Leaders Insights
Leaders Insights

Rester au meilleur niveau, un peu chaque jour.

DomainesMarketingDataFinanceIA
RessourcesApprendreTestOutilsBlogGlossaire
© 2026 Leaders Insights — Tous droits réservés.
Formations/Insurance: how the sector works/Regulation, major laws and compliance/Federal overlays: where Washington still shapes an insurance business
5/5+150 XP

Regulation, major laws and compliance

5Why insurance is regulated state by state, not federally+1506Solvency rules that decide if an insurer can pay claims+1507The laws that dictate what an insurer can charge and deny+1508Claims handling rules that turn a slow payout into a lawsuit+1509Federal overlays: where Washington still shapes an insurance business+150

Federal overlays: where Washington still shapes an insurance business

# Federal overlays: where Washington still shapes an insurance business

A health insurer in Ohio can be state-licensed, state-rate-approved, and state-examined, and still face a federal enforcement action for a data breach. That is the reality every compliance officer navigates: insurance is regulated primarily by states, but a growing stack of federal statutes reaches directly into how carriers underwrite, invest, market, and handle data. Understanding both layers, and where they intersect, is a baseline skill for anyone working in the sector.

The starting point: McCarran-Ferguson

The reason insurance is state-regulated at all traces to the McCarran-Ferguson Act (1945). It exempted insurance from most federal antitrust and regulatory law, affirming that "the business of insurance" is best left to the states, unless a federal law specifically says otherwise.

That "unless" clause is the whole story of this lesson. Congress has repeatedly decided that certain issues (health privacy, financial stability, systemic risk, consumer credit) are too important, or too cross-border, to leave entirely to 50 different state regimes. Each time it does, a federal overlay lands on top of the state framework.

Compliance officers therefore run two checklists simultaneously: the state one (licensing, rate filings, market conduct) and the federal one (privacy, financial holding company rules, sanctions, anti-money laundering). Missing either creates real exposure.

Health insurance: HIPAAHIPAA and the ACA

Health Insurance Portability and Accountability Act, loi américaine imposant la protection des données de santé (PHI). Violations : amendes jusqu'à 1,9M$ par catégorie de violation.

HIPAA (Health Insurance Portability and Accountability Act, 1996) is the law most non-technical staff have heard of, usually via its Privacy Rule and Security Rule. It sets a federal floor for how health insurers, health plans, and their business partners (called "covered entities" and "business associates") handle protected health information (PHI): names linked to health conditions, treatment, or payment data.

In practice, HIPAAHIPAAHealth Insurance Portability and Accountability Act, loi américaine imposant la protection des données de santé (PHI). Violations : amendes jusqu'à 1,9M$ par catégorie de violation. compliance means:

  • Access controls and encryption standards for systems holding PHI.
  • Breach notification obligations (affected individuals, HHS, sometimes media, within defined timeframes).
  • Business associate agreements with vendors (claims administrators, cloud hosts, analytics firms) that touch PHI.

Enforcement sits with the HHS Office for Civil Rights (OCR). Fines can run into the millions for large breaches, and OCR publishes settlement details, a useful reference is the HHS breach portal, often called "the wall of shame" by compliance teams.

The Affordable Care Act (ACA, 2010) layered federal product rules onto state-regulated health insurance markets: guaranteed issue (no denial for pre-existing conditions), essential health benefits, the Medical Loss Ratio (MLR) rule (insurers must spend a minimum share of premium, typically 80 to 85 percent depending on market segment, on medical care and quality rather than overhead), and subsidized exchanges. States still license the plans and review some rates, but the ACA's minimum standards apply nationwide regardless of state preference.

Systemic risk: Dodd-Frank and FIO

The 2008 financial crisis exposed a gap: AIG, primarily an insurer, generated systemic risk through its Financial Products division writing credit default swaps, yet no regulator was watching insurance-linked systemic exposure at a national level.

Dodd-Frank (2010) responded in two insurance-relevant ways:

1. It created the Federal Insurance Office (FIO) inside the Treasury Department. FIO has no direct regulatory or enforcement power over individual insurers, but it monitors the industry, represents the US in international insurance discussions (notably with the International Association of Insurance Supervisors, IAIS), and can recommend that a nonbank financial company, including an insurer, be designated systemically important.

2. It empowered the Financial Stability Oversight Council (FSOC) to designate Systemically Important Financial Institutions (SIFIs), subjecting them to Federal Reserve supervision. AIG itself was designated for a period after the crisis before later being de-designated as it shrank and restructured.

This is the clearest case of "federal overlay": a state-licensed insurer that becomes large and interconnected enough can end up under a federal banking-style regulator's supervision, on top of its state insurance regulators.

Data, marketing, and money movement: the quieter federal layer

Several other federal statutes rarely make headlines but shape daily compliance work:

  • Gramm-Leach-Bliley Act (GLBA, 1999): requires financial institutions, including insurers, to disclose privacy practices and safeguard nonpublic personal financial information. It also set up the framework letting insurance, banking, and securities affiliate under one holding company, which is why you see integrated financial groups selling insurance, banking, and investment products.
  • Fair Credit Reporting Act (FCRA): governs use of credit-based insurance scores in underwriting auto and home policies, requiring adverse action notices when a score affects pricing.
  • Bank Secrecy Act (BSA) and associated anti-money laundering (AML) rules enforced by FinCEN: apply to certain insurance products, particularly permanent life insurance and annuities with cash value, which can be used to move large sums.
  • OFAC (Office of Foreign Assets Control) sanctions screening: every insurer must check policyholders and beneficiaries against sanctions lists regardless of which state licensed the policy.

None of these displace state insurance codes, they sit alongside them, and a violation of any one can trigger federal, not state, enforcement.

Where NAIC and states still lead

It is worth being precise about the boundary. States, coordinated informally through the National Association of Insurance Commissioners (NAIC), still control:

  • Licensing of insurers and producers (agents/brokers).
  • Rate and form approval (what a policy can charge and what it must say).
  • Solvency regulation: risk-based capital (RBC) requirements, financial examinations, guaranty funds that pay claims if an insurer becomes insolvent.
  • Market conduct exams (how claims are handled, how policies are sold).

Federal law generally does not replace this; it adds specific, targeted requirements on top, usually where interstate commerce, financial stability, or nationally-defined consumer protections are at stake. The McCarran-Ferguson exemption remains intact for most day-to-day underwriting and pricing decisions.

🎬 [VIDEO: "How Insurance Is Regulated in the US" — youtube.com — search for NAIC or Federal Reserve explainer content on the state-federal insurance regulatory split, useful as a visual companion to this lesson]

Vérification des acquis

1. What is the core mechanism established by the McCarran-Ferguson Act that explains why insurance is primarily state-regulated?

2. A health insurer is fully compliant with its state insurance department's licensing and market conduct rules. Why might it still face a federal enforcement action?

3. Why does the lesson describe certain issues (health privacy, systemic risk, financial stability) as reasons Congress imposes federal overlays rather than leaving them to the states?

CHOIX MULTIPLES

4. Select ALL correct answers about the relationship between state and federal insurance regulation described in the lesson.

Sélectionnez toutes les réponses correctes.

CHOIX MULTIPLES

5. Select ALL correct answers about HIPAA's role as a federal overlay on health insurance.

Sélectionnez toutes les réponses correctes.

A practical example: launching a new life insurance product with cash value

Consider a mid-size life insurer designing a new universal life product with a cash accumulation feature. The compliance checklist spans both layers:

  • State: file the policy form and rates in every state where it will be sold; confirm producer licensing; ensure compliance with the state's version of NAIC's suitability-in-annuity-transactions model, if applicable.
  • Federal: implement AML/BSA customer due diligence given the cash value feature; ensure GLBA privacy notices are issued at policy issuance; if the product is marketed with investment-like features, check whether SEC registration requirements apply (this is why variable products, unlike traditional whole life, often require securities registration and broker-dealer involvement, an overlay from the Securities Act and Investment Company Act, enforced by the SEC, not a state insurance department).

This layering is precisely why insurance compliance teams are structured with both state regulatory affairs staff and federal/enterprise compliance staff, often reporting through different lines, but required to sign off jointly on new products.

Key Takeaways

  • Insurance regulation starts from a state-based default (McCarran-Ferguson, 1945), but federal statutes carve out specific, mandatory overlays wherever Congress decides state-by-state regulation is insufficient.
  • HIPAAHIPAAHealth Insurance Portability and Accountability Act, loi américaine imposant la protection des données de santé (PHI). Violations : amendes jusqu'à 1,9M$ par catégorie de violation. and the ACA impose federal privacy and product-design standards on health insurers regardless of state; enforcement runs through HHS/OCR, not state insurance departments.
  • Dodd-Frank created the Federal Insurance Office and gave FSOC power to designate systemically important insurers, pulling large, interconnected carriers (like AIG historically) under Federal Reserve-style supervision.
  • Quieter federal layers, GLBA privacy rules, FCRA credit-score disclosures, BSA/AML and OFAC sanctions screening, apply to insurers alongside state law and are common sources of enforcement actions.
  • Effective compliance functions track state filings (licensing, rates, forms, solvency) and federal obligations (privacy, AML, systemic risk designation, securities law where products are investment-like) as two parallel, mandatory tracks, not substitutes for each other.

Précédent

Claims handling rules that turn a slow payout into a lawsuit