18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- GLBA protects nonpublic financial information (privacy notice + opt-out); HIPAA protects PHI (authorization beyond treatment/payment/operations); some states require opt-in for health data.
- Under 18 U.S.C. 1033, a felony involving dishonesty bars insurance work unless the commissioner grants written consent (a 1033 waiver).
- FCRA requires an adverse-action notice when an applicant is declined based on a consumer or investigative report.
- Insurance fraud can be committed by applicants, insureds, producers, or insurers; fraud-warning statements and state fraud bureaus support enforcement.
- Confidential information from the insurance process must be used only for its intended purpose-never sold or disclosed without authorization.
Privacy Regulation: GLBA and HIPAA
Producers handle highly sensitive financial and health data, and two federal laws govern its protection. Know which law covers which information.
- The Gramm-Leach-Bliley Act (GLBA) protects consumers' nonpublic personal financial information. It requires financial institutions—including insurers and producers—to provide a privacy notice at the start of the relationship and annually, explain information-sharing practices, and give consumers the chance to opt out of sharing with nonaffiliated third parties. GLBA's Safeguards Rule requires a written information-security program.
- The Health Insurance Portability and Accountability Act (HIPAA) protects Protected Health Information (PHI). Its Privacy Rule limits use and disclosure of PHI to treatment, payment, and health-care operations unless the individual authorizes more, and its Security Rule protects electronic PHI. HIPAA also guarantees portability and limits preexisting-condition exclusions in group health.
| Information type | Governing law | Core consumer right |
|---|---|---|
| Nonpublic financial info | GLBA | Privacy notice + opt-out of third-party sharing |
| Protected health info (PHI) | HIPAA | Authorization required to disclose beyond TPO |
Many states also adopt the NAIC Privacy of Consumer Financial and Health Information Regulation, which can require opt-in consent for health-information sharing—stricter than GLBA's opt-out for financial data.
Insurance Fraud and Federal Law
Insurance fraud is a knowing misrepresentation made to obtain a benefit, payment, or advantage. It can be committed by applicants (false health answers), insureds (inflated or staged claims), producers (forging signatures, fake applications, theft of premium), or insurers (bad-faith claim denials). Most states maintain a fraud bureau, require a fraud-warning statement on applications and claim forms, and grant immunity for good-faith fraud reporting.
The central federal statute is the Violent Crime Control and Law Enforcement Act of 1994, Section 1033/1034. Under 18 U.S.C. 1033, it is a federal crime for anyone engaged in the business of insurance to commit fraud or to willfully embezzle funds.
Critically, a person convicted of a felony involving dishonesty or breach of trust may not work in the business of insurance without written consent (a 1033 waiver) from the state insurance commissioner. Penalties under 1033 can reach fines and up to 10-15 years imprisonment depending on the harm caused.
Expect a question that hinges on the 1033 felony-prohibition and the written-consent waiver. Note the difference between soft fraud (padding an otherwise legitimate claim, or shading answers on an application) and hard fraud (a deliberately staged or fabricated loss); both are crimes, but hard fraud carries the heavier penalties.
Other Consumer-Protection Laws
Several federal statutes complete the consumer-protection picture:
- Fair Credit Reporting Act (FCRA): governs use of consumer/credit reports and investigative consumer reports in underwriting. If an applicant is declined based on a report, the insurer must give an adverse-action notice identifying the reporting agency. Applicants must be notified that an investigative report may be obtained.
- USA PATRIOT Act / Anti-Money-Laundering (AML): insurers selling products with cash value or investment features must maintain an AML program and file Suspicious Activity Reports; producers complete AML training. A red flag: a client funds a large annuity with cash and quickly requests surrender.
- CAN-SPAM / Telemarketing rules and Do-Not-Call: govern unsolicited commercial communications.
- ERISA: federal protection of private employer benefit plans (reporting, disclosure, fiduciary standards).
The overarching theme: confidential information obtained in the insurance process must be protected and used only for its intended purpose, never sold, posted, or shared without authority.
The Medical Information Bureau (MIB) ties privacy and underwriting together. Member insurers report coded health information to the MIB, and an applicant must be notified that information may be obtained from and reported to it. The MIB is used only to detect omissions or fraud, and an insurer may not decline coverage solely on an MIB record—it must independently verify. This mirrors the FCRA principle: consumer reports support, but do not replace, a fair underwriting decision, and the applicant retains the right to learn the source and dispute inaccuracies.
An insurer wants to share a customer's nonpublic personal financial information with a nonaffiliated marketing firm. Under the Gramm-Leach-Bliley Act, the insurer must:
An individual convicted of a felony involving dishonesty wishes to work in the insurance business. Under 18 U.S.C. 1033, that person:
GLBA Notices vs. HIPAA Protected Health Information
The two privacy regimes cover different data. The Gramm-Leach-Bliley Act (GLBA) governs nonpublic personal financial information, requiring an initial and annual privacy notice and an opt-out before sharing with nonaffiliated third parties. HIPAA governs protected health information (PHI), generally requiring the consumer's authorization to disclose health data for non-treatment, non-payment purposes.
| Law | Protects | Default consumer right |
|---|---|---|
| GLBA | Financial information | Opt-out of third-party sharing |
| HIPAA Privacy Rule | Protected health info | Authorization required to disclose |
| Fair Credit Reporting Act | Consumer report data | Notice if report affects underwriting |
Fraud, the Fraud Warning, and Federal Reach
Insurance fraud is a crime for both applicants (material misstatements to obtain coverage or pay claims) and insiders, and applications carry a fraud warning stating that false statements are punishable. Under the federal Fraud and False Statements provisions (18 U.S.C. 1033/1034), a person convicted of a felony involving dishonesty is barred from the business of insurance without written regulatory consent — a federal overlay on state licensing the exam expects candidates to recognize.
Telemarketing, CAN-SPAM, and Do-Not-Call
Consumer-protection rules reach how producers contact prospects, not just how they handle data. The federal Telephone Consumer Protection Act and the National Do-Not-Call Registry restrict unsolicited sales calls, and the CAN-SPAM Act governs commercial email with opt-out and accurate-header requirements. Violations carry per-contact penalties independent of any policy sold.
The exam frames these alongside GLBA and HIPAA to make the point that consumer protection spans the entire relationship: how a producer first reaches a prospect, what financial and health data may be shared, and how fraudulent statements are punished — a single thread of trust running from solicitation through claims.