Privacy, Fraud & Consumer Protection
Key Takeaways
- GLBA requires an initial and annual privacy notice, plus an opt-out right before sharing nonpublic personal information with unaffiliated third parties outside listed exceptions
- FCRA requires an adverse action notice whenever credit information contributes to a higher premium, denial, or less favorable terms, separate from state insurance-score exception rules
- Hard fraud is a deliberately staged or fabricated loss; soft fraud is exaggerating or padding an otherwise legitimate claim — both are prosecutable, but intent is easier to prove for hard fraud
- The NAIC Model Insurance Fraud Act requires mandatory fraud reporting and grants good-faith immunity from civil suits arising from those reports
- Producers have a personal duty to report suspected fraud and must never coach or assist a client in exaggerating or fabricating a claim
Why Privacy and Fraud Rules Are Tested
A property and casualty producer sits at the point of contact where sensitive personal and financial information first enters the insurance system, and where a dishonest claim first has the chance to surface, so regulators layer specific affirmative duties onto the general ethical obligations already covered elsewhere in this outline. This section pulls together three related but distinct bodies of law: federal and state privacy protection for consumer information, the use of credit information in underwriting and rating, and the detection and reporting of insurance fraud. The exam tends to test these topics through scenarios where a producer did nothing actively dishonest but simply failed to complete a required affirmative step, so pay close attention to when each notice or report is legally required, not just what the underlying concept means in general terms.
Federal Privacy Law: The Gramm-Leach-Bliley Act
Although insurance is primarily state-regulated, the federal Gramm-Leach-Bliley Act, commonly called GLBA, applies to insurers and producers because they are treated as "financial institutions" under the Act. GLBA imposes two core obligations that the exam tests: a Privacy Notice requirement and a Safeguards Rule. Under the Privacy Notice requirement, a producer or insurer must give consumers a clear, conspicuous notice of its information-sharing practices at the time the customer relationship is established, and must thereafter provide an updated notice at least annually for as long as the relationship continues, describing what nonpublic personal information is collected and with whom it may be shared. If the insurer intends to share nonpublic personal information with unaffiliated third parties for purposes outside a short list of everyday-business exceptions, such as processing the transaction itself, complying with law, or preventing fraud, the consumer must be given a clear opt-out right and a reasonable opportunity to exercise it before the sharing occurs. No opt-out is required for sharing with affiliated companies within a common corporate family in many circumstances, and that distinction between affiliated and unaffiliated sharing is a frequent point of confusion on exam questions. The Safeguards Rule separately requires every insurer and financial institution to develop, implement, and maintain a comprehensive written information security program reasonably designed to protect the confidentiality and integrity of customer information, including designating an individual responsible for the program, conducting periodic risk assessments, and overseeing service providers who are given access to that information.
The NAIC Privacy Model and State Overlay
Most states have adopted a version of the NAIC Insurance Information and Privacy Protection Model Act, which works alongside GLBA and adds insurance-specific rules the federal statute does not directly address. This model act governs how insurers collect, use, and disclose personal information gathered during underwriting and claims handling, and it gives consumers specific rights: the right to be told, in certain circumstances, that an investigative consumer report may be prepared about them; the right to access the personal information an insurer holds about them; and the right to request correction, amendment, or deletion of information they reasonably believe is inaccurate. It also restricts the reasons insurers can disclose information to outside parties without authorization, generally limiting disclosure to specifically enumerated exceptions similar to GLBA's list, such as claims administration, fraud investigation, audit, and legal compliance, rather than allowing free use of the data for unrelated marketing purposes.
Credit Information and the Fair Credit Reporting Act
Many P&C insurers use credit-based insurance scores as one underwriting and rating factor, particularly in personal auto and homeowners lines, and this use is governed by the federal Fair Credit Reporting Act, commonly called FCRA. When an insurer takes an "adverse action" against a consumer based even partly on a credit report or credit-based insurance score, meaning the consumer is charged a higher premium, denied coverage, or offered less favorable terms than they otherwise would have received, the insurer must provide the consumer with an adverse action notice. That notice must disclose that credit information was a factor, identify the consumer reporting agency that supplied the report, and inform the consumer of their right to obtain a free copy of that report and to dispute inaccurate information directly with the reporting agency. This federal requirement is distinct from state insurance-score laws, which regulate whether and how credit can be used in rating at all and typically require insurers to also offer an exception process for consumers with extraordinary life circumstances, such as a medical emergency, divorce, or identity theft, that temporarily damaged their credit. The exam wants you to recognize that both layers exist side by side and serve different, complementary purposes.
Insurance Fraud: Hard Fraud Versus Soft Fraud
Insurance fraud is generally divided into two categories, and the distinction matters because it affects both detection strategy and the severity of legal exposure. Hard fraud is a deliberately staged or entirely fabricated loss, such as intentionally causing a collision, reporting a stolen vehicle that was actually sold or hidden by the owner, or setting a fire to collect on a property claim. Hard fraud is planned in advance and involves an intentional criminal act from the outset, and it is prosecuted aggressively because intent is easiest to prove when the loss itself never happened or was deliberately caused. Soft fraud, sometimes called opportunistic fraud, is far more common and involves exaggerating or padding an otherwise legitimate claim, such as inflating the value of damaged property, adding unrelated pre-existing damage to a claim after a genuine accident, or a policyholder omitting a material fact on an application, such as a prior claim history or an undisclosed household driver, in order to obtain a lower premium. Soft fraud is harder to prosecute because it blends a real loss with dishonest exaggeration, but it still constitutes fraud and can result in claim denial, policy rescission, and, in serious or repeated cases, criminal charges against the policyholder.
Fraud Detection and Reporting Infrastructure
| Element | Function |
|---|---|
| Special Investigative Unit | An insurer's internal team dedicated to identifying and investigating suspicious claims before payment |
| State Fraud Bureau | A state agency, often housed within the Department of Insurance, that receives mandatory fraud reports and can pursue criminal referral |
| NAIC Model Insurance Fraud Act | Requires insurers to report suspected fraud to the state and grants good-faith immunity from civil liability for making such reports |
| National Insurance Crime Bureau | A nonprofit that aggregates data across insurers to identify staged-accident rings and organized fraud patterns nationwide |
Most states, following the NAIC Model Insurance Fraud Act, require insurers to report suspected fraudulent claims to the state fraud bureau or a similar authority, and they grant the insurer, its employees, and its Special Investigative Unit good-faith immunity from being sued for defamation or invasion of privacy for making that report, even if the suspected fraud is never ultimately proven, so long as the report was made honestly and without malice. Producers themselves have a personal duty to report suspected fraud they encounter in the ordinary course of business, and must never coach, encourage, or assist an applicant or claimant in exaggerating or fabricating a loss, even informally or as a favor. Doing so can expose the producer personally to both license discipline and criminal liability as an accessory, regardless of whether the producer personally profited from the scheme.
Putting It Together for the Exam
The unifying theme across privacy, credit use, and fraud rules is that the law imposes affirmative duties rather than simple prohibitions: affirmatively deliver required privacy notices at the start of the relationship and again every year, affirmatively honor opt-out elections once a consumer exercises them, affirmatively provide adverse action notices whenever credit information affects a decision, and affirmatively report suspected fraud rather than staying silent about a suspicious claim. Exam questions in this area often present a producer who did nothing actively dishonest but simply failed to take one of these required affirmative steps, for example forgetting to provide an annual privacy notice or failing to report a claim the producer strongly suspected was staged, and the correct answer is usually the option describing that omitted duty rather than a more dramatic-sounding distractor describing an unrelated violation such as rebating or misrepresentation.
Under GLBA, when must an insurer provide a customer with a privacy notice describing its information-sharing practices?
An insurer charges a consumer a higher auto premium partly because of a low credit-based insurance score. What is the insurer required to do under the Fair Credit Reporting Act?
A policyholder involved in a genuine, accidental collision tells the adjuster that a dent from an earlier, unrelated incident was also caused by this accident, in order to get it repaired for free. This is an example of:
A Special Investigative Unit flags a claim as likely fraudulent and reports it to the state fraud bureau in good faith, but the investigation later concludes the claim was legitimate. Can the insurer be successfully sued by the policyholder for defamation over the report?