Protecting client data in the age of AI
Imagine your healthcare provider uploading your medical records into a public-facing artificial intelligence tool to summarize your health history. Or your accountant entering your tax returns to generate ideas on deductions.

You would have concerns about those actions — and rightly so.
AI tools can create meaningful efficiencies and benefits for financial professionals, but we cannot lose sight of the privacy and security protections we must uphold to ensure clients’ nonpublic personal information remains confidential.
AI is a valuable tool, but safeguarding client information remains a paramount professional obligation. A helpful tip is to think of AI as an acronym for Artificial Intelligence and Anonymous Information — a reminder that client data must be protected.
Innovation should never come at the expense of privacy. As AI tools become more accessible and powerful, it's easy to focus on the efficiencies they create while overlooking the obligations that continue to govern the use of client information. Although technology often advances more quickly than regulation, the requirements for protecting health and financial information remain firmly in place. The responsibility to safeguard NPI has not changed simply because the tools have.
Thoughtful insurance regulation strengthens our industry and protects our clients, especially regulations that help guide financial professionals in serving their clients responsibly and protecting their privacy. Working in this field requires a continuous effort to safeguard our clients’ NPI, especially when using new or existing technological tools in the marketplace.
The adoption of AI in the insurance industry is and will continue to be a game changer for all parties. As we evaluate our use of available AI tools, it’s essential that appropriate guardrails are in place to add value while considering the current regulatory environment. Privacy and security protections, such as HIPAA/HITECH, GLBA, and state cybersecurity regulations, continue to apply when using AI. Before using any public-facing AI tool, financial professionals should ensure that client information has been removed or de-identified in accordance with applicable privacy, security, carrier, firm and compliance requirements.
Here are four examples that could increase various risks for you and your clients when using a publicly available AI tool.
- Uploading medical records to produce a summary output
Although medical information can be summarized quickly with an AI tool, medical records are protected health information under HIPAA. To obtain, use or disclose PHI, certain federal and state requirements must be met. As a result, you may not have the proper authorization to upload your client’s medical records to a public-facing AI tool that could further use and share your client’s PHI. This activity could violate several privacy and information security regulations.
- Uploading a completed insurance application and medical information to obtain an underwriting classification
To generate a meaningful underwriting assessment, the AI tool would need access to significant client health and financial information, as well as carrier-specific underwriting considerations. Even then, the output would require review and validation by qualified underwriting professionals. AI should not replace established underwriting processes or professional judgment.
- Recording and transcribing phone calls and virtual meetings
Using an AI tool to record a call or meeting as it occurs and provide a transcript can be very convenient and may improve the accuracy of the information you obtain. However, if any NPI, including health and financial information, is discussed and included in the transcription, that information could now be in the hands of an unauthorized third party. Your meeting tool of choice now has this information, and you might not know how it protects it. This could create potential privacy, security and compliance concerns.
- Uploading suitability information to document best interest recommendations
It can be tempting to use an AI tool to obtain a suitability decision. However, doing so would require uploading the client’s detailed NPI to the AI tool, along with your product shelf details and the carrier’s suitability criteria. You would have limited ability to verify whether the information being analyzed is complete, current or accurate, and doing so could unnecessarily expose your clients’ NPI.
These examples highlight a common theme: Protecting client information remains a critical consideration when evaluating the use of AI. Privacy and security are important concerns, but so is the accuracy of the information and recommendations generated by these tools. Before using AI in situations involving sensitive client information, consider the following questions:
- Does the HIPAA authorization you are relying on to disclose health information take into consideration the use of a public AI tool?
- Does the public AI tool you are using need access to your clients’ protected health or financial information to perform the task? And does it have the right to know this information?
- Do you have confirmation that the public AI tool you decide to use will continue to protect NPI?
- Are you sure the AI tool you are using has all relevant information needed to provide accurate outputs?
If the answer to any of the above is “probably not” or “I don’t know,” your actions may result in noncompliance with various privacy and security requirements and reputational risk to you and your business. Most importantly, as financial professionals, we have a responsibility to protect our clients’ NPI.
Financial professionals handle highly personal information every day. "Anonymous Information" is a reminder that AI should help us understand information — not identify who it belongs to. As technology continues to evolve, education, human oversight and trusted industry partnerships remain essential. AI will undoubtedly create new opportunities and efficiencies, but innovation should not come at the expense of privacy.
© Entire contents copyright 2026 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.
Joy Dawe is senior vice president of compliance and market conduct with Crump Life Insurance Services. Contact her at joy.dawe@innfeedback.com.



New assessment tool helps insurers take a hard look at their AI game plan
CFA calls for insurers to be penalized over delayed claims payouts
Advisor News
- Ask the right questions to turn clients into raving fans
- The first 5 years of your career could determine the next 50
- Your client’s $3 million portfolio doesn’t tell you their insurance needs
- How life insurance can provide liquidity for wealthy families
- Retirement providers turn to digital engagement to retain assets
More Advisor NewsAnnuity News
- What lower interest rates mean to annuity payouts
- AM Best downgrades A-Cap insurers amid financial and regulatory troubles
- Lawsuit claims Delaware Life hid billions in insurer-linked investments
- AM Best to Deliver Presentation at 2026 ACLI Annual Conference
- Global Atlantic Announces Launch of ForeLifetime Income, a New Fixed Index Annuity
More Annuity NewsHealth/Employee Benefits News
Life Insurance News