Oregon Administrative Rules
Section 836-080-0620 - Notice of Personal Financial Information Practices
Current through Register Vol. 63, No. 12, December 1, 2024
(1) This rule governs the notice to be given by a licensee to an individual, in fulfillment of requirements of the federal Gramm-Leach-Bliley Act (P.L. 106-102), that informs the individual about the licensee's treatment of personal financial information concerning the individual in the course of the ongoing financial relationship between the licensee and the individual, in connection with a health insurance policy. A licensee shall provide a clear and conspicuous notice of its personal financial information practices to individuals under the circumstances and at the times as follows:
(2) A licensee shall provide a clear and conspicuous notice to a customer that accurately reflects the privacy policies and practices of the licensee not less than once in any period of 12 consecutive months during which the relationship described in section (1)(a) of this rule exists. A licensee may define the period of 12 consecutive months, but the licensee must apply the period to the customer on a consistent basis.
(3) The notice required by sections (1) and (2) of this rule shall be in writing, except that the notice may be provided in electronic form if the recipient agrees. In addition to any other information the licensee wishes to provide, the notice shall include the following items of information that apply to the licensee and to the individuals to whom the licensee sends the notice:
(4) A licensee that does not disclose personal financial information about customers or former customers to affiliates or nonaffiliates except as authorized in OAR 836-080-0670 or 836-080-0675, and does not wish to reserve the right to do so may satisfy the requirements of this rule by providing a customer a notice that so states and that also includes:
(5) Before a licensee discloses personal financial information to a nonaffiliated third party other than as described in the notice required in section (1) of this rule, the licensee shall send a revised notice that accurately describes its information collection and disclosure practices. The revised notice must comply with the requirements of section (3) of this rule.
(6) For purposes of this rule and OAR 836-080-0670 and 836-080-0675, an individual is not the consumer of a licensee solely because the individual is covered under a group life or health insurance policy issued by the licensee or is a participant or beneficiary of an employee benefit plan that the licensee administers or sponsors or for which the licensee acts as a trustee, insurer or fiduciary, if:
(7) When an individual becomes a consumer of a licensee under section (6) of this rule, then this rule and OAR 836-080-0670 and 836-080-0675 apply to the licensee with respect to the individual.
Stat. Auth.: ORS 731.244 & 746.608
Stats. Implemented: ORS 746.600 & 746.607