The duty you carry
An insurance file concentrates what privacy law protects most: identity, health, finances, and loss, often all in one claim. Adjusters summarizing a bodily-injury file or underwriters pricing a risk are handling medical and financial detail under PIPEDA and provincial insurance law, and conduct regulators have been explicit that fair treatment and governance expectations extend to how insurers use AI. A policyholder's file pasted into a personal chatbot is a privacy breach with a claim number attached.
The moment it breaks
Synthetic example. The real version happens on your busiest day.
The summary still lands. The policyholder, the policy number, and the medical detail stay inside — logged as evidence of governance.
Caught, in your vocabulary
Policyholder identities
Names, addresses, and contact details across claims, policies, and correspondence.
Medical and health details
Injury descriptions, treatment notes, and reports — the most sensitive class of personal information.
Policy, claim, and payment numbers
The identifiers that tie a prompt to a real file and a real payout.
The rules you answer to
PIPEDA and health privacy
Claims routinely contain health information, which carries the strictest safeguard and breach-notification expectations.
Fair treatment of customers
Conduct guidance from insurance regulators extends governance expectations to AI used in claims and underwriting.
Breach notification duties
A caught paste is a non-event. An uncaught one may be a notifiable breach with a paper trail that starts at a chatbot.
From our research
Answering the Client AI-Security Questionnaire: What Outside Counsel Needs to Show
Clients now send law firms AI-security questionnaires before handing over sensitive matters. The ones asking how you protect their data in AI tools want evidence, not assurances. Here's what a credible answer looks like.
The Opt-Out Illusion: Why Turning Off AI Training Doesn't Make Your Data Safe
Turning off AI training doesn't mean your data is safe. Understand why 'don't train on our data' is a narrow promise, and why you need upstream controls to prevent data leaks.
Why Banning ChatGPT Doesn't Work, and What Actually Reduces Shadow AI Risk
Blocking ChatGPT at the firewall feels decisive, but it just pushes AI use onto personal phones and accounts you can't see. Here's why bans backfire and what reduces Shadow AI risk instead.
Compliance standards that apply
Also built for
See it on your own scenarios
Twenty minutes, your examples, no slideware. Or start with the five-question readiness check. No email required.