18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- Gramm-Leach-Bliley Act (GLBA) requires insurers to give an INITIAL and ANNUAL privacy notice and an OPT-OUT before sharing nonpublic personal information (NPI) with nonaffiliated third parties; the Safeguards Rule mandates a written information-security program
- The Fair Credit Reporting Act (FCRA) governs insurance/consumer reports: adverse action based on a report requires NOTICE to the consumer plus the source so they can dispute it
- Insurance fraud is a felony under most state codes and the federal Fraud and False Statements provision (18 U.S.C. 1033/1034); soft fraud (padding a real claim) and hard fraud (staging a loss) are both prosecutable
- USA PATRIOT Act / anti-money-laundering (AML) rules require insurers offering products with cash value to maintain an AML program and file Suspicious Activity Reports (SARs); FinCEN oversees this federally
- Producers must give a HIPAA-style/Notice of Information Practices, obtain MIB and consumer-report consent, and follow do-not-call, CAN-SPAM, and TCPA telemarketing limits when soliciting
Privacy: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (1999) is the cornerstone privacy statute for financial institutions, including insurers and producers. It protects nonpublic personal information (NPI)—data a consumer provides that is not publicly available, such as Social Security numbers, account balances, claims history, and medical details. GLBA has three parts the exam tests:
- Privacy notices — an initial notice at the start of the relationship and an annual notice describing what NPI is collected and how it is shared.
- Opt-out — before sharing NPI with nonaffiliated third parties, the consumer must be given a reasonable chance to opt out (sharing with affiliates and for routine servicing is generally exempt).
- Safeguards Rule — insurers must maintain a written information-security program to protect NPI from unauthorized access.
Fair Credit Reporting Act (FCRA)
When an insurer uses an outside consumer report (credit-based insurance score, claims history via a database, or an investigative report) to underwrite or rate, the FCRA applies.
| Requirement | What the consumer gets |
|---|---|
| Disclosure of use | Notice that a report may be obtained |
| Adverse action notice | If a report causes a denial, higher rate, or reduced coverage, the consumer must be told |
| Source identification | Name/address of the reporting agency so the consumer can request the file and dispute errors |
| Free file disclosure | A free copy of the report after an adverse action |
An investigative consumer report (based on personal interviews about character or reputation) carries extra notice duties. Failure to send a required adverse-action notice is a frequent compliance violation.
An insurer denies a homeowners application after reviewing a credit-based insurance score from an outside agency. Under the FCRA, the insurer must:
Insurance Fraud
Fraud is a deliberate deception to obtain an unauthorized benefit and is a crime in nearly every state code, reinforced federally by the Fraud and False Statements provisions at 18 U.S.C. 1033 and 1034. Section 1033 makes it a federal offense for anyone in the business of insurance to act dishonestly; 1034 lets the U.S. Attorney General seek civil penalties.
- Soft fraud (opportunistic) — exaggerating a legitimate claim, e.g., padding a real $6,000 water-damage claim to $9,000.
- Hard fraud (premeditated) — staging or inventing a loss, e.g., deliberately burning a building for the insurance.
A convicted felon involved in dishonesty generally cannot work in insurance under 1033 without written consent (1033 waiver) from the state commissioner—a heavily tested point.
Anti-Money-Laundering (AML) and the PATRIOT Act
Products with a cash value or investment feature can be used to launder money, so the USA PATRIOT Act and Treasury rules require covered insurers to maintain a written AML program, train producers, and file Suspicious Activity Reports (SARs) with FinCEN. Red flags include a customer who overfunds a policy then quickly surrenders for a refund check, pays large premiums in cash, or is indifferent to product features and focused only on early liquidity.
Exam Key: SARs go to FinCEN (Treasury). The producer is the front line—report suspicious behavior up the chain; do NOT tip off the customer that a SAR is being filed ("tipping off" is itself prohibited).
Consumer Protection in Solicitation
Producers must respect marketing-conduct rules beyond the privacy statutes:
- Telephone Consumer Protection Act (TCPA) and the National Do-Not-Call Registry — no calls to registered numbers; honor internal do-not-call requests.
- CAN-SPAM Act — commercial email must allow opt-out and not use deceptive subject lines.
- Notice of Information Practices / MIB consent — obtain written authorization before pulling medical or MIB (Medical Information Bureau) data and disclose how information is used.
- Replacement regulations — when replacing existing coverage, deliver required comparison/disclosure forms so the consumer can evaluate the change and avoid twisting/churning.
These rules tie the privacy, fraud, and trade-practice chapters together: the consumer's data, money, and informed consent are protected at every step of the transaction.
How the Privacy Statutes Fit Together
The federal framework is layered, and the exam expects you to match each law to its job. GLBA controls how an insurer shares NPI (notices and opt-out). The FCRA controls outside reports used to underwrite (disclosure and adverse-action notice). State insurance information and privacy protection laws (modeled on the NAIC act) add state-level notice, access, and correction rights, letting consumers see and amend recorded personal data.
| Law | Triggers when... | Core duty |
|---|---|---|
| GLBA | Insurer shares NPI with third parties | Initial/annual notice + opt-out |
| FCRA | Insurer pulls a consumer/credit report | Disclosure + adverse-action notice |
| State privacy act | Insurer collects personal data | Access, correction, marketing limits |
Medical data carries the highest sensitivity; an authorization is required before disclosure, and improper release is both a privacy violation and a potential bad-faith act.
Detecting and Deterring Fraud
Fraud raises everyone's premiums, so the producer is positioned as the first line of defense. Most states require a fraud warning statement on applications and claim forms—language stating that knowingly filing false information is a crime—and many maintain a dedicated insurance fraud bureau that investigates referrals. Insurers must adopt anti-fraud plans and report suspected fraud to the bureau, often with statutory immunity for good-faith reports.
Practical red flags a producer should escalate include a claim filed immediately after a policy is bound, losses with no police or fire report, inflated repair estimates from a single favored vendor, and a claimant who is unusually eager to settle for cash. Recognizing these patterns—and never coaching a client to exaggerate—keeps the producer on the right side of both the criminal statutes and the UTPA.
A customer purchases a large cash-value policy, overfunds it with a cash payment, and within weeks requests a full surrender for a refund check to a third party. Under AML rules, the producer should: