Insurance

A claims file is two regulated data sets in one document.

Medical history, policyholder financials and identity, sitting in the same PDF and pasted into the same chat window. Itzal detects both on the device, before submission, and the text never reaches our servers.

HIPAA GLBA ONE DOCUMENT, TWO FRAMEWORKS
Built for Health insurers P&C carriers Life and annuity Brokers and MGAs Claims administrators

The threat

Underwriting and claims are paste-heavy by nature.

Every path below is somebody assessing a risk or settling a claim. The document they are working from is the document that carries the regulated data, which is why a policy banning AI moves the work rather than stopping it.

  1. Summarising a claims file

    The medical narrative is the claim. Summarising it means pasting it.

    Trips HIPAA

  2. Drafting a denial or appeal letter

    The justification has to cite the record, so the record gets pasted alongside it.

    Trips HIPAA

  3. Assessing an underwriting risk

    Financial and health data arrive together, and both go into the question.

    Trips GLBA

  4. Rewriting policyholder correspondence

    A letter is made clearer by pasting the letter, and the letter names the policyholder.

    Trips GLBA

A HIPAA finding needs an identifier and health context together; a GLBA finding needs one and financial context. A claims file routinely satisfies both at once, which is the thing that makes insurance different from either industry it borrows from.

How the detection layers work

What’s specific here

Two frameworks, one document.

Most DLP configuration assumes a document belongs to one regime. A claims file does not, and the consequences of getting that wrong run in both directions.

  1. 01

    Health data outside a hospital

    HIPAA follows the data, not the building. A carrier handling claims is a covered entity or a business associate, and the clinical detail in a claims file is PHI wherever it is read.

  2. 02

    Financial and health context in one paste

    The same paragraph can trip HIPAA on the diagnosis and GLBA on the account number. Both frameworks carry their own action and their own retention, and the finding says which fired.

  3. 03

    Volume arrives as attachments

    Nobody retypes a claims export. It is dropped in whole, which is why reading files on the device matters more here than in most sectors.

  4. 04

    Third-party administrators widen the surface

    Work moves between carrier, TPA and broker, on devices with different owners. Coverage is reported per device, so an unenrolled partner shows as uncovered rather than as compliant.

Where the other tools stop

What it does here

Someone pastes a claims note. Itzal stops it.

Banning AI does not work — the work moves to a personal phone and you lose sight of it entirely. Itzal sits on the laptop, watches the box people type into, and checks the text in the instant before it is sent.

The member ID is a pattern. The diagnosis beside it is what makes the whole span PHI. Your team gets a record saying what kind of value it was; the message itself never goes anywhere.

Illustration. The data shown is invented.

A claims handler pastes a claims note into an AI chat tool. Itzal checks the text on their own laptop, finds a name, a member ID and a diagnosis, masks all three, blocks the send, and reports an event that contains no readable health or policyholder data.
How it works, end to end

Rollout

Two frameworks means two tuning passes, not one.

A claims desk trips HIPAA and GLBA from the same paste, and the two have different actions and different retention. Tuning them together is what stops the second one arriving as a surprise in month three.

  1. 00

    Confirm covered-entity status

    Whether the carrier is a covered entity or a business associate decides whether HIPAA defaults to block or to warn. It is a legal answer, and it comes before any endpoint is touched.

    Before the clockPrerequisite
  2. 01

    Log-only pilot, one claims desk

    Nothing is warned or blocked. The measurement is false positives against real claims language — which is dense with dates, numbers and clinical terms.

    2–4 weeksLog only
  3. 02

    Tune both context lists

    Health context terms and financial context terms are separate admin-editable lists. A claims file needs both, and exception lists for the test member IDs in every training environment.

    1–2 weeksLog only
  4. 03

    Warn

    Watch the dismissal rate per framework, not in aggregate. A high click-through on GLBA and a low one on HIPAA is a tuning problem in one list, and averaging them hides it.

    2–4 weeksWarn
  5. 04

    Block, high-confidence only

    Enforcement starts on the findings whose precision has been measured. The two frameworks can carry different actions, and usually should.

    OngoingBlock

If every phase runs to its minimum How far it slides if they all run long

The full deployment guide

Straight answers

Does a claims file trip HIPAA or GLBA?

Often both, and the finding says which. HIPAA fires when an identifier co-occurs with health context; GLBA fires when one co-occurs with financial context. A claims file routinely carries both, so a single paste can produce findings under two frameworks with two different configured actions.

Can we block on claims data without stopping legitimate work?

Start log-only on one desk and measure the false-positive rate against real claims language before enabling anything. Member ID formats are carrier-specific, so they are usually a custom pattern rule rather than a built-in detector — and pattern rules can block inside the deadline.

What about the medical records we receive as scanned faxes?

A scanned page has no text layer, so it needs OCR. Fax-encoded (CCITT) and JPEG 2000 pages are refused rather than guessed at, and reported unscanned rather than recorded as clean.

More questions, answered

Bring a claims file you actually worry about.

A working demo on your own data, on a laptop you trust. The useful conversation is about the documents that carry two regimes at once.