18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- GLBA requires insurers to provide privacy notices and an opt-out before sharing nonpublic personal financial information with nonaffiliated third parties.
- HIPAA protects individually identifiable health information and gives insureds rights to access and limit disclosure of protected health information.
- The Fair Credit Reporting Act requires disclosure when an insurer uses a consumer or investigative report in an adverse underwriting decision.
- Insurance fraud is intentional deception for unlawful gain; the Fraud and False Statements Act (18 U.S.C. 1033/1034) bars prohibited persons from the business of insurance.
- The USA PATRIOT Act requires anti-money-laundering programs covering covered products such as annuities and permanent life insurance.
The final ethics cluster covers how producers protect consumer information, detect and avoid fraud, and comply with federal consumer-protection statutes. These federal laws sit alongside the state UTPA/UCSPA framework.
Privacy: GLBA, HIPAA, and FCRA
Three statutes dominate the privacy questions:
| Law | Protects | Key requirement |
|---|---|---|
| Gramm-Leach-Bliley Act (GLBA) | Nonpublic personal financial information | Privacy notice + opt-out before sharing with nonaffiliated third parties |
| HIPAA | Protected health information (PHI) | Access, minimum-necessary disclosure, authorization |
| Fair Credit Reporting Act (FCRA) | Consumer/credit report information | Notice of adverse action and source of the report |
GLBA distinguishes affiliated from nonaffiliated third parties. Sharing with an affiliate generally does not require an opt-out; sharing financial information with a nonaffiliated third party (for non-exempt purposes) triggers the opt-out right. Insurers must deliver an initial privacy notice and, where applicable, annual notices.
HIPAA in the Life & Health Context
HIPAA's Privacy Rule protects individually identifiable health information (PHI) held by covered entities. For producers, the practical effect is that an applicant's medical history, conditions, and records may be collected and shared only with proper authorization and only the minimum necessary for the underwriting or claims purpose.
HIPAA also addresses health-coverage portability and nondiscrimination: it limited preexisting-condition exclusions and prohibited group-health discrimination based on health status (rules later broadened by the ACA). On the exam, associate HIPAA with health information privacy plus group health portability, and associate GLBA with financial information privacy.
Fair Credit Reporting Act
Under the FCRA, when an insurer obtains a consumer report (e.g., from a credit bureau or the MIB) or an investigative consumer report (interviews about character and reputation) and takes an adverse action (declines, rates up, or charges more) based on it, the insurer must notify the applicant and identify the source so the applicant can obtain a copy and dispute errors. An applicant must also be told in advance when an investigative consumer report may be ordered.
An insurer wants to share a customer's nonpublic personal financial information with a nonaffiliated marketing company. Under the Gramm-Leach-Bliley Act, what must generally happen first?
Insurance Fraud and Federal Statutes
Insurance fraud is an intentional act of deception to obtain an unlawful benefit. It can be committed by applicants (misstating health or identity), producers (forging signatures, fabricating applications, churning), or insurers (bad-faith denials).
Two federal anti-fraud provisions are commonly tested:
- 18 U.S.C. 1033 makes it a federal crime to engage in deceptive acts affecting the business of insurance and bars any person convicted of a felony involving dishonesty or breach of trust from working in insurance.
- 18 U.S.C. 1034 authorizes civil penalties and injunctions for those violations.
A producer with such a felony conviction may work in insurance only with written consent (a 1033 waiver) from the state insurance commissioner. Operating without that consent is itself a federal violation.
Anti-Money-Laundering (AML) and the USA PATRIOT Act
The USA PATRIOT Act extended anti-money-laundering obligations to insurers offering covered products: permanent (cash-value) life insurance, annuities, and any product with cash value or investment features. Term life and most pure health products are generally not covered because they lack a cash or investment component that can launder funds.
Insurers must maintain an AML program with written policies, a designated compliance officer, ongoing training, and independent testing, and file Suspicious Activity Reports (SARs) for transactions over the threshold (commonly $5,000) that appear designed to disguise illicit funds. Producers are trained to spot red flags such as early surrenders, overpayment followed by refund requests, or structured cash payments just under reporting limits.
Telemarketing, CAN-SPAM, and Identity Safeguards
Consumer-protection rules also govern how producers reach prospects. The federal Telemarketing Sales Rule and the National Do-Not-Call Registry restrict cold calls to listed numbers and require calls to be made within permitted hours, with the caller identifying themselves and the purpose. The CAN-SPAM Act requires commercial email to include a truthful subject line, a valid physical address, and a working opt-out.
The FTC Safeguards Rule under GLBA obligates financial institutions, including insurers and agencies, to develop a written information security program that protects customer data against unauthorized access, covering administrative, technical, and physical safeguards. A producer who emails unencrypted PHI, leaves applications exposed, or fails to shred discarded records can create both a privacy violation and an identity-theft exposure for clients.
The Medical Information Bureau and Authorization
Many life and health applications authorize a report from the Medical Information Bureau (MIB), a nonprofit that maintains coded medical and lifestyle information shared among member insurers to deter fraud. The MIB does not make underwriting decisions; it flags information for the insurer to investigate. Because MIB data is consumer-report information, the FCRA applies: an applicant declined or rated based on it must be told and given the means to review and correct it.
The producer's role is to obtain a clear, signed authorization allowing the insurer to collect and verify health information, and to explain that information may be shared with the MIB. Collecting medical data without proper authorization, or using it beyond the disclosed purpose, breaches both HIPAA and the insurer's privacy obligations under GLBA.
Consumer Recourse and Bad Faith
Consumer protection is not only preventive; it provides remedies. A policyholder who believes a claim was mishandled may file a complaint with the state insurance department, which can investigate and discipline the insurer. Beyond regulatory action, an insurer that denies a valid claim without reasonable basis may face a civil bad-faith lawsuit, exposing it to damages beyond the policy limit.
State guaranty associations protect policyholders if an insurer becomes insolvent, paying covered claims up to statutory limits. Producers may not use guaranty-association protection as a sales inducement, because doing so is itself a prohibited practice. Complaint processes, bad-faith liability, and guaranty funds together form the consumer's backstop.
Under federal law (18 U.S.C. 1033), a person convicted of a felony involving dishonesty or breach of trust may work in the business of insurance only if they: