Life Insurance Privacy and Consumer Report Case Questions
Life underwriting may involve protected medical information and consumer reports, but different laws govern each.
- A covered health provider generally needs a valid HIPAA authorization to disclose records to a life insurer for underwriting.
- GLBA governs financial privacy notices, while FCRA requires an adverse-action notice when an insurance decision is based in whole or part on a consumer report.
- These original scenarios are not Pearson items.
On this page15 sections
- Question 1: medical records for underwriting
- Question 2: the insurer is not automatically a covered entity
- Question 3: authorization content
- Question 4: GLBA privacy notice
- Question 5: an adverse decision based partly on a report
- Question 6: contents of the notice
- Question 7: the report is inaccurate
- Question 8: report contributed only a little
- Question 9: consumer report permission
- Question 10: keep each notice separate
- How to solve privacy cases
- Identify the information source first
- Use the adverse-action sequence
- Keep medical underwriting distinct
- Resolve a disputed report without promising an outcome
These original cases test a common exam trap: HIPAA, the Gramm-Leach-Bliley Act (GLBA), and the Fair Credit Reporting Act (FCRA) do different work. HIPAA’s Privacy Rule applies to covered entities and business associates handling protected health information; a covered physician generally needs a compliant authorization before disclosing records to a life insurer for underwriting. GLBA requires privacy practices and notices for nonpublic personal financial information, subject to applicable exceptions and state law. FCRA regulates consumer reports and requires notice after an adverse insurance decision based in whole or part on a consumer report. Read who is disclosing what, to whom, and how the insurer used the information.
- HIPAA
- Covered provider or plan disclosure of PHI; life underwriting disclosure generally requires valid authorization
- GLBA
- Financial privacy notices and limits on sharing nonpublic personal information
- FCRA
- Consumer-report use; adverse-action notice if report contributes to unfavorable insurance decision
- Report source
- Medical, investigative, or consumer reporting agency reports may be subject to FCRA
- Adverse action notice
- Identifies reporting agency, says it did not decide, explains dispute/free-report rights
- Important distinction
- A life insurer is not automatically a HIPAA covered entity merely because it receives health data
- Practice status
- All questions are original study scenarios, not recalled Pearson items
Question 1: medical records for underwriting
A physician is a HIPAA-covered provider. A life applicant asks the physician to send specified medical records to an insurer evaluating an application. What generally permits the provider to disclose those records for this purpose?
- A valid HIPAA authorization that meets the Privacy Rule requirements.
- The insurer’s ordinary GLBA privacy notice, without the patient’s authorization.
- An agent’s verbal assurance that the applicant agreed.
- No authorization is ever needed because life underwriting is an insurance function.
Question 2: the insurer is not automatically a covered entity
An agent says the life insurer itself must be a HIPAA covered entity because it receives an applicant’s health information. Which response is most accurate?
- Correct; every recipient of medical information is automatically covered by HIPAA.
- Incorrect; HIPAA’s status depends on whether the organization is a covered entity or business associate, while the provider’s disclosure still may require authorization.
- Correct only if the insurer requests a paramedical exam.
- HIPAA never applies to medical information used in insurance underwriting.
Question 3: authorization content
An applicant signs a release stating only “all my health data may be shared with anyone for any purpose forever.” The physician is a covered entity. What should the agent do?
- Treat it as automatically valid because the applicant signed something.
- Use the insurer’s compliant authorization process; a HIPAA authorization must satisfy required specificity and content rules.
- Change the release by writing a new expiration date without the applicant.
- Ask the MIB to obtain the records instead of the provider.
Question 4: GLBA privacy notice
A customer asks why the insurer gave a notice explaining categories of nonpublic personal financial information and when it may share that information. Which federal law is most directly associated with these financial privacy notices?
- FCRA only
- HIPAA only
- GLBA
- The Sherman Antitrust Act
Question 5: an adverse decision based partly on a report
An insurer issues a life policy at a higher premium than requested. Its underwriting file shows that a consumer report contributed to the rating decision. What FCRA response is generally required?
- No notice, because the insurer issued some coverage.
- An adverse-action notice identifying the consumer reporting agency and the applicant’s relevant rights.
- A HIPAA authorization signed after the policy is issued.
- A report from the agency explaining the insurer’s underwriting judgment.
Question 6: contents of the notice
A consumer requests an adverse-action notice after an insurer declines an application based partly on a report. Which item belongs in the notice?
- The CRA’s contact information and a statement that it did not make the insurer’s decision.
- A promise that the insurer will reverse the decision if the consumer calls the CRA.
- The CRA’s confidential underwriting recommendation as the insurer’s final reason.
- Only the agent’s personal cell number.
Question 7: the report is inaccurate
The applicant believes a medical item in a consumer report is inaccurate after receiving an adverse-action notice. What is the most accurate next step under the notice framework?
- Ask the CRA that furnished the report to investigate the disputed information and obtain a free copy within 60 days if eligible.
- Ask the agent to delete the source record from the physician’s chart.
- Assume the insurer must approve coverage as soon as a dispute is filed.
- Dispute the insurer’s decision only with HHS under HIPAA.
Question 8: report contributed only a little
An insurer says the consumer report was only one of several factors in a policy denial, not the sole reason. Does that fact alone eliminate the FCRA adverse-action notice duty?
- Yes; notice applies only when the report is the sole cause.
- No; a report’s contribution in whole or in part can trigger the notice requirement.
- Yes; only medical records trigger notice.
- No; the CRA must issue the notice instead of the insurer.
Question 9: consumer report permission
An insurer asks a consumer reporting agency for a report to evaluate a life application and wants to use sensitive medical information from the report. Which is the best approach?
- Use the report only for a permissible insurance purpose and follow applicable FCRA limits, including any required permission for medical information.
- Request any report for any purpose because the consumer applied for insurance.
- Ignore FCRA because the insurer has a HIPAA authorization.
- Give the report to unrelated companies for marketing without restrictions.
Question 10: keep each notice separate
An applicant signs a medical-record authorization, receives a GLBA privacy notice, and is later declined partly because of a consumer report. Which statement best describes the separate compliance tasks?
- The authorization, privacy notice, and adverse-action notice serve different purposes; one does not replace the others.
- The GLBA notice replaces both the HIPAA authorization and any FCRA notice.
- The FCRA notice gives the insurer permission to collect all health records.
- Once the applicant signs one privacy form, no further notice can be required.
How to solve privacy cases
Map each fact to a flow: provider to insurer for medical records; financial institution to customer about information-sharing practices; or reporting agency to insurer for a consumer report. Ask whether the disclosing party is HIPAA covered, whether an authorization is required and valid, whether GLBA notice is implicated, and whether report information contributed to an adverse insurance decision. This prevents one signed form from being treated as universal consent.
These are original study questions based on the current Pearson VUE Texas Life Agent outline. They are not actual Pearson items. Privacy rules can depend on the exact entity, data, transaction, and applicable federal and state laws. A life agent should follow the insurer’s approved forms and procedures, protect applicant records, and refer disputes or legal interpretations to compliance counsel.
If an adverse-action notice is missing or incomplete, do not promise a policy issue or a specific remedy. The applicant can contact the consumer reporting agency to obtain and dispute the report, and can ask the insurer for its decision basis. The FTC’s FCRA guidance describes the notice elements. HHS explains when covered providers need authorization for disclosures to life insurers. Read those primary sources for detailed requirements.
Identify the information source first
Privacy questions become easier when the source is identified. A medical record received from a provider, a consumer report assembled by a reporting agency, and an insurer’s internal underwriting note can raise different laws and notice duties. Do not assume that every file is a “consumer report” or that every medical document is governed by HIPAA in the same way. The stem should tell you who collected the information, who furnished it, and how the insurer plans to use it. Then apply the relevant notice, authorization, disclosure, or dispute right rather than choosing a broad privacy slogan.
Use the adverse-action sequence
For a case involving a report that affects an insurance decision, check the sequence: was a consumer report obtained for a permissible underwriting purpose; did the insurer take adverse action based in whole or in part on the report; and did it provide the required notice identifying the reporting agency and explaining the consumer’s rights? The consumer generally must contact the reporting agency to dispute report accuracy, while the insurer remains responsible for its own decision and notice. An agent should not claim to rewrite or erase a third party’s file. Record the facts, give the applicant the proper contact details, and follow the carrier’s procedures.
Keep medical underwriting distinct
An application may authorize collection of medical information, but authorization does not turn every use into an unlimited permission. The insurer still must follow applicable privacy and insurance rules, and its underwriting decision should use information within the lawful process. Candidates should not treat the HIPAA privacy rule as a universal prohibition on an insurer receiving health information from an applicant or authorized source; HIPAA regulates covered entities and specific disclosures. In an exam stem, distinguish an applicant’s signed authorization from a consumer-report adverse-action notice and from the insurer’s internal handling obligations.
Resolve a disputed report without promising an outcome
If an applicant says a report is inaccurate, the practical response is to identify which agency supplied it, explain the dispute channel shown in the notice, and ask the insurer how it will consider corrected information. Reporting-agency reinvestigation rights do not guarantee a favorable underwriting result: accurate adverse data may remain, and the insurer may have other lawful reasons for its decision. Save the notice and correspondence. Do not forward sensitive medical details through an insecure channel or tell the applicant that a correction automatically requires issue at the requested rate.
Common questions
Does HIPAA apply to every life insurer?
No. HIPAA applies to covered entities and business associates as defined by the rules. A covered provider generally needs a valid authorization for a life-underwriting disclosure, but an insurer is not automatically a covered entity just because it receives health information.
When does an insurer need to send an FCRA adverse-action notice?
Generally when an unfavorable insurance action, such as denial or a rate increase, is based in whole or in part on a consumer report. The notice identifies the reporting agency and explains dispute and free-report rights.
Does a GLBA privacy notice authorize medical-record disclosure?
No. A GLBA notice explains financial privacy practices; it is not a substitute for a HIPAA authorization when a covered provider discloses protected health information to a life insurer for underwriting.
Are these actual Pearson VUE items?
No. They are original study cases based on privacy and underwriting topics in the official Texas Life Agent outline. They are not recalled secure questions and do not predict a score.