18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- GLBA protects nonpublic financial information with privacy notices and an opt-out; HIPAA protects PHI and limits pre-existing condition exclusions in health plans.
- FCRA requires disclosing the report source when an applicant is declined based on a consumer/investigative report.
- 18 U.S.C. 1033/1034 bars anyone convicted of a felony of dishonesty from insurance work without a written 1033 waiver from the commissioner.
- An MIB coded record cannot alone justify a declination; it only prompts further investigation.
- The free-look period (commonly 10 days) starts at policy delivery and allows a full refund; advertising guaranty-association coverage is prohibited.
Privacy Frameworks: GLBA and HIPAA
Two federal laws dominate insurance privacy questions.
The Gramm-Leach-Bliley Act (GLBA) governs how financial institutions, including insurers, handle nonpublic personal financial information. It requires an initial and annual privacy notice describing information-sharing practices and an opt-out right before sharing nonpublic information with nonaffiliated third parties (with exceptions for servicing and legal compliance).
The Health Insurance Portability and Accountability Act (HIPAA) protects protected health information (PHI) and, in health insurance, also bars discrimination based on health status in group plans and limits pre-existing condition exclusions. The Privacy Rule restricts use/disclosure of PHI to treatment, payment, and operations without authorization.
GLBA vs. HIPAA — Don't Confuse Them
| Feature | GLBA | HIPAA |
|---|---|---|
| Protects | Financial nonpublic personal info | Protected health information (PHI) |
| Core consumer right | Opt-out of third-party sharing | Authorization before PHI disclosure |
| Notice required | Initial + annual privacy notice | Notice of Privacy Practices |
| Insurance angle | All financial products | Health plans; portability & pre-ex limits |
A second privacy concept: the Fair Credit Reporting Act (FCRA) governs consumer/investigative reports used in underwriting. If an applicant is declined based on a report, the insurer must disclose the source so the applicant can dispute errors.
Insurance Fraud and the Fraud and False Statements Act (18 U.S.C. 1033/1034)
Fraud is an intentional misrepresentation to obtain something of value. Tested federal rule: 18 U.S.C. § 1033/1034 makes it a federal crime for anyone convicted of a felony involving dishonesty or breach of trust to work in the business of insurance without written consent (a 1033 waiver) from the state insurance commissioner. Penalties include fines and imprisonment up to 10 years (more if the act jeopardizes insurer solvency).
The MIB (Medical Information Bureau) helps insurers detect fraud by flagging discrepancies across applications. A coded MIB record is not grounds to decline on its own — it only prompts further investigation.
State anti-fraud statutes complement the federal rule. Most states require insurers to maintain a special investigative unit (SIU) and to report suspected fraud to a fraud bureau, and grant immunity from civil liability to those who report suspected fraud in good faith. Fraud takes two forms on the exam: hard fraud (a deliberately staged or fabricated loss) and soft fraud (padding an otherwise legitimate claim or misstating information on an application). Both are illegal; soft fraud is the more common and is what an inflated claim or a concealed medical history represents.
Consumer Protection Mechanisms
Several provisions exist purely to protect the buyer:
- Free-look period — typically 10 days (often 30 for replacement or seniors) to return a policy for a full refund, no questions asked
- Buyer's Guide and Policy Summary — must be delivered for life insurance/annuities so consumers can compare costs
- Grace period — keeps coverage in force after a missed premium
- Guaranty associations — protect policyholders if an insurer becomes insolvent (do not advertise this in sales — doing so is a prohibited practice)
- Advertising standards — ads must be truthful, clear, complete, and identifiable as insurance solicitations
The free-look clock generally starts on the date the policy is delivered to the owner, not the application date — a common trap.
HIPAA Portability and Pre-Existing Conditions
Beyond privacy, HIPAA's group-health rules are heavily tested. HIPAA limits how long a group plan may exclude a pre-existing condition and requires that prior creditable coverage reduce any such exclusion period. It guarantees that small-group coverage is available regardless of the group's health status and prohibits using an individual's health factor to charge them more than similarly situated members. The Affordable Care Act later went further by eliminating pre-existing condition exclusions for most plans, but HIPAA portability concepts remain on the exam.
A practical scenario: an employee who had 14 months of prior continuous creditable coverage moves to a new group plan with a 12-month pre-ex exclusion. The prior coverage fully offsets the exclusion, so the new plan may not impose any waiting period for that condition.
How the Privacy and Fraud Pieces Fit Together
Underwriting lawfully gathers data — from the application, an attending physician statement, the MIB, and consumer/investigative reports under FCRA. Privacy law then constrains how that data may be shared and reused: GLBA for financial data, HIPAA for health data. Fraud law (1033/1034) constrains who may participate in the business at all.
Sequence to remember for an FCRA investigative consumer report: the applicant must be notified in advance that such a report may be ordered, has the right to request the nature and scope of the investigation, and — if an adverse decision results — must be told which agency supplied the report. This lets the consumer challenge inaccurate data. Tying these threads together, the producer's role is to collect honestly, disclose required notices, and never act as a conduit for misrepresentation by either party.
HIPAA, GLBA, and the FCRA Privacy Triad
Three federal privacy regimes govern how producers and insurers handle consumer information:
- HIPAA Privacy Rule — protects protected health information (PHI); requires authorization to disclose health data and limits use to treatment, payment, and operations.
- Gramm-Leach-Bliley Act (GLBA) — requires financial institutions, including insurers, to give a privacy notice and an opt-out of sharing nonpublic personal financial information with nonaffiliated third parties.
- Fair Credit Reporting Act (FCRA) — governs consumer/investigative reports; the insurer must give advance notice that a report may be obtained and, on an adverse action, disclose the source and the consumer's right to a free copy and to dispute errors.
Trap: GLBA covers financial privacy with an opt-out; HIPAA covers health privacy with an authorization requirement. The FCRA's trigger is an adverse underwriting decision based on a consumer report.
An individual convicted of embezzlement (a felony involving breach of trust) wants to sell insurance. Under 18 U.S.C. 1033/1034, that person:
Which federal law requires insurers to give consumers an initial and annual privacy notice and an opportunity to opt out before sharing nonpublic personal FINANCIAL information with nonaffiliated third parties?