Download

New Attack Vector for Cyber Thieves

Thieves are hacking personal email to pose as an authority figure and dupe a subordinate into doing something quickly, without questions.

It has become commonplace for senior executives to use free Web mail, especially Gmail, interchangeably with corporate email. This has given rise to a type of scam in which a thief manipulates email accounts. The goal: impersonate an authority figure to get a subordinate to do something quickly, without asking questions. The FBI calls this “CEO fraud,” and a surge of these capers has resulted in scammers stealing a stunning $750 million from more than 7,000 U.S. companies from October 2013 through August 2015. Here is an example where the scammer targets an attorney from a big city in the Northeast. Attack vector: The scammer gathers intelligence about real estate transactions handled by an attorney and drills down on a specific deal in which the law firm is handling the purchase of a $450,000 home for a client. The scammer learns this attorney is in the habit of using his personal Gmail account interchangeably with his law firm’s email. As the transaction approaches the final step, the attorney’s paralegal receives a spoofed email that appears to come from her boss. She instantly follows a directive to cancel a check for $450,000 that she is about to mail and instead wires the funds into an account designated by the scammer. More video: Scammers exploit trust in Google’s platform Distinctive technique: The funds initially get routed to another law firm in the Southwest. A subordinate in this law firm also appears to have been spoofed by the scammer to be prepared to move funds once again, this time into an account set up in a U.S. branch office of Sumitomo Bank, a giant global institution with headquarters in Tokyo. “At this point, it is not likely the $450,000 will ever be recovered,” says IDT911 Chief Privacy Officer Eduard Goodman. “Once a transfer like this is made, you can’t really unring that bell.” Wider implications: U.S. consumers are well protected by federal law, and banks usually will reimburse individual consumers victimized by cyber criminals. However, banks are under no legal obligation to offer any relief to businesses, large or small, that have been tricked like this. Most of the $750 million lost in documented cases of CEO fraud has most likely been absorbed by the duped business entities. Infographic: More Americans living with data insecurity Excerpts from ThirdCertainty’s interview with Goodman. (Answers edited for length and clarity.) 3C: Businesses are losing one heck of a lot of money to CEO fraud.
Eduard Goodman, IDT911 chief privacy officer
Goodman: Yeah, absolutely. This one was for about $450,000. There is another woman with a ballet company who recently lost about $100,000. It’s significant chunks, let’s put it that way. And because this is happening in a business setting, it’s a little bit different in that your bank won’t stand behind you. It’s caveat emptor. There is no consumer protection. When something like this happens to your business, you’re out of luck. 3C: Why aren’t suspicious transactions flagged more often? Goodman: The government will tend to go after companies for anything that may have to do with consumer violations. But when businesses impact other businesses, the government doesn’t do a damn thing, even if the victim is a really small business and they’re essentially consumers in and of themselves. Banks have that unfair advantage to say, ‘Well, sorry, should have flagged it, but we just process it for you.’ 3C: So by using free Web mail this attorney sort of invited spoofing? Goodman: He kind of comingled accounts, that’s the thing. He had his law firm’s email, and he also had a personal Gmail account. He would send emails from both accounts. That is something that has become a very common practice. He probably had previously emailed himself something from his actual work account into his Gmail account. This scammer probably got into his Gmail account, and then made the connection to his law firm account. Then it was off to the races. The paralegal gets the wire transfer request from an email that’s very close to an authentic law firm email except there’s an extra letter in the domain name. It looks very credible. 3C: Could this have been avoided? Goodman. Yes, by taking the extra 45 seconds to make a phone call. Pick up the phone and verify things instead of getting caught up in the workday.

Byron Acohido

Profile picture for user byronacohido

Byron Acohido

Byron Acohido is a business journalist who has been writing about cybersecurity and privacy since 2004, and currently blogs at LastWatchdog.com.

How Bad Is Insurance Fraud Really?

For starters: Insurance fraud in the U.S. is estimated to be at least $80 billion a year.

sixthings
The-World-of-Insurance-Fraud-Infographic This infographic was originally published on Easy Life Cover.

Eamonn Freeman

Profile picture for user EamonnFreeman

Eamonn Freeman

Eamonn Freeman is managing director of Easy Life Cover, a life insurance company based in Ireland. He regularly researches and creates content relatable to his industry ranging from infographics to blog posts.

Data Science: Methods Matter

The details of exploratory analysis can be tedious, yet they are the crux of the genius involved in data science project methodology.

sixthings
When data analytics uses simple formulas, much conjecture and an arbitrary methodology, it often fails in what it was designed to do —give accurate answers to pressing questions. So, at Majesco, we pursue a proven data science methodology in an attempt to lower the risk of misapplying data and to improve predictive results. In Methods Matter, Part 1, we set the stage for explaining the Majesco Data Science Project Lifecycle. The goal is to give insurance organizations a picture of the methodology that goes into data science. We discussed CRISP-DM and the opening phase of the life cycle, project design. In Part 2, we will be discussing the heart of the life cycle — the data itself. To do that, we’ll take an in-depth look at two central steps: building a data set, and exploratory data analysis. These two steps compose the phase that is  extremely critical for project success, and they illustrate why data analytics is more complex than many insurers realize. Building a Data Set Building a data set, in one way, is no different than gathering evidence to solve a mystery or a criminal case. The best case will be built with verifiable evidence. The best evidence will be gathered by paying attention to the right clues. There will also almost never be just one piece of evidence used to build a case, but a complete set of gathered evidence — a data set. It’s the data scientist’s job to ask, “Which data holds the best evidence to prove our case right or wrong?” Data scientists will survey the client or internal resources for available in-house data, then discuss obtaining additional external data to complete the set. This search for external data is more prevalent now than previously. The growth of external data sources and their value to the analytics process has ballooned with an increase in mobile data, images, telematics and sensor availability. A typical data set might include, for example, typical external sources such as credit file data from credit reporting agencies and internal policy and claims data. This type of information is commonly used by actuaries in pricing models and is contained in state filings with insurance regulators. Choosing what features go into the data set is the result of dozens of questions and some close inspection. The task is to find the elements or features of the data set that have real value in answering the questions the insurer needs to answer. In-house data, for example, might include premiums, number of exposures, new and renewal policies and more. The external credit data may include information such as number of public records, number of mortgage accounts, number of accounts that are 30-plus days past due, among others. The goal at this point is to make sure that the data is as clean as possible. A target variable of interest might be something like frequency of claims, severity of claims or loss ratio. This step is many times performed by in-house resources, insurance data analysts familiar with the organization’s available data or external consultants. At all points along the way, the data scientist is reviewing the data source’s suitability and integrity. An experienced analyst will often quickly discern the character and quality of the data by asking, “Does the number of policies look correct for the size of the book of business? Does the average number of exposures per policy look correct? Does the overall loss ratio seem correct? Does the number of new and renewal policies look correct? Are there an unusually high number of missing or unexpected values in the data fields? Is there an apparent reason for something to look out of order? If not, how can the data fields be corrected? If they can’t be corrected, are the data issues so important that these fields should be dropped from the data set? Even further, is the data so problematic that the whole data set should be redesigned or the whole analytics project should be scrapped? It shouldn’t be overlooked that there is more value in identifying problematic issues early, than in a completed data science project where inaccurate or incomplete data was used. Scrapping data sets or even whole projects at this point will save wasted time and effort. Once the data set has been built, it is time for an in-depth analysis that steps closer toward solution development. Exploratory Data Analysis Exploratory data analysis takes the newly minted data set and begins to do something with it — “poking it” with measurements and variables to see how it might stand up in actual use. The data scientist runs preliminary tests on the “evidence.” The data set is subjected to a deeper look at its collective value. If the percentage of missing values is too large, the feature is probably not a good predictor variable and should be excluded from future analysis. In this phase, it may make sense to create more features, including mathematical transformations for non-linear relationships between the features and the target variable. For non-statisticians, marketing managers and non-analytical staff, the details of exploratory data analysis can be tedious and uninteresting. Yet they are the crux of the genius involved in data science project methodology. Exploratory data analysis is where data becomes useful, so it is a part of the process that can’t be left undone. No matter what one thinks of the mechanics of the process, the preliminary questions and findings can be absolutely fascinating. See Also: The Science (and Art) of Data, Part 1 Questions such as these are common at this stage:
  • Does frequency increase as the number of accounts that are 30-plus days past due increases? Is there a trend?
  • Does severity decrease as the number of mortgage trades decreases? Do these trends make sense?
  • Is the number of claims per policy greater for renewal policies than for new policies? Does this finding make sense? If not, is there an error in the way the data was prepared or in the source data itself?
  • If younger drivers have lower loss ratios, should this be investigated as an error in the data or an anomaly in the business? Some trends will not make any sense, and perhaps these features should be dropped from analysis or the data set redesigned.
The more we look at data sets, the more we realize that the limits to what can be discovered or uncovered are small and growing smaller. Thinking of relationships between personal behavior and buying patterns or between credit patterns and claims can fuel the interest of everyone in the organization. As the details of the evidence begin to gain clarity, the case also begins to come into focus. An apparent “solution” begins to appear, and the data scientist is ready to build it. In Part 3, we’ll look at what is involved in building and testing a data science project solution and how pilots are crucial to confirming project findings.

Denise Garth

Profile picture for user DeniseGarth

Denise Garth

Denise Garth is senior vice president, strategic marketing, responsible for leading marketing, industry relations and innovation in support of Majesco's client-centric strategy.

Protecting Institutions From Cyber Risks

In the wake of FSU’s inadvertent disclosure crisis, a review of the privacy procedures in place at institutions may be in order.

sixthings
Recently, an email glitch at Florida State University resulted in the accidental emailing of alleged misconduct and housing violations to more than 13,000 current and former students. The emails may have revealed the personal information of multiple students and may have disclosed confidentially reported information relating to harassment and alleged sexual assaults. The emails were not sent by anyone on campus but were the result of a technical glitch in the university’s database. The glitch left students confused and, in some cases, frightened and concerned for personal safety. University personnel, including FSU’s Title IX Coordinator, moved quickly to address student concerns, but the proverbial cat was already out of the bag. It will likely be some time before the full consequences of the breach will be known or what the final outcomes will be. In the wake of FSU’s inadvertent disclosure crisis, a review of the privacy procedures in place at an institutional level may be in order to prevent these types of unintended disclosures in the future. It is also important to review the indemnity agreements between the university and third-party service providers such as the database administrator or software provider. Finally, it is important to review how cyber liability insurance may respond in the event of a data breach. Data Privacy Protocols When discussing data privacy protocols, there are three primary areas of concerns. They are how to protect:
  1. Information (e.g., personally identifiable data stored on a server)
  2. Mechanisms/systems that make up the physical housing for the information (e.g., the server itself)
  3. Users accessing the information
A breach of confidential information or data loss can occur at any of the three levels in any number of ways. It is impossible to quantify or evaluate every single manner in which a breach may occur—or how data may be lost. What is important is establishing a protocol that takes into consideration all three areas where a breach may occur. In most cases, it is easy to focus on external threats and user misconduct but overlook the potential for data breach arising from internal system failures or glitches. See Also: How Colleges Can Work With Insurers In developing data security protocols, it is important to engage in a comprehensive threat assessment that includes evaluation of user-based or external potential breach areas as well as the possibility of an equipment failure/glitch. A few areas to consider when reviewing internal data breach/data loss response protocols:
  1. Who is the architect of the protocols? (Are the foxes guarding the hen house?)
  2. Does your protocol comply with statutory requirements and contractual requirements such as PCI compliance, Title IX, HIPAA or other state and federal laws?
  3. Does the protocol specifically address each element of concern identified above? (protection of information, protection of systems, protection of users)
  4. Is there a progressive (tree) notification process? (Do the participants understand where they are in the tree? Does the process include notification to external stakeholders such as legal authorities, insurers, external legal counsel, and crisis management or PR firm?)
  5. Is there strong leadership/executive level buy-in of the protocol?
  6. Is there a training element? (Does it include tabletop or scenario-based practice?)
  7. Is there periodic review of systems and processes to identify and change obsolete protocols and replace key stakeholders in the event of turnover?
Indemnity/Hold Harmless/Limitation of Liability Agreements Vendor service agreements, user license agreements and even software agreements typically include indemnity terms. In most cases, these terms are one-sided, in favor of the seller or service provider. Essentially, the purpose of an indemnity agreement is to contractually shift responsibility for loss/damage from one party (seller) to another party (buyer). These types of agreements vary in scope, strength and enforceability but, in most cases, involve a release or limitation of buyer’s claims or potential claims against the seller. In some cases, the buyer may assume full responsibility for any loss, including an affirmative responsibility to protect and defend the seller in the event of third-party claims. There may also be a limitation on the type and extent of damages a buyer may seek against the seller or service provider—in some cases, the recovery may be limited to the value of contract or agreement. Your institution’s risk management and legal teams should carefully review indemnity terms to fully understand the extent of risk assumed by the institution in executing an agreement with a third party. As part of a comprehensive risk management process, consider limiting acceptance of comprehensive indemnification terms in a contract. This is especially important where the institution is being asked to waive its legal rights or outright indemnify a vendor for the vendor's own negligence, misconduct or product/service failure. A few areas to consider in reviewing contract terms: Indemnity/Hold-Harmless Terms
  1. Who is the indemnitee (recipient of the indemnity) and who is the indemnitor (provider of the indemnity)?
  2. Does the indemnity agreement require one party to indemnify for the other party’s own negligence or misconduct?
  3. Does the indemnity agreement include an obligation to affirmatively defend the indemnitee? Is there is a time limit to accept or reject the defense?
  4. Who is responsible for counsel selection?
  5. Is approval needed to settle claims?
Limitation of Liability
  1. Is there a limitation of liability?
  2. Does the limitation favor the institution or vendor?
  3. Is the limitation reasonable in light of the potential for loss or damage or the nature of the service provided? (Limiting liability to the contract value may not be reasonable if the contract value is low and the risk of loss is high.)
  4. Are there carveouts for negligence or misconduct, or is the limitation of liability intended as the sole remedy?
  5. Does the limitation of liability conflict with the indemnity terms? 
Cyber Liability Insurance In the past few years, cyber liability insurance has gained significant attention among insurance brokers and clients. Cyber insurance refers to a suite of related insurance products that provide various types and levels of protection to insureds that may suffer from data loss or data breach. There are three major components of cyber liability insurance:
  1. First-party coverage for loss or damage to or interruption of the institution’s electronic equipment and electronic services
  2. Third-party coverage for the liability imposed upon the institution for loss or exposure of third-party data; coverage for third parties may include costs for notification, credit monitoring and credit restoration services
  3. Coverage for regulatory requirements as well as for fines and penalties assessed against the institution as part of a covered loss
Unlike some property and casualty insurance products such as general liability or auto insurance, cyber liability insurance is not standardized. Instead, each insurance company issues a customized policy. These policies may vary greatly from insurer to insurer and can often include a la carte coverages that may significantly affect the breadth and scope of coverage. A careful review of institutional and vendor policies is strongly recommended to ensure that the coverage purchased addresses the actual risks of the institution. Some questions to consider when reviewing your cyber liability policy:  See Also: A Better Way to Assess Cyber Risks? First-Party Coverage
  1. How does the policy respond to loss or damage to the institution’s own computer equipment, servers or other hardware components?
  2. How does the policy define a physical loss? (does it include loss of Internet-based platforms such as web portals or only loss to physical components)
  3. Is there a waiting period for business or data interruption? 
Third-Party Coverage
  1. How does the policy respond to breach of confidential or personally identifiable information?
  2. Is coverage provided based on a total number of affected persons or provided on a blanket limit basis?
  3. Is there a minimum/maximum affected person limit?
  4. How is a third-party loss defined? Does it include accidental loss, computer glitches or loss of non-electronic information? (e.g., is there coverage if a laptop containing personally identifiable information is lost? Or if physical records are removed or destroyed?)
  5. Is the coverage triggered only when there is a statutory or governmental notification requirement, or does it cover voluntary notification?
Fines/Penalties
  1. Does the policy include coverage for fines/penalties including payment card industry (PCI) data security standards noncompliance?
  2. Is there a sublimit for the coverage?
  3. Are punitive or exemplary damages included? 
Conclusion It is important to take a thoughtful approach to securing data in all its various forms. An individual protocol alone is not enough to fully secure your institution in the event of a data breach. It is also important to review vendor service agreements, user agreements and software licenses to ensure an understanding of the indemnity/hold-harmless and limitation of liability provisions, which may be present in a current agreement—and which may open up the institution to unintended liability due to the negligence or misconduct of a third party. Finally, it is important to review and understand the types and scope of the institution’s cyber liability coverage—or to consider purchasing this coverage if the institution does not currently maintain coverage.

Mya Almassalha

Profile picture for user MyaAlmassalha

Mya Almassalha

Mya Almassalha joined the Encampus team in early 2016; she brings with her more than a decade of general insurance and risk management expertise, with a strong focus on higher education and organizational risk management.

Risks of Malpractice Claims (Video)

Does spending more on tests reduce malpractice claims? Doctors believe so, but the data is confusing.

sixthings
Healthcare Matters sits down with Dr. Richard Anderson, chairman and CEO of the Doctors Company. In Part 3 of the series, we ask Dr. Anderson about the 2015 BMJ study: Physician spending and subsequent risk of malpractice claims: observational study. What did he find interesting about the results, and did he have any issues with the way the study was conducted?

Erik Leander

Profile picture for user ErikLeander

Erik Leander

Erik Leander is the CIO and CTO at Cunningham Group, with nearly 10 years of experience in the medical liability insurance industry. Since joining Cunningham Group, he has spearheaded new marketing and branding initiatives and been responsible for large-scale projects that have improved customer service and facilitated company growth.


Richard Anderson

Profile picture for user RichardAnderson

Richard Anderson

Richard E. Anderson is chairman and chief executive officer of The Doctors Company, the nation’s largest physician-owned medical malpractice insurer. Anderson was a clinical professor of medicine at the University of California, San Diego, and is past chairman of the Department of Medicine at Scripps Memorial Hospital, where he served as senior oncologist for 18 years.

2 Concepts on Social Media and Analytics

Can you filter out the vast amount of noise in the data? Handle the overwhelming amount of information?

sixthings
Recently, our team attended the Silicon Valley Insurance Disruption symposium and were privileged to engage in a number of conversations with insurance industry leaders, and innovators in technology. One of the conversations I had with an individual revolved around social media and how it has changed our society; the way people communicate; and how people demand instant information and results. Think about digital disruption in marketing and selling insurance products, i.e., the millennial (on-demand) generation. The term “social media” means a lot of different things in the insurance industry. I like the concept of using social media in two distinct methodologies; one, strategically; and two, tactically for the business of insurance. For strategic purposes, your company can use social media to communicate to customers and potential buyers of your products with a concise and cogent message. In addition, you can monitor and respond to what customers are saying about your company. For the tactical application, social media can be used for the underwriting and claims business processes. For example, tracking catastrophic events, like significant earthquakes, fire storms and hurricanes; monitoring what people are communicating while these events are occurring is invaluable for your response planning. For risk management in underwriting, the proper information can be obtained in a robust social media analytics solution that can be leveraged for better decision making. See Also: Does Social Media Have a Place? The key is to use next-generation analytics with dynamic modeling. Privacy and the ability to obtain information from social media websites have been analyzed and debated by governments and business leaders around the globe. Actions have been taken to protect an individual’s privacy. So how do you correctly utilize social media analytics in your business process? Dynamic modeling!strat Dynamic modeling of social media data begins with identifying the proper source of information. Dynamic modeling provides answers to questions in the underwriting process and claims process while keeping in mind the insured’s interest and experience. Is the API (application programming interface) open to web crawls? Can you filter out the vast amount of noise in the data? (An open-end Google-type search is not the best way to begin). Can you control the overwhelming amount of information? How do you know what to look for? If your team knows the “why” and the actual focus of deterring the risk, you will be able to deliver to the customer a better product, with a competitive price in the marketplace. Now is the time to start moving forward with next-generation analytics and start being innovative in the marketplace.

John Standish

Profile picture for user JohnStandish

John Standish

Chief John Standish, retired, is a 32-year veteran of California law enforcement, first serving in the California Highway Patrol and then in the Fraud Division of the California Department of Insurance. He is currently a consultant to the SAS Institute for the criminal justice-public safety and fraud framework programs.

Forget Big Data -- Focus on Small Data

Small data may sound quaint, but don’t be fooled. Using it can enhance customer experience without expensive overhead.

|
In their rush to jump on the big data bandwagon, many organizations have lost sight of a much simpler yet effective source of customer insight: “small data.” Big data is about synthesizing, mining and analyzing mounds of seemingly unrelated information to derive actionable insights about your customer. It’s a complex science but one that can be leveraged to understand and engage customers in new, surprising and sometimes even creepy ways. (Consider the well-documented case where retailer Target figured out that a teenage girl was pregnant before her father even knew—merely by analyzing her purchase history data. See “The Challenges Around Big Data and the Lessons to Be Learned.”) In contrast, small data is about listening to and observing your customers intently, picking up on simple cues that allow you to better personalize and customize your interactions with them. Small data doesn’t require supercomputers to decipher. It’s not really a new concept, either—it’s just a new moniker for a tried and true approach that the best sales and service people have employed for decades, if not centuries. That might make small data sound quaint and old-fashioned, but don’t be fooled. Using it can actually enhance your business’ customer experience in very material ways, without the expensive overhead associated with big data solutions. See Also: To Go Big (Data), Try Starting Small To get a flavor of how small data can influence your customer experience, consider these examples of the strategy put into practice: • Delta Airlines’ 800-Line Greeting Presuming a customer calls Delta from a phone number the airline has on record, the 800-line voice response system will skip the standard pleasantries and prompt you with a question such as “Are you calling about your delayed flight?” If the answer is yes, then Delta immediately routes the caller to an automated service or a live representative who can help, obviating the need to navigate through a series of menu options. Once the incoming phone number is identified, Delta’s systems check to see if the customer has reservations coming up, or if perhaps a flight that day has been delayed or canceled. That’s not a terribly complex undertaking from a data perspective, as it is a relatively simple look-up exercise, rather than a full-blown analytics task.  Yet it yields a much better and more efficient customer experience, particularly at a time when passengers may be frazzled about unexpected changes in their travel plans. • Ritz-Carlton’s Personalized Guest Experiences The Ritz-Carlton luxury hotel chain is renowned for its ability to create highly personalized guest experiences. If the Ritz in Boston learns that a guest is allergic to feathers, then the Ritz in Dubai—half a world away—will de-feather that same guest’s room prior to arrival. How does the company do that? Ritz staff are trained to listen carefully for guests’ likes, dislikes and general preferences. These are small pieces of data (such as a favorite newspaper or snack, or a preferred room location) that Ritz-Carlton employees dutifully record in a customer database dubbed “Mystique.” They’re also trained to consult that database prior to a guest’s arrival and act on any relevant information they find. This helps ensure that any previously captured small data is used to create an unusually customized guest experience during subsequent visits. These two examples are from outside of the insurance industry, but the approaches they illustrate are easily transferable. It’s simply a matter of putting your antennae up and looking for small pieces of data that can be used to deliver a more personalized, relevant and anticipatory customer experience. Consider the small data that’s available to insurance carriers—data that, if captured and capitalized on, could generate some very positive customer impressions: • Children’s Ages By recording information about a customer’s children during an initial needs analysis, insurers can engage the policy owner to assist in stressful parenting periods, such as when a child approaches driving age. While identifying households with youthful drivers isn’t a new idea for insurers, using that information to strengthen the customer relationship is. Historically, such data has been used by insurers to address situations where a new, uninsured driver may be behind the wheel (to adjust premiums). However, the identification of a youthful household driver shouldn’t just be an exercise in rate adjustment. It’s also an opportunity for the insurer to demonstrate the value it provides—in this case, by communicating relevant information to parents that helps them navigate a difficult family transition (e.g., determining what resources are available to teach their son/daughter how to drive or how they can best ensure their child’s safety while they learn to drive). Using small data in this way creates a customer experience that appears strikingly prescient to the policy owner, essentially addressing their concerns and questions before they even have a chance to raise them. • Sales For certain types of commercial lines coverages, insurers have visibility into business performance measures for their clients (such as sales), which are recorded annually via premium audits. Here again, as with youthful drivers, the industry has traditionally used such data exclusively to adjust premium rates for coverages that are tied to these business metrics. But this small data can be far more useful. Consider the first time a commercial lines customer crosses over the $10 million revenue threshold. That’s a milestone that would be reflected in the small data most insurers collect, yet few do anything with it, other than raise premiums. Imagine if that customer received a handwritten note from his insurer (or agent) a month after renewal, congratulating him on reaching that milestone. Imagine how that small token of recognition would make the customer feel. Business owners, after all, don’t really care about their business insurance—but they do care about their business. When their business grows, that affords an opportunity to celebrate alongside them, to give them a “pat on the back” that they likely weren’t expecting from their insurance provider but will remember fondly. • Recurring Information Requests At Ritz-Carlton hotels, if a guest requests the same newspaper, snack or room location visit after visit, the staff will notice and use that small data to shape the customer’s future stays. There is an analog for this in the insurance industry. Consider the reports and other information materials that a policy owner requests year after year—e.g., a commercial insured requesting updated certificates of insurance for her core set of clients, or a corporate risk manager requesting loss reports sorted by site. Every recurring information request represents a piece of behavioral small data that can be used to customize the policy owner’s future experience. Imagine if a policyholder didn’t even have to make those information requests, just as the Ritz-Carlton guest who’s allergic to feathers need not request a feather-free room. Imagine if an insurance provider, based on a policyholder’s prior history of information requests, offered all of those reports and certificates to the customer at precisely the right time each year. That would be the epitome of a more personalized and effortless customer experience, all made possible simply by acting on a piece of small data. Small data may be less glamorous than its more buzz-worthy big data counterpart, but it’s no less important. Big data has its merits, but as the “shiny new object” that every company covets it has unfairly eclipsed the value of simpler and more straightforward sources of customer insight. Better understanding your customers and her needs doesn’t always require intense data crunching and sophisticated analytics. Often, what’s really needed is just a watchful eye, an attentive ear and the discipline to act on whatever insights you uncover. Because when it comes to creating a positive, memorable and personalized customer experience, small data can have a really big impact. This article first appeared at Carrier Management.

Jon Picoult

Profile picture for user JonPicoult

Jon Picoult

Jon Picoult is the founder of Watermark Consulting, a customer experience advisory firm specializing in the financial services industry. Picoult has worked with thousands of executives, helping some of the world's foremost brands capitalize on the power of loyalty -- both in the marketplace and in the workplace.

3 Money Mistakes Newlyweds Make

In the midst of all of the planning and celebrating, the topic of money is often overlooked (aside from the wedding budget).

Being a newlywed is awesome. I reflect on that season of my life as one filled with joy and anticipation. Sure, that first year of marriage was full of challenges, enormous adjustments and unexpected changes, but on the whole it was great. We found such relief in finally being married and out of engagement. Engagement is a funny time. You often take on new priorities and responsibilities you’ve never had before (like part-time event planner), and that can wear on you and the relationship after awhile. Engagement is meant to be a temporary phase in life, and most friends I know, myself included, have been thrilled to see an end to it — the lists, planning, preparation, etc. In the midst of all of the planning and celebrating, the topic of money is often overlooked (aside from the wedding budget). Yet studies tell us money is a top cause of conflict and divorce among couples. Money can be hard to talk about. Our culture has made money-talk a taboo subject, which can make it all the more difficult to start talking about money (regularly) with another person, especially if you were used to keeping your money matters private for so many years. Here are a few money mistakes I see newlyweds make. Regardless of how long you’ve been married, though, it’s always important to check in and make sure you’re not letting the important things fall by the wayside. 1. Forgetting to Update Important Plans and Documents When you start a job and enroll in your employer’s various benefits, you are prompted to assign beneficiaries to things like your 401(k), group life insurance, even an emergency contact in some instances. Getting married means it’s time to review these beneficiary designations. You should also review current insurance policies and see if you need to add your spouse to the plan or review your coverage entirely. If you are both on individual health insurance plans through work, it’s worth comparing the cost of keeping your individual plans versus one of you joining the other’s plan. It’s possible you’ll save money by being on the same plan. When evaluating the cost, consider monthly premiums, deductibles, co-insurance and co-pays. If you happen to have estate-planning documents like wills, health care proxies, living wills, etc., these documents also warrant review and updating when you get married. 2. Overlooking the Need to Get Organized I know, it’s one more administrative thing that’s not fun to think about or act on, but it is important to be organized. If you don’t talk about it, habits will naturally form, and you’ll likely end up with unnecessary confusion and stress, which can lead to conflict. Don’t be scrappy with your finances. I survive by being scrappy as a parent (I’m a mom of two toddlers). But this ability doesn’t translate as well with finances. Try this: Sit down and list out all the accounts each of you have and then talk about which accounts you want to join, leave separate, combine, close, etc. Simplicity is a wonderful thing. Decide which account(s) you’ll use for routine expenses, where you’ll keep your emergency savings, longer-term savings and investments. Even if you plan to keep accounts separate, have this conversation so it’s intentional and there’s no confusion about how bills and shared expenses will be handled. You can also make your credit reports a part of this process — so you both have an understanding of each other’s credit history, and create a plan for building better credit, or maintaining your great credit if you have it. If you’re not familiar with your credit reports, you may find them to be overwhelming at first — here’s a guide to deciphering your credit report. You can get your free credit reports once a year from each of the three major credit reporting agencies, and you can get a free credit report summary on Credit.com, updated monthly. 3. Avoiding Money Talks Money is a leading cause of conflict and stress for couples, which can be enough to discourage some people from discussing the topic at all. If you learn to talk about money early on (especially when times are good and emotions aren’t running high), you’ll be prepared when money issues arise. Talking about money feels like creating a new habit. Sometimes you just have to start doing it, even before you’re comfortable doing so, and allow the habit to take shape. Here are a few starting points for your conversations about money:
  • Your history with money (What lessons about money did you learn as a child?)
  • Current stress points with money
  • Goals you hope to achieve with your money
  • Expectations for your current lifestyle and how you want to use your money
  • Spending habits (Where do you spend money the easiest, with most resistance?)
A Word of Encouragement Financial unity and stability with your spouse is a process. You don’t have to have all the answers or all of the kinks worked out from the beginning. If you and your spouse have different approaches to money, (how you spend versus save, what you value, etc.), this doesn’t have to mean never-ending conflict. It’s possible you both need to learn to compromise, and pushing each other toward a middle ground may be the healthiest thing for both of you. And that’s one of the great benefits of marriage — the messy but beautiful process of refining each other and growing together in ways you never could alone. This article originally appeared on Credit.com and was written by Julie Ford.

Adam Levin

Profile picture for user AdamLevin

Adam Levin

Adam K. Levin is a consumer advocate and a nationally recognized expert on security, privacy, identity theft, fraud, and personal finance. A former director of the New Jersey Division of Consumer Affairs, Levin is chairman and founder of IDT911 (Identity Theft 911) and chairman and co-founder of Credit.com .

5 Reasons Doctors Are 'Non-Standard'

It can be difficult for non-standard physicians to find affordable malpractice coverage because they are considered a higher risk.

Non-standard physicians and surgeons are practicing doctors who have had claims frequency or severity issues or board actions or have been previously or are currently on probation. It can often be difficult for non-standard physicians to find affordable malpractice insurance coverage because they are considered a higher risk by insurance companies. Typically, a doctor remains in the non-standard market for about five years, provided once they enter the non-standard market they have kept themselves clean. In this post, we examine the top five reasons doctors become non-standard physicians. #1 Claims – The common reasons for claims filed against physicians include: poor communication, poor bedside manner, erroneous documentation and failure, delay or change in diagnosis. To reduce the likelihood of lawsuits and claims, physicians might take just a few minutes of extra time to answer all questions and address all concerns. Patients and their families will walk away feeling as though they had all the information, even if a bad outcome occurred. They will be much less likely to seek the counsel of an attorney. Click here to read our blog post Top 5 Reasons Doctors Get Sued. #2 Lack of informed consent – Informed consent should occur with every patient encounter. Patients must be informed on the details of their options, especially when care involves an invasive or new, cutting-edge procedure. Top breaches in informed consent that lead a doctor to the non-standard market include the use of non-FDA approved medications, and new or innovative procedures. Physicians should engage with a risk management consultant to learn best practices and get risk management advice specific to a particular practice specialty, especially those that are considered high-risk. #3 Substance abuse issues – While physicians are about as likely to abuse alcohol or illegal drugs as any member of the general public, they are more likely to misuse prescription drugs. The motivation for this often initially includes the relief of stress or pain or to stay alert when suffering from sleep deprivation. Physicians often work strange hours and long shifts, especially in the ER. The cycle often begins by using medication to stay awake and alert to manage the stress and the hours. These stresses combined with easy access to medications can lead to substance abuse issues. #4 High-risk practice profile – Physicians in a practice with higher claim ratios automatically fall into the category of “high risk.” Examples of high-risk specialties include: bariatric surgery, OB/GYN, neurosurgery, plastic surgery and pain management. These specialties are either composed of high-risk and invasive procedures such as in the case of surgeons or they are prescribing medications that are new or dangerous, such as with weight-loss or pain-management clinics. Physicians in these practices will most likely have to remain in the non-standard market throughout their entire careers. #5 Poor record keeping – Following a bad outcome or an adverse event, the first thing that the patient’s attorney will request is a copy of medical records. These will be scrutinized. Any incorrect or conflicting information contained within the medical record will prove problematic for the physician’s case. Accurate and thorough record keeping proves especially challenging for older physicians, who may have been away from practice for some time and re-enter wanting to pick up where they left off. Or perhaps they are just resistant to change. Medical clinics are now using electronic medical records (EMR), which provides a more streamlined and accurate system of record keeping; they even have informed consent forms built right in. From a risk management perspective, EMR is highly encouraged. Bottom Line – Physicians should consult a clinical risk management expert for help in developing strategies to decrease the risk of becoming a non-standard physician. Thorough protocols covering documentation, informed consent and communication will all prove invaluable in risk reduction. It’s also important that doctors are honest about their personal bandwidth when it comes to patient load capacity, stamina for extended work hours, overall physical and emotional health and stresses that may be coming from personal circumstances. These factors are important to consider and if not tended to can lead to events that have a long and lasting impact on a doctor’s ability to practice medicine.

Jackie Johnston

Profile picture for user JackieJohnston

Jackie Johnston

Jackie Johnston joined Ultra in June 2010 and brings more than 25 years of insurance industry experience in a broad range of areas, including property/casualty and healthcare/medical malpractice. She has experience with both retail agencies and wholesale brokerage.

How to Win at Work Comp Claims

The No. 1 cost driver of a workers’ compensation claim is that the injured worker is not getting better, but that can change....

sixthings
So many people want to blame the injured worker for the high cost of workers’ compensation; they say the worker doesn't want to get better. But consider these two patients, limping into two different medical clinics with the same complaint. Both have trouble walking and appear to require hip surgery. The first patient is examined within the hour, is X-rayed the same day and has a time booked for surgery the following week. The second sees the physician after waiting three weeks for an appointment, then waits eight weeks to see a specialist, then gets an X-ray, which isn't reviewed for another week, and finally has surgery scheduled for six months later, pending the review of a utilization board, which will determine the employee's remaining value to his employer. Why the different treatment for the two patients? The first is a Golden Retriever taken to a veterinarian. The second is an injured employee entering the workers’ compensation system. Maybe we need to send our injured employees to a good vet! The No. 1 cost driver of a workers’ compensation claim is that the injured worker is not getting better. But the sad reality is that the injured worker isn’t even given an honest opportunity. Everyone just wants to kick the can down the work comp road, believing the best way to save money is by limiting treatment opportunities. Look at back pain, which is the most expensive industrial injury and the most common cause of disability in patients under 45 years of age. More than five million Americans are disabled by back pain, and more than half of those will develop a permanent condition. Studies show that direct healthcare expenditures exceed $20 billion annually, and indirect expenditures associated with back-related injuries are greater than $30 billion. Disorders of the musculoskeletal system are the most common causes of absence from work in both men and women between the ages of 30 and 65. Back pain is the dominating subgroup and is the second leading cause of workplace absenteeism. See Also: How Should Workers' Compensation Evolve? There are plenty of statistics showing the direct costs associated with occupational back injuries average $37,000. Indirect costs range from $147,000 to $300,000. It therefore follows that if an employer could redirect its resources and attention to the aggressive treatment of the acute back pain patient, with a view to preventing chronicity, the company would be able to reduce costs. In fact, we have a proven system that has direct and indirect cost savings; however, it requires the employer to take control of its workers’ comp group and change the way business is being done. Unfortunately, only a small minority of employers play at the tip of the spear and way too many employers who sit on the sideline and expect everyone else to take care of the issues. So, we are challenging you, the employer, to get in the game, change your team line-up and win the game of managing your workers’ compensation division. Here’s how: Once the injured employee enters the world of workers’ compensation as either a medical, indemnity or future medical claim, the healthcare professional becomes one of the key decision makers in the employee’s recovery and return-to-work. Usually, the professional helps the injured worker recover through minimum symptomatic treatment protocols authorized by utilization review boards and return to her job in a modified duty capacity with appropriate restrictions. The employee comes back to work, with restrictions, and in most cases the safety supervisor or human resources person assists in monitoring the employee to verify that the healthcare professional’s recommendations are being reasonably accommodated. In a perfect world, this scenario may work. The employee recovers, the medical bills are paid and the work tasks are re-evaluated. However, in most cases, once the employee is injured, delayed treatment ensues, the injured worker develops co-morbidities associated with his injury, an applicant’s attorney gets involved and the reserves then begin escalating. At this point, any optimal solution becomes a distant thought. The only player who has the incentive to change the game is the one paying the bills… the employer!! How can an employer change the workers’ compensation cycle to bring about solutions for all the players involved? It takes moral courage to change your team line-up and manage your claims better. Can it be done? Absolutely, and we’ve done it. Employers have historically taken an adversarial approach to workers’ compensation claims even though the law is on the employee’s side. It makes sense to immediately engage the injured employee and set the expectations for recovery. This is part of the overall strategy to create a claims handling “team” that will align with the core competencies of the business environment. Setting the team line-up to implement an active approach to claims management will be a game changer. As an employer, here’s an outline of what this would look like:
  1. Identify your team members; business unit manager, risk manager, safety professional, claims examiner manager, claims examiner, medical director, healthcare providers, nurse case manager, legal counsel and medical fitness consultant.
  2. Have a prominent seat at the workers’ compensation round table, whether you are fully insured or a self-insured employer.
  3. Know the workers’ compensation claim life cycle and your role in influencing outcomes.
  4. Be sure the claim examiners on your files know and understand the employer’s risk management goals and objectives.
  5. Have essential job functions (EJFs) for all positions readily accessible for the healthcare professionals and claims examiner.
  6. Perform quarterly claim review meetings on all open and recently closed claims. The meetings should include your entire workers’ comp team, so discussions can progress around treating the whole person and not just the affected body part. Remember, at some point a body part adds to the potentially new claim of cumulative trauma.
  7. As the employer, limit the claim examiner case load to 100 claims or less per examiner. This allows for more in-depth understanding of claim resolution solutions in addition to claims handling by regulatory deadlines.
  8. Make sure your insurance broker supports your desire to incorporate a medical aftercare program managed by a medical fitness organization that understands the workers’ compensation process and your strategic claims management system.
Savvy Health Solutions has worked strategically with employers as part of their claims management team and addresses the whole person by focusing on improving overall strength and flexibility, postural responsiveness to activities of daily living and a motivational element that embeds the components of the program into sustainable lifestyle changes. Savvy has found that, the sooner an employee begins the program, the quicker the employee is returned to full duties, and the claim is closed:
  1. The safety person, now having a more comprehensive understanding of musculoskeletal issues, can revisit the company’s job hazard analysis for accuracy and completeness. This technique breaks each job down into individual tasks to identify hazards and focuses on the worker, the task, the tools and the work environment. The analysis is also a key component for compliance with OSHA’s injury and illness prevention program requirements.
  2. The claims examiner is educated on the work environment. With fewer claims to handle, the examiner can spend extra time on the job to better understand the work environment from an employee’s perspective. Essential job functions and job hazard analysis have more meaning once seen in action. Claims examiners will begin to understand how people do the work, in addition to meeting the expectations of the Department of Workers’ Compensation in managing a claim.
  3. A team approach helps the claims examiner to think more like a business person. Outside consultants, like Savvy Health Solutions, help the employer see a new way of claims resolution and prevention of further injuries.
  4. The effectiveness of the workers’ compensation team can be measured with metrics created as part of your annual insurance renewal process/contract or as part of your third party administrator contract renewal.
Too many internal silos and “leaving it to the claims experts” can run against a culture of treating employees with respect and dignity when injured. The employer needs to be the key stakeholder in the process, having the same key performance indicators (KPIs) for workers’ compensation as it is done for safety metrics and profitability. This methodology is counterintuitive to the typical workers’ compensation claims handling structure. Success starts with the employer and involves every single team member, business unit manager, risk manager, safety professional, claims examiner manager, claims examiner, medical director, healthcare providers, nurse case manager, legal counsel, insurance agents and brokers and medical fitness consultants. Developing a winning line-up with your team will improve your ability to control costs and reach a desired outcome for the employee first, and then the organization. Because when the injured employee recovers from his injury, restores normal function and improves quality of life, then everyone wins.

Nancy Moorhouse

Profile picture for user NancyMoorhouse

Nancy Moorhouse

Nancy Moorhouse, CSP is a multi-faceted, multi-talented business partner in the risk management/workers' compensation/safety consulting industry. With more than 28 years of experience, she influences clients in culture change and progress.