Industry

Insurance: Underwriting, Claims, and Data on the Move

March 9, 2026 Hilt 6 min

Your most valuable data leaves on access you granted on purpose. Insurers move PII and claims data across underwriting, adjusters, and reinsurers on sanctioned access. Where the permitted-pattern blind spot lives across the insurance lifecycle.

Insurance: Underwriting, Claims, and Data on the Move cover image

A policyholder's name, date of birth, Social Security number, medical history, and claim record enter at the quote. Then they move. To underwriting. To a data broker. To an independent adjuster's laptop. To a medical reviewer, a repair vendor, a reinsurer, defense counsel, an actuary's model. Every one of those moves is sanctioned. Every one happens because you granted someone access on purpose.

That is the exposure. Not the break-in. The data that matters most leaves on the access you designed, so every control you own waves it through.

The move you cannot see is the permitted one

Insurance data security mostly answers a question the business already answered. Did this person have permission to open the file? Was the channel approved? Is the user provisioned in the policy admin system? Yes, yes, and yes. That is how claims get paid.

The danger is not the move that breaks a rule. It is the pattern across moves that break none. An adjuster who pulls one claim file is working. An adjuster who pulls four hundred files across three lines of business in an afternoon, two weeks before joining a competitor, is doing something else through the same login. The access was right. The behavior is not.

A permission check evaluates whether a move was allowed. It was never built to ask whether the shape of the movement was normal. That gap sits under the whole lifecycle, and it is structural. No vendor caused it.

Where the data actually moves

Underwriting. Quote and bind pull PII, credit data, prior-claims history, and telematics, often from outside enrichment vendors, then push to rating engines and third-party models. Each handoff carries a large volume of sensitive records on a channel built to carry exactly that.

Claims and adjusting. The most mobile data in the company. First notice of loss spawns photos, recorded statements, medical bills, repair estimates, police reports. Field staff and independent adjusters work off endpoints nowhere near the data center. Files route to medical reviewers, special investigations, defense counsel, repair networks. At the permission layer, the legitimate copy and the stolen copy are the same copy.

Reinsurance and actuarial. Bordereaux, loss runs, and modeling extracts ship whole books of policyholder data to reinsurers and actuarial teams. These are bulk transfers by design. Bulk is the shape an exfiltration hides inside.

The regulators expect you to know where regulated data went the whole way through: state laws modeled on the NAIC Insurance Data Security Model Law, the GLBA Safeguards Rule, HIPAA where PHI is in play, the state privacy statutes. Reconstructing it after the fact from a forensic timeline is the disclosure letter. The moment that helps you is while the data is still in motion.

Catch it on the move, not before and not after

Predictive and policy tools guess up front. They classify, tag, and write rules, generate alarms by the thousand, and still pass the permitted move straight through, because it broke no rule.

Detection and response tells you after. The timeline is accurate and complete, and it lands once the records are gone and the notification clock is already running.

Runtime data movement governance watches the move itself, as it forms. Hilt watches data movement at the kernel, metadata only by default, off the path. It does not read the claim file or the medical record to see the pattern is wrong. It resolves each move to a probabilistic, source-dependent identity: which user or service, which job, which destination, and whether this is how that identity normally moves data.

So when the adjuster's afternoon pull happens, the deviation lands across layers at once. The job is unusual for that identity. The access is a bulk read of high-value claim paths across lines of business this person never touches together. The volume out is unusual for the approved channel. Alone, each is noise. Together they are a pattern, and a pattern is a case, not an alert. Hilt writes the case, and when warranted it isolates the host at the network from the control plane. It never sits inline. It never blocks, drops, or alters the traffic that runs your business.

Why insurance can actually run this

Insurance infrastructure is heterogeneous and partly old: policy admin on systems that have run for decades, claims platforms, a fleet of field laptops, cloud workloads for the newer stack. A heavy agent that has to sit in the path of production traffic is dead on arrival with the team that keeps claims processing up.

Hilt stays off the path. The collector runs at negligible overhead, on the order of 0.1% of one core and 4 to 8 MB of memory per host. It is single-tenant inside your own cloud, AWS, GCP, Azure, or Ali Cloud, and the events never leave your account. One collector unit covers a cloud workload and a user endpoint alike, which matters when your exposure runs from the actuarial cluster to an adjuster's laptop in a parking lot. You see the movement without standing in front of it.

What this does not replace

Your stack is doing real work, and Hilt fits into it. Identity and access governance still decides who is provisioned for what. Email and web controls still catch the obvious outbound path, the screenshot to a personal account, the rule-flagged bulk download. They are good at what they cover, and Hilt does not displace them. Endpoint protection is different. Hilt can stand in for your endpoint sensor, and many insurers retire their EDR once it is in place. Keep an EDR alongside only if you want the malware and intrusion layer too, since Hilt does not do malware or live-intrusion detection.

What stays uncovered is the move all of them are built to allow: the real identity, the sanctioned channel, the permitted action, arranged in a pattern that is wrong. That is the gap runtime data movement governance closes, and in this industry that gap is what becomes a breach notification.

An insurer cannot stop moving policyholder data. Underwriting needs it, adjusters need it, reinsurers need it, and the regulators expect you to govern it the whole way through. The threat is not the stranger taking what they were never allowed to touch. It is the person already allowed to touch it moving it in a way no permission check can flag.

If your controls cannot answer "what did this adjuster's data actually do this afternoon, resolved to the job behind it and scored against how their claims data normally moves," that is the blind spot, and it runs the length of the lifecycle.

If you want to see how this maps onto your own underwriting, claims, and reinsurance flows, the fastest path is a 30-minute technical call. We walk the data movement, not a slide deck.