Insurance agencies
AI for insurance agencies, with policyholder data kept out.
Short answer
An insurance agency can use AI for quotes, renewals and claim letters if nonpublic personal information stays out of the AI provider's hands. Safe-Desk swaps Medicare numbers, health plan IDs, claim numbers, bank details and credit scores for placeholders before a message leaves, and reports each catch to the agency owner.
Updated September 24, 2026 · SOPHIA XT LLC
The risk
Producers and CSRs write renewal letters, claim updates and coverage summaries all day. The details that make those letters useful, such as policy and claim numbers, Medicare numbers and bank details for premium drafts, are the nonpublic personal information the agency is bound to protect.
The rules that apply
Gramm-Leach-Bliley Act. 15 U.S.C. 6801 obliges financial institutions, insurance agencies included, to protect the security and confidentiality of customers' nonpublic personal information. For insurers and producers, state insurance regulators enforce it.
NAIC Insurance Data Security Model Law (#668). The model law requires a licensee to keep an information security program based on a risk assessment, to oversee third-party service providers, and to investigate and report cybersecurity events. It applies only where your state has adopted it, and states have changed details, including small-agency exemptions. Your state insurance department can tell you what applies.
Agencies that sell health or Medicare products may hold health information, too. Safe-Desk does not sign a Business Associate Agreement, so check with your carrier or compliance advisor before using any AI tool with that information.
How Safe-Desk works in an agency
Staff keep using ChatGPT, Claude, Gemini, Copilot, Perplexity or DeepSeek. The Safe-Desk extension for Chrome and Edge, or the Safe-Desk Windows app for the ChatGPT, Claude and Copilot desktop apps, checks each message before it leaves. Client data becomes a placeholder such as [SSN_1], and only that version reaches the AI provider. When the answer comes back, the staff member who sent it sees the real values again; nobody else does. Passwords, keys and text marked privileged are stopped and sent nowhere. The owner gets a log of who sent what kind of data and which rule caught it, never the value itself, plus phone alerts and a monthly report. See how it works and the security page.
What the insurance template catches
Pick Insurance agencies at sign-up. The owner can change names, places and dates to off, flag or protect, and paste the client list so insureds' names are caught wherever they appear.
| What | What happens by default |
|---|---|
| Medicare number (MBI) | Swapped for a placeholder and reported to the owner. |
| Health plan member ID | Swapped for a placeholder and reported to the owner. |
| Claim number | Swapped for a placeholder and reported to the owner. |
| Insurance policy number | Swapped for a placeholder. |
| Vehicle VIN | Swapped for a placeholder. |
| Driver's license number | Swapped for a placeholder. |
| Bank routing number | Swapped for a placeholder and reported to the owner. |
| Bank account number | Swapped for a placeholder and reported to the owner. |
| Diagnosis code | Swapped for a placeholder and reported to the owner. |
| Credit score | Swapped for a placeholder and reported to the owner. |
| Private key | Stopped. Nothing is sent. |
| API key or access token | Stopped. Nothing is sent. |
| Login token | Stopped. Nothing is sent. |
| Password inside a link | Stopped. Nothing is sent. |
| Password or PIN | Stopped. Nothing is sent. |
| Payment card number | Swapped for a placeholder and reported to the owner. |
| ITIN (taxpayer number) | Swapped for a placeholder and reported to the owner. |
| Social Security number | Swapped for a placeholder and reported to the owner. |
| Privileged or work-product material | Stopped. Nothing is sent. |
| Date of birth | Swapped for a placeholder. |
| Email address | Swapped for a placeholder. |
| Phone number | Swapped for a placeholder. |
| Names on your client list | Swapped for a placeholder wherever they appear as written. |
| Other people's names, found from context | Swapped for a placeholder. |
| Addresses, found from context | Swapped for a placeholder. |
| Dates, found from context | Sent as written and reported to the owner. |
| Custom topics the owner adds (a matter, a deal, a code name) | Handled as the owner sets for each topic. |
Read from the Insurance agencies template in the product. In strict mode, messages with identifiers such as SSNs and account numbers are stopped instead of swapped.
A worked example
Your staff type
Write a claim status email for client Linda Park, claim number CLM-2025-448812, Medicare number 1EG4-TE5-MK73, credit score 712.
The AI sees
Write a claim status email for client Linda Park, claim number [CLAIM_1], Medicare number [MEDICARE_ID_1], credit score [CREDIT_SCORE_1].
The owner's log
Sep 24, 2026, 2:14 PM UTC: Front desk. The message was sent. Swapped out: Medicare number (MBI), Claim number, Credit score.
The staff member reads the answer with the real values back in. The log names what kind of data was caught, never the values.
What it does not do
Safe-Desk does not make a firm compliant on its own and does not certify compliance. It has not been audited for SOC 2. It does not sign a Business Associate Agreement, so it is not for patient information. Names, addresses and dates are caught from your client list and from context; context detection is a best effort, because names have no checksum. Anything your firm sets to Flag is sent as written and reported to the owner.
Setup and price
Safe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.
Questions
Does GLBA apply to a small insurance agency?
GLBA covers financial institutions, and insurance agencies are among them. State insurance regulators enforce its privacy and security requirements for insurers and producers, and many states add their own data security law based on NAIC Model Law #668. Some states exempt the smallest licensees from parts of it.
Is Safe-Desk a third-party service provider under the model law?
Treat it as one. The gate reads each message in memory to check it. The security review covers storage, encryption, retention and subprocessors for your vendor file.
Can we use it for Medicare supplement or health plan work?
For everyday office work, yes, and it swaps Medicare numbers and health plan IDs by default. Safe-Desk does not sign a Business Associate Agreement, so do not submit protected health information to it.
Related
- How to stop staff pasting client data into ChatGPTPolicy, approved accounts, a gate in the browser, and a log the owner reads.
- A ChatGPT and AI use policy for small firmsWhat the policy should say, and a one-page sample to copy.
- How Safe-Desk compares with the other ways to keep client data out of AIEnterprise DLP, browser-only extensions, private workspaces and banning AI, side by side.
- Security reviewArchitecture, storage and retention, encryption, tenancy and audit.
Try it at your firm.
Start free trialSee how it worksSafe-Desk costs $19 per staff member a month, with a 14-day free trial. Each seat includes $5 of AI a month inside Safe-Desk, pooled across the firm, and AI beyond that is billed at the model's cost plus 30%. Using your own ChatGPT or Claude through the extension or the connector costs nothing extra. Optional setup: we set it up for $149 for up to 10 staff, $10 for each extra person.