# Federal overlays: where Washington still shapes an insurance business
A health insurer in Ohio can be state-licensed, state-rate-approved, and state-examined, and still face a federal enforcement action for a data breach. That is the reality every compliance officer navigates: insurance is regulated primarily by states, but a growing stack of federal statutes reaches directly into how carriers underwrite, invest, market, and handle data. Understanding both layers, and where they intersect, is a baseline skill for anyone working in the sector.
The reason insurance is state-regulated at all traces to the McCarran-Ferguson Act (1945). It exempted insurance from most federal antitrust and regulatory law, affirming that "the business of insurance" is best left to the states, unless a federal law specifically says otherwise.
That "unless" clause is the whole story of this lesson. Congress has repeatedly decided that certain issues (health privacy, financial stability, systemic risk, consumer credit) are too important, or too cross-border, to leave entirely to 50 different state regimes. Each time it does, a federal overlay lands on top of the state framework.
Compliance officers therefore run two checklists simultaneously: the state one (licensing, rate filings, market conduct) and the federal one (privacy, financial holding company rules, sanctions, anti-money laundering). Missing either creates real exposure.
HIPAA (Health Insurance Portability and Accountability Act, 1996) is the law most non-technical staff have heard of, usually via its Privacy Rule and Security Rule. It sets a federal floor for how health insurers, health plans, and their business partners (called "covered entities" and "business associates") handle
In practice, HIPAA compliance means:
Enforcement sits with the HHS Office for Civil Rights (OCR). Fines can run into the millions for large breaches, and OCR publishes settlement details, a useful reference is the HHS breach portal, often called "the wall of shame" by compliance teams.
The Affordable Care Act (ACA, 2010) layered federal product rules onto state-regulated health insurance markets: guaranteed issue (no denial for pre-existing conditions), essential health benefits, the Medical Loss Ratio (MLR) rule (insurers must spend a minimum share of premium, typically 80 to 85 percent depending on market segment, on medical care and quality rather than overhead), and subsidized exchanges. States still license the plans and review some rates, but the ACA's minimum standards apply nationwide regardless of state preference.
The 2008 financial crisis exposed a gap: AIG, primarily an insurer, generated systemic risk through its Financial Products division writing credit default swaps, yet no regulator was watching insurance-linked systemic exposure at a national level.
Dodd-Frank (2010) responded in two insurance-relevant ways:
1. It created the Federal Insurance Office (FIO) inside the Treasury Department. FIO has no direct regulatory or enforcement power over individual insurers, but it monitors the industry, represents the US in international insurance discussions (notably with the International Association of Insurance Supervisors, IAIS), and can recommend that a nonbank financial company, including an insurer, be designated systemically important.
2. It empowered the Financial Stability Oversight Council (FSOC) to designate Systemically Important Financial Institutions (SIFIs), subjecting them to Federal Reserve supervision. AIG itself was designated for a period after the crisis before later being de-designated as it shrank and restructured.
This is the clearest case of "federal overlay": a state-licensed insurer that becomes large and interconnected enough can end up under a federal banking-style regulator's supervision, on top of its state insurance regulators.
Several other federal statutes rarely make headlines but shape daily compliance work:
None of these displace state insurance codes, they sit alongside them, and a violation of any one can trigger federal, not state, enforcement.
It is worth being precise about the boundary. States, coordinated informally through the National Association of Insurance Commissioners (NAIC), still control:
Federal law generally does not replace this; it adds specific, targeted requirements on top, usually where interstate commerce, financial stability, or nationally-defined consumer protections are at stake. The McCarran-Ferguson exemption remains intact for most day-to-day underwriting and pricing decisions.
🎬 [VIDEO: "How Insurance Is Regulated in the US" - youtube.com - search for NAIC or Federal Reserve explainer content on the state-federal insurance regulatory split, useful as a visual companion to this lesson]
Knowledge check
1. What is the core mechanism established by the McCarran-Ferguson Act that explains why insurance is primarily state-regulated?
2. A health insurer is fully compliant with its state insurance department's licensing and market conduct rules. Why might it still face a federal enforcement action?
3. Why does the lesson describe certain issues (health privacy, systemic risk, financial stability) as reasons Congress imposes federal overlays rather than leaving them to the states?
4. Select ALL correct answers about the relationship between state and federal insurance regulation described in the lesson.
Select all the correct answers.
5. Select ALL correct answers about HIPAA's role as a federal overlay on health insurance.
Select all the correct answers.
Consider a mid-size life insurer designing a new universal life product with a cash accumulation feature. The compliance checklist spans both layers:
This layering is precisely why insurance compliance teams are structured with both state regulatory affairs staff and federal/enterprise compliance staff, often reporting through different lines, but required to sign off jointly on new products.