consumer protection
Consumer Report Disputes
If a consumer report leads to an adverse action (e.g., denial of coverage, rate increase, policy cancellation), the affected individual must be notified.
Notification includes:
Right to receive a free copy of the report.
Right to dispute the report's accuracy.
Upon a dispute, the consumer reporting agency has up to 6 months to reinvestigate.
Example: If a policyholder disputes a non-renewal driven by report information, the policy remains in effect until the investigation is concluded.
Identity Theft and Fraud Alerts
Identity theft can severely harm credit reports, prompting specific responses from consumer reporting agencies.
If an individual (or their representative) reports potential fraud in good faith, a fraud alert will be placed on their file for at least 90 days.
Consumers can request earlier removal of this alert.
Agencies must provide a free copy of the consumer's file upon request.
Within 4 business days of a fraud report, agencies must block any fraudulent information upon proper identity verification.
Gramm-Leach-Bliley Act of 1999 (GLBA)
GLBA implemented major changes to the financial services industry:
Repeal of parts of Glass-Steagall Act: Allowed the merger of banks, securities firms, and insurance companies.
Introduction of Privacy Protections: Established Financial Privacy Rule and Safeguards Rule to protect consumer privacy.
Financial Privacy Rule
Financial institutions must inform consumers about their information sharing practices when disclosing non-public personal information to third parties.
Requirements include:
Notice at the time of establishing customer relationships and annually thereafter.
Details on what information is collected, shared, how it’s used, and protections in place.
Consumers must be informed of their right to opt-out of information sharing.
Changes in privacy policy require updated consumer notices and new opt-out opportunities.
Safeguards Rule
Institutions must develop a written information security plan to protect non-public personal information.
Must outline:
Measures to meet encryption and confidentiality standards.
Protective strategies against potential threats or unauthorized data access.
Terrorism Risk Insurance Act (TRIA)
TRIA was instituted in response to the 09/11/2001 terrorist attacks to assist in providing coverage for terrorism risk.
Created a federal reinsurance facility to share losses between the government and private insurers in the event of certified acts of terrorism.
Aims to ensure availability and affordability of commercial property and casualty insurance for terrorism risks.
Key Coverage Exclusions:
Federal crop insurance, flood insurance, professional liability insurance, and several others including life and health insurance.
Program Details
TRIA is temporary but has been extended several times and is set to expire on 12/31/2027.
Authority: The Treasury Department with definitions of terrorism services by the Secretary of Treasury, Homeland Security, and Attorney General.
Definition updated to include attacks by domestic individuals under the 2007 Reauthorization Act.
Must cause at least $5,000,000 in property and casualty losses to qualify as terrorism.
Insurance Triggers and Limits
Certified acts of terrorism have a loss trigger, which was $100,000,000 in 2015, increasing by $20,000,000 annually until reaching $200,000,000 in 2020.
Losses above the trigger but below a program cap of $100,000,000,000 are co-shared between private insurers and the government.
Insurer deductible set at 20% of covered losses.
Co-share payment began at 15% (government covers 85%) in 2015 and increased incrementally to a 20% share (government covers 80%) from 2020 onwards.