18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- The Gramm-Leach-Bliley Act (GLBA) requires privacy notices; financial NPI is generally opt-out, health information generally opt-in.
- A material misrepresentation can void coverage even if unintentional, because materiality is the test for rescission.
- Title 18 U.S.C. 1033 bars felons convicted of dishonesty from the insurance business without written 1033 consent.
- The Fair Credit Reporting Act (FCRA) requires an adverse-action notice when a credit report drives a declination or higher rate.
- Most states require good-faith fraud reporting and grant immunity for it.
Privacy Protection: GLBA and the Privacy Rules
Insurance producers handle nonpublic personal information (NPI) — financial and health data — so federal and state privacy law applies.
- The Gramm-Leach-Bliley Act (GLBA) requires financial institutions, including insurers and producers, to protect customers' nonpublic personal information and to give a clear privacy notice describing information-sharing practices.
- GLBA distinguishes opt-out rights (the consumer may stop sharing of financial NPI with nonaffiliated third parties) from stricter opt-in treatment of certain health information.
- The NAIC privacy models add HIPAA-aligned handling of protected health information when health data is involved.
Exam Key: Sharing financial NPI with nonaffiliated third parties is generally opt-out; using or sharing health information generally requires opt-in (affirmative consent).
What the Privacy Notice Must Do
A GLBA privacy notice is required at the start of the relationship and annually in many cases (with some exceptions when practices have not changed). It must describe:
- The categories of nonpublic personal information collected and disclosed.
- The categories of affiliates and nonaffiliated third parties that may receive it.
- The consumer's right to opt out of certain sharing, and how to exercise it.
- The insurer's policies for protecting the information.
Distinguish a customer (an ongoing relationship — gets annual notices) from a one-time consumer (gets a notice only before sharing).
Insurance Fraud
Fraud is an intentional deception or misrepresentation made to gain an unfair or unlawful benefit. It cuts two ways:
| Fraud By | Example |
|---|---|
| Applicant/Insured | Staging a theft; inflating a damage claim; lying about prior losses |
| Producer | Conversion of premiums; selling fictitious "phantom" policies; forging signatures |
Key federal/structural concepts:
- Material misrepresentation on an application can void coverage — the misstatement is material if the insurer would have charged more or declined had it known the truth.
- The Fraud and False Statements Act (18 U.S.C. 1033/1034) bars anyone convicted of a felony involving dishonesty or breach of trust from working in the business of insurance affecting interstate commerce without written 1033 consent from the regulator.
- Most states require a producer who suspects fraud to report it and grant immunity for good-faith reporting.
Scenario: An applicant conceals two prior fire losses. A later fire claim is investigated, the concealment is material, and the insurer may rescind the policy from inception (returning premium but paying no loss).
Concealment, Misrepresentation, and Fraud Distinguished
- Concealment — silent withholding of a material fact the applicant knew should be disclosed.
- Misrepresentation — an affirmative false statement of a material fact.
- Fraud — either of the above committed intentionally to deceive for gain.
Materiality (would it have changed underwriting?) — not intent — is the test for rescission, but intent is what elevates conduct to criminal fraud with fines and imprisonment under state insurance-fraud statutes.
Under the Gramm-Leach-Bliley Act privacy rules, sharing a consumer's nonpublic financial information with a NONAFFILIATED third party generally requires the insurer to:
Consumer Protection Frameworks
Several layers of law protect insurance consumers, and the exam expects you to match each to its purpose.
- Fair Credit Reporting Act (FCRA) — when an insurer uses a consumer/credit report and takes an adverse action (declination, higher rate, nonrenewal), it must give the applicant an adverse-action notice identifying the reporting agency.
- USA PATRIOT Act / Anti-Money-Laundering (AML) — applies mainly to cash-value products; producers must watch for suspicious activity. Pure P&C products carry limited AML exposure but the concept is testable.
- Do-Not-Call and CAN-SPAM — restrict telemarketing and commercial email solicitations.
- Replacement and free-look rules — give consumers a window to review and return a policy.
- Terrorism Risk Insurance Act (TRIA) — requires insurers to offer terrorism coverage and disclose its premium on commercial property/casualty policies.
Data Breach and Cybersecurity
The NAIC Insurance Data Security Model Law, adopted by a growing number of states, requires licensees to maintain a written information security program and to notify the commissioner of a cybersecurity event (often within 72 hours). Producers who store client Social Security numbers, financial data, or claim files fall within these duties.
Common Exam Traps
- GLBA is opt-out for financial NPI but opt-in for health information — do not reverse them.
- A material misrepresentation can void coverage even if unintentional, because materiality (not intent) is the test for rescission.
- 1033 consent is required for a felon (crime of dishonesty) to re-enter the business — a state license alone is not enough.
- An adverse-action notice under FCRA is triggered by a credit-based decision, not by every quote.
- Rescission returns the premium and voids coverage from inception — it is not the same as a cancellation (which ends coverage prospectively) or a nonrenewal.
Putting Consumer Protection Together
Match each statute to its trigger: GLBA = privacy notices and information sharing; FCRA = credit reports and adverse-action notices; 1033 = felons of dishonesty needing written consent; state fraud statutes = rescission for material misrepresentation plus criminal exposure for intentional deceit; data-security law = breach notification. The exam rewards candidates who can name the right framework for the right fact pattern rather than memorizing any one law in isolation.
An applicant intentionally conceals two prior fire losses, and the insurer later proves the concealment was material to the underwriting decision. The insurer's most likely remedy is to: