18.3 Privacy, Fraud, and Consumer Protection
Key Takeaways
- GLBA governs financial nonpublic personal information (privacy notice + opt-out); HIPAA governs protected health information.
- FCRA adverse action based on a consumer report or credit-based score requires an adverse action notice naming the reporting agency.
- Hard fraud fabricates a loss; soft fraud pads a legitimate one—both can void the entire claim under the concealment/fraud condition.
- Section 1033 makes it a federal crime for a felon (dishonesty/breach of trust) to work in insurance without a written 1033 waiver.
- Consumer-protection rules—free-look, replacement disclosures, privacy notices—all drive toward informed, transparent buying.
Federal Privacy: GLBA and HIPAA
Two federal laws frame insurance privacy on the national exam. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions, including insurers and producers, to give consumers a privacy notice describing what nonpublic personal information is collected and shared, and an opt-out for sharing with nonaffiliated third parties. The Health Insurance Portability and Accountability Act (HIPAA) protects individually identifiable health information. The exam contrasts the two: GLBA governs financial nonpublic personal information; HIPAA governs protected health information.
The Fair Credit Reporting Act (FCRA)
The FCRA governs the use of consumer and credit-based information in underwriting. Tested rules:
- An insurer that obtains a consumer report must have a permissible purpose (e.g., underwriting an application the consumer initiated).
- If the insurer takes an adverse action (declination, higher rate, reduced coverage) based on a report, it must give the applicant an adverse action notice and identify the reporting agency.
- An investigative consumer report (interviews about character or reputation) requires advance written disclosure to the consumer.
The FCRA pairs naturally with credit-based insurance scores: a higher premium driven by credit information is an adverse action requiring notice.
Insurance Fraud and the Fraud Act
Fraud is intentional deception for unlawful gain, and it cuts in two directions the exam tests separately.
| Type | Who Commits It | Example |
|---|---|---|
| Hard fraud | Insured/claimant | Staging a theft or arson to collect |
| Soft (opportunistic) fraud | Insured/claimant | Padding a legitimate claim with extra damage |
| Producer fraud | Producer | Fictitious policies, premium theft, forged signatures |
The federal Violent Crime Control and Law Enforcement Act (1994), Section 1033/1034, makes it a federal crime for anyone convicted of a felony involving dishonesty or breach of trust to engage in the business of insurance without written consent (a 1033 waiver) from the regulator. This is a frequent national-portion question.
Worked Example: Soft Fraud and Claim Inflation
An insured suffers a genuine $8,000 water-damage loss but submits a claim for $12,000 by adding undamaged items. The $4,000 inflation is soft fraud—opportunistic padding of an otherwise valid claim.
Consequences tested: the insurer may deny the entire claim under the policy's concealment/fraud condition, not merely the padded portion, because most P&C policies void coverage for intentional misrepresentation of a material fact. So the insured risks losing the legitimate $8,000 to gain a fraudulent $4,000. The exam wants you to know fraud can void the whole claim, not just the dishonest slice.
Fraud Reporting and Immunity
States run insurance fraud bureaus, and most statutes require insurers to report suspected fraud and grant civil immunity to those who report in good faith. The exam tests two recurring rules: first, the fraud-warning statement many states require on applications and claim forms (a notice that filing a false claim is a crime); second, the good-faith immunity that shields an insurer or producer from defamation liability for reporting suspected fraud to authorities.
- Insurers must establish antifraud plans or special investigation units (SIUs) in many states.
- A producer who knowingly helps an insured submit a fraudulent claim becomes a participant—exposing both the producer's license and potential criminal liability.
- Good-faith reporting to a fraud bureau is generally immune from civil suit, encouraging disclosure.
Anti-Money-Laundering and the Terrorism Risk Backstop
Two federal programs round out the national consumer/regulatory framework. AML rules require certain insurers to maintain programs to detect suspicious transactions, though traditional P&C products carry lower money-laundering risk than cash-value life products. The Terrorism Risk Insurance Act (TRIA), reauthorized through 2027, requires commercial property/casualty insurers to offer terrorism coverage and creates a federal backstop that shares catastrophic certified-terrorism losses above a statutory program trigger.
The tested point on TRIA is the mandatory make-available requirement: the insurer must offer terrorism coverage on the same terms as other perils, the insured may reject it in writing, and the federal government shares losses only for losses certified as acts of terrorism above the trigger threshold.
Consumer Protection and Replacement Safeguards
State consumer-protection rules give applicants disclosure and cooling-off safeguards. Tested items:
- Free-look / right to examine periods (more common in life/health) let a buyer cancel for a full refund within a set window.
- Replacement regulations require comparison disclosures so a consumer is not misled into a worse policy (ties back to twisting/churning in 18.1).
- Privacy notices must be delivered at the time of application or policy delivery and annually thereafter where required.
- Buyer's guides and disclosure statements must be accurate and not misleading.
The consumer-protection theme unifies the unit: every rule pushes toward transparency so the buyer can make an informed choice. When a stem asks what a producer or insurer 'must do,' the answer almost always favors disclosure, written notice, or the consumer's right to choose.
The Privacy and Fraud Framework on the Exam
Producers handle sensitive financial and health data, so several federal laws govern its use. The Gramm-Leach-Bliley Act (GLBA) requires insurers to give consumers a privacy notice and an opportunity to opt out of sharing nonpublic personal information with unaffiliated third parties. The Fair Credit Reporting Act (FCRA) governs the use of credit-based information in underwriting and requires an adverse action notice when credit data leads to a declination or higher rate. HIPAA protects health information.
| Law | Core Producer Duty |
|---|---|
| GLBA | Provide privacy notice; honor opt-out |
| FCRA | Adverse-action notice when credit affects the decision |
| HIPAA | Safeguard protected health information |
| Fraud statutes | Report suspected fraud; do not commit/aid it |
Insurance fraud divides into hard fraud (a staged or fabricated loss) and soft fraud (padding an otherwise legitimate claim, such as inflating repair estimates). Both are crimes. Most states grant immunity to insurers and producers who report suspected fraud in good faith to the authorities, encouraging reporting without fear of a defamation suit.
An insurer raises an applicant's premium based partly on a credit-based insurance score drawn from a consumer report. Under the FCRA, the insurer must:
Under Section 1033 of the federal Violent Crime Control Act, a person convicted of a felony involving dishonesty or breach of trust may engage in the business of insurance only if they: