18.3 Privacy, Fraud, and Consumer Protection

Key Takeaways

  • Gramm-Leach-Bliley (GLBA) requires financial institutions, including insurers, to give a privacy notice and opt-out before sharing nonpublic personal information with nonaffiliated third parties.
  • The Fair Credit Reporting Act (FCRA) governs use of consumer/credit reports for underwriting; an adverse action based on a report requires notice to the consumer with the reporting agency's name and address.
  • Insurance fraud is a felony in most states; the Fraud Enforcement and the McCarran-Ferguson framework leave anti-fraud enforcement primarily to state fraud bureaus, with the federal mail/wire fraud statutes layered on.
  • Soft fraud (padding a legitimate claim) and hard fraud (staging or fabricating a loss) are both criminal; the Insurance Fraud Prevention Act makes it a federal crime for an insurance-business person to embezzle or make false statements affecting solvency.
  • Producers must comply with the USA PATRIOT Act anti-money-laundering rules, the Do-Not-Call Registry, CAN-SPAM, and the Telephone Consumer Protection Act when marketing.
Last updated: June 2026

Privacy: Gramm-Leach-Bliley and FCRA

Even though insurance is state-regulated under McCarran-Ferguson, several federal consumer-protection laws apply directly and appear on the national exam.

The Gramm-Leach-Bliley Act (GLBA) of 1999 requires financial institutions—including insurers and producers—to protect consumers' nonpublic personal information (NPI). Key requirements:

  • Provide an initial and annual privacy notice describing information-sharing practices.
  • Give consumers the right to opt out before NPI is disclosed to nonaffiliated third parties.
  • Maintain administrative, technical, and physical safeguards for the data.

Note: GLBA distinguishes affiliated sharing (within a corporate family, generally allowed) from nonaffiliated sharing (requires opt-out). NPI includes any information a consumer provides to obtain a financial product, plus any data resulting from the transaction—names, account numbers, claims history, and medical underwriting data all qualify. The NAIC adopted a model privacy regulation so states could implement GLBA's standards in the insurance context, and most states layer their own data-breach notification requirements on top.

Fair Credit Reporting Act (FCRA)

The FCRA governs how insurers use consumer reports and credit-based insurance scores in underwriting. If an insurer takes an adverse action—declining coverage, charging a higher rate, or canceling—based wholly or partly on a report, it must:

  1. Notify the consumer that an adverse action was taken.
  2. Provide the name, address, and phone number of the consumer reporting agency that supplied the report.
  3. Inform the consumer of the right to a free copy of the report and to dispute inaccuracies.

A related law, the Fair and Accurate Credit Transactions Act (FACTA), added identity-theft and disposal-rule protections. The exam trap: the insurer is not required to tell the consumer the specific score, only that a report was used and where it came from.

Privacy, Fraud Statutes, and Consumer Protection

Several layered laws protect insurance consumers' information and combat fraud.

LawProtects / requires
Gramm-Leach-Bliley Act (GLBA)Financial-privacy notices; opt-out before sharing nonpublic personal information with third parties
Fair Credit Reporting Act (FCRA)Rules for using consumer/credit reports in underwriting; adverse-action notice required
HIPAAPrivacy of health information
Fraud statutesInsurance fraud is a crime; the Coalition Against Insurance Fraud and state fraud bureaus pursue it; producers must report suspected fraud
NAIC Insurance Information & Privacy ProtectionNotice, access, and correction rights for applicant data

Insurance fraud - inflating claims, staging losses, misrepresenting facts to obtain coverage or payment - raises premiums for everyone and is prosecuted criminally. Federal fraud statutes (18 U.S.C. 1033/1034) bar anyone convicted of a crime involving dishonesty/breach of trust from working in insurance without regulatory consent.

Exam trap: Under the FCRA, when an insurer takes an adverse action (declination, higher rate) based on a credit/consumer report, it must give the applicant an adverse-action notice identifying the reporting agency. GLBA requires privacy notices and an opt-out before sharing nonpublic personal financial information. 18 U.S.C. 1033 bars individuals convicted of dishonesty/breach-of-trust felonies from the insurance business absent written regulatory consent - a federal overlay on state licensing.

Test Your Knowledge

An insurer raises an applicant's homeowners premium after reviewing a credit-based insurance score. Under the FCRA, the insurer MUST:

A
B
C
D

Insurance Fraud: Soft vs. Hard

Fraud is the deliberate deception for unlawful gain and is a crime committed by applicants, insureds, producers, and insurers alike. The exam distinguishes:

TypeDefinitionExample
Soft fraudPadding or exaggerating an otherwise legitimate claimInflating a real $6,000 theft loss to $9,000
Hard fraudDeliberately staging or fabricating a lossStaging a car accident or arson for the claim

The federal Violent Crime Control / Insurance Fraud Prevention Act (18 U.S.C. §1033-1034) makes it a federal crime for anyone engaged in the business of insurance to embezzle funds, make false statements affecting solvency, or obstruct an investigation. A person convicted of a felony involving dishonesty or breach of trust is also barred from working in the insurance business under §1033 without written consent (a 1033 waiver) from the state commissioner.

Enforcement is layered: most states operate a dedicated insurance fraud bureau within the department of insurance, and many require insurers to maintain a Special Investigations Unit (SIU) and to file fraud reports. A typical anti-fraud notice on the application warns that knowingly presenting false information is a crime—this statutory fraud warning is itself often mandated by state law on every claim form and application.

Worked Example: Soft Fraud Exposure

An insured suffers a genuine kitchen fire with $18,000 in documented damage. On the proof of loss, the insured lists a non-existent $4,000 espresso machine and inflates cabinet repairs by $3,000, claiming $25,000 total.

Because the policy contains a Concealment, Misrepresentation, or Fraud condition, the insurer can void coverage for the entire claim—not just the $7,000 padding—if it proves the misstatement was material and intentional. The insured risks losing the legitimate $18,000 and faces criminal referral to the state fraud bureau. This is why the standard ISO fraud condition is one of the most powerful tools in claims handling, and why padding even a real loss is a high-stakes gamble for the insured.

Marketing and Anti-Money-Laundering Rules

Producers must also comply with several conduct rules when marketing:

  • National Do-Not-Call Registry / Telephone Consumer Protection Act (TCPA): no telemarketing calls to registered numbers; honor internal do-not-call lists; restrictions on autodialers and prerecorded messages.
  • CAN-SPAM Act: commercial email must have a truthful subject line, a physical address, and a functioning unsubscribe mechanism.
  • USA PATRIOT Act / Anti-Money-Laundering (AML): insurers offering products with cash value must maintain an AML program and file Suspicious Activity Reports (SARs); cash payments over $10,000 trigger IRS/FinCEN reporting.

The ethical throughline of this entire unit: a producer who discloses, documents, safeguards data, and never deceives satisfies both the letter of these consumer-protection laws and the broader fiduciary duty of utmost good faith.

Test Your Knowledge

An insured exaggerates a genuine $5,000 water-damage claim to $8,000 by adding fictitious damaged items. This conduct is BEST classified as:

A
B
C
D