18.3 Privacy (HIPAA/GLBA), Fraud, and Consumer Protection
Key Takeaways
- Gramm-Leach-Bliley (GLBA) requires financial privacy notices and opt-out rights for sharing nonpublic personal financial information with nonaffiliated third parties.
- HIPAA protects individually identifiable health information (PHI) and sets portability rules; the Privacy Rule limits use/disclosure without authorization.
- The Fair Credit Reporting Act (FCRA) governs use of consumer/investigative reports; applicants must be notified and may receive adverse-action notices.
- The federal Fraud and False Statements statute (18 U.S.C. 1033/1034) bars persons convicted of a felony involving dishonesty from the insurance business without written 1033 consent.
- Insurance fraud (false applications, false claims, fake policies) is prosecutable; producers must report and avoid participating in fraudulent schemes.
Gramm-Leach-Bliley Act (GLBA) — financial privacy
The Gramm-Leach-Bliley Act governs how financial institutions, including insurers and producers, handle nonpublic personal financial information (NPI). Three components matter for the exam:
- Privacy Rule — Requires an initial and annual privacy notice describing what information is collected and shared.
- Opt-out right — Consumers may opt out of disclosure of NPI to nonaffiliated third parties (sharing with affiliates and certain service providers is generally permitted).
- Safeguards Rule — Requires reasonable administrative, technical, and physical safeguards to protect customer data.
Distinction: GLBA protects financial information; HIPAA protects health information. Exam questions test which statute governs which data type.
HIPAA — health information and portability
The Health Insurance Portability and Accountability Act:
- Limits pre-existing condition exclusions and prohibits health-status discrimination in group health (portability/guaranteed renewability).
- The Privacy Rule protects Protected Health Information (PHI) — individually identifiable health data. Use or disclosure beyond treatment, payment, and operations generally requires written authorization.
- The Security Rule sets standards for electronic PHI (ePHI).
| Law | Protects | Core consumer right |
|---|---|---|
| GLBA | Financial NPI | Opt out of third-party sharing |
| HIPAA | Health PHI | Authorization before disclosure |
| FCRA | Consumer report data | Notice + adverse-action notice |
Fair Credit Reporting Act (FCRA)
FCRA governs consumer reports and investigative consumer reports (which include interviews about character, reputation, or lifestyle). Applicants must be notified that a report may be obtained. If an insurer takes adverse action (declines, rates up, or charges more) based on a report, it must give an adverse-action notice identifying the reporting agency so the consumer can dispute errors.
An applicant for life insurance is declined based on information in a consumer report. Under the FCRA, the insurer must:
Federal fraud statutes (18 U.S.C. 1033 and 1034)
The federal Fraud and False Statements provisions make it a crime to engage in fraud affecting the business of insurance in interstate commerce. The most-tested rule:
- A person convicted of a felony involving dishonesty or breach of trust is prohibited from engaging in the business of insurance unless they obtain written consent (a 1033 waiver) from the state insurance regulator.
- Section 1034 authorizes civil penalties and injunctions.
Exam trap: The 1033 consent is granted by the state insurance commissioner, even though 1033 is a federal statute. Engaging in insurance after such a conviction without written consent is itself a federal violation.
Insurance fraud and producer obligations
Insurance fraud includes:
| Type | Example |
|---|---|
| Application fraud | Misstating health or smoking status to lower premium |
| Claims fraud | Filing a false or inflated claim |
| Premium theft | Producer collects premium but never remits it |
| Fake policies | Selling coverage from a nonexistent or unauthorized insurer |
Producers must not participate in or facilitate fraud and, in many states, must report suspected fraud. Most policies contain a fraud/concealment provision; material misrepresentation on an application can void coverage during the contestable period.
The key contract concepts behind application fraud are tested directly. Concealment is the failure to disclose a known material fact; misrepresentation is an affirmative false statement; and fraud adds intent to deceive. After the incontestable period (typically two years), the insurer generally cannot void a life policy for misstatements except for proven fraud in some jurisdictions or non-payment — making the contestable window the moment when application accuracy matters most.
Telemarketing and electronic consumer protections
- Do-Not-Call Registry (TCPA) — Producers may not cold-call numbers on the federal Do-Not-Call list absent an established business relationship or consent.
- CAN-SPAM Act — Commercial emails must have accurate headers, a clear opt-out, and a physical mailing address.
These rules protect consumers and carry their own penalties separate from state insurance law.
Quick comparison of remedies
| Violation | Primary enforcer |
|---|---|
| GLBA / privacy breach | FTC / functional regulator |
| HIPAA breach | HHS Office for Civil Rights |
| 1033 (felony, no consent) | Federal prosecutors + state commissioner |
| Do-Not-Call / CAN-SPAM | FTC / FCC |
How privacy and fraud rules intersect a sale
A single application touches several of these statutes at once. The producer collects financial information (GLBA), may order a medical/MIB report or an investigative consumer report (HIPAA authorization plus FCRA notice), and certifies the application is truthful (fraud statutes). The exam likes layered fact patterns: identify which obligation each step triggers. Collecting health data without an authorization, ordering a report without notice, or remitting premium late each implicate a different law.
The MIB and shared underwriting data
Insurers exchange coded underwriting information through the Medical Information Bureau (MIB). MIB data may flag discrepancies but cannot, by itself, be the sole basis for an adverse decision — the insurer must independently verify. Consumers have a right to know an MIB report was used and to correct errors, mirroring FCRA's dispute framework.
Exam trap: A privacy or consumer-protection question often hides the real issue in the notice/authorization step rather than the decision itself. Ask whether the consumer was told, whether consent was obtained, and whether an adverse-action or report-source notice was required.
Under 18 U.S.C. 1033, a person previously convicted of a felony involving dishonesty may work in the business of insurance only if they:
Worked Scenario: Privacy Notices and Opt-Out
Under GLBA, an insurer must give a privacy notice at the start of the relationship and annually, and allow the consumer to opt out of sharing nonpublic personal information with unaffiliated third parties. HIPAA separately protects health information, requiring authorization before protected health data is disclosed for non-treatment purposes.
| Law | Protects | Consumer right |
|---|---|---|
| GLBA | Financial information | Opt out of third-party sharing |
| HIPAA | Health information | Authorize disclosure |
| FCRA | Consumer-report data | Notice + access + dispute |
Trap: federal law 18 U.S.C. 1033 bars anyone convicted of a felony involving dishonesty or breach of trust from working in insurance without written 1033 consent from the regulator — a frequently tested fraud-statute item.