Skip to main content
Insurance

Policyholder Data Stays on Your
Organization's Machines.

Claims adjusters, underwriters, and service agents are using ChatGPT, Claude, and Copilot every day — pasting medical records, SSNs, financial histories, and claims data into prompts. Shield sits on your organization's machines and stops policyholder data from ever reaching an external AI model. No cloud. No vendor access. Just a local proxy that redacts sensitive data before it leaves your network.

Talk to Our TeamSee Data Redaction in Action
Quick Answer

Shield for Insurance is a local desktop application that stops policyholder data — medical records, SSNs, financial details, claims information, and payment data — from ever leaving your organization's computers before that data reaches ChatGPT, Claude, Copilot, or any AI model. It runs on your existing machines, requires no cloud infrastructure, and helps insurers meet HIPAA, GLBA, NAIC AI Principles, and state data security requirements without changing how claims adjusters, underwriters, and service agents use AI tools.

88%
of auto insurers use or plan to use AI

The NAIC's survey of 193 private passenger auto insurers found that 88% report using, planning to use, or planning to explore AI and machine learning models in their operations. For home insurers (194 surveyed), the figure was 70%, and for health insurers (93 surveyed), 92% reported AI/ML use. Insurance companies are among the most AI-forward industries — yet only 7% have successfully scaled AI systems beyond pilots, according to BCG's 2024 global study.

Source: NAIC AI/ML insurer surveys (2022–2025); BCG Build for the Future 2024
Multiple
Regulatory frameworks govern insurance data

Insurance carriers operate under a complex regulatory web: HIPAA (health data), GLBA (financial privacy), state insurance data security laws (based on the NAIC model), GDPR (EU policyholders), CCPA (California residents), PCI DSS (payment data), and SOC 2 (vendor assurance). The NAIC Model Bulletin on AI (adopted December 2023) adds specific AI governance requirements. A single prompt sent to an external AI model can expose data subject to several of these frameworks simultaneously.

Multiple statutes — HIPAA, GLBA, NAIC model laws, GDPR, CCPA, PCI DSS
Zero
Policyholder data leaves your network

Shield runs locally on your insurance organization's machines — no cloud processing, no vendor data access. Policyholder PII, medical records, financial details, and proprietary actuarial data never reach external AI providers. The redaction mapping stays on your machine, inside your organization's network boundary.

Shield operates within your network boundary

Insurance teams handle the broadest range of sensitive data in any industry — and they're using AI

When a claims adjuster pastes a claimant's medical records into an AI prompt, or an underwriter shares an applicant's full financial and health history, that data leaves your organization's controlled environment. A single AI prompt can contain data subject to HIPAA, GLBA, state insurance regulations, GDPR, and PCI DSS — simultaneously. Shield eliminates this vector: sensitive policyholder information never leaves your network, so it never creates a compliance exposure across any of these frameworks.

Interactive Demo

What Insurance Data Looks Like in AI Prompts

Three real-world scenarios where insurance professionals send sensitive data to AI models. Click each tab to see the raw prompt with identifiable information — and how Shield redacts it before it leaves your network.

Claims Adjuster Using AI to Summarize a Bodily Injury Claim
Before Shield
Summarize this BI claim for settlement authority review. Claimant: Robert Chen, DOB 03/14/1979, SSN 521-88-3047. Claim #CL-2026-08421. Date of loss: January 12, 2026. Injuries: C5-C6 herniated disc with radiculopathy (confirmed MRI Jan 18), post-concussion syndrome. Treating physician: Dr. Sarah Okonkwo, NPI 1528049763, Orthopedic Spine Center, 415-555-0188. Medical bills to date: $87,342.18 (hospital $52,100; PT $18,400; diagnostics $16,842.18). Lost wages claimed: $63,500 (construction foreman, $4,230/week). Current demand: $285,000. Insured policy limits: $250,000/$500,000. Liability: adverse — insured ran red light per police report #SF-2026-001294. Reserves set: $210,000. Prior settlement discussions: Plaintiff attorney James Morrison (Bar #287614, Morrison & Wells LLP, 510-555-0122) rejected $165,000 on March 3.
After Shield
Summarize this BI claim for settlement authority review. Claimant: [CLAIMANT_NAME], DOB [DATE], SSN [SSN]. Claim #[CLAIM_NUMBER]. Date of loss: [DATE]. Injuries: [MEDICAL_CONDITION], [MEDICAL_CONDITION]. Treating physician: [PROVIDER_NAME], NPI [NPI], [FACILITY], [PHONE]. Medical bills to date: [AMOUNT] (hospital [AMOUNT]; PT [AMOUNT]; diagnostics [AMOUNT]). Lost wages claimed: [AMOUNT] ([OCCUPATION], [AMOUNT]/week). Current demand: [AMOUNT]. Insured policy limits: [AMOUNT]/[AMOUNT]. Liability: [LIABILITY_ASSESSMENT]. Reserves set: [AMOUNT]. Prior settlement discussions: Plaintiff attorney [ATTORNEY_NAME] (Bar #[BAR_NUMBER], [FIRM], [PHONE]) rejected [AMOUNT] on [DATE].
Detected (12 matches)
PII — NameRobert Chen
PII — Date03/14/1979
PII — SSN521-88-3047
PII — IDCL-2026-08421
PHI — MedicalC5-C6 herniated disc
PHI — ProviderDr. Sarah Okonkwo
PII — ID1528049763
PII — Phone415-555-0188
Financial$87,342.18
Financial$285,000
PII — NameJames Morrison
PII — ID287614

Compliance

How Shield Maps to Insurance Regulatory Frameworks

Insurance carriers operate under an overlapping set of federal, state, and international data protection regulations. Shield's local proxy architecture provides a single technical control that supports compliance across HIPAA, GLBA, NAIC AI Principles, GDPR, CCPA, PCI DSS, and SOC 2 — without adding cloud dependencies to your data governance scope.

FrameworkScopeKey RequirementHow Shield Helps
HIPAAHealth insurers, P&C claims with medical records, life underwritingProtect PHI — medical records, diagnoses, provider details. Breach notification requirements for unauthorized disclosures. Penalties up to $1.5M/year per violation category.Redacts PHI — diagnoses, NPI numbers, procedure codes, medication lists — before prompts reach external AI. PHI never leaves the covered entity's control. Audit logs document every redaction for compliance evidence.
GLBAAll insurance companies handling nonpublic personal information (NPI)Financial institutions must protect customer NPI — names, SSNs, account numbers, medical information. The Safeguards Rule requires technical controls. Penalties up to $100,000 per violation.Redacts NPI before it reaches external AI systems. Reduces data exposure surface for GLBA-regulated information. Provides technical safeguard documentation for compliance assessments.
NAIC AI PrinciplesAll insurers using AI — underwriting, pricing, claims, marketingModel Bulletin (Dec 2023) establishes expectations: fairness, accountability, transparency, safety. AI Systems Evaluation Tool (piloting 2026) will assess governance and risk mitigation.Supports consumer protection principle by preventing unauthorized data disclosure through AI channels. Tamper-evident audit logs provide documentation for AI Systems Evaluation Tool assessments.
GDPREU/EEA policyholder data processed by any insurer globallyData minimization, purpose limitation, security of processing. Cross-border transfer restrictions. Fines up to €20M or 4% of global annual turnover.Implements data minimization by default — policyholder PII is redacted before it reaches non-EU AI providers. Supports GDPR's 'data protection by design and by default' requirement.
CCPA / CPRACalifornia resident policyholders and claimantsRight to know, delete, opt-out of sale/sharing. Sensitive personal information (SSN, precise geolocation, health data) requires enhanced protection.Prevents sensitive PI (SSNs, health data, geolocation) from being shared with AI providers — which could constitute a 'sale' or 'sharing' under CCPA. Reduces exposure for CCPA compliance.
PCI DSSPayment card data in premium payments and claims settlementsProtect cardholder data — PAN, expiry, CVV. Never store sensitive authentication data. Maintain secure systems and access controls.Detects and redacts payment card numbers (PAN), expiry dates, and bank account details before they reach external AI systems. Prevents accidental cardholder data exposure in AI prompts.
SOC 2Insurers providing services to enterprise clients — vendor assuranceTrust Services Criteria: Security, Availability, Confidentiality. Independent auditor assessment of controls protecting customer data.Redaction audit trails provide evidence of confidentiality controls. Demonstrates technical measures to protect client data from unauthorized AI exposure — supporting SOC 2 attestation.

Architecture

Policyholder Data Never Leaves Your Insurance Network

Shield runs as a local proxy on your organization's machines. When a claims adjuster, underwriter, or service agent sends a prompt to an AI model, Shield intercepts it — redacts all policyholder PII, PHI, financial data, and protected records — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine, inside your organization's network boundary.

🏢 InsurerClaims / UW / Serviceprompt + PII / PHI🛡️ ShieldLocal Redaction ProxySSNs → [SSN] · PHI → [DIAGNOSIS]clean prompt only🤖 AI ProviderChatGPT / Claude / etc.AI responserehydrate locallyresponse with data restoredYour Insurance NetworkExternal Internet

Local Installation

Install Shield on any Mac, Windows, or Linux machine. No cloud infrastructure, no vendor data access, no policyholder data leaves your network.

One Environment Variable

Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools — Guidewire, Duck Creek, or any core system.

Full Audit Trail

Every redaction event is logged with a cryptographic hash. Prove to regulators, auditors, and state insurance departments exactly what data was caught and when — with tamper-evident integrity.

Configurable Policies

Choose which data categories to redact — PII, PHI, PCI, financial. Add custom patterns for your claim numbering schemes and producer codes. Run in audit-only mode to validate coverage first.

FAQ

Common Questions

Shield operates at the API layer — it sits between your AI client and the LLM provider, not inside any specific policy administration or claims system. This means it works with Guidewire, Duck Creek, Majesco, and any other core system — with zero integration work. As long as the AI request flows through Shield's local proxy, policyholder data is caught before it leaves your network, regardless of which system the employee copied it from.
Health insurers and any carrier processing PHI (including P&C claims with medical records and life insurance underwriting) fall under HIPAA's privacy and security rules. Shield's local architecture means PHI is redacted before it ever reaches an external AI provider — the data never leaves your covered entity's control. Shield's filter packs detect PHI patterns including ICD-10 codes, NPI numbers, medication names, and procedure descriptions. Audit logs provide cryptographic proof of every redaction event, supporting your HIPAA compliance documentation.
Yes. The NAIC Model Bulletin on the Use of Artificial Intelligence by Insurance Companies (adopted December 2023) establishes expectations for AI governance, risk management, and consumer protection. Shield directly supports several NAIC principles: it prevents unauthorized data disclosure (a key consumer protection concern), provides audit trails for regulatory examination, and operates transparently — you control exactly what data categories are redacted. The NAIC's AI Systems Evaluation Tool (being piloted by 12 states as of 2026) will assess insurers' AI governance and risk mitigation — Shield's tamper-evident audit logs provide documentation that supports this evaluation.
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions — including insurance companies — to protect nonpublic personal information (NPI). Most states have adopted the NAIC Insurance Data Security Model Law, which mandates risk assessments, data encryption, and incident response planning. Shield provides a technical safeguard that supports GLBA compliance: policyholder NPI — names, SSNs, account numbers, medical information — is redacted before it reaches external AI systems. This reduces your data exposure surface without changing how your team uses AI tools. GLBA violations can carry penalties of up to $100,000 per violation.
Insurance companies handle one of the broadest ranges of sensitive data in any industry. Shield's configurable filter packs cover PII (names, SSNs, driver's licenses, addresses), PHI (medical diagnoses, NPI numbers, procedure codes), PCI (credit card numbers, bank accounts), financial data (income, net worth, policy values), and proprietary business data (actuarial models, underwriting guidelines, settlement authority thresholds). You can enable or disable filter categories based on your specific compliance requirements and risk appetite. Run in audit-only mode first to understand your actual data exposure before enforcing redaction.
Yes. Shield installs on any Mac, Windows, or Linux machine — including laptops used by field adjusters and remote claims staff. For enterprise deployment, your IT team can push Shield via MDM or group policy with consistent policy configurations across all machines. Shield operates entirely locally, so field adjusters working from home or in disaster zones get the same data protection as office-based staff — no VPN or cloud dependency required. Audit logs can be centrally collected for compliance reporting across your entire workforce.

Ready to Protect Your Policyholders' Data?

Shield installs in minutes. Your policyholders' medical records, SSNs, financial details, and claims data stay on your organization's machines — where HIPAA, GLBA, and state insurance regulators expect them to be.

Talk to Our TeamHow Shield Works

Last updated: July 22, 2026