FEDERAL REGULATION · 6 MIN READ
Privacy Rules: GLBA, HIPAA, and HITECH
The Gramm-Leach-Bliley Act treats insurers as financial institutions and regulates their handling of nonpublic personal information. Customers must receive privacy notices at the start of the relationship and annually (6803), and before sharing nonpublic information with nonaffiliated third parties the institution must give an opt-out opportunity - subject to the 6802(e) exceptions for things like processing transactions the customer requested. The pretexting provisions (6821) criminalize obtaining customer financial information by false pretenses, and the Safeguards Rule (updated in 2023) requires administrative, technical, and physical safeguards for customer information. HIPAA governs protected health information held by covered entities and their business associates. A valid authorization under 45 CFR 164.508(c)(1) requires six core elements - description of the PHI, who may disclose, who may receive, the purpose, an expiration date or event, and the individual's dated signature - plus required statements about revocation and redisclosure. Notarization is not a HIPAA requirement. Individuals have a right of access to PHI in a designated record set: the entity must act within 30 calendar days, with one 30-day extension available on written explanation, and may charge only a reasonable cost-based fee. PHI can be de-identified two ways: Expert Determination, or the Safe Harbor - removing all 18 enumerated identifiers plus lacking actual knowledge that the remainder could identify anyone. The Security Rule organizes protections into administrative, physical, and technical safeguards; a workforce sanction policy is an administrative safeguard. HITECH layered on breach notification and a four-tier civil penalty structure keyed to culpability: unknowing violations at the bottom, reasonable cause next, willful neglect that is corrected within 30 days of discovery third, and uncorrected willful neglect at the top. The 30-day correction window is the dividing line between Tiers 3 and 4. Related health statutes travel with this material: GINA Title I bars health insurers from using genetic information for eligibility, premiums, or underwriting (it does not regulate life, disability, long-term care, or P&C), and the mental health parity act (MHPAEA) requires MH/SUD benefits to be no more restrictive than the predominant requirements applied to substantially all medical/surgical benefits.
Key rules
GLBA requires privacy notices plus an opt-out before nonaffiliated sharing.
Insurers must deliver initial and annual privacy notices and give customers a chance to opt out before sharing nonpublic personal information with nonaffiliated third parties, subject to statutory exceptions such as servicing the customer's own transaction.
Why the exam cares: Questions test both the notice cadence and which sharing requires an opt-out - affiliate sharing and transaction processing do not.
A HIPAA authorization needs six core elements — and notarization is not one of them.
Description of the PHI, the discloser, the recipient, the purpose, an expiration date or event, and a dated signature, plus statements on revocation, conditioning, and redisclosure.
Why the exam cares: The exam's favorite distractor adds a notarized signature to the element list; knowing the real six lets you eliminate it.
Right of access: act within 30 days, one 30-day extension, cost-based fees only.
The covered entity must act on an access request within 30 calendar days; a single extension requires a written statement of reasons and a completion date, for a 60-day maximum. Fees are limited to labor, supplies, postage, and agreed summaries.
Why the exam cares: The 30-plus-30 structure is tested numerically, and fee questions check that only cost-based charges are allowed.
Safe Harbor de-identification removes all 18 identifiers plus actual-knowledge screening.
Under 164.514(b)(2) every one of the 18 enumerated identifiers must go, and the entity must lack actual knowledge the residual data could identify someone; Expert Determination is the alternative path.
Why the exam cares: De-identified data escapes HIPAA entirely - the exam tests the identifier count and the two available methods.
HITECH penalty tiers turn on culpability, with a 30-day cure line at the top.
Four tiers run from unknowing violations through reasonable cause to willful neglect; correcting a willful-neglect violation within 30 days of discovery keeps it in Tier 3 rather than Tier 4.
Why the exam cares: Scenario questions give a culpability level and correction timing, then ask for the tier and minimum penalty.
Numbers to memorize
- 18 — identifiers that must be removed under the HIPAA Safe Harbor de-identification method
- 30 days + one 30-day extension — HIPAA right-of-access response timeline (60-day maximum)
- $10,000 — minimum per-violation penalty for HITECH Tier 3 (willful neglect, corrected within 30 days)
- $50,000 per violation / $1.5 million annual cap — HITECH Tier 4 (willful neglect, uncorrected)
- 30 days — correction window separating HITECH Tier 3 from Tier 4
- 6 — core elements of a valid HIPAA authorization under 164.508(c)(1)
Common traps
- Filing a sanction policy under technical safeguards — remember workforce policies, training, and sanctions are administrative safeguards; technical safeguards are access controls, audit controls, and transmission security.
- Extending GINA to all insurance lines — remember Title I restricts only health insurers; life, disability, long-term care, and P&C underwriting are governed by state law.
- Believing a HIPAA authorization must be notarized — remember HIPAA never requires notarization; only the six core elements and required statements are mandatory.
- Confusing the GLBA opt-out with affiliate sharing — remember the opt-out applies to sharing with nonaffiliated third parties; several 6802(e) exceptions permit sharing without it.
Build a two-column chart - GLBA for financial privacy, HIPAA/HITECH for health privacy - and drill the numbers on the HIPAA side, because that is where the exam hides its arithmetic.
Test it before the exam does
Our P&C bank drills Federal Regulation with AI-explained answers. 20 questions free, no signup.
Taking the P&C exam in your state?
Studying for the Property & Casualty insurance exam? Track every lesson free — progress syncs with the app.
Start free