18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- Gramm-Leach-Bliley (GLBA) requires initial and annual privacy notices and an OPT-OUT before sharing nonpublic personal financial information with unaffiliated third parties
- The Fair Credit Reporting Act (FCRA) governs insurance scores and consumer/investigative reports; an adverse action (decline, higher rate) triggers a required adverse-action notice
- Insurance fraud is a knowing misrepresentation to obtain a benefit; SOFT fraud is padding/exaggeration, HARD fraud is staged or deliberately caused losses—both are crimes
- The Fraud Enforcement section (18 U.S.C. 1033/1034) and state fraud bureaus enforce against fraud; many states require a fraud-warning statement on applications and claims
- Money laundering (Bank Secrecy Act/USA PATRIOT Act) and anti-money-laundering rules reach insurers selling products with cash value or investment features
Privacy: Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA, 1999) is the backbone of insurance privacy. It requires financial institutions—including insurers and producers—to protect nonpublic personal information (NPI): financial data a consumer provides, account information, and any list derived from it. GLBA imposes three duties tested on the exam:
- Privacy notice — provide an initial notice at the start of the relationship and an annual notice describing information-sharing practices.
- Opt-out right — before sharing NPI with nonaffiliated third parties, give the consumer a reasonable chance to opt out (sharing with affiliates and for servicing the policy is exempt).
- Safeguards — maintain administrative, technical, and physical safeguards to protect customer data.
The annual-notice rule has a narrow relief: an institution that has not changed its sharing practices and shares only within GLBA exceptions may be excused from re-sending the annual notice, but the safest exam answer treats the annual privacy notice as required. A producer must also know that sharing for routine servicing—processing the policy, handling a claim, or working with a reinsurer—is exempt from the opt-out, because that sharing is necessary to deliver the product the consumer bought.
GLBA distinguishes financial privacy from health privacy. Medical information receives heightened protection: the NAIC privacy model and HIPAA generally require affirmative consent (opt-in) before sharing health information, whereas financial NPI uses the weaker opt-out standard.
| Information Type | Standard | Example |
|---|---|---|
| Nonpublic financial (NPI) | Opt-OUT before third-party sharing | Premium, account, claim-payment data |
| Health/medical | Opt-IN (affirmative consent) | Medical records for a liability claim |
| Publicly available | No restriction | Property records, published phone listing |
Exam Key: Financial NPI = opt-out. Health information = opt-in. Reversing these is the most common privacy trap.
The Fair Credit Reporting Act
The Fair Credit Reporting Act (FCRA) governs how insurers use consumer reports and insurance scores (credit-based scores predictive of loss). Two report types appear on the exam:
- Consumer report — credit history, claims history (e.g., a CLUE report), and public records.
- Investigative consumer report — gathered through personal interviews with neighbors, associates, or employers about character and reputation; the consumer must be notified that such a report may be obtained and may request the nature and scope of the investigation.
When an insurer takes an adverse action—declining coverage, charging a higher premium, or non-renewing based wholly or partly on a report or score—the FCRA requires an adverse-action notice telling the consumer the action, the reporting agency used, and the right to a free copy of the report and to dispute inaccuracies.
An auto insurer charges an applicant a higher premium partly because of a low credit-based insurance score. Under the FCRA, what must the insurer do?
Insurance Fraud: Soft vs. Hard
Insurance fraud is a knowing misrepresentation or concealment of a material fact to obtain a benefit to which one is not entitled. It runs in both directions—claimant fraud and insurer/producer fraud. The exam draws a sharp line between two kinds:
| Type | Definition | Example |
|---|---|---|
| Soft fraud | Exaggerating or padding an otherwise legitimate claim | Inflating the value of stolen property; adding undamaged items |
| Hard fraud | Deliberately staging or causing a loss that never legitimately occurred | Staged auto collision; arson for insurance money |
Both are crimes. Soft fraud is more common and harder to detect; hard fraud is rarer but prosecuted aggressively. Producer-side fraud includes fictitious policies, fake claims, premium theft, and application fraud (falsifying an applicant's answers).
Anti-Fraud Enforcement and Required Warnings
Enforcement is layered. State fraud bureaus (often within the insurance department) investigate and refer cases for prosecution; many states require insurers to maintain a special investigation unit (SIU) and file an anti-fraud plan. Federal exposure for industry insiders comes from 18 U.S.C. 1033/1034.
Most states mandate a fraud-warning statement on applications and claim forms, substantially in this form:
"Any person who knowingly and with intent to defraud any insurance company files an application or claim containing materially false information... commits a fraudulent insurance act, which is a crime, and may be subject to fines and confinement in prison."
The warning's purpose is to establish the knowing/intent element and deter false statements at the point of application and claim.
Anti-Money-Laundering and Telemarketing
Insurers selling products with cash value or investment features (less common in pure P&C, but tested as general knowledge) are subject to the Bank Secrecy Act and USA PATRIOT Act anti-money-laundering (AML) rules: customer identification, suspicious-activity reporting (SARs), and an AML compliance program. Cash-laundering risk in P&C is lower, but large premium overpayments later refunded can be a red flag the AML program must catch.
Consumer-contact rules also apply: the Telephone Consumer Protection Act (TCPA) and Do-Not-Call registry restrict unsolicited calls and texts, and the CAN-SPAM Act governs commercial email—producers must honor opt-outs and identify themselves.
Finally, distinguish the federal fraud-warning purpose from the privacy notices above so the exam does not blur them. The fraud-warning statement on an application establishes the knowing-and-intent element of a fraudulent insurance act; the GLBA and HIPAA notices govern data sharing; the FCRA adverse-action notice governs report-based decisions. Three different notices, three different triggers—matching each notice to its statute is a frequent multiple-choice question on the national consumer-protection material.
A homeowner has a legitimate $4,000 theft loss but lists $7,000 of items, adding $3,000 of property that was never stolen, to recover more. This is best classified as: