18.3 Privacy, Fraud, and Consumer Protection

Key Takeaways

  • GLBA governs financial nonpublic personal information (privacy notice + opt-out); HIPAA governs protected health information.
  • FCRA adverse action based on a consumer report or credit-based score requires an adverse action notice naming the reporting agency.
  • Hard fraud fabricates a loss; soft fraud pads a legitimate one—both can void the entire claim under the concealment/fraud condition.
  • Section 1033 makes it a federal crime for a felon (dishonesty/breach of trust) to work in insurance without a written 1033 waiver.
  • Consumer-protection rules—free-look, replacement disclosures, privacy notices—all drive toward informed, transparent buying.
Last updated: June 2026

Federal Privacy: GLBA and HIPAA

Two federal laws frame insurance privacy on the national exam. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions, including insurers and producers, to give consumers a privacy notice describing what nonpublic personal information is collected and shared, and an opt-out for sharing with nonaffiliated third parties. The Health Insurance Portability and Accountability Act (HIPAA) protects individually identifiable health information. The exam contrasts the two: GLBA governs financial nonpublic personal information; HIPAA governs protected health information.

The Fair Credit Reporting Act (FCRA)

The FCRA governs the use of consumer and credit-based information in underwriting. Tested rules:

  • An insurer that obtains a consumer report must have a permissible purpose (e.g., underwriting an application the consumer initiated).
  • If the insurer takes an adverse action (declination, higher rate, reduced coverage) based on a report, it must give the applicant an adverse action notice and identify the reporting agency.
  • An investigative consumer report (interviews about character or reputation) requires advance written disclosure to the consumer.

The FCRA pairs naturally with credit-based insurance scores: a higher premium driven by credit information is an adverse action requiring notice.

Insurance Fraud and the Fraud Act

Fraud is intentional deception for unlawful gain, and it cuts in two directions the exam tests separately.

TypeWho Commits ItExample
Hard fraudInsured/claimantStaging a theft or arson to collect
Soft (opportunistic) fraudInsured/claimantPadding a legitimate claim with extra damage
Producer fraudProducerFictitious policies, premium theft, forged signatures

The federal Violent Crime Control and Law Enforcement Act (1994), Section 1033/1034, makes it a federal crime for anyone convicted of a felony involving dishonesty or breach of trust to engage in the business of insurance without written consent (a 1033 waiver) from the regulator. This is a frequent national-portion question.

Worked Example: Soft Fraud and Claim Inflation

An insured suffers a genuine $8,000 water-damage loss but submits a claim for $12,000 by adding undamaged items. The $4,000 inflation is soft fraud—opportunistic padding of an otherwise valid claim.

Consequences tested: the insurer may deny the entire claim under the policy's concealment/fraud condition, not merely the padded portion, because most P&C policies void coverage for intentional misrepresentation of a material fact. So the insured risks losing the legitimate $8,000 to gain a fraudulent $4,000. The exam wants you to know fraud can void the whole claim, not just the dishonest slice.

Fraud Reporting and Immunity

States run insurance fraud bureaus, and most statutes require insurers to report suspected fraud and grant civil immunity to those who report in good faith. The exam tests two recurring rules: first, the fraud-warning statement many states require on applications and claim forms (a notice that filing a false claim is a crime); second, the good-faith immunity that shields an insurer or producer from defamation liability for reporting suspected fraud to authorities.

  • Insurers must establish antifraud plans or special investigation units (SIUs) in many states.
  • A producer who knowingly helps an insured submit a fraudulent claim becomes a participant—exposing both the producer's license and potential criminal liability.
  • Good-faith reporting to a fraud bureau is generally immune from civil suit, encouraging disclosure.

Anti-Money-Laundering and the Terrorism Risk Backstop

Two federal programs round out the national consumer/regulatory framework. AML rules require certain insurers to maintain programs to detect suspicious transactions, though traditional P&C products carry lower money-laundering risk than cash-value life products. The Terrorism Risk Insurance Act (TRIA), reauthorized through 2027, requires commercial property/casualty insurers to offer terrorism coverage and creates a federal backstop that shares catastrophic certified-terrorism losses above a statutory program trigger.

The tested point on TRIA is the mandatory make-available requirement: the insurer must offer terrorism coverage on the same terms as other perils, the insured may reject it in writing, and the federal government shares losses only for losses certified as acts of terrorism above the trigger threshold.

Consumer Protection and Replacement Safeguards

State consumer-protection rules give applicants disclosure and cooling-off safeguards. Tested items:

  • Free-look / right to examine periods (more common in life/health) let a buyer cancel for a full refund within a set window.
  • Replacement regulations require comparison disclosures so a consumer is not misled into a worse policy (ties back to twisting/churning in 18.1).
  • Privacy notices must be delivered at the time of application or policy delivery and annually thereafter where required.
  • Buyer's guides and disclosure statements must be accurate and not misleading.

The consumer-protection theme unifies the unit: every rule pushes toward transparency so the buyer can make an informed choice. When a stem asks what a producer or insurer 'must do,' the answer almost always favors disclosure, written notice, or the consumer's right to choose.

The Privacy and Fraud Framework on the Exam

Producers handle sensitive financial and health data, so several federal laws govern its use. The Gramm-Leach-Bliley Act (GLBA) requires insurers to give consumers a privacy notice and an opportunity to opt out of sharing nonpublic personal information with unaffiliated third parties. The Fair Credit Reporting Act (FCRA) governs the use of credit-based information in underwriting and requires an adverse action notice when credit data leads to a declination or higher rate. HIPAA protects health information.

LawCore Producer Duty
GLBAProvide privacy notice; honor opt-out
FCRAAdverse-action notice when credit affects the decision
HIPAASafeguard protected health information
Fraud statutesReport suspected fraud; do not commit/aid it

Insurance fraud divides into hard fraud (a staged or fabricated loss) and soft fraud (padding an otherwise legitimate claim, such as inflating repair estimates). Both are crimes. Most states grant immunity to insurers and producers who report suspected fraud in good faith to the authorities, encouraging reporting without fear of a defamation suit.

Test Your Knowledge

An insurer raises an applicant's premium based partly on a credit-based insurance score drawn from a consumer report. Under the FCRA, the insurer must:

A
B
C
D
Test Your Knowledge

Under Section 1033 of the federal Violent Crime Control Act, a person convicted of a felony involving dishonesty or breach of trust may engage in the business of insurance only if they:

A
B
C
D