Back to Home

Solutions · Insurance

Faster claims. Policyholder data that stays home.

Claims notes, medical reports, underwriting files — the paperwork-heaviest jobs reach for AI first. What matters is what rides along in the prompt, and whether you can show it never left.

The duty you carry

An insurance file concentrates what privacy law protects most: identity, health, finances, and loss, often all in one claim. Adjusters summarizing a bodily-injury file or underwriters pricing a risk are handling medical and financial detail under PIPEDA and provincial insurance law, and conduct regulators have been explicit that fair treatment and governance expectations extend to how insurers use AI. A policyholder's file pasted into a personal chatbot is a privacy breach with a claim number attached.

The moment it breaks

Synthetic example. The real version happens on your busiest day.

TypedSummarize this claim: Priya Sharma, policy AP-2210-4471, soft-tissue injury per the attached orthopedic report, claimant requesting $42,000.
SentSummarize this claim: [NAME], policy [POLICY], soft-tissue injury per the [MEDICAL], claimant requesting $42,000.

The summary still lands. The policyholder, the policy number, and the medical detail stay inside — logged as evidence of governance.

Caught, in your vocabulary

Policyholder identities

Names, addresses, and contact details across claims, policies, and correspondence.

Medical and health details

Injury descriptions, treatment notes, and reports — the most sensitive class of personal information.

Policy, claim, and payment numbers

The identifiers that tie a prompt to a real file and a real payout.

The rules you answer to

01

PIPEDA and health privacy

Claims routinely contain health information, which carries the strictest safeguard and breach-notification expectations.

02

Fair treatment of customers

Conduct guidance from insurance regulators extends governance expectations to AI used in claims and underwriting.

03

Breach notification duties

A caught paste is a non-event. An uncaught one may be a notifiable breach with a paper trail that starts at a chatbot.

Also relevant: Quebec Law 25 · CCPA/CPRA · NIST AI RMF

Answers for your situation

All guides

What the rules say

Credit unions, wealth managers, and MGAs: do OSFI B-10 and B-13 apply to employee AI use?

OSFI Guidelines B-10 and B-13 bind federally regulated financial institutions, so most provincially regulated credit unions, wealth managers, and MGAs are not directly subject to them. They still tend to reach you through the federally regulated insurers, banks, and trust companies you work with, and through provincial guidance built on the same expectations. Either way, the practical test is the same: can you show that client and member data does not leave in an employee's AI prompt?

Read the guide

Governance in practice

Our cyber insurance renewal is asking about AI controls: how do we answer?

Answer only what you can support with evidence. Renewal applications increasingly ask whether you know which AI tools staff use, whether a written AI policy exists, whether technical controls stop sensitive data from reaching those tools, and whether staff are trained. Gather the inventory, policy, training records, and control records before you fill in the form, and ask your broker how the insurer treats answers you cannot fully support.

Read the guide

Specific work and data

Can contact centre agents use AI to draft replies that contain customer personal information?

Agents can use AI to improve tone and structure, but customer identifiers, account numbers, card data and health or claim details should not go into a public AI tool. The organization remains accountable for customer information it hands to any third party, and a personal AI account comes with no contract that protects it. The practical answer is to keep AI in the workflow while removing personal information before a prompt is submitted.

Read the guide

From our research