Give consumers the right to opt out of sharing NPI with nonaffiliated third parties (sharing with affiliates or for servicing the policy is generally allowed).
- Safeguard the information against unauthorized access.
The NAIC's privacy model regulation implements GLBA at the state level.
The Fair Credit Reporting Act (FCRA)
The Fair Credit Reporting Act (FCRA) governs consumer reports and investigative consumer reports used in underwriting. Key rules:
- The applicant must be notified that a report may be obtained.
- If the insurer takes an adverse action (declination, higher rate, or nonrenewal) based wholly or partly on the report, it must give the consumer notice of the adverse action and the name and address of the reporting agency.
- The consumer may then obtain the report and dispute inaccuracies.
Trap: the adverse-action notice must name the agency, not merely state that a report was used.
An insurer raises an applicant's auto premium partly because of a consumer report. Under the FCRA, what must the insurer provide?
Two Tiers of Privacy Information
State privacy regulations split protected data into two tiers, and the exam tests the distinction:
- Nonpublic personal financial information — account numbers, premiums, payment history; opt-out rights apply to third-party sharing.
- Nonpublic personal health information — medical data, which generally requires affirmative authorization (opt-in) before disclosure, a higher standard than financial data.
Information lawfully made public (e.g., real-property records) is not NPI. A producer who shares a client's claims history with an unaffiliated marketing firm without an opt-out opportunity violates the privacy rule.
Insurance Fraud
Insurance fraud is a knowing material misrepresentation made to obtain a benefit one is not entitled to. The exam distinguishes two types:
| Type | Description | Example |
|---|---|---|
| Soft fraud | Exaggerating an otherwise legitimate claim | Padding a real theft loss with items never owned |
| Hard fraud | Deliberately causing or fabricating a loss | Staging a collision or arson for proceeds |
Both are typically felonies. Fraud can be committed by insureds, producers, or even insurers, and most states make it a crime to knowingly assist a fraudulent scheme.
Fraud Controls and Warnings
Most states require a fraud-warning statement on applications and claim forms, advising that providing false information is a crime subject to fines and imprisonment. Insurers maintain Special Investigation Units (SIUs) to investigate suspicious claims and must report suspected fraud to the state fraud bureau, often with immunity from civil liability for good-faith reporting.
Scenario: an insured submits receipts for a stolen laptop never purchased, inflating a genuine burglary claim. This is soft fraud — a material misrepresentation that voids that portion of the claim and may support criminal charges.
Material Misrepresentation and Concealment
Fraud connects directly to two contract-law doctrines the exam pairs with it:
- Material misrepresentation — a false statement of fact that, if known, would have changed the insurer's underwriting or rating decision. Materiality, not the size of the lie, is the test.
- Concealment — the deliberate failure to disclose a known material fact.
During the policy contestability window an insurer can rescind for material misrepresentation on the application. In a property claim, fraud or intentional concealment can void the entire claim under the policy's Concealment, Misrepresentation, or Fraud condition — not merely the padded portion.
Federal Anti-Money-Laundering and OFAC
Anti-money-laundering (AML) rules under the USA PATRIOT Act focus on products with cash value (more relevant to life than P&C), but every producer must comply with OFAC — the Office of Foreign Assets Control. OFAC bars transacting business with individuals or entities on its Specially Designated Nationals (SDN) list.
A producer must screen applicants against the SDN list and may not issue coverage or pay a claim to a sanctioned party. Violations carry steep federal penalties independent of state insurance law.
Other Federal Consumer-Protection Touchpoints
Several other federal regimes shape P&C practice:
- Terrorism Risk Insurance Act (TRIA) — requires insurers to offer terrorism coverage on commercial property and to disclose the federal backstop and any premium charge.
- Fair and Accurate Credit Transactions Act (FACTA) — adds the Red Flags Rule requiring written identity-theft prevention programs.
- CAN-SPAM / TCPA — limit unsolicited marketing emails, faxes, and calls.
Trap: TRIA requires only that terrorism coverage be offered and disclosed — the insured may reject it in writing; it is not mandatory.
Privacy Frameworks Producers Must Know
Several overlapping privacy regimes govern how producers and insurers collect, use, and share consumer data. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions, including insurers and agencies, to give consumers a privacy notice and an opt-out for sharing nonpublic personal financial information with nonaffiliated third parties. The Fair Credit Reporting Act (FCRA) governs the use of credit-based insurance scores and consumer reports, requiring adverse-action notices when a report leads to a declination or higher rate.
The HIPAA rules protect health information relevant to health and certain disability lines. Many states, following NAIC models, add insurance data-security laws requiring written information-security programs and prompt breach notification. The producer's takeaway: collect only what is needed, safeguard it, and give the required notices.
Fraud Reporting and Immunity
Insurance fraud statutes typically classify fraud as a felony and create fraud bureaus with investigative authority. Crucially, most states grant civil immunity to insurers and producers who report suspected fraud in good faith, encouraging reporting without fear of a defamation suit. Producers must understand they have an affirmative role in detecting and reporting suspicious claims, and that mandatory anti-fraud warnings appear on applications and claim forms.
Exam Tip: GLBA = privacy notice and opt-out; FCRA = consumer reports and adverse-action notices; good-faith fraud reporting carries civil immunity; and TRIA terrorism coverage must be offered but can be rejected in writing.
A policyholder reports a real kitchen fire but lists a designer oven that was never installed to increase the payout. How is this best classified?