Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

Life Insurance Privacy and Consumer Report Case Questions

Updated 13 min read
Key takeaway

Life underwriting may involve protected medical information and consumer reports, but different laws govern each.

  • A covered health provider generally needs a valid HIPAA authorization to disclose records to a life insurer for underwriting.
  • GLBA governs financial privacy notices, while FCRA requires an adverse-action notice when an insurance decision is based in whole or part on a consumer report.
  • These original scenarios are not Pearson items.
On this page15 sections
  1. Question 1: medical records for underwriting
  2. Question 2: the insurer is not automatically a covered entity
  3. Question 3: authorization content
  4. Question 4: GLBA privacy notice
  5. Question 5: an adverse decision based partly on a report
  6. Question 6: contents of the notice
  7. Question 7: the report is inaccurate
  8. Question 8: report contributed only a little
  9. Question 9: consumer report permission
  10. Question 10: keep each notice separate
  11. How to solve privacy cases
  12. Identify the information source first
  13. Use the adverse-action sequence
  14. Keep medical underwriting distinct
  15. Resolve a disputed report without promising an outcome

These original cases test a common exam trap: HIPAA, the Gramm-Leach-Bliley Act (GLBA), and the Fair Credit Reporting Act (FCRA) do different work. HIPAA’s Privacy Rule applies to covered entities and business associates handling protected health information; a covered physician generally needs a compliant authorization before disclosing records to a life insurer for underwriting. GLBA requires privacy practices and notices for nonpublic personal financial information, subject to applicable exceptions and state law. FCRA regulates consumer reports and requires notice after an adverse insurance decision based in whole or part on a consumer report. Read who is disclosing what, to whom, and how the insurer used the information.

HIPAA
Covered provider or plan disclosure of PHI; life underwriting disclosure generally requires valid authorization
GLBA
Financial privacy notices and limits on sharing nonpublic personal information
FCRA
Consumer-report use; adverse-action notice if report contributes to unfavorable insurance decision
Report source
Medical, investigative, or consumer reporting agency reports may be subject to FCRA
Adverse action notice
Identifies reporting agency, says it did not decide, explains dispute/free-report rights
Important distinction
A life insurer is not automatically a HIPAA covered entity merely because it receives health data
Practice status
All questions are original study scenarios, not recalled Pearson items

Question 1: medical records for underwriting

Identify the covered entity and disclosure

A physician is a HIPAA-covered provider. A life applicant asks the physician to send specified medical records to an insurer evaluating an application. What generally permits the provider to disclose those records for this purpose?

  1. A valid HIPAA authorization that meets the Privacy Rule requirements.
  2. The insurer’s ordinary GLBA privacy notice, without the patient’s authorization.
  3. An agent’s verbal assurance that the applicant agreed.
  4. No authorization is ever needed because life underwriting is an insurance function.
Answer: A. A is best. HHS explains that a covered provider’s disclosure to a life insurer for coverage purposes is an example requiring an individual’s written HIPAA authorization. The authorization must identify information and recipients and include required elements such as expiration and revocation rights. B addresses financial privacy notices, not a provider’s HIPAA disclosure. C is not a compliant substitute for written authorization. D reverses the rule. HIPAA coverage attaches to covered entities and business associates, not every organization that handles medical information.

Question 2: the insurer is not automatically a covered entity

Avoid overextending HIPAA

An agent says the life insurer itself must be a HIPAA covered entity because it receives an applicant’s health information. Which response is most accurate?

  1. Correct; every recipient of medical information is automatically covered by HIPAA.
  2. Incorrect; HIPAA’s status depends on whether the organization is a covered entity or business associate, while the provider’s disclosure still may require authorization.
  3. Correct only if the insurer requests a paramedical exam.
  4. HIPAA never applies to medical information used in insurance underwriting.
Answer: B. B accurately separates the recipient’s organizational status from the provider’s disclosure duty. A covered physician generally needs a valid authorization to disclose PHI to a life insurer for underwriting, but a life insurer is not automatically a HIPAA covered entity merely because it receives the information. A expands the statute too broadly. C invents an exam-based rule. D wrongly suggests provider disclosures are exempt. Other privacy and insurance laws may still apply to insurers and their vendors.

Question 3: authorization content

Evaluate a vague medical release

An applicant signs a release stating only “all my health data may be shared with anyone for any purpose forever.” The physician is a covered entity. What should the agent do?

  1. Treat it as automatically valid because the applicant signed something.
  2. Use the insurer’s compliant authorization process; a HIPAA authorization must satisfy required specificity and content rules.
  3. Change the release by writing a new expiration date without the applicant.
  4. Ask the MIB to obtain the records instead of the provider.
Answer: B. B is appropriate because a signature alone does not guarantee that an authorization satisfies HIPAA requirements. HHS requires plain-language and specific information, including who may disclose and receive information, what information is involved, purpose, expiration, and revocation rights. A ignores required content. C improperly alters the applicant’s authorization. D confuses consumer reporting with a provider’s medical-record disclosure. The covered provider should receive a valid form, not a vague blanket statement.

Question 4: GLBA privacy notice

Match a financial privacy notice to its law

A customer asks why the insurer gave a notice explaining categories of nonpublic personal financial information and when it may share that information. Which federal law is most directly associated with these financial privacy notices?

  1. FCRA only
  2. HIPAA only
  3. GLBA
  4. The Sherman Antitrust Act
Answer: C. C is correct. GLBA concerns privacy notices and treatment of nonpublic personal financial information by financial institutions, including insurers within applicable rules. A FCRA governs consumer reports and related rights; it is not the general source for the insurer’s GLBA privacy notice. B concerns protected health information handled by covered entities and business associates. D has no bearing on the stated notice. Separate state insurance privacy laws and exceptions may also apply, so the notice itself and governing regulations matter.

Question 5: an adverse decision based partly on a report

Apply the FCRA trigger

An insurer issues a life policy at a higher premium than requested. Its underwriting file shows that a consumer report contributed to the rating decision. What FCRA response is generally required?

  1. No notice, because the insurer issued some coverage.
  2. An adverse-action notice identifying the consumer reporting agency and the applicant’s relevant rights.
  3. A HIPAA authorization signed after the policy is issued.
  4. A report from the agency explaining the insurer’s underwriting judgment.
Answer: B. B is correct because an insurance rate increase based in whole or part on a consumer report can be an adverse action under FCRA. The notice must identify the reporting agency and tell the consumer the agency did not make the decision, plus rights to dispute and obtain a free report within the statutory period. A wrongly limits adverse action to denial. C is unrelated to report-based notice. D misstates the CRA’s role; the CRA does not make the insurer’s underwriting decision.

Question 6: contents of the notice

Choose the required adverse-action information

A consumer requests an adverse-action notice after an insurer declines an application based partly on a report. Which item belongs in the notice?

  1. The CRA’s contact information and a statement that it did not make the insurer’s decision.
  2. A promise that the insurer will reverse the decision if the consumer calls the CRA.
  3. The CRA’s confidential underwriting recommendation as the insurer’s final reason.
  4. Only the agent’s personal cell number.
Answer: A. A reflects FCRA notice elements described by the FTC: the reporting agency’s name and contact details, a statement that the agency did not make the adverse decision, and information about the consumer’s right to dispute and obtain a free report within 60 days on request. B invents a guaranteed reversal. C confuses the CRA’s report with the insurer’s decision and overstates what the CRA can explain. D omits required information. The insurer remains responsible for its decision and notice.

Question 7: the report is inaccurate

Route the dispute to the correct party

The applicant believes a medical item in a consumer report is inaccurate after receiving an adverse-action notice. What is the most accurate next step under the notice framework?

  1. Ask the CRA that furnished the report to investigate the disputed information and obtain a free copy within 60 days if eligible.
  2. Ask the agent to delete the source record from the physician’s chart.
  3. Assume the insurer must approve coverage as soon as a dispute is filed.
  4. Dispute the insurer’s decision only with HHS under HIPAA.
Answer: A. A identifies the consumer reporting agency as the route to dispute report accuracy and request a free report within 60 days after the adverse-action notice. B mixes a report dispute with a medical-record amendment request to a provider. C promises a particular underwriting outcome; a dispute does not automatically require approval. D misdirects an FCRA report dispute to HHS. The applicant may separately ask the insurer about its decision, but the CRA handles its file under FCRA procedures.

Question 8: report contributed only a little

Do not require the report to be the sole cause

An insurer says the consumer report was only one of several factors in a policy denial, not the sole reason. Does that fact alone eliminate the FCRA adverse-action notice duty?

  1. Yes; notice applies only when the report is the sole cause.
  2. No; a report’s contribution in whole or in part can trigger the notice requirement.
  3. Yes; only medical records trigger notice.
  4. No; the CRA must issue the notice instead of the insurer.
Answer: B. B is correct. The FTC’s insurance guidance states the FCRA notice is required when the decision is based partly or completely on consumer-report information. A adds a sole-cause requirement not present in the standard. C confuses medical records with consumer reports. D shifts the user’s duty to the CRA; the insurer taking adverse action gives the notice. Document the report’s contribution rather than arguing it was not the only factor.

Question 9: consumer report permission

Check the FCRA purpose and medical-information rules

An insurer asks a consumer reporting agency for a report to evaluate a life application and wants to use sensitive medical information from the report. Which is the best approach?

  1. Use the report only for a permissible insurance purpose and follow applicable FCRA limits, including any required permission for medical information.
  2. Request any report for any purpose because the consumer applied for insurance.
  3. Ignore FCRA because the insurer has a HIPAA authorization.
  4. Give the report to unrelated companies for marketing without restrictions.
Answer: A. A correctly recognizes that applying for insurance can provide a permissible purpose for an insurance consumer report, but it does not eliminate FCRA limits or special medical-information requirements. The FTC notes medical information use may require consumer permission and can be limited to the transaction or otherwise permitted by law. B and D overstate access and sharing rights. C confuses HIPAA authorization for provider disclosure with FCRA obligations governing reports. Verify current law and the report type.

Question 10: keep each notice separate

Use the correct notice for each information flow

An applicant signs a medical-record authorization, receives a GLBA privacy notice, and is later declined partly because of a consumer report. Which statement best describes the separate compliance tasks?

  1. The authorization, privacy notice, and adverse-action notice serve different purposes; one does not replace the others.
  2. The GLBA notice replaces both the HIPAA authorization and any FCRA notice.
  3. The FCRA notice gives the insurer permission to collect all health records.
  4. Once the applicant signs one privacy form, no further notice can be required.
Answer: A. A is the accurate synthesis. A covered provider’s HIPAA authorization permits a specified disclosure of PHI; a GLBA notice explains financial privacy practices; and FCRA adverse-action notice informs the consumer about report-based unfavorable insurance decisions and dispute rights. B, C, and D collapse distinct legal duties. A form’s title does not control its legal function. Identify the party, information, use, and decision at each stage, then apply the corresponding rule and current state requirements.

How to solve privacy cases

Map each fact to a flow: provider to insurer for medical records; financial institution to customer about information-sharing practices; or reporting agency to insurer for a consumer report. Ask whether the disclosing party is HIPAA covered, whether an authorization is required and valid, whether GLBA notice is implicated, and whether report information contributed to an adverse insurance decision. This prevents one signed form from being treated as universal consent.

These are original study questions based on the current Pearson VUE Texas Life Agent outline. They are not actual Pearson items. Privacy rules can depend on the exact entity, data, transaction, and applicable federal and state laws. A life agent should follow the insurer’s approved forms and procedures, protect applicant records, and refer disputes or legal interpretations to compliance counsel.

If an adverse-action notice is missing or incomplete, do not promise a policy issue or a specific remedy. The applicant can contact the consumer reporting agency to obtain and dispute the report, and can ask the insurer for its decision basis. The FTC’s FCRA guidance describes the notice elements. HHS explains when covered providers need authorization for disclosures to life insurers. Read those primary sources for detailed requirements.

Identify the information source first

Privacy questions become easier when the source is identified. A medical record received from a provider, a consumer report assembled by a reporting agency, and an insurer’s internal underwriting note can raise different laws and notice duties. Do not assume that every file is a “consumer report” or that every medical document is governed by HIPAA in the same way. The stem should tell you who collected the information, who furnished it, and how the insurer plans to use it. Then apply the relevant notice, authorization, disclosure, or dispute right rather than choosing a broad privacy slogan.

Use the adverse-action sequence

For a case involving a report that affects an insurance decision, check the sequence: was a consumer report obtained for a permissible underwriting purpose; did the insurer take adverse action based in whole or in part on the report; and did it provide the required notice identifying the reporting agency and explaining the consumer’s rights? The consumer generally must contact the reporting agency to dispute report accuracy, while the insurer remains responsible for its own decision and notice. An agent should not claim to rewrite or erase a third party’s file. Record the facts, give the applicant the proper contact details, and follow the carrier’s procedures.

Keep medical underwriting distinct

An application may authorize collection of medical information, but authorization does not turn every use into an unlimited permission. The insurer still must follow applicable privacy and insurance rules, and its underwriting decision should use information within the lawful process. Candidates should not treat the HIPAA privacy rule as a universal prohibition on an insurer receiving health information from an applicant or authorized source; HIPAA regulates covered entities and specific disclosures. In an exam stem, distinguish an applicant’s signed authorization from a consumer-report adverse-action notice and from the insurer’s internal handling obligations.

Resolve a disputed report without promising an outcome

If an applicant says a report is inaccurate, the practical response is to identify which agency supplied it, explain the dispute channel shown in the notice, and ask the insurer how it will consider corrected information. Reporting-agency reinvestigation rights do not guarantee a favorable underwriting result: accurate adverse data may remain, and the insurer may have other lawful reasons for its decision. Save the notice and correspondence. Do not forward sensitive medical details through an insecure channel or tell the applicant that a correction automatically requires issue at the requested rate.

Common questions

Does HIPAA apply to every life insurer?

No. HIPAA applies to covered entities and business associates as defined by the rules. A covered provider generally needs a valid authorization for a life-underwriting disclosure, but an insurer is not automatically a covered entity just because it receives health information.

When does an insurer need to send an FCRA adverse-action notice?

Generally when an unfavorable insurance action, such as denial or a rate increase, is based in whole or in part on a consumer report. The notice identifies the reporting agency and explains dispute and free-report rights.

Does a GLBA privacy notice authorize medical-record disclosure?

No. A GLBA notice explains financial privacy practices; it is not a substitute for a HIPAA authorization when a covered provider discloses protected health information to a life insurer for underwriting.

Are these actual Pearson VUE items?

No. They are original study cases based on privacy and underwriting topics in the official Texas Life Agent outline. They are not recalled secure questions and do not predict a score.