Sources of insurability and HIPAA privacy disclosures
Two questions field underwriting answers
Every application you take is really an answer to two questions the home office must settle: is this risk insurable at all, and if so, at what rate class? You are the insurer's field underwriter. Your job is to gather accurate facts about the proposed insured — and to gather them only in the ways the applicant has authorized.
Sources of insurability information
The application. This is the primary source. Personal data (age, occupation, income, other coverage, replacement) and medical history come from the applicant, and your duty is to record the answers exactly as given, then have the applicant read and sign.
The producer's report. A separate statement you send to the underwriter: how long and how well you have known the applicant, your observations about health, habits, and finances, and anything you know that the application does not show. It is your report, not the applicant's, and it is not part of the contract.
Medical and paramedical examinations. Based on age and face amount, the insurer may order a paramedical exam or a full physical, including blood, urine, and vitals.
Attending physician's statement. When the history needs clarification, the insurer asks the applicant's own physician for records. This request only moves if a valid authorization is in hand.
Member information exchange (the Medical Information Bureau). Member insurers file coded impairment information from prior applications and check it on new ones. A code is a lead for further investigation, not proof — insurers verify before acting on it.
Third-party reports. Investigative consumer or inspection reports on finances, lifestyle, and reputation; motor vehicle records for driving history; and, where authorized, prescription-history databases.
The authorization is the gatekeeper
Health information is protected. Nothing flows from a doctor, hospital, lab, pharmacy, or member exchange without a valid, written authorization signed and dated by the applicant (or a personal representative). A usable authorization is written in plain language and identifies:
- the specific information that may be disclosed;
- who is permitted to disclose it;
- who may receive it (the insurer, its reinsurers, its examiners);
- the purpose — underwriting and claim administration;
- an expiration date or event;
- the applicant's right to revoke, and how;
- the applicant's signature and date, with a copy given to the applicant.
Two habits keep you inside the lines. First, minimum necessary: request only the information underwriting actually needs, and use it only for the disclosed purpose. Second, confidentiality: protected information does not travel to family, employers, other prospects, or your own marketing files, and paper and devices holding it stay secured.
No signature, no records. An unsigned, undated, or expired authorization is not a technicality you can paper over later — it is a wall.
Also give the applicant the insurer's notice of information practices at or before the time the application is taken, and let the applicant know that if information gathered leads to a declination, a rating, or reduced benefits, the insurer will state the reasons and identify the sources on request.
Why sloppy handling becomes a market conduct problem
Misrepresenting what a form does — telling an applicant the authorization is "just the receipt," implying answers are never verified, or presigning or altering a form — is a misrepresentation and a deceptive practice, not a shortcut (Tex. Ins. Code ch. 541). And the collection, transmission, and safekeeping of this information is part of the conduct expected of a licensed life, accident, and health agent (Tex. Ins. Code ch. 4054). Clean sourcing plus a clean authorization is what makes a file both underwritable and defensible.
Sample questions
In field underwriting a life insurance risk, which source is considered the primary source of information about the proposed insured?