18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- GLBA protects nonpublic personal financial information through privacy notices and an opt-out before third-party sharing.
- HIPAA protects protected health information via authorization rules and portability/pre-existing-condition protections.
- FCRA requires adverse-action notice and identification of the reporting agency when underwriting uses a consumer report.
- The Fraud and False Statements Act bars felons convicted of dishonesty from insurance work without a 1033 waiver from the commissioner.
- Consumer protections include the free-look period, Buyer's Guide/Policy Summary delivery, replacement disclosures, and AML/SAR programs for cash-value sales.
The final ethics cluster covers consumer privacy, insurance fraud, and federal consumer-protection statutes. These topics blend federal law (HIPAA, GLBA, the Fair Credit Reporting Act, and the Fraud and False Statements Act) with state enforcement. The exam tests the purpose and the triggers of each rule, so anchor your study to what protection each statute provides and what event sets the duty in motion.
Privacy: GLBA and HIPAA
The Gramm-Leach-Bliley Act (GLBA) governs how financial institutions, including insurers, handle nonpublic personal information (NPI). Key mechanics:
- Insurers must give consumers an initial and annual privacy notice describing information-sharing practices and the consumer's rights.
- For sharing NPI with nonaffiliated third parties (outside the marketing and servicing exceptions), the consumer must receive an opt-out opportunity and a reasonable time to exercise it.
- GLBA distinguishes financial information from health information, which receives stronger protection under separate rules.
GLBA divides into the Financial Privacy Rule, the Safeguards Rule (requiring administrative and technical security of customer data), and the Pretexting provisions (barring obtaining information under false pretenses). A producer who emails a client's application data to an outside marketer without notice and opt-out violates the privacy rule.
The Health Insurance Portability and Accountability Act (HIPAA) protects protected health information (PHI). Its Privacy Rule limits use and disclosure of PHI to treatment, payment, and operations unless the patient authorizes more; its Portability provisions limit pre-existing condition exclusions and guarantee certain group-to-individual conversions. Authorization is generally required before PHI is disclosed for any other purpose.
| Statute | Protects | Core mechanism |
|---|---|---|
| GLBA | Nonpublic personal financial info (NPI) | Privacy notice + opt-out for third-party sharing |
| HIPAA | Protected health information (PHI) | Authorization + portability protections |
| FCRA | Consumer report data | Disclosure when adverse action is based on a report |
Fair Credit Reporting Act (FCRA)
When an insurer obtains a consumer report or investigative consumer report and takes adverse action (declines, rates up, or cancels), it must notify the applicant and identify the reporting agency so the applicant can obtain and dispute the data. An investigative consumer report gathers information through personal interviews about character and reputation; the applicant must be told one may be requested and may ask for its nature and scope. Medical Information Bureau (MIB) data used in underwriting falls under these disclosure duties, and the MIB only stores coded information, not full records.
Insurance Fraud and the Fraud and False Statements Act
Insurance fraud is intentional deception to obtain an unfair or unlawful benefit — by applicants (false applications), insureds (padded or staged claims), producers (forgery, fictitious policies, premium theft), or insurers (bad-faith denials). It is committed by all sides, and the exam expects you to know that producers, not just consumers, can commit it.
- The federal Fraud and False Statements Act (18 U.S.C. 1033/1034) makes it a federal crime for anyone engaged in the business of insurance affecting interstate commerce to make false statements, embezzle funds, or obstruct regulators.
- A key trap: a person convicted of a felony involving dishonesty or breach of trust is prohibited from working in insurance without written consent (a 1033 waiver) from the state insurance commissioner.
- Penalties can include fines and imprisonment (up to 10 to 15 years depending on the offense), with longer terms if the act jeopardizes the insurer's solvency, plus civil remedies under section 1034.
Other Consumer Protections
- Free-look period — a 10- to 30-day window (commonly 10 days, often longer for replacement transactions and seniors) to return a policy for a full premium refund, beginning at policy delivery.
- Buyer's Guide and Policy Summary — must be delivered in life insurance sales so consumers can compare products and understand costs.
- Replacement regulation — requires disclosure forms, notice to the existing insurer, and comparison documentation to deter twisting and churning, and gives the existing insurer a chance to conserve the policy.
- USA PATRIOT Act / Anti-Money Laundering (AML) — insurers selling cash-value products and annuities must maintain AML programs and file Suspicious Activity Reports (SARs); large single-premium purchases paid in cash and early surrenders absorbing penalties are red flags.
Worked Example: Adverse Action Trigger
An insurer rates up a life applicant 50% after reviewing a consumer report showing a poor driving record. Under FCRA, the insurer must notify the applicant of the adverse action and name the reporting agency, allowing the applicant to dispute inaccurate data. Failing to do so is a consumer-protection violation independent of whether the underwriting decision itself was correct.
Telemarketing and Advertising Rules
Producers must also respect the federal Do-Not-Call Registry and the Telephone Consumer Protection Act: calling registered numbers, calling outside permitted hours (generally 8 a.m. to 9 p.m. local time), or using prerecorded sales messages without consent can trigger penalties. Advertising must be filed or retained per state rule and must not be deceptive, tying these rules back to the false-advertising prohibition in Section 18.1. A producer's business cards, websites, and social posts are all "advertisements" subject to truthful-disclosure requirements.
Putting It Together
These protections form overlapping layers: GLBA and HIPAA guard data, FCRA governs how outside reports are used, the 1033/1034 framework polices fraud and felon participation, and free-look, buyer's guides, and replacement rules give the consumer time and information to make an informed choice. On the exam, match each fact pattern to the one statute whose trigger the scenario describes — a data-sharing question points to GLBA, a health-record question to HIPAA, an adverse-action question to FCRA, and a felon-employment question to section 1033.
Under the Gramm-Leach-Bliley Act, before an insurer shares a consumer's nonpublic personal information with a nonaffiliated third party for marketing, it generally must:
A producer was previously convicted of a felony involving breach of trust. Under the federal Fraud and False Statements Act (1033/1034), this individual may work in the business of insurance only if: