Insurance Information and Privacy Protection Act
MT Insurance Privacy Act
Financial · Health · Breach notification · Data security
Montana's version of the NAIC insurance privacy model law governs how insurers, producers and insurance-support organizations collect, use and disclose personal and health information. It gives individuals notice, access, correction and adverse-decision explanation rights, limits disclosure and marketing use, and contains an insurance-specific data breach notification and security policy requirement.
- Where
- Montana
- Citation
- Mont. Code Ann. Title 33, ch. 19 (33-19-101 to 33-19-409)
- Status
- In force
- Enforced by
- Montana Commissioner of Securities and Insurance (State Auditor)
- People can sue
- Limited
- Penalties
- Civil penalty under 33-1-317 (33-19-405); individuals may seek equitable relief for access, correction and adverse-decision violations and damages for unlawful disclosures under 33-19-306/307, with costs and fees and a 2-year limit (33-19-407); obtaining information under false pretenses is punishable by up to $10,000 and 1 year (33-19-409).
- Applies to
- Insurance institutions, insurance producers and insurance-support organizations (licensees) collecting personal information in connection with insurance transactions (33-19-103)
- Persons receiving personal information to perform an insurance function, for breach notice to the licensee (33-19-321(2))
- Title 33 entities are excluded from the general breach law (30-14-1702(1)(b)) and follow 33-19-321 instead
What a privacy notice must say
- Give reasons for adverse underwriting decisions.Mont. Code Ann. 33-19-303
- Provide a clear and conspicuous notice of information practices reflecting the licensee's privacy policies to individuals whose information is collected and disclosed.Mont. Code Ann. 33-19-202
Rights it gives people
- Individuals may access recorded personal information on written request and request its correction, amendment or deletion (response within 30 business days).Mont. Code Ann. 33-19-301, 33-19-302
Practices it requires
- Do not disclose personal or privileged information except as permitted, and do not use or disclose personal information for marketing except as permitted.Mont. Code Ann. 33-19-306, 33-19-307
- Do not use pretext interviews to obtain information in connection with an insurance transaction (limited claim-investigation exception).Mont. Code Ann. 33-19-201
Security duties
- Develop and maintain an information security policy for safeguarding personal information and breach notice procedures.Mont. Code Ann. 33-19-321(4)
Breach duties
- Notify affected individuals of a breach of unencrypted personal information, and simultaneously file a copy of the notice with the insurance commissioner; vendors must notify the licensee immediately.Mont. Code Ann. 33-19-321(1)-(2), (5)
Sources
- Official text
- Mont. Code Ann. Title 33, ch. 19, parts 1-4 (Montana Legislature, MCA 2025)
- Mont. Code Ann. 33-19-321 (insurance breach notice)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Enacted by Ch. 580, L. 1981 with obligations applying from July 1, 1982 (33-19-103); exact original effective date and the latest amendment date across the chapter were not determined. The breach section 33-19-321 was enacted in 2005 and last amended by Ch. 62, L. 2015. | 33-19-105 HIPAA-compliance exemption and 33-1-317 penalty amounts not summarised.
Research reference, not legal advice.