consumer protection

Consumer Report Disputes

  • If a consumer report leads to an adverse action (e.g., denial of coverage, rate increase, policy cancellation), the affected individual must be notified.

    • Notification includes:

    • Right to receive a free copy of the report.

    • Right to dispute the report's accuracy.

  • Upon a dispute, the consumer reporting agency has up to 6 months to reinvestigate.

  • Example: If a policyholder disputes a non-renewal driven by report information, the policy remains in effect until the investigation is concluded.

Identity Theft and Fraud Alerts

  • Identity theft can severely harm credit reports, prompting specific responses from consumer reporting agencies.

    • If an individual (or their representative) reports potential fraud in good faith, a fraud alert will be placed on their file for at least 90 days.

    • Consumers can request earlier removal of this alert.

    • Agencies must provide a free copy of the consumer's file upon request.

  • Within 4 business days of a fraud report, agencies must block any fraudulent information upon proper identity verification.

Gramm-Leach-Bliley Act of 1999 (GLBA)

  • GLBA implemented major changes to the financial services industry:

    • Repeal of parts of Glass-Steagall Act: Allowed the merger of banks, securities firms, and insurance companies.

    • Introduction of Privacy Protections: Established Financial Privacy Rule and Safeguards Rule to protect consumer privacy.

Financial Privacy Rule

  • Financial institutions must inform consumers about their information sharing practices when disclosing non-public personal information to third parties.

    • Requirements include:

    • Notice at the time of establishing customer relationships and annually thereafter.

    • Details on what information is collected, shared, how it’s used, and protections in place.

    • Consumers must be informed of their right to opt-out of information sharing.

  • Changes in privacy policy require updated consumer notices and new opt-out opportunities.

Safeguards Rule

  • Institutions must develop a written information security plan to protect non-public personal information.

    • Must outline:

    • Measures to meet encryption and confidentiality standards.

    • Protective strategies against potential threats or unauthorized data access.

Terrorism Risk Insurance Act (TRIA)

  • TRIA was instituted in response to the 09/11/2001 terrorist attacks to assist in providing coverage for terrorism risk.

    • Created a federal reinsurance facility to share losses between the government and private insurers in the event of certified acts of terrorism.

    • Aims to ensure availability and affordability of commercial property and casualty insurance for terrorism risks.

  • Key Coverage Exclusions:

    • Federal crop insurance, flood insurance, professional liability insurance, and several others including life and health insurance.

Program Details

  • TRIA is temporary but has been extended several times and is set to expire on 12/31/2027.

  • Authority: The Treasury Department with definitions of terrorism services by the Secretary of Treasury, Homeland Security, and Attorney General.

    • Definition updated to include attacks by domestic individuals under the 2007 Reauthorization Act.

    • Must cause at least $5,000,000 in property and casualty losses to qualify as terrorism.

Insurance Triggers and Limits

  • Certified acts of terrorism have a loss trigger, which was $100,000,000 in 2015, increasing by $20,000,000 annually until reaching $200,000,000 in 2020.

  • Losses above the trigger but below a program cap of $100,000,000,000 are co-shared between private insurers and the government.

    • Insurer deductible set at 20% of covered losses.

    • Co-share payment began at 15% (government covers 85%) in 2015 and increased incrementally to a 20% share (government covers 80%) from 2020 onwards.