Blog
September 27, 2026

Claims AI and Data Security: 12 Questions Your IT Team Will Ask

by
Andrej Evtimov

The questionnaire in the order IT and GRC work through it, and what a good answer looks like.

Security review is the second thing that stops a claims AI deal, after accuracy, and the questionnaire barely changes between carriers. This is the list in the order an IT and GRC team works through it, with what a good answer looks like and where the published answers sit.

‍

The questionnaire is the same every time

‍

Security review is the second thing that stops a claims AI deal, after accuracy. The questions are not obscure, and they barely change between carriers.

‍

This is the list, in the order an IT and GRC team usually works through it. Each question has a short answer explaining what a good response looks like, and where to find the vendor's actual position.

‍

Run it on any vendor, including this one. The published answers below sit in the trust center and the security FAQ. A vendor that cannot point you at an equivalent page is asking you to take the answers on trust.

‍

1. Where is our data hosted, and can we choose the region?

‍

This is first because it is binding. Data residency is often a contractual or regulatory requirement, not a preference.

‍

A good answer names the cloud provider, the specific regions, and whether the customer chooses. The trust center states that customers can choose between US or EU data centres. The security FAQ says processing and storage happen "either in Switzerland, in Germany or in another country of the customers choice", on AWS.

‍

Ask where backups and logs live too. They frequently sit in a different region from the primary data, and that is where residency commitments quietly break.

‍

2. Is data encrypted in transit and at rest, and with what?

‍

Expect named algorithms and versions, not the word "encrypted".

‍

The security FAQ states that "All data at rest is encrypted with the industry-standard AES-256" and that TLS 1.2 or higher protects data in transit. It also describes a bring-your-own-key option, with client-side encryption before transfer.

‍

This question has a regulatory backdrop. The HIPAA Security Rule at 45 CFR 164.312 treats encryption as an addressable implementation specification, not a flat requirement. Addressable does not mean optional. It means the covered entity must assess it and document the decision.

‍

3. Do you hold SOC 2 Type II and ISO 27001?

‍

Ask for the report, not the badge. A logo on a website is not an attestation.

‍

The published trust center states SOC 2 Type II and ISO 27001. The underlying criteria are the AICPA's 2017 Trust Services Criteria, issued by the Assurance Services Executive Committee, covering security, availability, processing integrity, confidentiality and privacy.

‍

Three follow-ups separate a real answer from a marketing one. Which trust services categories are in scope? What is the report period? And were there exceptions?

‍

A Type II report covers a period of operating effectiveness. A Type I covers design at a point in time. They are not interchangeable, and vendors sometimes let the distinction blur.

‍

4. Is our claim data used to train your models?

‍

This is the question most likely to be answered vaguely, and the one your legal team will care about most.

‍

Get it in writing, in the contract, not in a sales email. The answer needs to cover three separate things: training, fine-tuning, and human review of inputs or outputs for quality purposes.

‍

A vendor that uses a third-party foundation model must also state what that provider does with the data. Your contract is with the vendor; the exposure may sit one layer down.

‍

If the published material does not address this, treat that as an open item rather than an implied no.

‍

5. Who are your subprocessors, and how are we told when they change?

‍

A subprocessor is any third party the vendor passes your data to. Every SaaS platform has them: cloud hosting, identity, email, analytics, monitoring.

‍

The security FAQ names AWS for infrastructure, Auth0 for identity, and Clarity and Mixpanel for analytics on anonymised data. Ask for the complete current list as a contractual artefact, plus a notification commitment when it changes.

‍

The notification term is the part that gets skipped. A subprocessor list without a change-notice clause tells you about today only.

‍

6. How is our data isolated from other customers?

‍

Multi-tenant is normal. Undocumented multi-tenancy is not.

‍

The security FAQ describes "Strong Tenant Isolation" with logical separation, customer-specific encryption keys and tenant-authorised requests, on a multi-tenant microservice architecture.

‍

Ask how isolation is tested rather than how it is designed. Design documents describe intent; test results describe behaviour.

‍

7. How do users authenticate, and do you support SSO and MFA?

‍

Your identity team will want the platform inside your existing identity provider, not beside it.

‍

The trust center lists SAML single sign-on, enforced two-factor authentication, and SCIM controls for automated user provisioning. The security FAQ adds Auth0 as the identity layer, with optional integration of the customer's own identity provider. It also lists multi-factor authentication, bot detection and brute-force protection.

‍

SCIM matters more than it looks. Without automated provisioning, deprovisioning depends on someone remembering, and leavers keep access.

‍

8. What happens to our data when the contract ends?

‍

Ask this during procurement, because it is unnegotiable afterwards.

‍

Three things need to be specified: the export format, the deletion timetable including backups, and who confirms deletion in writing.

‍

The security FAQ notes contractual provisions for data return. It also states that original documents stay in the customer's primary system, with metadata and annotations transferable at any time. Get the deletion side written down with the same specificity.

‍

9. What are your backup, RTO and RPO commitments?

‍

These belong in the contract, not in a slide.

‍

The security FAQ states daily automated backups, with "Amazon RDS snapshots are retained for 30 days". It gives a recovery point and recovery time objective of one day each. It also describes multi-availability-zone AWS deployment, with automated failover in 60 to 120 seconds.

‍

Then ask the harder question. When was the restore last tested end to end, and what was the result?

‍

10. How is protected health information handled?

‍

Claim files contain medical records, so this question is unavoidable in a bodily injury context.

‍

The standard sets the floor. 45 CFR 164.312 requires technical policies allowing access "only to those persons or software programs that have been granted access rights". It also requires unique user identification, integrity protection and transmission security. Audit controls must "record and examine activity in information systems".

‍

Each vendor's own position on PHI is a contractual question, and the trust center states it. Read that statement carefully against what the product actually does with records. A platform built for bodily injury claim file review handles medical documents by design. The PHI wording and the product scope need to line up. Then read both against your counsel's view of whether a business associate agreement is required.

‍

11. How do you detect an incident, and when do we hear about it?

‍

Detection and notification are separate commitments. Vendors often describe the first and leave the second vague.

‍

The security FAQ describes monitoring for unauthorised access, login monitoring, and alerting and escalation with customer notification. What you need in the contract is a defined notification window, measured in hours, and a named contact on both sides.

‍

Ask who declares an incident. If only the vendor can, your notification clock starts when they decide it should.

‍

Ask for breach history too. A vendor with none should say so plainly, and a vendor with one should be able to describe what changed afterwards.

‍

12. What evidence will you give our auditor and our regulator?

‍

This is the question that determines whether the deal survives your second-line review.

‍

The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers was adopted on 4 December 2023. Under it, oversight of third parties acting for the insurer is an insurer obligation. The bulletin "advises insurers of documentation that a state Department of Insurance may request during an investigation or examination."

‍

So the vendor's evidence has to be good enough for your examiner, not just for your security team. Ask for four things:

‍

  • the SOC 2 report;
  • the ISO certificate with its scope statement;
  • penetration test summaries, with the testing cadence and who performs them;
  • a named contact who answers auditor questions during the term.

The twelve at a glance

‍

  • 1. Hosting and region. Named provider, named regions, and where backups and logs sit.
  • 2. Encryption. Named algorithms and TLS versions, in transit and at rest.
  • 3. SOC 2 and ISO 27001. The report itself, its scope, period and exceptions.
  • 4. Model training. A contract clause covering training, fine-tuning and human review.
  • 5. Subprocessors. The current list plus a change-notification term.
  • 6. Tenant isolation. How isolation is tested, not how it is designed.
  • 7. Authentication. SSO, MFA and automated provisioning and deprovisioning.
  • 8. Exit. Export format, deletion timetable including backups, written confirmation.
  • 9. Backup, RTO and RPO. The commitments, plus the date of the last tested restore.
  • 10. Protected health information. The vendor's contractual position, read against the product scope.
  • 11. Incident response. A notification window in hours, a named contact, and breach history.
  • 12. Audit evidence. Reports, certificate scope, pen test cadence, a named contact for auditors.

Give the questionnaire a permanent home

‍

The reason this list repeats across deals is that the answers usually live in a sales deck, and decks go stale.

‍

Published answers in one place do three things. The buyer self-serves the first pass. The sales team stops rewriting the same document. And the version everyone is quoting is the current one.

‍

Where a page like a trust center exists, send the questionnaire there first and handle only the gaps by email. Where it does not, expect the review to take weeks longer, whatever the product does.

‍

The three answers to insist on in writing

‍

Most of the twelve can be satisfied by a published page. Three cannot, and they are the ones to put in the contract.

‍

  • Model training. Whether claim data trains, fine-tunes or is human-reviewed, and what any upstream model provider does with it.
  • Subprocessor change notice. The current list, plus how much warning you get before it changes.
  • Incident notification. A window in hours, a named contact, and who has authority to declare an incident.

A vendor that answers all three plainly has usually been through this review before. That is worth more than any certification logo.

‍

Key takeaways

‍

  • The twelve questions are the same at every carrier: hosting and region, encryption, SOC 2 and ISO 27001, model training, subprocessors, tenant isolation, authentication, exit, backup and RTO/RPO, protected health information, incident response, and audit evidence.
  • Ask for the SOC 2 report rather than the badge, and check three things: which trust services categories are in scope, the report period, and whether there were exceptions. Type I and Type II are not interchangeable.
  • Three answers cannot come from a published page and belong in the contract: whether claim data trains or fine-tunes models, the current subprocessor list plus a change-notification term, and an incident notification window measured in hours.
  • Backups and logs often sit in a different region from the primary data. That is where residency commitments quietly break.
  • Under the NAIC Model Bulletin, adopted 4 December 2023, oversight of third parties is an insurer obligation, so vendor evidence has to satisfy your examiner and not only your security team.
  • Publishing the answers in one place cuts the first pass out of every deal. Where a trust center exists, send the questionnaire there and handle only the gaps by email.

‍