2.4 Federal Law, Fraud Warnings, Consumer Privacy (Regulation 169), Cybersecurity (23 NYCRR 500) & TRIA

Key Takeaways

  • Under 18 U.S.C. § 1033(e), a person convicted of a felony involving dishonesty or breach of trust may not engage in the business of insurance without written consent from an insurance regulator — the so-called 1033 waiver.
  • 18 U.S.C. § 1034 authorizes federal civil penalties of up to $50,000 per violation or the compensation received, whichever is greater, for conduct prohibited by § 1033.
  • Regulation 169 (11 NYCRR Part 420) requires licensees to protect nonpublic personal financial information, deliver privacy notices, and obtain authorization before disclosing nonpublic personal health information.
  • DFS cybersecurity rules (23 NYCRR Part 500) cover persons licensed under the Insurance Law; covered entities must report qualifying cybersecurity events to DFS within 72 hours.
  • The Terrorism Risk Insurance Act of 2002, as extended, requires insurers to make terrorism coverage available on commercial property/casualty policies; the program runs through December 31, 2027.
Last updated: September 2026

Why These Rules Matter to a Public Adjuster

The PSI content outline for the New York Public Adjuster examination (Series 17-62) ends its Insurance Regulation domain with a cluster of rules that are not unique to adjusting: consumer privacy (Regulation 169), cybersecurity requirements for financial services companies, and two federal items—the 1033 prohibited-person rule and the Terrorism Risk Insurance Act (TRIA). A public adjuster handles tax returns, bank statements, medical and personal details, mortgage information, and photographs of a client's home. That makes privacy and data security daily concerns, not abstractions. And because the 1033 rule can bar an applicant from the business entirely, it is also a licensing issue.

18 U.S.C. §§ 1033 and 1034: The "Prohibited Person" Rule

The Violent Crime Control and Law Enforcement Act of 1994 created federal crimes affecting the business of insurance.

  • 18 U.S.C. § 1033 makes it a federal crime to embezzle insurer funds, to make materially false statements to insurance regulators, and to obstruct regulatory proceedings.
  • § 1033(e)(1) reaches individuals who have been convicted of a felony involving dishonesty or breach of trust (or of a § 1033 offense). Such a person who willfully engages in the business of insurance affecting interstate commerce—or anyone who willfully permits that person to participate—commits a crime unless the person has obtained written consent from an insurance regulatory official authorized to regulate the insurer. This consent is commonly called a 1033 waiver.
  • 18 U.S.C. § 1034 adds civil penalties of up to $50,000 for each violation or the amount of compensation the person received or offered for the prohibited conduct, whichever is greater, and allows the Attorney General to seek injunctions.

Exam angle: a license application question about prior convictions is not only a New York character issue under Ins. Law § 2108(c)'s "trustworthy and competent" standard. A qualifying felony also triggers the federal consent requirement, and a public adjusting firm that knowingly employs a prohibited person without a waiver has its own exposure.

New York's Fraud Warning Statement

New York requires claim forms, including proofs of loss, to carry a fraud warning. The standard statement for claim forms reads, in substance: any person who knowingly and with intent to defraud any insurance company or other person files a statement of claim containing any materially false information, or conceals for the purpose of misleading information concerning any fact material thereto, commits a fraudulent insurance act, which is a crime, and shall also be subject to a civil penalty not to exceed $5,000 and the stated value of the claim for each such violation.

For a public adjuster this is practical, not theoretical. You prepare the inventory, the estimate, and often the sworn proof of loss the insured signs. Padding an inventory or describing old wear as storm damage exposes the insured to criminal prosecution under the Penal Law's insurance fraud provisions. It exposes the adjuster to the same prosecution and to license discipline under Ins. Law § 2110. Ins. Law § 2108(o) separately forbids any licensee from making a misrepresentation of facts while acting as an adjuster.

Regulation 169: Privacy of Consumer Financial and Health Information

Insurance Regulation 169 (11 NYCRR Part 420) is New York's implementation of the privacy provisions of the federal Gramm-Leach-Bliley Act for insurance licensees. The Series 17-62 outline cites Parts 420.0 to 420.4 (definitions, scope, and notice requirements). Key concepts:

ConceptWhat it means for an adjuster
Nonpublic personal financial informationAccount numbers, income, mortgage balances, claim payment history, and similar data about a consumer or customer
Nonpublic personal health informationHealth data (for example, injury details in a claim file); disclosure generally requires the individual's authorization (an opt-in)
Privacy noticeA clear and conspicuous description of the licensee's information-sharing practices, delivered when a customer relationship is established and as the regulation otherwise requires
Opt-outBefore sharing nonpublic personal financial information with nonaffiliated third parties outside the regulation's exceptions, the licensee must give the consumer a reasonable opportunity to opt out
Processing and servicing exceptionsDisclosures needed to administer the claim, such as sending documents to the insurer handling the loss, fall within exceptions and do not require an opt-out

A public adjuster who emails a client's tax returns to a contractor, or posts a client's loss photos with an address visible for marketing, is making the kind of disclosure Regulation 169 is designed to control.

Cybersecurity Requirements for Financial Services Companies (23 NYCRR Part 500)

DFS adopted its cybersecurity regulation, 23 NYCRR Part 500, effective March 1, 2017 and substantially amended it in November 2023. It applies to covered entities, meaning persons operating under a license, registration, or similar authorization under the Banking Law, Insurance Law, or Financial Services Law. Individual licensees, including public adjusters, fall within that definition.

  • Cybersecurity program and policy: Covered entities must maintain a risk-based program to protect nonpublic information and information systems.
  • 72-hour notice: A covered entity must notify DFS of a qualifying cybersecurity event within 72 hours of determining that it occurred.
  • Annual filing: Covered entities file an annual certification of compliance, or an acknowledgment of noncompliance, with DFS by April 15.
  • Limited exemptions: Small covered entities, measured by headcount, revenue, or assets, qualify for limited exemptions but must still file a notice of exemption. An individual licensee who is an employee or agent of a covered entity and is covered by that entity's program can rely on it.

Terrorism Risk Insurance Act (TRIA)

The Terrorism Risk Insurance Act of 2002 created a federal backstop after insurers began excluding terrorism following September 11, 2001. It was extended in 2005 and 2007 (the outline references the 2007 Extension Act) and reauthorized again in 2015 and 2019, currently through December 31, 2027.

  • Make-available requirement: Insurers writing covered commercial property/casualty lines must offer terrorism coverage on terms that do not differ materially from other coverage. The insured may accept or reject it.
  • Certified act of terrorism: Federal sharing applies only to acts certified by the Secretary of the Treasury, in consultation with the Secretary of Homeland Security and the Attorney General.
  • Personal lines are not part of the program. Homeowners and dwelling fire losses are handled under the policy's own terms, including war and other exclusions.

For an adjuster working a commercial loss, the first question after a deliberate attack is whether the policy included (or the insured rejected) TRIA terrorism coverage and whether the event has been certified.

Test Your Knowledge

A job applicant for a New York public adjusting firm has a prior felony conviction for embezzlement. Under 18 U.S.C. § 1033(e), what must occur before the applicant may willfully engage in the business of insurance?

A
B
C
D
Test Your Knowledge

Under DFS's cybersecurity regulation (23 NYCRR Part 500), how quickly must a covered entity notify DFS after determining that a qualifying cybersecurity event has occurred?

A
B
C
D
Test Your Knowledge

Which statement about the Terrorism Risk Insurance Act (TRIA) is accurate?

A
B
C
D