PassSprint
State RegulationsMI specificDifficulty 3/5

An insurer plans to sell its Michigan customers' personal health information to a marketing firm without the customers' consent, arguing that the data was collected in the ordinary course of business. Under Michigan's consumer privacy regulation for insurance, the insurer's plan is:

Select an option to reveal the answer and the full 3-part explanation — free, no signup.

Answer & full 3-part explanation (select an option above, or peek)

Why C is correct

The Michigan Insurance Code's consumer privacy provisions (M.C.L. 500.501 to 500.535) and the Michigan Administrative Code rules (R 500.551 to R 500.560) restrict the disclosure of customers' personal information collected in connection with insurance transactions unless proper authorization or a recognized exception applies. Selling customers' health information to a marketing firm without consent is a prohibited disclosure, and DIFS can enforce the privacy rules against the insurer.

Why the other options are wrong

  • A) A later opt-out does not authorize a disclosure the rules prohibit; the authorization must be proper before the personal information is disclosed.
  • B) Removing names does not take the records outside protection, because other identifying details remain personal information covered by the privacy rules.
  • D) The marketing firm's licensure is irrelevant; the disclosure restrictions bind the insurer holding the data and are not cured by the recipient's license.

Memory hook

Customer data is not inventory — no sale without proper authorization.

Related Practice Questions