18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- GLBA financial-privacy sharing is OPT-OUT; HIPAA health-information disclosure is OPT-IN—this contrast is a recurring exam trap.
- Under the FCRA, any adverse underwriting action based on a consumer/credit report requires an adverse-action notice naming the reporting agency.
- 18 U.S.C. 1033/1034 bar felons (dishonesty/breach of trust) from the insurance business without a written 1033 waiver from the commissioner.
- Insurer-initiated cancellation refunds premium pro rata; insured-initiated cancellation is short-rate (less refund due to a penalty).
- Guaranty associations protect policyholders of insolvent admitted insurers, but advertising that protection to sell a policy is prohibited.
Privacy: GLBA, HIPAA, and the FCRA
Producers handle sensitive financial and sometimes medical data, so three federal frameworks dominate exam privacy questions.
- Gramm-Leach-Bliley Act (GLBA, 1999) — requires a privacy notice at the point of sale and annually, plus an opt-out before sharing nonpublic personal financial information with nonaffiliated third parties.
- HIPAA — protects nonpublic personal health information; an opt-in (authorization) is generally required before disclosing health data.
- Fair Credit Reporting Act (FCRA) — governs use of consumer/credit reports in underwriting. If an insurer takes adverse action (declines, charges more, cancels) based even partly on a report, it must give an adverse action notice identifying the reporting agency.
Exam Key: Financial info = OPT-OUT (GLBA). Health info = OPT-IN (HIPAA). Memorize this contrast—it is a recurring distractor pair.
GLBA also defines two notice types the exam separates: an initial/annual privacy notice (what data is collected and shared) and an opt-out notice (the consumer's right to block sharing with nonaffiliated third parties). Sharing with affiliates and as needed to service the policy or process claims is generally permitted without opt-out. A producer who sells a client list of names, addresses, and policy data to an unaffiliated marketing firm without honoring opt-outs violates GLBA—even if no health data is involved.
Privacy: Gramm-Leach-Bliley and HIPAA
Federal privacy law shapes how insurers handle customer data. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions, including insurers, to give an initial and annual privacy notice, explain information-sharing practices, and allow consumers to opt out of certain disclosures of nonpublic personal financial information to nonaffiliated third parties. HIPAA governs protected health information. States layer their own privacy and data-breach notification rules on top. Producers must safeguard client data and follow these notice-and-consent requirements.
Insurance Fraud and the Anti-Fraud Framework
Insurance fraud is a knowing misrepresentation to obtain a benefit, ranging from a claimant inflating a claim to a producer submitting false applications. The federal Fraud and False Statements statute (18 U.S.C. 1033/1034) bars anyone convicted of a felony involving dishonesty or breach of trust from working in insurance without written consent of the regulator, a heavily tested rule. Many states require fraud-warning statements on applications and claim forms and operate fraud bureaus. Producers have a duty to report suspected fraud and to avoid participating in it.
Federal Consumer Protection: FCRA and TCPA
The Fair Credit Reporting Act (FCRA) governs the use of consumer and credit reports in underwriting: insurers must notify applicants when information from a report leads to an adverse action (declination, higher rate) and identify the reporting agency so the consumer can dispute errors. The Telephone Consumer Protection Act (TCPA) and CAN-SPAM restrict telemarketing and email solicitation. Recognizing the adverse-action notice trigger and the 1033 employment bar are the two highest-yield federal points in this section.
An insurer declines an applicant partly because of information in a consumer credit report. Which law requires the insurer to send an adverse-action notice naming the reporting agency?
Insurance Fraud and the Fraud Acts
The Fraud and False Statements provisions (18 U.S.C. §1033/§1034) make it a federal crime for anyone convicted of a felony involving dishonesty or breach of trust to engage in the business of insurance affecting interstate commerce without written consent (a 1033 waiver) from the state commissioner. Penalties include fines and imprisonment up to 10–15 years.
Fraud is committed by multiple parties, and the exam tests each:
| Party | Typical Fraud | Example |
|---|---|---|
| Applicant/Insured | Material misrepresentation | Staging a theft; inflating a claim |
| Producer | Premium theft, fake policies | Selling coverage from a nonexistent insurer |
| Insurer | Bad-faith denial; phantom carrier | Refusing clear claims to retain premium |
Soft fraud (padding a legitimate claim) and hard fraud (deliberately causing a loss) are both illegal. Most states run a Fraud Bureau and grant immunity to insurers/producers who report suspected fraud in good faith.
Consumer Protection Mechanics
Several consumer-protection rules generate frequent exam items:
- Free-look / right to examine — though more common in life/health, P&C jurisdictions provide cancellation and refund rights; return premium is typically computed pro rata when the insurer cancels and may be short-rate (a penalty) when the insured cancels.
- Notice of cancellation/nonrenewal — statutes require advance written notice, commonly 10 days for nonpayment and 30–60 days for other reasons, with a stated reason on request.
- Replacement disclosure — when replacing coverage, the producer must give comparison disclosures so the client can judge twisting/churning risk.
- Guaranty associations — protect policyholders if an admitted insurer becomes insolvent, paying covered claims up to statutory caps; advertising guaranty-fund protection to sell a policy is itself prohibited.
A Worked Return-Premium Numeric
Return-premium math appears in consumer-protection questions. Suppose an annual P&C policy costs $1,200 and is canceled at the 90-day mark (one quarter of the 365-day term).
- Insurer cancels (pro rata): earned = 90/365 × $1,200 ≈ $295.89; refund ≈ $904.11.
- Insured cancels (short-rate): the insurer keeps earned premium plus a penalty, so the refund is less than $904.11 (e.g., a 10% short-rate penalty on the unearned portion reduces the refund to roughly $813.70).
The takeaway the exam wants: insurer-initiated cancellation = pro rata (more refund); insured-initiated = short-rate (less refund).
Anti-Money-Laundering and Information Security
Two modern compliance layers appear on updated exams. Under federal AML rules, certain insurers must maintain an anti-money-laundering program and file Suspicious Activity Reports (SARs)—a red flag is a client who overpays a premium and requests a refund to a third party.
Separately, the NAIC Insurance Data Security Model Law requires licensees to maintain a written information security program, conduct risk assessments, and notify the commissioner of a data breach, often within 72 hours. Producers who collect SSNs, bank data, and loss histories are 'licensees' under these rules even as sole proprietors, so encryption, access controls, and a documented incident-response plan are now baseline obligations, not optional best practices.
A person was convicted of embezzlement (a felony of dishonesty). Under federal law (18 U.S.C. 1033), this person may work in the business of insurance affecting interstate commerce only if: