Blog

Cloud Computing in Insurance: Where Does the Data Go, Exactly?

Joe McKendrick
Insurance Experts' Forum, November 24, 2009

Cloud computing offers some compelling value propositions, and the economics seem hard to beat. But this nascent industry appears to still be struggling with the issue of data security, and this is a show-stopper for many within the insurance industry.

This was the first and foremost issue raised by an insurance company executive in a keynote panel I observed at last week’s Interop conference in New York. The panel, which focused on enterprise cloud computing, featured representatives of end-user organizations who were given the opportunity to ask pointed questions of leading cloud vendors. John Merchant, assistant VP for The Hartford Financial Services Group, as joined by Louis Gutierrez, former CIO of the Commonwealth of Massachusetts and former CIO of Harvard-Pilgrim Healthcare and Rico Singleton, deputy state CIO for New York on the end-user side of the panel, facing off against representatives of Amazon Web Services, Google, Microsoft and Joyent.

John Merchant said that when it comes to cloud computing, “my main worry is that wee need to know where all the information my company will collect will be maintained,” adding that this applies to both non-regulated data such as customer contact information, and regulated data under the aegis of HIPAA.

Adam Selipsky of Amazon Web Services replied that such workloads need to be kept separated by a hybrid cloud and on-site computing model.

Merchant added that The Hartford has a “staggering amount of regulations”—both state, federal and international mandates. “If my data is lost in any way, if our cloud provider has an issue, I'm on the hook.”

Massachusetts' Gutierrez said that cloud vendors ought to be certified with some kind of “Good Housekeeping” seal of approval to certify that they meet key industry standards. The vendors agreed, but pointed out that such a certification doesn't exist yet.

New York's Singleton said the he felt that many internal enterprise applications just aren't suited for the cloud. He said there are “serious legal concerns and impediments,” along with “boundary issues where public cloud doesn't make sense.” The best functions suitable for public cloud computing are storage, disaster recovery and peak-time extensions, he said.

At least one vendor seemed to agree that peripheral applications are the best candidates for cloud. Don Dodge of Google urged that those companies adopting cloud computing move slowly into the process.

“Do the easy things first,” he said. “Don't make it more complicated than it is. Start with things like email and productivity applications.”

Joe McKendrick is an author, consultant, blogger and frequent INN contributor specializing in information technology.

Readers are encouraged to respond to Joe using the “Add Your Comments” box below. He can also be reached at joe@mckendrickresearch.com.

The opinions of bloggers on www.insurancenetworking.com do not necessarily reflect those of Insurance Networking News.

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments...

Already Registered?

If you have already registered to Insurance Networking News, please use the form below to login. When completed you will immeditely be directed to post a comment.

Forgot your password?

Not Registered?

You must be registered to post a comment. Click here to register.

Blog Archive

The Other Auto Insurance Telematics Shoe Drops

Progressive's decision to charge Snapshot drivers more if their driving data indicates higher risk has started the industry down a road of data-driven adverse selection.

Core Transformation – Configuring in the Rain

The whole point of core transformation is that changes at the micro level can be used as a stimulus for changes at the macro level.

6 Ways to Develop a Productive IT-Business Dialog

Relationship management 101 for keeping IT and business on the same page.

Unified Digital Strategy: Succeeding in the Digital Revolution

A unified digital strategy recognizes that all business strategies and technologies touch the customer in some way and that a one-size-fits-all channel model is obsolete.

Agile and Continuous Delivery in a Regulated Environment

Just because a development team is doing continuous delivery or packaging releases into two-week sprints doesn’t mean that code is being moved to production.

Dealing with the COBOL Brain Drain

Documentation on aging systems often is akin to tribal knowledge, and the potential for things to go bump in the night increases as these environments face generational transition.