18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection

Key Takeaways

  • GLBA requires initial and annual privacy notices and an opt-out before sharing nonpublic personal financial information with nonaffiliated third parties.
  • HIPAA protects PHI; TPO uses need no authorization, but marketing/sale of PHI requires written authorization, and breaches trigger HHS notification.
  • The tested contrast: GLBA generally uses opt-out, while HIPAA marketing uses of health data generally require opt-in.
  • Under 18 U.S.C. 1033, a felon convicted of dishonesty or breach of trust needs a written 1033 waiver from the commissioner to work in insurance.
  • AML/PATRIOT Act, FCRA adverse-action notices, and CAN-SPAM/Do-Not-Call rules all govern insurer and producer conduct.
Last updated: June 2026

Federal Privacy Framework

Two federal laws dominate the national portion's privacy questions: the Gramm-Leach-Bliley Act (GLBA) for financial privacy and the Health Insurance Portability and Accountability Act (HIPAA) for protected health information.

GLBA requires financial institutions, including insurers, to give consumers an initial and annual privacy notice describing what nonpublic personal information is collected and shared. It protects nonpublic personal financial information under the Financial Privacy Rule and the Safeguards Rule, which requires a written information-security program with administrative, technical, and physical controls.

For insurance, the state insurance commissioner — not a federal banking regulator — typically enforces GLBA's privacy provisions through a state privacy regulation modeled on the NAIC. A producer who improperly discloses a client's financial information therefore faces state disciplinary action in addition to any federal exposure.

Opt-Out vs. Opt-In

The most tested GLBA mechanic is the opt-out right. Before sharing a consumer's nonpublic personal information with nonaffiliated third parties, the institution must give a privacy notice and a reasonable opportunity to opt out.

Sharing scenarioConsumer right
With affiliatesGenerally no opt-out required
With nonaffiliated third parties (marketing)Opt-out required first
To service the account / process a claim (joint marketing, legal compliance)Exception — no opt-out needed

Note the contrast tested on exams: GLBA generally uses opt-out, while HIPAA marketing uses of health data generally require opt-in authorization.

GLBA also distinguishes a customer (an ongoing relationship, owed an annual notice) from a mere consumer (a one-time inquiry, owed a notice only before nonpublic information is shared). A producer who collects a Social Security number, account balance, or income figure during an application is handling nonpublic personal information and must protect it under the Safeguards Rule — locking files, encrypting data, and disposing of records securely. Casual disclosure to a friend or unsecured email of client financials is a violation regardless of intent.

HIPAA Privacy

HIPAA's Privacy Rule protects Protected Health Information (PHI) — individually identifiable health data held by a covered entity. Covered entities may use PHI without separate authorization for Treatment, Payment, and health-care Operations (TPO).

Most other disclosures — especially marketing and the sale of PHI — require the individual's written authorization. The Privacy Rule also requires using the minimum necessary information for a purpose and gives individuals a right to access and amend their records.

For life and disability underwriting, the producer obtains a signed HIPAA authorization so the insurer can access medical records; that authorization must state what is disclosed, to whom, and an expiration date, and the individual may revoke it in writing. A breach of unsecured PHI triggers federal breach-notification duties to the individual and to the Department of Health and Human Services (HHS), and large breaches must also be reported to the media.

Remember the boundary: HIPAA covers health information held by covered entities, while GLBA covers financial information. A life insurer's medical questionnaire is PHI; the same insurer's record of premium payments and bank routing data is GLBA-protected financial data.

Test Your Knowledge

Under GLBA, before an insurer may share a customer's nonpublic personal financial information with a nonaffiliated marketing company, it must:

A
B
C
D

Insurance Fraud and Federal Law

Insurance fraud is a criminal offense. The federal Fraud and False Statements provision (18 U.S.C. 1033/1034) makes it a felony for anyone engaged in the business of insurance to willfully make false statements, embezzle funds, or use threats. A critical, heavily tested rule: a person convicted of a felony involving dishonesty or breach of trust may not work in the business of insurance affecting interstate commerce without written consent (a 1033 waiver) from the state insurance commissioner. Penalties under 1033 include fines and imprisonment, scaled up if the conduct jeopardizes an insurer's solvency.

Fraud takes two forms the exam contrasts. Hard fraud is a deliberately fabricated loss — staging a death or faking a disability claim. Soft fraud (opportunistic fraud) is exaggerating an otherwise legitimate claim or shading answers on an application to obtain a better rate. Application misstatements interact with the policy's incontestability and material-misrepresentation rules: a material lie discovered within the contestable period lets the insurer rescind, while fraudulent statements can void coverage even later in many states.

Consumer Protection: USA PATRIOT Act, AML, and CAN-SPAM

Several federal consumer-protection regimes touch insurance sales:

  • USA PATRIOT Act / Anti-Money-Laundering (AML) — insurers issuing products with cash value or investment features must maintain an AML program and file Suspicious Activity Reports (SARs); producers complete AML training. Large or structured cash transactions are red flags.
  • Fair Credit Reporting Act (FCRA) — if an insurer uses a consumer/investigative report and takes adverse action (declines or rates up), it must give an adverse-action notice and the source of the report.
  • CAN-SPAM / Do-Not-Call — commercial email and telemarketing rules apply to producer prospecting; honoring opt-outs is mandatory.
  • Telemarketing/Telephone Consumer Protection — scrub against the national Do-Not-Call registry.
  • NAIC Insurance Data Security Model Law — adopted by many states, it requires licensees to maintain an information-security program and to investigate and notify the commissioner of cybersecurity events.

The through-line of every consumer-protection rule is the same fiduciary instinct that governs claims and sales: the producer safeguards the consumer's money, health data, and financial data, discloses material facts, and never uses deception or pressure to make a sale. On the exam, when a fact pattern describes mishandled information, ask first which regime applies — financial (GLBA), health (HIPAA), fraud (1033), or marketing (CAN-SPAM/Do-Not-Call) — then apply that regime's specific duty.

Test Your Knowledge

An applicant for an insurance-agency position has a prior felony conviction for embezzlement. Under federal law (18 U.S.C. 1033/1034), the person may work in the business of insurance only if:

A
B
C
D