Download

The Case for Connected Wearables

Although the Apple Watch has its flaws, it has moved the idea of wearables into the mainstream and created opportunities for savvy insurers.

||
It was an event maybe even more anticipated than Neil Armstrong’s Moon shot in 1969. I had never tuned into one before, yet there I was, sitting in my pajamas at 1 a.m., frantically trying to get back onto the streaming podcast that my iPad had just dropped, as millions of other nerds the world over were trying to do the same thing. Apple’s product announcement event on Sept. 9, 2014, had drawn unprecedented interest. I certainly was expecting Apple to “do it again” – you know, change the world in a subtle yet pervasive way, as I am sure many others struggling to get onto the live webcast also believed would happen. After all, the company that Steve built had done it with iTunes, with the iPhone and with the iPad. And now we all wanted to see if Apple’s first wearable device – the Apple Watch, was going to change our lives in the same way. apple Well, we definitely saw something that early morning in September, but the realization of the promise still lies ahead, with the first retail delivery of Apple Watches not until late April 2015. What is certain is that Apple has successfully moved the idea of a connected wrist health and fitness tracker from the niche arena of health-conscious individuals to the mainstream “Joe Public.” Interestingly, even if Apple falls short this time, it has set in motion a great race with Microsoft, Google, Samsung, Fitbit and many others to fulfill and surpass the vision that we all saw in September. In 2014, world-wide revenue from the sale of wearables was roughly $4.5 billion, but, in 2015, expectations are sky-high. Some experts predict sales will increase as much as three times, fueled in the most part by the Apple Watch. So why are wearables a good thing for insurance? watch The rise of wearable fitness trackers as part of corporate wellness programs has been an emerging trend over the last 10 years. In the past, enlightened companies were giving out Fitbits to help employees track their own fitness. More recently, companies have been trading program participation and fitness data captured from such programs for discounts on their corporate health insurance. For example, Appirio, a San Francisco-based cloud computing consultancy, was able to get a 5% discount ($300,000) off its insurance bill in 2014, while BP America distributed around 16,000 Fitbits to employees as part of an integrated wellness program and claim to have put a brake on corporate healthcare cost increases by slowing them to below the U.S. national growth rate in 2013. A key ingredient to the success of these programs is the engagement of the members, so that healthy behaviors are encouraged and rewarded. In the BP example, the Fitbit data was easy to “gamify” because of the connected nature of the device. Members competed on a number of challenges, including the “1 million step” challenge, simply by wirelessly “syncing” their devices. Cory Slagle, the spouse of a BP employee, was able to trim $1,200 off his insurance bill through participation in this program -- dropping nearly 32 kilograms and 10 pants sizes and reducing his high blood pressure and cholesterol back to normal range in just 12 months. Vitality of South Africa has recognized the importance of a holistic health and wellness program for well over a decade and has built up an impressive array of statistics, including: --Participation in health and fitness programs reduces health claims by 16% --Logging fitness activities reduces risk by 22% for the unhealthiest category of participants --Participating members are as much as 64% less likely to lapse on their insurance as non-participants are --Participating members have as much as a 53% lower mortality rate than non-participants The only trouble is that participation in such programs remains minuscule, with opt-in rates in some cases of just 5% for those eligible to join. Despite the programs’ value propositions being augmented with an affinity network of providers supplying goods and services at a discount for participating members, opt-in rates and persistency remain problematic. A recent survey by PWC found that, if the connected wearable device was free to the member, then about two-thirds said they would wear a smart watch or fitness band provided by their employer or insurer. Cigna completed a connected wearable pilot in 2013 involving 600 subjects, which indicated 80% of the participants were “more motivated to manage their health at the end of the study than at the beginning.” In the U.S., United Health, Cigna and Humana have already created programs to integrate connected wearables into their policies, to create reward systems based on data sharing. In one innovative program, a “wager” penalty system was found to be three times more effective in motivating healthy behavior than the typical rewards these programs offer. The “wager” involved the member's signing up to achieve and then maintain reasonable fitness targets over the course of the year to avoid having the cost of the health screening be deducted from their salary. A key hurdle to overcome with the data generated from connected wearables is privacy and security. Individuals want to know what insights are being generated from the data being collected and want to selectively share with the program based on the perceived value they get back. They also need to know that the data continues to be secure and private once shared. Apple is working this angle through its HealthKit, which is positioned as the data control room for consolidating and securely sharing health- and fitness-related data to selected parties. There are already in-the-field health trials in progress with Stanford and Duke universities that are being powered by HealthKit. Google, Samsung and several others have also launched similar competing frameworks, so the data privacy issue is understood and being addressed by the technology companies offering products in this space. I want to mention an innovative, data-driven, life insurance program that currently doesn’t use any wearables but easily could. AllLife of South Africa provides affordable life and disability insurance to policyholders who suffer from manageable chronic diseases, such as HIV and diabetes, and who sign up to a strict medical program. Patients get monthly health checks and receive personalized advice on managing their conditions. Data driving the program is pulled directly from medical providers, based on client permission. If a client fails to follow or stops the treatment, then the benefits will be lowered or the policy will be canceled after a warning. The company assesses its risk continuously during the policy period, contrasting with the approach of other companies, which typically only assess risk once, in the beginning. This approach allows AllLife to profitably serve an overlooked market segment and improve the health and outlook for its customers. It plans to cover more than 300,000 HIV patients by 2016. The video of AllLife’s CEO, Ross Beerman, on YouTube is quite inspirational, and I recommend you see it. He says, “Our clients get healthier just by being our clients.” He also mentions the challenges of building an administration system to support AllLife’s customer-engagement model. In summary, several intersecting trends have conspired to make this the perfect time to consider the launch of insurance programs and products powered by the new insights from the data being made available through wearable fitness and health trackers: The whole fitness and healthy lifestyle perspective has entered into the mainstream culture Devices like the Apple Watch have become fashionable, objects of desire The data from these devices is easy to capture and share – no forms to fill in --The data is of clinical quality, in at least some cases, and therefore useful for actuarial models --Insurers have already started to jump on the idea of “telematics” for humans for risk pricing --Feedback from this data is able to positively modify behavior to reduce health risks and improve the quality of life for those participating I am still undecided if I’m going to be up at 1am again, this time outside the Apple Store, waiting for the Apple Watch to go on sale. However, the line outside the Apple Store that night could be very fertile ground for agents selling polices driven by the data these new devices will provide, if only companies act now and get their programs in place. Thanks for reading, and see you in the gym :-) This article originally appeared in the January 2015 edition of Asia Insurance Review.

Andrew Dart

Profile picture for user andrewdart

Andrew Dart

Andrew Dart is a partner with The Digital Insurer. He was previously the sole insurance industry strategist for CSC in AMEA and one of CSC’s “ingenious minds” globally. With more than 30 years of international insurance experience, Dart has worked in Asian cities, including Tokyo, Jakarta, Singapore and Hong Kong.

Tools for Fighting Fraud Come of Age

A technology triple threat—the Internet, databases and pervasive social media—make fighting fraud in workers' comp far easier and more effective.

Insurance fraud, that ever-present nemesis of claims professionals, has a new opponent. A technology triple threat—the Internet, extensive and accessible databases and the pervasiveness of social media—has come of age, and the result is an increased exposure of workers’ compensation fraud and a rise in prosecutions. As with many industries, the tools used in fighting fraud have evolved over the years, and today’s high-tech resources are completely different from the tools employed a mere 20 years ago. In the pre-Internet era, employers and insurance industry professionals who suspected potential workers’ compensation fraud had limited, and often expensive, options to gather evidence. Even the initial paperwork was more cumbersome. The adjuster would first complete a hand-written referral form requesting investigative services, which would slowly pass through the fax machine to materialize in the investigator’s office. That’s much different from today’s data integration of claim systems with investigative partners, where a click of a button auto-fills the referral form, and the complete claim file is populated into the investigative company’s web-based case management system. For surveillance conducted pre-Internet, the investigator would review the Thomas Brothers map, load the large VHS video camera and extra batteries in the van and drive to the subject’s last known residence to roll the dice on filming the correct person. Employers were not able to email photos of employees, and there were no online social networks to locate vacation photos and other important information. Going From Print and Tape to Digital Today’s technology allows those fighting fraud to conduct a more comprehensive pre-surveillance investigation than they could have been imagined just a few years ago. Mapping technology provides a clear visual of the subject’s residence and surrounding neighborhood. This allows the investigator to create a detailed surveillance plan including routes, local and covert tail opportunities and other strategies. Online database searches, Department of Motor Vehicle records and social networking searches provide a plethora of information. Additional tools such as GPS tracking and video streaming also have improved the success rate of surveillance. Today’s video cameras do not resemble their older brothers from the '90s. The heavy cameras of the past were best used with a tripod to hold the weight, making quick maneuvers difficult. Getting out of the vehicle to obtain film from an on-foot pursuit was extremely challenging. A large duffle bag with a hole cut in the end for the lens was hard to keep clandestine approach. And covert cameras lacked the quality needed to prove identity. Today’s compact, powerful, digital HD video cameras provide high-quality video and fit comfortably in one hand. Additionally, current covert cameras are undetectable—the camera lens can easily be part of a hat, a shirt button or a keychain. Significantly, these tiny video cameras can capture clear footage almost on par with film obtained using a standard video camera. In addition to the VHS video camera, the tools of the trade back then included a pager, a heavy cellular phone with a large antenna, a stack of phone books, a shoebox full of maps, several proven pretext scenarios and, most importantly, a Rolodex. Information that we now find on the Internet certainly was obtainable before the Internet-era, but it had to be acquired with different and often creative methods. Digging for Information While investigators today have Internet connection in their vehicles and can quickly conduct database and social network searches while onsite, the pre-Internet investigator’s most valuable tool was relationships, as information was shared by people, not technology. The investigator often had little information about the subject upon initiation of the investigation and gathered details the old school way—by digging. Investigators could be found reviewing records at the voter registration office or scanning microfiche at the court to ascertain critical information. They spent a lot of time standing in lines at public agencies and searching through endless records stored in large ledgers, microfiche or index card catalogs. The information found in public records was invaluable—current and former addresses, real property data, encumbrances, marriage licenses, divorce records, birth certificates, bankruptcies, criminal records, traffic tickets, tax liens, civil lawsuits, evictions, business licenses, professional licenses and more. While this information was vital, it was tedious work retrieving it, especially if the subject had a common name or a maiden name or aliases. Successful investigators had to be not only good at investigation, they also had to be successful at establishing connections to build a Rolodex of contacts. An effective investigator leveraged strategic connections to successfully and quickly gather information. Making connections with the people who worked in the records departments of courts, law enforcement agencies, recorder’s office, voter registration, licensing bureaus and the like, then gathering phone numbers that rang directly to desks, was essential to efficiently obtain vital information. Likewise, networking with fellow investigators in other areas to trade resources saves time. Gaining Public and Private Details Public records have always been a critical source for identifying information, financial information, business records, criminal records, civil litigation records and the like. However, those records did not provide the personal insight that we can find on the Internet. Today, a search of social networking can yield information, insight and often photographic evidence of a subject’s habits, activities, interests, schedules and behavior. If obtained legally and ethically and stored appropriately for chain of custody, this online evidence can be submitted to medical providers and the Workers’ Compensation Board and used as evidence in Superior Court, including in criminal cases of workers’ compensation fraud. To learn personal information pre-Internet, one needed connections and creative sleuthing talent. Delivery companies, utilities, contest and sweepstakes promoters, magazines, debt collection agencies, credit reporting agencies, retail and catalog ordering companies often made additional revenue by selling their customers’ personal data. Today, calling people to obtain information has been replaced with Internet searches. Several companies provide database services, including instant access to credit reporting agencies, public records, utility company records and other information. Now, what previously took many hours, if not days, of phone calls and in-person searches and cost a significant amount is accomplished in mere seconds. Pretexting—the practice of presenting oneself as someone else to obtain private information—is one strategy that has carried over from pre-Internet days. Indeed, it was all but impossible to conduct a successful investigation without it before the Internet, and it remains useful today. Pretexting is legal in many states, and investigators have historically used it to obtain needed information. A successful pretext call results in a willingness by the subject or other source to share information and, if done correctly, leaves no footprint behind, so the people are never aware they spoke to an investigator. The successful investigator uses a combination of old and new to navigate today’s complex world of insurance fraud. Pretexting still works in some cases, relationships always will matter and technology continues to evolve and to provide even better data. Workers’ compensation fraud will, unfortunately, always be with us. However, old, new and yet-to-be developed techniques will bring that fraud to light, resulting in a better system for us all. See Darlene's interview here.

Dalene Bartholomew

Profile picture for user DaleneBartholomew

Dalene Bartholomew

Dalene Bartholomew is an insurance fraud specialist, investigative training expert, recognized speaker and author. Bartholomew is vice president with VRC Investigations, a certified fraud examiner, certified insurance fraud investigator, expert witness and workers' compensation fraud authority.

Is EEOC an Unlikely Friend on Work Comp?

Surprising EEOC guidelines on the Americans with Disabilities Act may sound onerous but actually create an opportunity for employers.

The traditional school of thought since the Americans with Disabilities Act (ADA) was enacted in 1990 is that it did not apply to state workers' comp cases because they involve temporary disabilities and work restrictions. Claimants were not considered "qualified individuals with a disability" under the ADA. Even if the ADA provision for a "reasonable accommodation without undue hardship" is to be taken into consideration, the process would not begin until the claimant reached maximum medical improvement (MMI). But informal EEOC guidelines released in December 2014 stated that these traditional understandings may not be legal.

The EEOC release stated that it is "not true" that MMI should be considered the trigger for ADA-related protections for employees and obligations for employers. Employers must begin the ADA interactive process for return to work (RTW) much sooner than commonly thought. The EEOC is saying that workers' comp and the ADA process are to run simultaneously, not sequentially. In addition, the worker must be an active participant in the process. This is a major surprise to many in the industry.

I have been a proponent of using "the spirit of the ADA" to implement return-to-work practices in workers' comp programs for 25 years. (See previous ITL article, "Return-to-Work: A Success Story," June 25, 2014.) However, these new "interactive process" guidelines may change the whole practice of RTW in workers' comp because most employers and their third-party administrators (TPAs) or insurers typically postpone attempts at a reasonable accommodation until the claimant reaches MMI. That may now be construed as a violation of employee rights and employer obligations under the ADA.

In addition, the EEOC guidelines give a very broad definition of disability and when it applies under the ADA. The EEOC spokesperson said the ADA applies "all the time" and "as soon as notified" when "a medical condition has the potential to significantly disrupt an employee's work participation. . . . The only relevant question is whether the disability is now, or is perceived as potentially, having an impact on someone's ability to perform their job, bring home a paycheck and stay employed."

That is a mouthful to swallow and think about. The ADA would apply if the disability is "perceived" as having an impact on the ability to perform a job. Perceived by whom? The employer? The employee? The physician? What physician?

What does this mean for employers?

The EEOC stated that its biggest concern is the employee who has a disability but who can perform the essential functions of a job with a reasonable accommodation. The cause of the disability is considered irrelevant under the ADA. It will now be very difficult for employers to say that a worker is not a "qualified" individual under the ADA because the person obviously held the job prior to the disability.

The EEOC stated that everyone, including treating physicians, TPAs and employers, should "keep that in mind" but that only the employer is accountable for complying with the ADA. Treating physicians and employer vendors who fail to communicate with employers during the "stay @ home" process may be exposing the employer to increased risk and liability, and the EEOC spokesperson said this failure would be particularly troublesome if a treating physician who is picked by the employer doesn't tell the employee about adjustments that might allow her to work. The employer may be liable for failing to provide that accommodation even if not properly passed along. The EEOC spokesperson went on to say that physicians and vendors should be educating employers. But who, may I ask, is educating the physicians and employer vendors?

How should employers react to these EEOC process guidelines for workers' comp and other non-occupational disability programs? Employers should embrace them!

Most that is truly considered workers' comp managed care and RTW best practices are encompassed in these interactive guidelines: prompt, high-quality medical care followed by 24-hour contact between workers, treating providers and supervisors. Safe return to work, with or without reasonable accommodations, should be the goal from day one and documented in each case, even without intervention by the EEOC.

Sebastian Grasso, CEO of Windham Group in Manchester, NH:

sgrasso@windhamgroup.com

which specializes in "failed return-to-work," agrees and argues that the EEOC action should be a "wake-up call" for employers. Grasso, like several other industry experts interviewed for this article, said that in his 25-year career in the RTW business his employer/insurer clients have never brought up the ADA in workers' comp cases. He said the two problems faced on a daily basis in the workers' comp industry that severely hamper RTW efforts are erroneous job descriptions and inflexible employers who won't take injured workers back unless they are "100%." This traditional mindset and passive approach to RTW may now be considered an ADA violation, so employers and insurers may have to re-think their RTW policies and procedures.

Grasso stated; "We get injured workers back to their original jobs; it's what we do every day. It's the right thing to do; it's non-adversarial and benefits all the players in the process." This approach appears to be both within the spirit and now actual guidelines of the ADA, according to the EEOC.

Ted Ronca (medsearch7@optionline.net), a leading workers' comp and disability attorney based in New York, also stated that he never saw the ADA brought up in a workers' comp case in New York in the past 24 years. Ronca also feels employers should "champion" the new approach for workers' comp RTW programs. He recommends the first thing for employers is to establish job requirements and bring the employee into these preliminary discussions. Ask the worker for his input on reasonable accommodations and document the discussion.

Back when the ADA was enacted in 1990, many believed a slew of litigation would result from workers' comp cases. This has rarely, if ever, happened. Most experts I have spoken to are not aware of any cases, but the original fears may now come to fruition. As Ronca noted; "75% of the cases in the New York work comp system involve cases where the claimant's attorney is claiming total disability and seeking a lump-sum award." Getting that injured worker back to work is not on the claimant's attorney agenda but should be on the employer's.

Employers should not fear the ADA but embrace it. The ADA has built-in protections for employers such as that any accommodations must be "reasonable without undue hardship." This means significantly difficult or expensive. In addition, employers are not required to eliminate or reduce the essential functions of a job even temporarily. The EEOC is simply saying that employers may choose to reduce job demands and productivity expectations on a case-by-case basis and that no blanket policy is appropriate.

However, the EEOC goes on say that the ADA cannot be used to deny a benefit or privilege to which an employee is entitled, such as time off under the Family and Medical Leave Act (FMLA), workers' comp, disability, sick leave, accrued vacation or any other leave and benefits. The EEOC considers the ADA "civil rights for people with disabilities."

I just loved the EEOC comment that an employer's stay @ home policy is not a reasonable accommodation. Not only is an interactive process the right thing to do for disabled workers, it will save money, improve productivity and protect employers from potential ADA violations and obligations.

It may be time to rethink your return to work program. It's about time!

Global Outlook for P&C, Life-Annuity

EY's global outlook finds generally positive conditions for 2015, but uses of technology will separate the winners from the losers.

In 2015, the macroeconomic environment across much of the world shows significant improvement, with GDP rising in many countries and both the middle class and high-net-worth populations expanding in number and financial resources. These factors bode well for the global outlook for international property-casualty and life-annuity insurance companies. Key challenges in 2015 include rising competition, generally soft pricing conditions and tight profit margins. To effectively surmount these problems, many insurers are investing in technological solutions that improve front-end sales, distribution and customer service and enhance back-end operational efficiency and expense management. If one word could sum up the focus of insurers in 2015, it is “technology.” Many insurers are investing in digital platforms that strengthen their relationships with customers across all product classifications and geographies. Their goal is to empower both businesses and consumers to better shop for insurance, making products more transparent, easier to understand and compare. Across all regions, insurers are capitalizing on data analytics, cloud computing and modeling techniques to sharpen their market segmentation strategies, reduce claims fraud and strengthen underwriting and risk management. They are also investing in technology solutions to optimize processes, increase collaboration across the enterprise and demonstrate capital adequacy and financial solvency for regulatory compliance purposes. Now that much of the world has returned to more stable economic conditions, it makes eminent sense for property-casualty and life-annuity insurance companies to invest in digital solutions that widen margins and provide competitive differentiation. But technology is a two-edged sword, as the shocking number of data breaches clearly demonstrates. Thus, one last important “spend trend” in 2015 for international insurers—cyber security.

Our comprehensive global outlook explores the various challenges and opportunities confronting global insurance organizations in 2015. In this report, we offer our perspective on the property-casualty and life-annuity insurance markets in Asia-Pacific, Canada, Europe, Latin America and the U.S.

 Asia-Pacific
  • Although insurers in Asia-Pacific are likely to confront deteriorating economic conditions in 2015, growth prospects remain solid for life and non-life insurance products, with GDP projected to rise 5.5%.
  • Rising real estate and financial asset values are enabling insurers throughout the region to produce higher premium volume from the increased protection levels.
  • The growth of the middle class and high-net-worth population in Asia-Pacific presents the opportunity for insurers to increase their sales of personal lines insurance products, as well as health insurance.
  • Commercial lines insurance prospects remain strong, given the region’s elevated catastrophe risk, the rise in infrastructure and home building across much of Asia- Pacific and a low insurance penetration rate.
  • Insurers are challenged to invest in data analytics and modeling capabilities, as well as Internet and mobile digital sales, distribution and customer service solutions, given an increasingly technologically sophisticated population.
  • Regulations addressing insurer solvency, capital and risk management are moving to the front burner, in addition to consumer protections in the areas of data privacy and security.
 Canadian Property and Casualty
  • Profit margins for property-casualty insurance companies in 2015 are challenged by continuing low interest rates and GDP growth, the volatile investment climate and expense increases from needed infrastructure improvements.
  • A major competitive opportunity for insurers is to strengthen their relationships with customers, effectively putting them in focus across all product classifications and geographies, while digitally empowering them to better shop for and compare insurance products.
  • A key challenge in 2015 for Canadian property-casualty insurers is to improve the industry’s low level of consumer trust by integrating distribution and communication channels and providing more transparent information.
  • Opportunities to improve both commercial and personal lines sales and optimize growth are available to insurers that invest in technologies, such as cloud computing, mobile solutions and business collaboration software.
  • Building an enterprise data excellence infrastructure via more robust data analytics and predictive modeling will help insurers pinpoint new growth opportunities, optimize claims outcomes, reduce the incidence of claims fraud and mitigate bottom line risks.
  • Regulatory pressures in 2015 include demands on property-casualty insurers to become more disciplined in their risk management, capital planning and operational oversight.
 Canadian Life
  • Although providers of life insurance and annuities in Canada have endured several years of constrained growth, opportunities exist to improve competitive standing by providing products to underserved consumer markets.
  • A key challenge for insurers in 2015 is the need to develop more robust mobile digital technologies, data analytics and social media strategies to address growing consumer expectations of more refined product sales and distribution.
  • To boost sales revenue, providers of life insurance and annuities in Canada must make their products easier to understand and compare, in addition to streamlining the transaction process.
  • To enhance customer experience and enable self-service features, life insurers must consider the value of a digital platform enabling the sharing of information with and among intermediaries and consumers.
  • A key opportunity in 2015 for life insurers is to develop solutions absorbing the longevity risks of pension plan actions to lower risk, which are driven by improvements in life expectancy and the low-interest-rate environment.
  • Regulatory pressures continue to intensify, putting the onus on life insurers to improve their compliance and control functions, implementing more robust governance programs to address key business risks.
 U.S. Life-Annuity
  • Growth prospects are promising for U.S. providers of life insurance and annuities, as the overall economy improves, consumer wealth increases and interest rates creep higher.
  • Key challenges in 2015 include growing competition, especially from new capital entrants seeking to disrupt traditional market positions with new models and market approaches, aligning with rising customer expectations.
  • To succeed in this environment, providers of life insurance and annuities must expand their digital capabilities with new Internet, social media and mobile tools that empower customers and distributors with self-service features, while also making insurance products easier to understand, compare and buy.
  • A major opportunity to widen margins exists for insurers that leverage big data and the cloud to transform back offices systems and processes; these decisions must be weighed against the cyber security risks and regulatory issues they present.
  • As many consumers turn to online banking and investment services to manage their finances, they will seek similar opportunities from providers of life insurance and annuities, presenting opportunities for insurers that develop online advice and transactional models.
  • A continuing challenge in 2015 is the need to navigate the wide array of complex capital solvency and risk management regulations enacted in the aftermath of the financial crisis and overseen by competing regulatory authorities with different demands.
 U.S. Property-Casualty
  • Despite slow-to-rebound interest rates and inflationary medical and food costs, strong performance for U.S. property-casualty insurers is expected, with combined ratios returning to those in the years before the financial crisis.
  • A key challenge includes slow premium growth, which continues to be inhibited by rising competition, an overabundance of capital and inexpensive reinsurance, the latter a consequence of low insured catastrophe losses the last two years.
  • The soft pricing conditions are constraining profit margins, compelling insurers to focus on expense management and operational efficiency, reducing costs through technology upgrades, process optimization, selective offshoring and enhanced risk management.
  • The use of data analytics and modeling techniques to improve underwriting and back-office processes remains a potent opportunity for U.S. property-casualty insurers to bolster their competitive standing.
  • On the distribution front, insurers will optimize the channel mix, adding distribution outlets and expanding aggregator and direct-to-consumer models, while providing consumers with enhanced product price transparency and real-time support and service.
  • To address the evolving array of capital solvency and risk management regulations, and achieve compliance with different regulatory authorities, property-casualty insurers will need to invest in more skilled management and data analytics resources in 2015.
 Latin America
  • Insurer growth prospects are generally favorable, although market demand for property-casualty and life insurance products is evolving at different rates, given disparate economic factors across the region.
  • The expansion in Latin America’s middle class and high net worth populations, as well as the region’s technologically savvy younger generations, create opportunities for providers of automobile insurance and mobile technology warranties.
  • As more homes and office buildings are built throughout the region, the need to insure these structures from the damaging effects of natural disasters is a positive trend for commercial property and homeowners insurers.
  • A key challenge for many insurers in 2015 is the need to modernize their operations and distribution models to adapt to rising business and consumer expectations of digital, mobile and Internet interactions, particularly for commercial lines of insurance where intermediaries retain control.
  • On the regulatory front, regions are addressing global standards on capital solvency and risk management on different timetables, putting the onus on insurers to continually monitor and evaluate these developments to exploit a competitive advantage.
  • As competition throughout Latin America intensifies in 2015, insurers that best leverage data analytics and predictive modeling techniques to improve their underwriting and management of risks have the opportunity to make more profitable business decisions.
 Europe
  • European insurers will continue to be challenged on both sides of the balance sheet in 2015, as economic recovery throughout the region is overshadowed by low business investment rates, slower global growth and heightened competition in many classes of business.
  • There is a greater responsibility for insurance companies to interact with the customer, provide a range of digital communication channels, encourage loyalty and brand awareness and tailor products and services to individual needs.
  • A growing number of insurers are scaling up their analytical capabilities to be in a better position to use data in a more connected way, drawing meaningful insights at virtually every stage of the insurance life cycle from customer targeting to product design and pricing, underwriting, claims and reporting.
  • Regulatory initiatives will require greater transparency regarding the information provided to customers, revisions to relationships with distributors and greater governance and oversight over new and existing products.
  • Finance is under pressure to show it can be a better business partner in planning, budgeting and forecasting, adding more value while also responding to regulatory requirements and tax challenges.
For the full EY report from which this was excerpted, click here.

Shaun Crawford

Profile picture for user ShaunCrawford

Shaun Crawford

Shaun Crawford leads Ernst & Young's $1.4 billion global insurance business. He has been in the financial services industry for 27 years, having worked both in consulting or line management with the majority of European life assurers and U.K. retail banks at some point.

How to Link Risk and Strategy

This article, the fifth and last in a series, describes how to build a risk appetite statement and understand the links between risk and strategy.

Risk Appetite
This is Paper 5 of a series of five on the topic of risk appetite and associated questions. The author believes that enterprise risk management (ERM) will remain locked in organizational silos until boards comprehend the links between risk and strategy. This is achieved either through painful and expensive crises or through the less expensive development of a risk appetite framework (RAF). Understanding of risk appetite is in our view very much a work in progress for many organizations, but RAF development and approval can lead boards to demand action from executives. Paper 1 is the shortest paper and makes a number of general observations based on experience working with a wide variety of companies. Paper 2 describes the risk landscape, measurable and unmeasurable uncertainties and the evolution of risk management. Paper 3 answers questions relating to the need for risk appetite frameworks and describes their relationship to strategy. Paper 4 answers further questions on risk appetite and goes into some detail on the questions of risk culture and risk maturity. This paper, Paper 5, describes the characteristics of a risk appetite statement and provides a detailed summary of how to operationalize the links between risk and strategy. What are the characteristics of an effective risk appetite statement? The purpose of a risk appetite statement (RAS) is to provide clear guidance to people, at all levels, of the ranges of risk within which they are required to operate in pursuit of objectives. An RAS exists within a risk appetite framework (RAF). The RAF is the ‘’overall approach including the policies, controls and systems, through which risk appetite is established, communicated and monitored.’’[1] As a particular RAS is devolved down through an organization, its content will change based on the intended recipients. For example, a RAS at:
  • Group executive level will be high level and inclined toward expressing appetite for risks to objectives that deliver value and increase performance. The RAS will describe objectives, risks, expected returns and control(s) requirements,
  • Middle management level will articulate levels of tolerance that, if breached, will require escalation and "circuit breaking" reports, with priority given to immediate interdictions and a review of internal controls,
  • Business unit level will be more detailed and inclined toward expressing risk limits and internal controls.
A RAS that is not explicit and clearly communicated has limited value. For this reason, a RAS exists within a compendium of (risk appetite) statements that take their root at the intersection between a particular group-level objective and its associated subsidiary objective(s). The RAF, like the strategic plan, is explictly approved by the board. Properly crafted and implemented, it has powerful utility to directors in that the RAS approval process requires a series of linear RAF discussions. Wisely conducted, these discussions can result in a peeling back of the many layers of complexity  associated with operational drivers and the business model. Independent, non-executive directors (INEDs), in particular, can find this immensely useful as most INEDs will typically only possess a relatively superficial understanding of the principal operational exigiencies that drive performance. The RAF discussions will include discussions on:
  1. Explictly stated objectives[2] and where they reside on the risk appetite continuum,
  2. The associated subsidiary objectives[3] and where they reside on the risk appetite continuum,
  3. First RAS drafts at group and subsidiary levels,
  4. RAS approvals, once operational and business model implications are fully understood and satisfied.
RAF template headings: RMI offers frequently used headings that we use in helping organizations develop their RAFs.
  1. Mission/purpose/mandate:

a. Large, privately held companies will have clearly established and communicated mission statements, etc.

b. For a large number of regulated entities in Ireland, this will reflect the goal set by the parent for the subsidiary,

c. For public companies, this will be reflected in the legislation establishing the entity,

2. Strategic initiatives:

a. Very many organizations will not have a board-approved, 10-15 year strategic plan. Rather, they will have business plans within which various strategic initiatives are either implied or explicitly stated,

b. The development of a strategic plan is outside of the scope of a RAF, but each document informs the other,

3. Board (risk committee) statement of risk assurance requirements: This is a prescriptive statement addressing a wide range of requirements and would include the following, among others:,

a. Objectives that are clearly articulated, aligned with strategy and performing to expectations,

b. Risks to objectives that are identified, assessed and evaluated against approved risk criteria,

c. Risk treatment plans that are executed efficiently and effectively, increasing the likelihood of achieving objectives,

4.Objectives: As discussed above, 5. Risk appetite continuum: five-level continuum against which company (group and subsidiary) objectives are mapped relative to appetites for risk (from very high to very low) 6. Risk appetite statements:

a. Overall group RAS

b. Objectives level RASs’

c. Risk treatment level RASs’[4]

7. Risk criteria tables (risk tolerances and limits)

a. Five levels (substantial, down to negligible impacts),

b. Measurable risk limits[5]

c. Measurable risk tolerances.

How can organizations ensure that RAFs are both actionable and measurable? The RAF is to the board of directors what risk management is to the rest of the organization. As such, there is a direct correlation between the efficacy of the RAF and the efficacy of the risk management framework. Ensuring that RAFs are both actionable and measurable requires an understanding of how boards work in this particular context. When RMI converses with board members and the executive, we share what we call the RMI "Tell me, Show me, Prove it to me" questions. Questions will vary from company to company, but broad results in terms of an informal scoring that we would thereafter apply do not vary greatly. For example:
  • Tell me: (Score: 3/10)
    • How you relate your strategic plan to critical objectives and their associated key performance indicators (KPIs),
    • About your board audit/risk charter,
    • Risk management framework.
We are told about external attestation (sometimes exemplary), policies, board committees and rich processes.
  • Show me: (Score: 5/10)
    • Your strategic plan/objectives statements,
    • Your risk register and how it links to objectives, KPIs and threats/risks to the enterprise,
    • Your risk appetite statements,
    • Your risk treatment plans,
    • Your top five contingency plans.
We find that most of these documents do not always exist and that the Excel spreadsheets, word documents and Power Points (invariably with differing formats for different parts of the organization) make no consistent reference to objectives, other than obliquely. In addition, we find that original risk reports are edited on multiple occasions as they travel from original risk owners to the executive and the board.
  • Prove to me that: (Score: 2/10)
    • Your risk register is not just a list of risks,
    • Top 10 risks are the real top 10,
    • Risk owners actually provide input to the flow of information and ultimately to the risk register,
    • Known issues and risks on the ground can be escalated to decision makers, without jeopardy to the originators of information,
    • Dynamic risks can be aggregated in real time and with confidence because of your data governance practices,
    • Your crisis management team (CMT)[6] is developed and capable.
We find that risk data governance is so poor that answers to these questions can only be determined after manual searches over a number of days. This is compounded when, invariably, we also find that managers have not been adequately trained in the use of common language, risk management processes or board risk-assurance requirements. Furthermore, we find that  ‘’risk culture’’ is such that people are disinclined to speak up with regard to matters giving them cause for concern lest they jeopardize relationships with colleagues and their next reports. We therefore recommend that fundamental questions for the CEO and INEDS should include:
  1. What demonstrable evidence do you have that your top five group risks are the right top five?
  2. Can you monitor threats and risks to objectives in real time, and what kind of dynamic tests can you run on your red flags?
  3. What proofs do you have that management is capable of switching from business as usual, to delivery of credible solutions to stakeholders under abnormal/adverse conditions?
  4. Where are you in terms of risk maturity, and how do you know?
RMI also recommends the following framework, which summarizes how to ‘’Operationalize the links between Risk and Strategy,’’ ensuring that RAFs are measurable and actionable. The framework is summarized as follows:
  1. Reporting to the CEO:
Strategy/Risk Program Office reporting to the CEO and Board Audit/Risk Committee, with:
  • Focus 1: Defend operations, reputation, business model,
  • Focus 2: Exploit opportunities faster than less adaptive competitors.
2. Board Audit/Risk Committee: Executing responsibilities with regard to risk in the manner described earlier in this paper and in particular as described in the RMI answer to the FAQ: "What are characteristics of an effective risk appetite statement?" 3. Data Governance: Putting System to Process: Understanding the significance of integrating:
  • Executive and management (risk) training;
  • Inclusion of risk management KPIs in annual appraisals, and
  • Deployment of a database solution designed and specified to the ISO 31000 series
(Note: Lessons learned from the global financial crisis include that database solutions, by themselves, are not the solution. The adage, "poor information input, misinformation output," is appropriate and reminds us that tools and techniques in the wrong hands can precipitate disaster.) 4. Library of Responses to Top 5-10 Threat/Opportunity Rehearsals Seminal works that have been undertaken include:
  • 1996: The Impact of Catastrophes on Shareholder Value: Rory F. Knight & Deborah J. Pretty, The Oxford Executive Research Briefings, Templeton College, University of Oxford, Oxford OX1 5NY, England[7].
What contributed to catastrophic failure?
  • Poor crisis management,
  • Failure to recognize the significance of the event early enough in the crisis,
  • Poor stakeholder communications, including with news and social media,
  • Lack of awareness of the potential for reputational damage,
  • Failure to appreciate the importance of transparency early enough,
  • Failure to learn from prior experience (even with the same company).
Resilient Companies:
  • Have exceptional risk radar,
  • Build effective internal and external networks,
  • Review and adapt based on excellent communications,
  • Have the ability to respond rapidly and flexibly,
  • Have diversified resources.
These separate and unrelated studies similarly conclude that management’s capability to defend operations, the business model and reputation are mission-critical to sustainable performance in the 21st century In conclusion, it is our view that operationalizing the links between risk and strategy in the manner outlined above will, with positive CEO and board endorsement, fulfill the role of the board as concluded by the Financial Reporting Council (FRC) report:  Boards and Risk: A Summary of Discussions with Companies, Investors and Advisors, September 2011. References
[1]http://www.financialstabilityboard.org/publications/r_131118.htm.
[2] Strategic plans and business plans without explicitly stated objectives have no meaning.
[3] Theoretically, objectives are devolved from group to subsidiary boards. In reality, what happens is that group and subsidiary executives and directors (the latter through respective risk committees) engage in operational discussions directed at ensuring understanding, thus increasing likelihood of success.
[4] Properly constructed risk treatments are the leading indicators of the future state of health of objectives. As such, risk treatments are at the cutting edge of the management of risks to objectives.
[5] Dr. Peter Drucker: ‘’ If it can’t be measured, it can’t be managed." As with determination of leading indicators in balanced score cards, these can often be difficult to establish.
[6] CMTs are activated when issues and events that threaten to overpower operations, the business model or reputation arise.

Peadar Duffy

Profile picture for user PeadarDuffy

Peadar Duffy

Peadar Duffy is founder and chairman of Risk Management International (RMI) a firm that has been advising clients in relation to risk in Ireland and internationally for more than 20 years. He is a member of the International Organisation for Standardization (ISO) TC 262 Working Group 2, which is currently undertaking a review of the global standard for risk management (ISO 31000).

Healthcare Breaches: How to Respond

Recent healthcare breaches are a reminder that employers and insurers are legally required to take immediate, specific steps to tighten policies.

The news of a data breach at Premera Blue Cross, following on the heels of the recent announcements of large-scale,  healthcare breaches at Anthem, is another reminder that employers and other health plan sponsors, fiduciaries and insurers need to take immediate steps to assess and tighten up their privacy, data security and data breach compliance and risk management. Health plans and their employers, administrators, insurers and other vendors and service providers need to take immediate steps to conduct documented investigations, provide mandated breach notifications and take other actions that are required by the Privacy, Security & Breach Notification Rules imposed by the Health Insurance Portability & Accountability Act and other potentially applicable laws. Employers or other plan sponsors, fiduciaries, administrators and service providers also may be subject to additional responsibilities under the fiduciary responsibility requirements of the Employee Retirement Income Security Act of 1974 (ERISA), the Internal Revenue Code and a host of other laws. Whether they are subject to the additional responsibilities depends on the scope of data affected and their involvement with the affected plans, Insurance industry or other vendors providing services to these plans also may face specific responsibilities under applicable insurance, health care, federal or state identity theft, privacy or data security or other federal or state laws. (See, e.g., Restated HIPAA Regulations Require Health Plans to Tighten Privacy Policies and Practices; Cybercrime and Identity Theft: Health Information Security Beyond; HIPAA Compliance & Breach Data Shares Helpful Lessons for Health Plans, Providers and Business Associates.) The need for prompt assessment and action is not necessarily limited to health plans and organizations sponsoring, administering or doing business with the plans involved in the Premera or Anthem breaches. The report of these and other healthcare breaches, as well as recent reports of identity theft and other fraud affecting federal tax returns and other large data breach reports involving retailers and other prominent businesses are spurring recognition of the large risks and need for greater scrutiny and accountability to business collection, use and protection of sensitive personal and other data. Of course, the risk is exploding largely in response to the continued evolution of electronic payment and other business operating systems coupled with the emergence of data harvesting and other capabilities at virtually every U.S. business. Cyber criminals seem to always be one step ahead of business and government in leveraging these emerging opportunities for their criminal purposes. Everyone from the Internal Revenue Service, other federal and state government agencies and private business partners are pushing for electronic transactions and data. So, businesses are conducting more and more transactions electronically containing business and individual tax information, personal financial information, personal health information, confidential business and personal information. Meanwhile, "big data" and other business and marketing gurus also encourage businesses to use data from customers, prospects and other sources to benefit marketing and other parts of the business. As these practices have taken hold over the past decade, data breaches, other cyber crimes and risks have also grown. Privacy, identity theft and other cyber crimes have led federal and state lawmakers to enact an ever-growing list of notice, consent, disclosure, security and other laws and regulations, including the Fair and Accurate Credit Transaction Act (FACTA),the Gramm-Leach-Bliley Act, the Privacy and Security Rules of the Health Insurance Portability and Accountability Act and state identity theft, data security and data breach and other electronic privacy and security laws. As notorious breaches occur and judgments, penalties and other costs soar, federal and state regulators are looking at the need for expanded rules and penalties. (See Cybercrime Enforcement Statistics; DOJ Enforcement Priorities and Statistics.) Widening data privacy and security concerns from incidents like the recent reports of breaches at Anthem and elsewhere have prompted Congress and state regulators to hold hearings to consider the need for added reforms, and the Federal Trade Commission has just announced plans to host a workshop on Nov. 16, 2015, to look at the privacy issues around the tracking of consumers’ activities across their different devices for advertising and marketing purposes. While these and other legal and enforcement developments promise new liabilities and expenses, the business losses and customer and business partner implications experienced by Target, Anthem and other businesses illustrate the severe business consequences that inevitably result if a business appears to have failed to take customer privacy or other data security concerns seriously. The notorious Target hacking data breach event is illustrative. Target reported in late 2013 that credit and debit card thieves stole the name, address, email address and phone number from the credit and debit card records of around 70 million Target shoppers between Nov. 27 and Dec. 15, 2013. After announcing the breach, Target reported a 46% drop in profits in the fourth quarter of 2013, compared with the year before. The company announced plans to invest $100 million upgrading its payment terminals to support Chip-and-PIN-enabled cards and millions of dollars more in rectification efforts. Subsequently, Target’s losses have continued to mount, and it now faces lawsuits and other enforcement actions as a result of the breach. Beyond a general need to tighten their defenses, health plans, their sponsors, fiduciaries, administrators and vendors have specific obligations that require immediate, well-documented action when an actual or potential breach happens. The Privacy, Security and Breach Notification requirements of HIPAA require that health plans adopt specific policies and maintain and administer specific safeguards. In the event of a breach, these rules require that the health plan, usually acting through its fiduciaries, and affected service providers that qualify as business associates both investigate and redress the breach, as well as provide specific notification as soon as possible, usually no later than 30 days after the health plan knows or has reason to know of the breach. Significant civil and even criminal penalties can apply. Beyond the specific requirements of HIPAA, employers and other plan sponsors and others involved in the maintenance and administration of the health plan or the selection and oversight of its vendors often may have less-realized responsibilities. As health plan data often includes payroll and other tax data, employers, there may be specific responsibilities under the Internal Revenue Code or other laws. To the extent that the plan sponsor or another party is named as the plan administrator or otherwise exercises control over the selection of the insurer or other plan vendor or other plan operations, the fiduciary obligations of ERISA also may require a prudent investigation and other action. Brokers, insurers, third party administrators, preferred provider organizations or other managed care providers and others doing business with the health plan also may have specific responsibilities under state insurance, health care, data breach and identity theft or other laws. Under the provisions of most of these laws, leaving it to the insurer or other vendor involved in the breach generally will not suffice to fulfill applicable legal responsibilities, much less allay the fears of plan members, employees, healthcare providers and others involved with the health plan. In the face of these developments, health plans and their sponsors, fiduciaries and others working with them must take immediate action in response to breaches. Businesses also should check the adequacy and defensibility of their current overall data collection, use and security practices while remaining ever-vigilant for new requirements, as well as weaknesses in their own practices. Businesses need to build their defenses in anticipation of breaches both to withstand government and private litigation and enforcement, and the judgment of public opinion.

Cynthia Marcotte Stamer

Profile picture for user CynthiaMarcotteStamer

Cynthia Marcotte Stamer

Cynthia Marcotte Stamer is board-certified in labor and employment law by the Texas Board of Legal Specialization, recognized as a top healthcare, labor and employment and ERISA/employee benefits lawyer for her decades of experience.

Pointers on Managing GRC Issues

A Forrester report is wrong to talk about a governance, risk management and compliance (GRC) technology market; there is no such thing.

MetricStream has shared with us a November 2014 report from the analyst firm Forrester: Predictions 2015: The Governance, Risk and Compliance Market Is Ready For Disruption. (Registration required.) I have had serious issues in the past with Forrester, its portrayal of governance, risk management and compliance (GRC), its assessment of vendors’ solutions and its advice to organizations considering purchasing software to address their business problems. However, Forrester does talk to a lot of organizations, both those that buy software as well as those that sell it. So, it is worth our time to read their reports and consider what they have to say. I’m going to work my way through the report, with excerpts and comments as appropriate. “…the governance, risk, and compliance (GRC) technology market is ripe for disruption.” I have a problem with the whole notion of a GRC market. For a start, the “G” is silent! The analysts seem to forget that there are processes, each of which can be enabled by technology, to support governance of the organization by the board and others. For example, there is a need to enable the secure, efficient and useful sharing of information with the board – for scheduled meetings and throughout the year. In addition, there are needs to support whistleblower processes, legal case management, investigations, the setting and cascading of business objectives and goals, the monitoring of performance and so many more. In addition, organizations should not be looking for a GRC solution. They should instead be looking for solutions to meet their more critical business needs. Many organizations are purchasing a bundle of GRC capabilities but only use some of what they have bought – and what they do use may not be the best in the market to address that need. Finally, I have written before about the need to manage risk to strategies and objectives. Yet, most of these so-called GRC solutions don’t support strategy setting and management. There is no integration of risk and strategy. Executives cannot see, as they review progress against their strategies and objectives, both performance progress and the level of related risks. “A corporate risk event will lead to losses topping $20 billion.” What is a “risk event”? This is strange language. Why can’t Forrester just talk about an “event” or, better still, a “situation”? I agree that management of organizations continue to make mistakes – as they have ever since Adam and Eve ate the apple. Some mistakes result in compliance failures, penalties, reputation damage and huge losses. I also agree that the size of those losses continues to rise. But what about mistakes in assessing the market and customers’ changing needs, bringing new products and services to market or price-setting (consider how TurboTax alienated and lost customers)? I have seen several companies fall from leaders in their market to being sold for spare parts (Solectron and then Maxtor). Management should consider all potential effects of uncertainty on the achievement of objectives. “Embed risk best practices across the business…. Risk management helps enhance strategic decision-making at all organizational levels, and, when company success or failure is on the line, formal risk processes are essential.” The focus on decision-making across the enterprise is absolutely correct. Risk management should not be a separate activity from running the business. Every decision-maker needs to consider risk as she makes a decision, so she can take the right amount of the right risk. “Read and understand your country’s corporate sentencing guidelines.” This is another excellent point! Unfortunately, the authors didn’t follow through and point out that the U.S. Federal Sentencing Guidelines require that organizations take a risk-based approach to ensuring compliance; those that do will have reduced penalties should there be a compliance failure. “Build and maintain a culture of compliance.” Stating the obvious. It is easy to say, not so easy to accomplish. “Review risks in your current register and add ‘customer impact’ to the relevant ones.” All the potential consequences of a risk should be included when analyzing it. Rather than "customer," I would include the issues that derive from upsetting the customer, such as lost sales and market share. Further, it’s not a matter of reviewing risks in your risk register. It’s about including all potential consequences every time you make a decision, as well as when you conduct a periodic review of risks. Risk management should be an integral part of how decisions are made and the organization is run – not just when the risk register is reviewed. Forrester makes some comments and predictions concerning GRC vendors. I don’t know whether they are right or wrong. However, I say again that organizations should not focus on which is the best GRC platform. They should instead look for the best solution to their business needs, whatever it is called. I do agree with Forrester that there are some excellent tools that can be used for risk monitoring. They should be integrated with the risk management solution, with ways to alert appropriate management when risk levels change. What do you think of the report, the excerpts and my comments? Should we continue to talk about GRC platforms? Is it time to evaluate risk management solutions? How about integrated strategy, performance and risk solutions? [By way of complete disclosure, I have a relationship with a number of vendors of “GRC” solutions, including MetricStream and Resolver. I no longer have a relationship with SAP.]

Norman Marks

Profile picture for user NormanMarks

Norman Marks

Norman Marks has spent more than a decade as a chief audit executive (CAE) for major companies, with as much as $28 billion in annual revenue. He has implemented risk management, ethics programs and disclosure processes at multiple organizations.

2015 Is Watershed for Healthcare Hacking

Criminals are moving up the hacking food chain: Why use financial data to spend someone's money for a time when you can be him for life?

Predictions that 2015 would be a watershed year for stolen healthcare records are bearing out. Health insurer Premera Blue Cross has disclosed that a cyber attack that commenced in May 2014 resulted in exposure of medical data and financial information of 11 million customers. Stolen records included claims data and clinical information, as well as financial account numbers, Social Security numbers, birth dates and other personal data. The Premera breach appears to involve a record number of victims. Records for some 80 million people were stolen from the nation’s No. 2 insurer Anthem, and records for 4.5 million people were hacked from Community Health Systems, parent of 206 hospitals in 29 states, disclosed last summer. But the Anthem and CHS breaches involved the theft of personal data only, not medical records. More: 7 steps to take if your healthcare records are in the wild Personal and medical records are the building blocks for the worst forms of identity theft. With Premera, "hackers not only got the skeleton keys to lives, they got the key ring and the key chain,” says Adam Levin, chairman and co-founder of identity and data risk management consultancy, IDT911, which sponsors ThirdCertainty. “Members and employees whose data was exposed – especially their SSNs – will be forced to look over their shoulders for the rest of their lives.” Seattleites hit hard More than half of the victims — about 6 million Premera patrons – reside in Washington state, including employees of Amazon, Microsoft and Starbucks. These companies now are prime targets for spear phishing attacks. It doesn’t take much imagination for a criminal to use stolen data to create spoofed accounts to come across as a trusted colleague to send viral email and social media posts to fellow employees as a way to breach any of these corporate networks. On a lower rung of criminal activity, a whole generation of scammers who’ve mastered fraudulent online transaction using stolen credit card account numbers are ready to move to the next level, observes Lisa Berry-Tayman, senior privacy and governance advisor at IDT911 Consulting. “Criminals learn,” Berry-Tayman says. “The credit card thief steals the data, charges until the account is closed and the money is gone. To steal more money over a longer period of time, he or she must think bigger, and bigger is identity theft. Why just spend their money for a finite period of time when you can become them and spend their money for years and years?” The healthcare industry has arisen as a target because it has moved aggressively to get rid of paper records and to collect, store and make use healthcare data in digital form. The goal: to boost productivity. Trouble is the healthcare industry, like many other industries, continues to make the digital push, including intensive use of the Internet cloud, without adequately accounting for security basics, security experts argue. Healthcare data at riska three-part series: Why medical records are easy to hack, lucrative to sell “Today’s Premera breach news once again demonstrates the failure of flawed, outdated assumptions, an over-reliance on guard-the-entry-point security and simplistic single-key encryption schemes,” says Richard Blech, CEO of encryption technology company Secure Channels. “This is a quaint and dangerous approach to a 21st century problem.” Trent Telford, CEO of data security company Covata, agrees. “For many of these companies, data security has been an afterthought or something they did not deem necessary,” Telford says. “However, this breach again highlights how vulnerable the health care and insurance industries are to attacks. People are entrusting these organizations with their personal information, and it is the responsibility of corporations to take appropriate steps to ensure it is protected – this must include data encryption.” Common culprits? Premera is keeping details of how the breach was carried out close to the vest. The FBI and IT forensics specialist Mandiant, a division of FireEye, are investigating. A good guess is that Premera was the focus of a targeted attack, says Josh Cannell, malware intelligence analyst at Malwarebytes Labs. “A vast majority of cyberattacks targeting enterprise networks originate by attackers gaining access to internal networks through social engineering techniques like phishing/spear phishing e-mails that closely resemble something employees are familiar with,” Cannell says. “Once attackers have an access point inside an enterprise network, they can then use privilege escalation techniques and install malware to maintain a presence on the network.” Cannell says it’s plausible the same hacking collective hit Anthem and Premera. “Since the attack happened around the same time as the Anthem breach, and was targeting a similar organization, it seems reasonable to say the threat likely originated from the same actors,” Cannell says.

Byron Acohido

Profile picture for user byronacohido

Byron Acohido

Byron Acohido is a business journalist who has been writing about cybersecurity and privacy since 2004, and currently blogs at LastWatchdog.com.

Voice of the Customer: They're Not Happy

If you really listen to the voice of the customer, you'll hear horror stories. It can be easier to find early-stage funding than to buy insurance.

Early in November 2014, immediately following the release of the SMA research report Crowdsourcing and Open Innovation: Powering the Sharing Economy, which explored the shared economy and its implications for insurance, I received an interesting email from the CEO of a shared shipping start-up. The CEO stated, “I just wanted to let you know that I have found the hardest problem to solve as the CEO is that, after talking with 12 different insurance companies, I am still stuck on finding someone to write a policy for me! I am not sure you can overstate the tsunami of change that insurers are trying to avoid. It is frustrating to me as a CEO trying to get my company going.” My instant reaction was … what a powerful voice, and what a compelling, if troubling, customer statement! I immediately reached out to him to discuss his predicament. In our SMA research, we have written about how the shared economy is empowering individuals and businesses to access specialized skills, resources, goods or services from anyone, anywhere, at any time based on an instantaneous need. The change is spawning new business models and leveraging the combination of crowdsourcing, open innovation and technology. These new business models are challenging decades of business assumptions, models, pricing and growth that were based on the principle of ownership, rather than access or subscription. As a result, the fundamentals of insurance, from risk models to pricing, products and services, are feeling shockwaves. My discussion with the CEO about his business provides a great but jolting example of the need for these new business models, new risk models and (especially) new insurance products. He agreed to do a webinar to describe his needs and his frustrating experiences for our SMA Innovation Communities. During the webinar, the CEO shared his experience and powerful insights for insurers: It was easier to obtain $2 million for investment funding than to find insurance. The funding would likely be completed within 30 days. Contrast that with finding insurance coverage: After talking to more than 20 insurers, brokers or agents, over nearly 12 months, there is still no coverage. He found two companies, one of which works with Peers (the non-profit company backed by shared economy companies), that are bringing insurance to this market segment. But he is still awaiting confirmation. Outdated insurance business models don’t fit today’s market needs. The old models are based on historical actuarial models, rather than real, point-in-time data (i.e. coverage when driving and shipping something). The lack of visibility into capabilities of insurers and independent agents and the language barrier (the coverage needed is inland marine, which implies the use of a boat rather than land surface shipping) make it especially difficult to find exactly the right coverage. Finding the right independent agent is “tricky” because of referral chains, lack of skill sets, unclear representations, and agent incentives. In seeking coverage, he was told by many in the industry that, “Insurance has not updated the business model since the 1800s, so you won’t find anything.” What does this mean for the insurance industry? Mildly put, listening to the voice of the customer should be a wake-up call. The lack of understanding and inability to respond rapidly to new market needs opens the door to new competitors and the potential loss of customers. Just like many other industries that are being disrupted and transformed, insurance must reimagine its business models – from the mission to the customer to the product, pricing, operational and revenue models. Historically, insurance has been about the transfer of the risk of a loss from one entity to another in exchange for payment. In today’s fast-paced, changing world of emerging technologies, new business models and shifting industry boundaries, is that focus limiting our opportunities? This experience by a “could-be” customer clearly suggests we are at least limiting our future, if not risking it altogether. Other industries (and companies) are noticeably redefining their visions and focus to compete in this new world. At the 2015 Consumer Electronics Show, the media noted that Ford CEO Mark Fields sees Ford as rethinking itself as a mobility company rather than being defined by its legacy as an automotive company, and Ford is delivering a wide array of new services and experiences via the auto. Even Google’s CEO, Larry Page, has acknowledged that its vision statement – “To organize the world’s information and make it universally accessible and useful” – is too narrow, as reported in a Nov. 13, 2014, Fortune magazine article, “Google's Larry Page: The most ambitious CEO in the universe.” Page is creating a future by leveraging emerging technologies to reshape the business beyond the legacy as a search engine. Yet the view that insurance vision and business models are shackled in decades or even centuries of tradition is, unhappily, very real. This notion is reinforced in a Jan. 21, 2015, Forbes article titled “Insurance: $7 Trillion Goliath” that compares banking with insurance relative to change and innovation. The article notes that 15 years ago banking was a lumbering, vertically integrated giant that was largely untouched by the technology revolution. Today, however, there are a group of “Davids” like CoverHound, Lending Club and Square that are challenging traditional banking “Goliaths” with some digital “slingshots.” The article further observes that insurance has also remained largely untouched by the technology revolution, but that we are beginning to see the emergence of “Davids” who will challenge the traditional “Goliaths,” leveraging the technology revolution to disrupt the traditional business assumptions and models of insurance. Insurers must redefine their vision and reinvent their business model, taking into consideration the new and emerging technologies, the growing amount of real-time data, new market trends and much, much more. If they do not, they risk facing a disruption that will be devastating, when it could have been transformational, creating new relevance in a rapidly changing world. The reimagination of businesses in the context of today’s world and tomorrow’s potential are already defining and revealing future market leaders and winners. Will insurance remain focused on risk transfer products? Or will we look more broadly toward offering products and services that provide much more, enhance the lives or businesses of our customers and meet the needs of a reimagined business model, like the shared economy? The possibilities are significant. Are you reimagining your business, considering the impossible as the new possible? Insurers need ingenuity and outside-in thinking to reimagine their business as a Next-Gen Insurer and ignite a vision of possibilities. If not you, then someone else will. So dream the impossible and become a Next-Gen insurer

Denise Garth

Profile picture for user DeniseGarth

Denise Garth

Denise Garth is senior vice president, strategic marketing, responsible for leading marketing, industry relations and innovation in support of Majesco's client-centric strategy.

Rethinking the Claims Value Chain

It is now possible to make the claims process virtual -- and monitor all your vendors from a dashboard in your beach house or on your boat.

|
As a claims advisor, I specialize in helping to optimize property casualty claims management operations, so I spend a lot of time thinking about claims business processes, activities, dependencies and the value chains that are commonly used to structure and refine them. Lately, I have been focusing on the claims management supply chain -- the vendors who provide products and perform services that are critical inputs into the claims management and fulfillment process. In a traditional manufacturing model, the supply chain and the value chain are typically separate and -- the supply chain provides raw materials, and the value chain connects activities that transform the raw materials into something valuable to customers. In a claims service delivery model, the value chain and the supply chain are increasingly overlapping, to the point where it is becoming hard to argue that any component of the claims value chain couldn’t be handled directly by the supply chain network. image5 Which creates an intriguing possibility for an insurance company -- an alternative to bricks and mortar and company cars and salaries, a virtual claims operation! Of course, there are third-party administrators (TPAs) that are large and well-developed enough to offer complete, end-to-end claims management and fulfillment services to an insurance company through an outsourced arrangement. That would be the one-stop shopping solution: hiring a TPA to replace your claims operation. But try to envision an end-to-end process in which you invite vendors/partners/service providers to compete to handle each component in your claims value chain (including processing handoffs to each other.) You select the best, negotiate attractive rates, lock in service guarantees and manage the whole process simply by monitoring a performance dashboard that displays real time data on effectiveness, efficiency, data quality, regulatory compliance and customer satisfaction. You would need a system to integrate the inputs from the different suppliers to feed the dashboard, and you would also need to make certain the suppliers all worked together well enough to provide the ultimate customer with a seamless, pain free experience, but you are probably already doing some of that if you use vendors. You would still want to do quality and compliance and leakage audits, of course, but you could always hire a different vendor to do that for you or keep a small team to do it yourself. Your unallocated loss adjustment expenses (ULAE) would become variable, tied directly to claim volume, and your main operating challenge would be to manage your supply/value chain to produce the most desirable cost and experience outcomes. Improved cycle time, efficiency, effectiveness, data accuracy and the quality of the customer experience would be your value propositions. You could even monitor the dashboard from your beach house or boat -- no more staff meetings, performance reviews, training sessions -- and intervene only when needed in response to pre-defined operational exceptions. Sounds like a no-brainer. Insurance companies have been outsourcing portions of their value chain to vendors for years, so why haven’t they made their claims operations virtual? If you are running an insurance company claims operation, you probably know why. Many (probably most) claims executives are proud of and comfortable with their claims operations just the way they are. They believe they are performing their value chain processes more effectively than anyone else could, or that their processes are “core” (so critical or so closely related to their value proposition they cannot be performed by anyone else) and thus sacrosanct, or that they have already achieved an optimal balance between in-house and outsourced services so they don’t need to push it any further. Others don’t like the loss of control associated with outsourcing, or they don’t want to consider disruptive change. Still others think it might be worth exploring, but they don’t believe they can make a successful business case for the investment in systems and change costs. Unfortunately, this may help explain why claims executives are often accused of being stubbornly change averse and overly comfortable with the status quo, but I think it is a bit more complicated than that -- it all begins with the figurative “goggles” we use to self-evaluate claims operations. If you are running a claims operation, you have an entire collection of evaluation goggles -- the more claims experience you have, the larger your collection. When you have your “experience” goggles on, you compare your operation to others you have read about, or seen in prior jobs, or at competitors, to make sure your activities and results benchmark well and that you are staying up to date with best practices. At least once a year, someone outside of claims probably demands that you put your “budget” goggles on o look for opportunities to reduce ULAE costs. or legal costs, or fines and penalties, or whatever. You probably look through your “customer satisfaction” goggles quite a bit, particularly when complaints are up, or you are getting bad press because of your CAT response, or a satisfaction survey has come out and you don’t look good. Your “stakeholder” goggles help you assess how successful you have been at identifying those who have a vested interest in how well you perform, determining what it is they need from you to succeed, and delivering it. You use your “legal and regulatory compliance” goggles to identify problems before they turn into fines, bad publicity or litigation, much as you use your “no surprises” goggles to continually scan for operational breakdowns that might cause reputational or financial pain, finger pointing and second guessing. Then there are the goggles for “management” -- litigation, disability, medical, vendor -- and for “fraud mitigation” and “recovery” and “employee engagement.” Let’s not forget the “efficiency” goggles, which help you assess unit costs and productivity, and the “effectiveness” and “quality control” goggles, which permit you to see whether your processes are producing intended and expected results. And of course your “loss cost management” goggles give you a good read on how well you are managing all three components of your loss cost triangle, i.e., whether you are deploying and incurring the most effective combination of allocated and unallocated expenses to produce the most appropriate level of loss payments. Are all those goggles necessary? You bet. Claims management involves complex processes and inputs and a convoluted web of variables and dependencies and contingencies. Most claims executives would probably agree it makes sense to regularly evaluate a claims operation from many different angles to get a good read on what’s working well , what isn’t and where there is opportunity for improvement. The multiple perspectives provided by your goggles help you triangulate causes, understand dependencies and impacts and intelligently balance operations to produce the best outcomes. So even if you do have a strong bias that your organization design is world-class, your people are the best and all processes and outcomes are optimal, the evaluation should give you plenty of evidence-based information with which to test that bias and identify enhancement opportunities -- as long as you keep an open mind. No matter what you do, however, there will always be others in your organization who enjoy evaluating your claims operation, and they usually aren’t encumbered by such an extensive collection of goggles. They may have only one set that is tuned to budget, or customer experience, or compliance, or they may be under the influence of consultants whose expensive goggles are tuned to detect opportunities for large-scale disruptive/destructive process innovation or transformation in your operation. On the basis of that narrow view, they just might conclude that things need to change, that new operating models need to be explored. Whether you agree or disagree, your evidence-based information should be of some value in framing and joining the debate. Will we ever see virtual claims operations? Sure. There are many specialized claims service providers operating in the marketplace right now that can perform claims value chain processes faster, cheaper and better than many insurance companies can perform them. The technology exists to integrate multiple provider data inputs and create a performance dashboard. And there are a few large insurance company claims organizations pursuing this angle vigorously right now. I fully expect the companies that rethink and retool their claims value chains to take full advantage of integration of supply chain capabilities and begin to generate improved performance metrics and claim outcomes, ultimately creating competitive advantage for themselves. Does that mean it is time for you to rethink your claims value chain? I think the best way to find out is to put on your “innovation” goggles and take a look!

Dean Harring

Profile picture for user DeanHarring

Dean Harring

Dean K. Harring retired in February 2013 as the executive vice president and chief claims officer at QBE North America in New York. He has more than 40 years experience as a claims senior executive with companies such as Liberty Mutual, Commercial Union, Providence Washington, Zurich North America, GAB Robins and CNA.