AI for Insurance Professionals
Aware · M8 · lesson 8 of 15 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The Other Frameworks That Apply - GLBA, HIPAA, FCRA, Mental Health Parity, State Privacy
📖
now learning

The Other Frameworks That Apply - GLBA, HIPAA, FCRA, Mental Health Parity, State Privacy

15 min

The NAIC bulletin and the state DOI bulletins are not the only law that applies to AI on the insurance desk. A federal layer - the Gramm-Leach-Bliley Act Safeguards Rule (16 CFR §314), the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, the Fair Credit Reporting Act §615 adverse-action requirement, Reg AB broker disclosure scope, the Mental Health Parity and Addiction Equity Act (MHPAEA) Non-Quantitative Treatment Limitation analysis - overlays on every AI workflow. A state privacy layer - California's CCPA/CPRA, Colorado's CPA, Virginia's VCDPA, Connecticut's CTDPA, Utah's UCPA, Texas's TIPA, plus the rapidly expanding 2025–2026 state privacy patchwork - adds notice, access, deletion, and opt-out obligations on top of insurance-specific carve-outs. And the coverage-law layer - the Anti-Concurrent-Cause analysis under ISO CGL CG 00 01 and ISO HO 00 03 - applies to property losses where multiple proximate causes meet AI-driven photo or aerial-imagery evidence. This lesson maps each framework to the AI surface it touches.

GLBA Safeguards Rule - NPI Handling at the AI Boundary

The Gramm-Leach-Bliley Act (GLBA), enacted 1999, governs how financial institutions - including every insurance carrier, agency, MGA, and brokerage in the United States - handle nonpublic personal information (NPI) about consumers. The Safeguards Rule (16 CFR §314, originally promulgated by the FTC and revised most recently in 2022–2023) requires every covered financial institution to "develop, implement, and maintain a comprehensive information security program" that includes administrative, technical, and physical safeguards over NPI. The 2023 amendments raised the bar materially: a board-reported written risk assessment, encryption of NPI in transit and at rest, multi-factor authentication for access to NPI systems, secure development practices, an incident response plan, and vendor oversight with contractual safeguards.

The intersection with insurance AI is constant. Every Cytora submission triage, every Federato workbench query, every Akur8 GLM that includes named-insured attributes, every Tractable photo upload with insured-identifying information in the EXIF, every Hi Marley SMS thread, every Five Sigma coverage summary, every Coalition cyber-scan dataset, every Munich Re / Swiss Re Magnum / RGA AURA NEXT / SCOR Velogica accelerated-UW model run - all touch NPI. The Safeguards Rule requires the carrier to know where the NPI is, who can access it, how it's protected, who the sub-processors are, and what the incident-response plan does when the AI vendor has a breach.

Written information security program (WISP). The §314.3 written document that names the qualified individual responsible for the program (typically the CISO or CCO at a carrier), the program scope, the risk-assessment methodology, the safeguards selected, and the testing and monitoring cadence. The WISP is the bridge artifact between GLBA and the AI program - and the WISP integrates the AI risk assessment with the broader information-security risk assessment. A 2026 WISP at a mid-size carrier is 40–120 pages with a dedicated AI section that maps to NAIC bulletin §4.2.

Vendor oversight (§314.4(f)). The Safeguards Rule requires the carrier to take "reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards" and to "require [those] service providers by contract to implement and maintain such safeguards." This is where the GLBA framework directly intersects with the NAIC bulletin's §4.2 third-party AI requirement. The contract addendum that satisfies §4.2 must also satisfy GLBA §314.4(f) - they are operationally one document.

Incident response (§314.4(h)). Written incident-response plan, including notification procedures. If a third-party AI vendor experiences a security event affecting customer NPI, the carrier must be able to detect, respond, and notify within the timeframes required by applicable state breach-notification laws (which vary state-to-state, but are typically 30–90 days after discovery).

HIPAA Privacy, Security, and Breach Notification - L&H AI Surface

The Health Insurance Portability and Accountability Act (HIPAA) applies to "covered entities" - health plans, healthcare providers that conduct certain electronic transactions, and healthcare clearinghouses - and to "business associates" who handle Protected Health Information (PHI) on behalf of covered entities. For insurance, HIPAA's covered-entity reach is primarily L&H insurers operating health plans, ERISA group health plans, group long-term disability plans handling medical-records review, and group life carriers in some scenarios. P&C carriers handling BI claim medical records, WC carriers handling treating-physician records, and auto carriers handling PIP medical bills are generally not covered entities but become subject to HIPAA's BAA requirements when they receive PHI from a covered entity for claims defense or coverage purposes.

The Privacy Rule and Minimum Necessary

HIPAA's Privacy Rule (45 CFR §164 Subpart E) controls the use and disclosure of PHI. The most operationally consequential provision for AI is §164.502(b) - the "minimum necessary" rule. A covered entity using AI to process PHI for treatment, payment, or healthcare operations must limit the PHI used to the minimum reasonably necessary to accomplish the purpose. An L&H accelerated-UW model that ingests a complete electronic health record when it needs only specific diagnostic codes violates minimum necessary; the same model with a feature-selection layer that pulls only the relevant ICD-10 / CPT codes complies. The minimum-necessary analysis is a §4.4 documentation artifact on the AI-program side and a §164.502(b) compliance artifact on the HIPAA side.

The Business Associate Agreement Chain

Every third-party AI vendor that handles PHI on behalf of an L&H carrier or other HIPAA-covered entity must sign a Business Associate Agreement (BAA) under §164.504(e). The BAA defines permitted uses, requires safeguards, restricts disclosures, and obligates breach notification. Munich Re / Swiss Re Magnum / RGA AURA NEXT / SCOR Velogica handling L&H underwriting PHI all sign BAAs. Sub-processors (the cloud host, the model-monitoring vendor, the data-warehouse vendor) sign BAAs with the AI vendor. The chain has to be intact end-to-end; a single gap creates HIPAA exposure for every entity in the chain. The Exhibit D AI-data response under the NAIC Evaluation Tool asks for the BAA chain explicitly.

Breach Notification - 60 Days and the OCR

HIPAA's Breach Notification Rule (45 CFR §164.400–414) requires notification within 60 days of discovery to the affected individuals, to HHS Office for Civil Rights (OCR), and (for breaches affecting 500+ individuals) to prominent media outlets. An AI vendor's security incident affecting PHI triggers breach notification through the BAA chain. The 2024–2026 OCR enforcement record shows $2M–$15M settlements for major breaches, with corrective action plans typically running 2–3 years.

FCRA §615 - The Pre-Notice and Adverse-Action Letter

The Fair Credit Reporting Act (FCRA) governs the use of consumer-report data - credit reports, MVR records, LexisNexis public-records data, Milliman IntelliScript Rx history, ExamOne ScriptCheck, MIB code data, certain employment-history data. When any of these consumer-report data sources influences an insurance underwriting, pricing, or claim decision adversely to the consumer, FCRA §615 requires both a pre-adverse-action notice (sometimes) and a formal adverse-action notice (always) that includes the name of the consumer-reporting agency, the consumer's right to obtain a free copy of the report, the consumer's right to dispute, and the principal reasons for the adverse action.

AI on the insurance desk almost always invokes FCRA. An accelerated-UW knockout that uses Milliman IntelliScript Rx history adversely is an FCRA-covered adverse action. A homeowners pricing decline based on a LexisNexis public-records hit is an FCRA adverse action. A commercial-auto rate impact based on MVR data is an FCRA adverse action. An L&H decline based on MIB code is an FCRA adverse action. The §615 adverse-action letter has to identify the principal reasons in human-reviewable language - which means the AI model's reason code has to be FCRA-compliant by design, not retrofitted after the fact.

The pre-notice (FCRA §615(a)(3)). In certain employment-related contexts, FCRA requires a pre-adverse-action notice before final action is taken. The insurance context is narrower - most insurance adverse actions only require the post-decision letter - but accelerated-UW workflows that touch consumer-report data and result in a coverage decline trigger the consumer's right to receive the data and dispute before the decline is finalized. The pre-notice is required for the L&H workflows that use ECDIS data; the operational drafting happens in L2 Ch7 of this program.

The adverse-action letter. The §615(a)(2) artifact. Identifies the consumer-reporting agency by name and address, states the consumer's right to free disclosure, states the right to dispute, and identifies the principal reasons for the adverse action. The reasons must be specific enough that the consumer can challenge them; "the model said so" fails §615 in the same way it fails §4 of the NAIC bulletin.

Reg AB Broker Disclosure Scope

Reg AB - informally referred to but more formally the SEC's Regulation AB (asset-backed securities disclosure) - does not directly apply to most insurance AI workflows. However, the term is sometimes used colloquially to refer to the broader broker-disclosure regulatory framework, including the surplus-lines disclosure obligations, the SLAP (Surplus Lines Authority of the Producer) attestations, and the wholesale broker E&O posture. For practical purposes in 2026 insurance AI work, broker disclosure obligations sit at the intersection of (a) state-specific surplus-lines stamping requirements (FSLSO in Florida, SLSI in Texas, SLA in California), (b) the NAIC's producer-licensing framework, and (c) state-specific consumer-disclosure rules for AI-influenced recommendations. The agency-built chatbot that recommends a policy needs disclosure that an AI is involved; the wholesale broker submitting an AI-cleared diligent-effort declination affidavit needs the AI involvement traceable in the FSLSO filing.

Mental Health Parity - The NQTL Analysis for Behavioral-Claims AI

The Mental Health Parity and Addiction Equity Act (MHPAEA), enacted 2008 and significantly expanded by the 2020 Consolidated Appropriations Act, requires group health plans and group health insurance issuers to provide mental health and substance-use-disorder (MH/SUD) benefits on terms no more restrictive than medical/surgical benefits. The Non-Quantitative Treatment Limitation (NQTL) analysis is the operational compliance artifact: the plan or issuer must document that any non-quantitative limitation (medical necessity criteria, prior authorization, step therapy, network adequacy, fail-first protocols, utilization management) applied to MH/SUD is comparable to and applied no more stringently than the limitation applied to medical/surgical benefits.

The intersection with AI is direct and consequential. An AI utilization-review tool that denies behavioral-health requests at a rate disparate to the medical/surgical denial rate is an MHPAEA NQTL violation - even if no human ever consciously discriminated, and even if the AI model never saw a "mental health vs. medical/surgical" indicator directly. The playbook scenario from the Atlanta claims adjuster - 14 of the last 22 IOP (Intensive Outpatient Program) requests denied by the AI tool, against a 4-of-22 medical/surgical benchmark - is the canonical MHPAEA NQTL trigger. The disparity (64% MH/SUD denial rate vs. 18% medical/surgical denial rate) is the quantitative signal that triggers the analysis.

The NQTL analysis the carrier produces in response has three parts. Part 1 - describe the NQTL (the AI utilization-review tool and its applied criteria). Part 2 - document the design and application of the NQTL to MH/SUD and to medical/surgical benefits, including the factors used in designing the tool, the evidentiary standards relied on, and the practical application in claims handling. Part 3 - produce the comparative analysis demonstrating that the design, application, and outcomes are no more restrictive on MH/SUD. The Department of Labor (DOL), the Department of Health and Human Services (HHS), and state regulators all have enforcement authority; the Tri-Agency 2024 final regulations under MHPAEA significantly tightened the comparative-analysis content requirements.

The State Privacy Patchwork - CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA, TIPA

By mid-2026 the U.S. state-privacy-law patchwork includes a growing set of comprehensive statutes that overlay GLBA, HIPAA, and insurance-specific privacy rules.

California CCPA/CPRA. The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide California residents with rights to know, access, delete, correct, and opt out of sale or sharing of personal information. CCPA/CPRA includes a partial GLBA exemption for personal information collected and processed under GLBA, but the exemption does not extend to all data the insurance carrier holds - particularly behavioral, telematics, and third-party-purchased data outside the GLBA NPI definition. The California Privacy Protection Agency (CPPA) enforces CCPA/CPRA with administrative fines up to $7,500 per intentional violation.

Colorado Privacy Act (CPA). Colorado's CPA, effective 2023, provides similar rights and includes a GLBA exemption with a broader insurance-data carve-out. The CPA's enforcement is by the Colorado Attorney General; the regulation has been amended through 2024–2026 to add provisions on automated decision-making and consumer profiling.

Virginia VCDPA. The Virginia Consumer Data Protection Act, effective 2023, follows a similar framework with a GLBA exemption.

Connecticut CTDPA. The Connecticut Data Privacy Act, effective 2023, provides comparable rights and a GLBA exemption.

Utah UCPA. The Utah Consumer Privacy Act, effective late 2023, has a more limited scope but applies to large entities meeting threshold criteria.

Texas TIPA. The Texas Data Privacy and Security Act (TIPA), effective 2024, applies broadly to entities doing business in Texas and includes a GLBA exemption.

The operational implication for insurance AI: the GLBA exemption in most state privacy laws covers personal information collected and processed under GLBA, but does not necessarily cover (a) inferences derived from the AI model that go beyond GLBA NPI scope, (b) behavioral data purchased from third parties for AI model features, (c) telematics data, or (d) data collected for non-insurance purposes (marketing, lead generation, web analytics). Carriers running multi-state AI programs maintain a state-by-state matrix of which privacy obligations apply and which exempt under the GLBA carve-out.

Anti-Concurrent-Cause Analysis - When AI Photo Evidence Meets Multiple Proximate Causes

Property losses involving multiple proximate causes - wind and flood after a hurricane, faulty workmanship and resulting water damage, fire and smoke versus fire and water damage from firefighters - are governed by the Anti-Concurrent-Cause (ACC) language in the policy form. The most common ACC clauses are ISO CGL CG 00 01 (the commercial general liability coverage form) and ISO HO 00 03 (the homeowners 3 special form). The ACC clause says that an excluded cause concurrently combined with a covered cause does not produce coverage - the loss is excluded.

The intersection with AI is that property-claim AI (Tractable photo estimating, CCC photo analysis, EagleView aerial roof imagery, Snapsheet virtual inspection) produces evidence that supports or undermines the ACC analysis. An EagleView report that shows a 25-year-old roof with pre-existing wear, combined with a hailstorm photo set showing fresh impact, produces an ACC issue: how much damage is the new wind/hail (covered) versus the pre-existing wear (excluded)? The adjuster's coverage analysis under HO 00 03 has to allocate. The AI's photo evidence informs the allocation but does not decide it; the licensed adjuster's professional judgment, the policy form's exclusions, and the controlling case law in the venue state make the final call.

The L1 learner should know that ACC analysis is one of the property-claim contexts where AI evidence is most contested. Bad-faith litigation in Texas (Tex. Ins. Code §541), Florida (Fla. Stat. §624.155), and California (the Cumis/Brandt framework) has been examining AI-driven coverage decisions on ACC issues, and the trend through 2025–2026 is heightened scrutiny on adjuster reliance on AI photo evidence without documented independent verification.

How the Frameworks Interact With Each Other

The frameworks layer rather than stack. A single L&H accelerated-UW knockout decision can simultaneously invoke: NAIC bulletin §4 (the reason code), Colorado Reg 10-1-1 (the algorithm-inventory entry), NY DFS proxy test (if NY-applicable), GLBA Safeguards Rule (the NPI handling in the data feed), HIPAA Privacy Rule and BAA chain (if PHI is involved), FCRA §615 (if consumer-report data is involved - and ECDIS attributes almost always include consumer-report data), MHPAEA NQTL (if behavioral-health attributes are involved), state privacy laws (CCPA/CPRA notice and access rights, with GLBA exemption analysis), and the ASOP framework for the actuary's certification. The reason-code memo, the proxy-test memo, the FCRA adverse-action letter, the algorithm-inventory entry, and the NQTL analysis are all artifacts produced from the same underlying analysis with different framings.

What This Means for the People on the Desk

For the underwriter: every adverse action - knockout, decline, quote-with-restriction - that touches consumer-report data invokes FCRA §615. The reason code has to satisfy §4 of the NAIC bulletin and §615 of FCRA simultaneously. The data feed has to satisfy GLBA Safeguards Rule §314.4(f) vendor oversight.

For the adjuster: every coverage decision on a property loss involving multiple proximate causes invokes Anti-Concurrent-Cause analysis under HO 00 03 or CG 00 01. AI photo evidence informs the analysis but does not control it. The file note documents the AI involvement, the adjuster's independent verification, and the policy-form citation.

For the producer: agency-built chatbots that recommend products invoke producer-licensing disclosure obligations and state-specific AI-disclosure rules. The chatbot's training data subject to GLBA NPI and CCPA/CPRA personal-information obligations needs the appropriate notices.

For the actuary: every model that uses consumer-report data invokes FCRA's adverse-action-reason framework; every L&H model that touches PHI invokes HIPAA's minimum-necessary rule; every model that produces disparate impact on protected classes invokes NAIC §4, NY DFS proxy test, and Colorado SB 21-169 simultaneously. The actuarial certification under ASOP 56 must reference the applicable framework set explicitly.

Key Takeaways

  • GLBA Safeguards Rule (16 CFR §314) requires every insurance carrier, agency, MGA, and brokerage to maintain a written information security program (WISP) covering NPI. §314.4(f) vendor oversight requirements operationally merge with NAIC bulletin §4.2 third-party AI requirements - the contract addendum satisfies both.
  • HIPAA Privacy/Security/Breach Notification applies to L&H insurers as covered entities and to others as business associates. §164.502(b) minimum necessary, §164.504(e) BAA chain, and the 60-day breach-notification rule apply to every AI workflow handling PHI. Munich Re, Swiss Re Magnum, RGA AURA NEXT, SCOR Velogica all sign BAAs.
  • FCRA §615 requires an adverse-action notice when consumer-report data influences an insurance decision adversely. MIB, MVR, LexisNexis, IntelliScript, ScriptCheck, and most ECDIS attributes are FCRA-covered. The adverse-action letter must identify the principal reasons in human-reviewable language - same standard as NAIC §4 reason codes.
  • MHPAEA NQTL analysis applies when AI utilization-review tools produce disparate MH/SUD denial rates compared to medical/surgical. The 14-of-22 IOP vs. 4-of-22 medical/surgical example is the canonical trigger. The Tri-Agency 2024 final regulations significantly tightened the comparative-analysis content requirements; DOL, HHS, and state regulators enforce.
  • State privacy laws - CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA, TIPA - overlay GLBA and HIPAA. Most include a GLBA exemption, but inferences, behavioral data, telematics, and non-insurance-purpose data may fall outside the exemption. CPPA fines up to $7,500 per intentional violation; state AG enforcement in other jurisdictions.
  • Anti-Concurrent-Cause analysis under ISO CGL CG 00 01 and ISO HO 00 03 governs property losses with multiple proximate causes. AI photo evidence (Tractable, CCC, EagleView, Snapsheet) informs the ACC allocation but does not decide it; the licensed adjuster's professional judgment controls. Bad-faith litigation in TX, FL, CA scrutinizes AI reliance.
  • A single AI decision can invoke 8 frameworks simultaneously: NAIC §4, state DOI bulletin, GLBA, HIPAA, FCRA §615, MHPAEA NQTL, state privacy law, and ASOP modeling standard. The reason-code memo, proxy-test memo, FCRA letter, algorithm-inventory entry, and NQTL analysis are artifacts produced from the same underlying analysis with different framings.
  • The frameworks layer rather than stack - meaning compliance with one does not satisfy another. The insurance professional in 2026 has to know which framework attaches at which step of the AI workflow, and what artifact each requires. Confidentiality and consumer-adverse decisions are the two surfaces where the layering bites hardest.