Privacy Law Library

Privacy of Consumer Financial and Health Information (Iowa Insurance Division rules)

Iowa Insurance Privacy Rule

Financial · Health · Data security

Iowa's insurance privacy rules, based on the NAIC model, require insurance licensees to give privacy notices, let consumers opt out of sharing financial information with nonaffiliated third parties, and obtain authorization before disclosing health information except for core insurance functions. They also require an information security program.

Where
Iowa
Citation
Iowa Admin. Code r. 191-90.1 to 191-90.40 (implementing Iowa Code 505.8(6) and GLBA Title V)
Status
In force
In force since
2000-11-13
Last amended
2024-04-24
Enforced by
Iowa Commissioner of Insurance (Iowa Insurance Division)
People can sue
No
Penalties
Violations are unfair trade practices under Iowa Code 507B.4, subject to chapter 507B penalties (191-90.25, 191-90.39).
Applies to
  • All licensees of the Iowa Insurance Division (insurers, producers, and other licensees) handling nonpublic personal financial or health information of individuals who obtain insurance products primarily for personal, family, or household purposes (191-90.1)

What a privacy notice must say

  • Provide an initial privacy notice to consumers and customers, and annual notices to customers, describing information collection and sharing practices.Iowa Admin. Code r. 191-90.3, 191-90.4, 191-90.5

Rights it gives people

  • Give consumers a reasonable opportunity to opt out before disclosing nonpublic personal financial information to nonaffiliated third parties, subject to exceptions.Iowa Admin. Code r. 191-90.6, 191-90.9

Practices it requires

  • Do not share account numbers with nonaffiliated third parties for marketing.Iowa Admin. Code r. 191-90.11
  • Obtain the individual's authorization before disclosing nonpublic personal health information, except for listed insurance functions such as claims, underwriting, and fraud detection.Iowa Admin. Code r. 191-90.17, 191-90.18

Security duties

  • Establish and implement an information security program with administrative, technical, and physical safeguards for customer information.Iowa Admin. Code r. 191-90.37, 191-90.40

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The rule text was read from the section headings and a few rules; the opt-out exceptions and delivery rules were not reviewed in detail. The information security program rules may be partly superseded for larger licensees by the Insurance Data Security Act (Iowa Code ch. 507F).

Research reference, not legal advice.