18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection

Key Takeaways

  • GLBA governs financial privacy and requires privacy notices plus an opt-out before sharing nonpublic personal information with nonaffiliated third parties.
  • HIPAA protects health information; the privacy and security rules limit use and disclosure of protected health information (PHI).
  • The Fair Credit Reporting Act requires notice and disclosure when consumer or investigative reports are used in underwriting.
  • Insurance fraud includes soft and hard fraud; the Fraud and False Statements Act (18 U.S.C. 1033/1034) bars convicted felons from the business without written consent.
  • The Gramm-Leach-Bliley opt-out, USA PATRIOT Act anti-money-laundering rules, and Do-Not-Call rules round out consumer protection.
Last updated: June 2026

Two federal laws dominate the privacy questions on the exam, and the trap is matching the right law to the right kind of information. Read the stem carefully: is the data financial or medical?

GLBA — Financial Privacy

The Gramm-Leach-Bliley Act (GLBA) governs how financial institutions, including insurers, handle nonpublic personal financial information — account numbers, balances, payment history, and information collected on an application. Its three pillars:

GLBA RuleRequirement
Privacy RuleProvide an initial and annual privacy notice describing information practices
Opt-OutAllow the consumer to opt out before sharing data with nonaffiliated third parties
Safeguards RuleMaintain administrative, technical, and physical safeguards for the data

The opt-out is the heavily tested point. It applies only to disclosures to nonaffiliated third parties for non-permitted purposes. Sharing with affiliates, and sharing necessary to service the policy or process a claim, does not require an opt-out. So an insurer may send claim data to its own claims administrator without an opt-out, but must offer one before selling a customer list to an outside marketer.

HIPAA — Health Privacy

The Health Insurance Portability and Accountability Act (HIPAA) protects protected health information (PHI). Its Privacy Rule limits the use and disclosure of PHI to the minimum necessary, and its Security Rule safeguards electronic PHI. HIPAA also delivers portability — limiting pre-existing condition exclusions when workers change group plans — and guaranteed renewability in the group market. Remember the shortcut: GLBA = financial data; HIPAA = health data.

Test Your Knowledge

An insurer wants to share a customer's nonpublic personal financial information with an unaffiliated marketing company. Under the Gramm-Leach-Bliley Act, the insurer must FIRST:

A
B
C
D

Consumer Reports — FCRA

The Fair Credit Reporting Act (FCRA) governs the use of consumer and investigative reports in underwriting. At application, the applicant must be notified that a report may be obtained about them.

Distinguish the two report types:

  • A consumer report contains factual data — credit, payment, and public-record information from a reporting agency.
  • An investigative consumer report is built from interviews about the applicant's character, reputation, and lifestyle. It requires extra disclosure and gives the consumer the right to request the nature and scope of the investigation.

If the insurer takes an adverse action — declining, rating up, or charging more based on the report — it must notify the applicant and identify the reporting agency so the consumer can obtain a free copy and dispute errors.

Federal Fraud Statutes

Insurance fraud divides into two degrees the exam expects you to label:

  • Soft fraud (opportunistic) — padding an otherwise legitimate claim or shading answers on an application.
  • Hard fraud — deliberately fabricating or staging a loss that never occurred.

The Fraud and False Statements Act, 18 U.S.C. §§ 1033 and 1034, makes it a federal crime to engage in deceptive acts affecting the business of insurance in interstate commerce. Section 1033 also prohibits anyone convicted of a felony involving dishonesty or breach of trust from working in the business of insurance without the written consent of the state regulator — the so-called 1033 waiver. The bar is not permanent, but reentry is impossible until the waiver is granted.

Test Your Knowledge

A producer was previously convicted of a felony involving breach of trust. Under 18 U.S.C. 1033/1034, this person may work in the insurance business:

A
B
C
D

How the Privacy Laws Fit Together

Think of the federal framework as layers, each guarding a different exposure. The table below is a fast pre-exam review:

LawProtectsCore Producer/Insurer Duty
GLBAFinancial nonpublic infoPrivacy notice + opt-out before nonaffiliated sharing
HIPAAProtected health info (PHI)Minimum-necessary use; safeguard electronic PHI
FCRAUnderwriting report dataNotice of report; adverse-action notice on decline/rating
18 U.S.C. 1033/1034Integrity of the businessNo felon participation without a 1033 waiver
USA PATRIOT (AML)Financial systemAML program, training, file SARs

The practical compliance picture for a producer is straightforward: collect only the information you need, store it securely, share it only as the law allows, and give the consumer notice and a meaningful choice. State privacy regulation layers on top of the federal floor — most states have adopted the NAIC privacy model and, increasingly, data-security/breach-notification rules requiring insurers to notify consumers and the commissioner after a security event. Where state law is stricter than the federal baseline, the producer follows the stricter rule.

Other Consumer Protections

Several other federal rules round out the consumer-protection picture and surface as one-off exam questions:

  • USA PATRIOT Act / Anti-Money-Laundering (AML) — insurers offering products with cash value or investment features (permanent life, annuities) must maintain written AML programs, designate a compliance officer, and file Suspicious Activity Reports (SARs). Producers must complete AML training. Cash-laden products are attractive to launderers, which is why term insurance is generally exempt.
  • Telephone Consumer Protection Act / Do-Not-Call — restricts unsolicited telemarketing calls and requires producers to scrub prospect lists against the National Do-Not-Call Registry, honoring requests not to be called.
  • CAN-SPAM Act — governs commercial email: honest "from" and subject lines, a valid physical address, and a working unsubscribe mechanism.
  • Free-look and disclosure — reinforce protection at the policy level. The free-look lets a policyowner return the policy within a set period (often 10 to 30 days) for a full premium refund, and illustration rules require that projected values be clearly labeled as non-guaranteed.

The unifying theme across all of these laws is consistent: force transparency, consumer opt-out control, and honest conduct so consumers can make informed decisions, protect their data, and seek redress when they are harmed. On the exam, anchor each rule to the harm it prevents — data misuse (GLBA/HIPAA), inaccurate underwriting data (FCRA), criminal infiltration and laundering (1033/PATRIOT Act), and unwanted solicitation (Do-Not-Call/CAN-SPAM).

Test Your Knowledge

Which federal law requires an insurer to maintain a program to detect and report suspicious transactions on cash-value and investment-type insurance products?

A
B
C
D