18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- GLBA requires a privacy notice and opt-out before sharing NPI with nonaffiliated third parties; affiliate sharing generally has no opt-out.
- HIPAA requires authorization to disclose PHI and limits health-coverage pre-existing-condition rules.
- FCRA requires adverse-action notice when underwriting decisions rely on consumer reports.
- 18 U.S.C. 1033/1034 bars felons convicted of dishonesty from insurance work without a commissioner's 1033 waiver.
- Consumer safeguards include the Buyer's Guide, policy summary, free-look (commonly 10–30 days), replacement notices, and fraud-warning statements.
18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
The final ethics section covers the federal privacy and fraud framework layered on top of state law. Insurance producers handle highly sensitive nonpublic personal information (NPI) and protected health information (PHI), so federal statutes impose disclosure, security, and consent rules that the exam tests by acronym and trigger.
Federal Privacy Statutes
| Law | Scope | Key Requirement |
|---|---|---|
| GLBA (Gramm-Leach-Bliley Act) | Financial NPI held by financial institutions | Provide privacy notice at account opening and annually; allow opt-out before sharing NPI with nonaffiliated third parties |
| HIPAA | Protected health information | Privacy and Security Rules; authorization needed to disclose PHI; portability and limits on pre-existing-condition exclusions |
| Fair Credit Reporting Act (FCRA) | Consumer reports used in underwriting | Notify applicants when an adverse decision is based on a report; allow access and dispute |
GLBA distinguishes opt-out (NPI to nonaffiliated third parties — consumer can decline) from affiliate sharing, which generally does not require opt-out. HIPAA generally requires affirmative authorization before PHI is disclosed for non-treatment, non-payment purposes.
Privacy Mechanics and Notices
- A privacy notice must be delivered when the customer relationship begins and annually thereafter (the annual notice can be omitted if practices and sharing have not changed).
- The Privacy of Consumer Financial and Health Information regulation (NAIC model) requires both financial and health privacy notices for insurers.
- An applicant signs a HIPAA authorization and a Fair Credit Reporting disclosure allowing the insurer to obtain MIB, prescription, and credit-based data for underwriting.
Insurance Fraud and Consumer Protection
The Fraud and False Statements provision (18 U.S.C. 1033/1034) makes it a federal crime for anyone engaged in the business of insurance to make false statements, embezzle, or commit fraud affecting interstate commerce. A person convicted of a felony involving dishonesty or breach of trust may not work in insurance without written consent (a 1033 waiver) from the state insurance commissioner. Penalties include fines and imprisonment up to 10 years (15 years if the misconduct jeopardizes the insurer's solvency).
Consumer-protection backstops the exam tests:
- Buyer's Guide and Policy Summary — must be delivered to life insurance applicants so they can compare costs.
- Free-look period — typically 10–30 days to return a policy for a full premium refund; replacement sales often extend it (e.g., 20–30 days).
- Cooling-off and replacement notices — the producer must give the prospect a replacement disclosure and notify the existing insurer.
- Do-Not-Call / CAN-SPAM and telemarketing rules — govern solicitation conduct.
- Fraud warning statements — applications must carry a notice that knowingly false statements are insurance fraud.
Detecting and Reporting Fraud
Fraud flows in two directions, and the exam tests both. Hard fraud is a deliberate fabricated loss; soft fraud is padding an otherwise legitimate claim. Producers must recognize warning signs and avoid participating — submitting an application they know contains false health answers makes the producer a party to the fraud.
- The MIB (Medical Information Bureau) flags coded discrepancies across applications to detect concealment.
- State Insurance Fraud Bureaus receive referrals; many states grant immunity for good-faith fraud reports.
- Knowingly omitting a material health condition to issue a policy is concealment, a basis to rescind within the contestability period.
Worked Privacy-Notice Timing and the Replacement Stack
Tie the federal rules to concrete events. Suppose a client buys a life policy in March: the insurer must deliver the GLBA/health privacy notice at issue and again on the annual cycle, may skip the annual notice only if nothing changed, and must obtain a signed HIPAA authorization before pulling prescription and MIB data.
If the sale replaces an existing policy, layer on the replacement requirements: deliver the replacement notice, list all policies being replaced, give the Buyer's Guide and policy summary, and trigger the extended free-look (often 30 days). Missing any single step in this stack is the most commonly tested compliance failure.
How the Privacy Laws Interlock
The three federal statutes cover different data and trigger at different moments, so the exam rewards knowing which one applies. GLBA governs financial NPI and is built around the privacy notice plus the opt-out for nonaffiliated sharing. HIPAA governs PHI and is built around authorization plus the Security Rule safeguards for electronic health data. FCRA governs third-party consumer reports used in underwriting and is built around adverse-action notice and the consumer's right to dispute.
A single application can touch all three: the insurer pulls a credit-based report (FCRA), obtains prescription and MIB data under a HIPAA authorization, and delivers a GLBA financial-privacy notice. Mixing up which document satisfies which law is a classic distractor — an opt-out does not replace a HIPAA authorization, and an authorization does not satisfy FCRA's adverse-action duty.
State law layers on top of the federal floor and frequently goes further. The NAIC privacy model lets states require opt-in consent for sharing health information, stricter than GLBA's opt-out for financial data. Producers must also honor data-security obligations — the NAIC Insurance Data Security model requires carriers and producers to maintain a written information-security program and to report a data breach to the commissioner within a set window, often 72 hours.
The unifying ethical principle is stewardship: NPI and PHI are entrusted, not owned. The producer collects only what is needed, shares only what is permitted, and safeguards it against unauthorized access for as long as it is retained.
Under the Gramm-Leach-Bliley Act, before an insurer shares a customer's nonpublic personal information with a NONAFFILIATED third party, it must:
A producer was convicted of a felony involving breach of trust. Under 18 U.S.C. 1033, this person may continue working in insurance only if: