18.3 Privacy, Fraud, and Consumer Protection

Key Takeaways

  • UTPA/UCSPA violations generally require a 'general business practice' (a pattern), not a single isolated error.
  • Twisting = misrepresentation to replace an EXISTING policy; churning = replacement using the insured's own policy values with the same insurer.
  • Premiums are fiduciary funds owed to the insurer; commingling them with operating funds is conversion and a fast route to revocation.
  • E&O is claims-made, covers negligent errors/omissions (not intentional dishonest acts), and documentation of declined coverage is the best defense.
  • GLBA financial info uses opt-out; health info uses opt-in. FCRA adverse-action notices follow any report-driven decline, cancel, or surcharge.
Last updated: June 2026

Privacy, Fraud, and Consumer Protection

Property and casualty producers handle sensitive consumer data and stand at the front line of fraud detection. Three federal frameworks plus state insurance fraud statutes dominate exam questions.

Privacy: GLBA and the model privacy act

The Gramm-Leach-Bliley Act (GLBA) and the NAIC privacy model require that insurers give consumers a privacy notice describing what nonpublic personal information is collected and how it is shared. Two categories are tested:

  • Nonpublic personal financial information — must allow consumers to opt out of sharing with non-affiliated third parties.
  • Nonpublic personal health information — generally requires affirmative opt-in (authorization) before disclosure.

A privacy notice must be delivered at the point of sale and annually thereafter (with limited exceptions if nothing has changed). Confusing the financial opt-out standard with the health opt-in standard is the single most common privacy trap.

Fair Credit Reporting Act (FCRA)

When an insurer uses a consumer report or credit-based insurance score to decline, cancel, surcharge, or non-renew, it must give an adverse action notice that names the reporting agency and informs the consumer of the right to a free copy of the report and to dispute it. The producer is not the decision-maker but must understand that any rate or eligibility decision driven by a report triggers FCRA notice duties.

The exam also tests the boundary between prescreening and adverse action. Pulling a credit-based insurance score to offer a quote is a permissible purpose under the FCRA. But the moment that score causes a higher premium, a declination, or a non-renewal, the adverse-action notice clock starts. A common distractor states that no notice is needed 'because the consumer was only quoted, not declined.' That is wrong whenever the score actually worsened the offered terms — a surcharge counts as adverse action just as a flat refusal does.

Insurance fraud and the Fraud Prevention Act

The federal Violent Crime Control Act (18 U.S.C. 1033/1034) makes it a crime for anyone convicted of a felony involving dishonesty or breach of trust to engage in the business of insurance affecting interstate commerce without written consent of the regulator. State fraud statutes layer on top, defining fraud as a knowing misrepresentation of a material fact to obtain a benefit. Key tested elements of fraud:

ElementMeaning
Knowing / willfulHonest mistakes are not fraud
Material factMust affect the risk or the claim outcome
Intent to deceiveThe purpose is an unwarranted benefit
Reliance / benefitA claim paid or coverage obtained

A fraud warning statement on applications and claim forms (notifying the applicant that fraud is a crime) is mandatory in most states. Soft fraud (padding an otherwise legitimate claim) is still fraud.

Worked example: the inflated claim

A homeowner has a legitimate $6,000 water-damage loss but submits receipts inflating it to $9,500 to absorb the $1,000 deductible and 'come out ahead.' The padding is material (it changes the payable amount), knowing (fabricated receipts), and intended to obtain an unwarranted benefit. Even though a real loss occurred, the $3,500 inflation is insurance fraud and can void the claim under the Concealment or Fraud condition found in nearly every ISO property form.

Consumer protection wrap-up

Producers protect consumers by giving accurate quotes, delivering required notices on time, reporting suspected fraud to the state fraud bureau, and never altering an application after the client signs. Replacing a signed answer — even to 'correct' it — is itself a prohibited practice.

Data security and breach response

Beyond the GLBA privacy notice, the NAIC Insurance Data Security Model Law (adopted in a growing number of states) requires licensees to maintain a written information-security program and to notify the regulator of a cybersecurity event, commonly within 72 hours of determining a breach occurred. Producers who store client Social Security numbers, driver-license numbers, or banking details are 'licensees' subject to these duties even as small agencies. Disposal of records must use shredding or secure deletion; tossing applications in an open dumpster is itself a violation.

Telemarketing and contact rules

Consumer-protection law also reaches how producers solicit. The federal Do-Not-Call and CAN-SPAM rules restrict cold calls and require opt-out mechanisms in marketing email. Robocalls to cell phones without prior express consent can carry steep per-call penalties. The exam frames these as part of the producer's ethical obligation not to harass or mislead prospects.

Putting it together: the fraud-reporting duty

Most state fraud bureaus grant producers civil immunity for good-faith reports of suspected fraud, which removes the fear of a defamation suit and encourages reporting. A producer who notices that a client's three prior 'theft' claims at different addresses all list the same untraceable serial numbers has a reasonable basis to report. Reporting in good faith is protected; ignoring an obvious red flag, or worse, assisting the scheme, exposes the producer to criminal liability and license revocation.

FrameworkCore dutyTested trigger
GLBA / NAIC privacyPrivacy notice; opt-out (financial) / opt-in (health)Sharing data with third parties
FCRAAdverse-action noticeDecline/surcharge from a report or insurance score
18 U.S.C. 1033/1034Regulator consent for prohibited personsFelony of dishonesty/breach of trust
Data Security ModelWritten program; ~72-hr breach noticeCybersecurity event
Test Your Knowledge

Under GLBA and the NAIC privacy model, how do the default consumer-choice standards differ for financial versus health information?

A
B
C
D
Test Your Knowledge

A homeowner suffers a genuine $6,000 loss but submits fabricated receipts inflating it to $9,500. Which statement is correct?

A
B
C
D