Privacy Law Library

Insurance Information and Privacy Protection Act

MT Insurance Privacy Act

Financial · Health · Breach notification · Data security

Montana's version of the NAIC insurance privacy model law governs how insurers, producers and insurance-support organizations collect, use and disclose personal and health information. It gives individuals notice, access, correction and adverse-decision explanation rights, limits disclosure and marketing use, and contains an insurance-specific data breach notification and security policy requirement.

Where
Montana
Citation
Mont. Code Ann. Title 33, ch. 19 (33-19-101 to 33-19-409)
Status
In force
Enforced by
Montana Commissioner of Securities and Insurance (State Auditor)
People can sue
Limited
Penalties
Civil penalty under 33-1-317 (33-19-405); individuals may seek equitable relief for access, correction and adverse-decision violations and damages for unlawful disclosures under 33-19-306/307, with costs and fees and a 2-year limit (33-19-407); obtaining information under false pretenses is punishable by up to $10,000 and 1 year (33-19-409).
Applies to
  • Insurance institutions, insurance producers and insurance-support organizations (licensees) collecting personal information in connection with insurance transactions (33-19-103)
  • Persons receiving personal information to perform an insurance function, for breach notice to the licensee (33-19-321(2))
  • Title 33 entities are excluded from the general breach law (30-14-1702(1)(b)) and follow 33-19-321 instead

What a privacy notice must say

  • Give reasons for adverse underwriting decisions.Mont. Code Ann. 33-19-303
  • Provide a clear and conspicuous notice of information practices reflecting the licensee's privacy policies to individuals whose information is collected and disclosed.Mont. Code Ann. 33-19-202

Rights it gives people

  • Individuals may access recorded personal information on written request and request its correction, amendment or deletion (response within 30 business days).Mont. Code Ann. 33-19-301, 33-19-302

Practices it requires

  • Do not disclose personal or privileged information except as permitted, and do not use or disclose personal information for marketing except as permitted.Mont. Code Ann. 33-19-306, 33-19-307
  • Do not use pretext interviews to obtain information in connection with an insurance transaction (limited claim-investigation exception).Mont. Code Ann. 33-19-201

Security duties

  • Develop and maintain an information security policy for safeguarding personal information and breach notice procedures.Mont. Code Ann. 33-19-321(4)

Breach duties

  • Notify affected individuals of a breach of unencrypted personal information, and simultaneously file a copy of the notice with the insurance commissioner; vendors must notify the licensee immediately.Mont. Code Ann. 33-19-321(1)-(2), (5)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Enacted by Ch. 580, L. 1981 with obligations applying from July 1, 1982 (33-19-103); exact original effective date and the latest amendment date across the chapter were not determined. The breach section 33-19-321 was enacted in 2005 and last amended by Ch. 62, L. 2015. | 33-19-105 HIPAA-compliance exemption and 33-1-317 penalty amounts not summarised.

Research reference, not legal advice.