Wednesday, 20 March 2019

The line between life and general insurance is getting blurred - convergence in insurance


Almost a year ago I argued that most functionalities of traditional insurance policy administration systems (PAS) or core system, could be easily replicated by using tools which all major cloud vendors have made available to subscribers (1). 

Basically traditional PAS were basically a rule/calculation engine plus a workflow management system plus a document management system.

Think about it.

Any policy you buy today, the premiums you will pay over your lifetime, based on current assumptions, are already calculated. After all that's how the insurance company priced the product. All the say, age-driven, premium changes exist at inception. Then it's just a question of applying these rules.

The rules are part of workflows. First for acquisition, then for renewal and re-evaluation. (There also would be workflows for claims...)

Finally, all this is managed in a document management system since there may be lot of paperwork. Of course the insurer can control that within limits set by local regulators, go as electronic as possible...

Technology has moved on. Now with or without blockchain, large chunks of workflows and document management can be automated. Blockchain's "immutability" of the past helps in building and maintaining trust and avoiding post-hoc retrospective changes, but this is more important for organisations that do not have reputation/trust to start with.

Smart contracts are not the privilege of blockchain. Many smart contracts built on blockchain rely on the immutability of the past and the lack of trust to work. But this need not always be the case. (Afterall you trusted you efforts on pokemon-go with all its complex rules, real time activity, activity and reward storage to non-blockchain based systems, but I am not saying blockchain is useless, far from it, but this is not the topic of the blog)

One not so new but now more widely practiced approach is containerisation with orchestration that further makes the little machines built for specific purposes more portable, secure, and cheaper to operate.

So in sum, I am an even more strident advocate of running the insurance policy administration functions (and more) without a clunky traditional core system simply because it can be done, cheaper, better, faster, more reactive, and even proactive.

Today I am going further in my charge towards the traditional insurer windmill.

I am going to give some reasons why I believe that the dichotomy between life and general insurance is an anachronism. To me, as insurance becomes more and more of a service that is consumed in a context, the distinction between life and GI becomes irrelevant.



First of all, let me be clear; I believe in horses for courses. When you do your financial planning, whether on the back or an envelope or using complicated AI, it pays to have clarity as to what your objectives are. Your financial planner or the chat bot you use should help you.

I will also make a disclaimer here, I own a few traditional policies, endowments rather than term policies because when I made the purchase, monthly investment options were limited (yes I am that old and backward), hence endowment products offered me a nice combination.

But this isn't the case anymore, regular (even irregular) savings/investment plans are common.

Hence, today it is easy to split savings/investment goals from insurance/protection goals.

Insurance and Savings/Investment can easily be decoupled
So my first step towards my argument is that it is not necessary to couple insurance and savings thanks to democratisation of savings and investment.

People buy life insurance so that their loved ones have something to fall back on in case of their deaths or themselves in case of disability (death and total permanent disability (tpd) usually coupled).

So if someone plans properly, decouple their goals, and "life insurers" come up with right products, life policies can become plain, no-frill term policies. The investment bit of endowment of life policies can be removed. Of course though, traditional life insurers would not want to do that, their profits would suffer.

But in any case, why, you argue would that affect the dichotomy?

One of the major differences between LI and GI today is the complexity of products, including the 'life-span' of the products, therefore the pricing and actuarial wizardry, including reserve and solvency calculations required.

But if life is reduced to term, then despite the still different product life-spans, the degree of complexity falls. Yes, you will still have non-cancellable features, but the degree of complexity drops by quite a lot with term policies.

Lifestyle choices – more people have taken care of themselves
Another step is that the way people need insurance is changing because people's lifestyles are changing.

I bought insurance quite late compared to my contemporaries. The reason is simple, I argued that my parents were taken care of by their savings/pension schemes, and if I died the main impact would be emotional (I hope haha). It is surviving that was my concern and I saw insurance as compulsory savings, so in my mind the 2 reasons were - in case I survive something bad, tpd kind of stuff and in case I survive longer and need to fund my own 'retirement'.

NTUC Income has a nice campaign in Singapore, and has the same spirit: the best gift for your children is protecting your own retirement (2). So they have seen the increasing need for inter-generational independence that has arisen with the loosening of extended family structures, urbanisation and focus on self or a really small nucleus that shrinks over time.

Basically while you have dependents a term policy would be useful, once you don't you only need the fruit of your savings/investments. Hence, decoupling insurance and investment works in this area too.

Lifestyle choices – temporary increase in risk, convergence more GI-like less Life-like
To this lifestyle change I would add an extra one: the temporary increase in risk that warrants insurance. For example, many health or life policies exclude cases when the insured party is taking place in “competitive sports”. Hence as the insured you have 2 choices, either you pay even more for a policy that doesn’t have that exclusion if you can find one, or you purchase coverage just for this period where your main policy does not apply.

Personally, I find the second option more attractive. Now, is the policy that covers my life for say  specific day, a life policy (covers life, pays fixed amount upon death…) or a general policy (short term, single premium, relatively simple actuarial calculations…)?

Basically the lines between the 2 are getting blurred, and in my view, the policies are taking on more characteristics of general insurance than life. Taking a look at some such products available, it becomes obvious that this is a repurposed product, likely a travel product (3), not a product built for purpose.

Big Data and Synergies/Convergence
One important aspect of the dichotomy is that the focus is on the organisation, on the operations, the actuarial work required, in other words, the focus is on the navel. "You know, a life product is so different from a GI product, we need to get that product right!"

What the navel gazers are missing out on is customer-centricity. What makes you think that this product in your navel is what customers need?

The potential customer does not care whether he/she is buying a life insurance, or a general insurance, all the customer needs is that the specific protection that they require is given to them at an affordable price and via a channel they prefer and preferably right before they need it.

The potential customer generates tons of data that an insurer can have access to and learn about the needs of each individual, even proactively make the offer. This is something insurers have been slow to learn.

Contrary to banks who are used daily by their customers and who see constant interaction with them as a matter of routine, insurers have traditionally only interacted with their customers (and that via agents/brokers) quite rarely. Hence not only do the organisations know only little about the customers, but the whole sales process insurers have been using is heavy, making insurance an important decision – it is when the consequences of decisions are long term, financial investments quite heavy, and there is limited information on the customer. Hence there is a lot of thought that has to go into advice, planning, and managing risks.

But now, with big data, insurers can learn more about their customers, and at a minimum get a better estimate of the risk each customer faces daily, this can allow the insurer to manage the risk, offer a more appropriate premium to the customer. (The actuarial community should be looking at big data, else their guild-like monopoly will disappear)

Furthermore, the information that can be obtained is so granular that very specific risks can be insured. For example, if I know you have been looking at high altitude climbing, and have ordered specialised gear, the moment you book a trip to Nepal, I can make you a customised offer that will protect you specially for the risks you may encounter, not only to your life, but also including problems with equipment, and include emergency repatriation. If I am smart enough, I can even consult local weather forecasts, and price this is, and keep you informed. This offer that I have customised for you, is it a life product (travel may be?) or a general insurance product (equipment) or is it both (and hence neither)? How about I go further, work with partners and go beyond insurance so our composite offer takes care of your welfare? That brings us to the realm of platforms.

Platforms

So where does that bring us? I believe insurance is a service just like another. Insurance is being slowly but surely embedded in other products services:
  • buy a car and get offered a comprehensive protection policy that will ensure your car will be repaired and any third party damage covered
  • get a mortgage and buy a reducing balance term policy to protect your family’s roof in case something happens to you
  • buy a phone even, and get extended warranty for repairs, or even get a replacement in case your phone gets damages
  • buy an airline ticket and get compensated for delays (even almost instantly) or lost luggage
  • buying a long distance bus ticket and have insurance embedded in
  • run a marathon and get extra protection for the day of the race as part of your race pack

To me this is just the beginning; insurance companies are barely scratching the surface when it comes to collaboration with other product/service providers. 

Numerous studies have shown that most people are underinsured, often because they underestimate the risks, often because the current forms of insurance they have access to are too expensive, often because insurance does not reach them. The latter is a result of business strategies employed by traditional insurers, and whether consciously or unconsciously the strategies are driven by the product set available, chunky-clunky, with strict dichotomy between life and GI – you have to adjust your needs to our products. However, less traditional insurers have been hugely successful (4).

We have seen insurers collaborate with other platforms grab and ZhongAn “The tie-up will address the usual pain points of insurance discovery, unaffordable premiums and payment options by allowing for insurance premium payments to be adjusted and automatically deducted through GrabPay or its affiliate payment partners”(5), but this is not going far enough, this is an insurer taking advantage of a new channel and payment platform. Another interesting idea is from Alibaba (6), but why are the platforms led by non-insurers?

Simply because too many insurers are too fixated on life/non-life dichotomy, on old fashioned table driven (granted it is probably in a neat interface rather than dusty book nowadays, but still is fixed rule driven) risk estimation, on being afraid of customer interaction (because this often means complaints of claims).

Conclusion
In my view, in the future, insurers will be doing business via platforms where offers from various industries will be available and customers consuming insurance in small chunks sometimes almost unknowingly, probably after having a term type protection, similarly investing as and when they feel like it. Successful insurers would have learnt to be customer centric to such a degree that they are able to proactively tailor protection/coverage to short term lifestyle experiences of their customers. For that, being able to mash together all sorts of coverage will be critical, and hence insurers who harp on the distinction between life and non-life (GI) are very unlikely to be winners.

  1. http://thegatesofbabylon.blogspot.com/2018/03/re-imagining-insurance-company-do-you.html
  2. https://www.marketing-interactive.com/ntuc-income-worst-parents-ad-on-the-brink-of-virality-what-makes-it-tick/
  3. https://www.kl-marathon.com/media/downloadablepdf/2018/12/17/scklm-2019-summary-of-cover.pdf
  4. http://www.bimamobile.com/our-services/
  5. https://asia.nikkei.com/Business/Companies/Grab-partners-with-China-s-ZhongAn-to-offer-insurance
  6. https://www.aseantoday.com/2017/11/alibabas-entry-into-chinese-online-insurance-market/


Wednesday, 27 February 2019

History of and thoughts on the 14200 HIV related leak in MoH Singapore


The Singapore health sector has been hit with a second information leak in a few months. After the hacking episode at SingHealth, there has been a willful disclosure of confidential information from the Ministry of Health (MoH). The case is made more serious because of the potential impact of the leak on peoples’ lives. It contains the names and contact details of 14,200 people who have been found HIV positive in Singapore and some of their contacts.

While the current case only became public in January 2019, this is part of a much longer story, where the 2 principal actors are Mr Brochez a US citizen, and Dr Ler, a Singapore citizen and who briefly headed the National Public Health of the MoH.

Many of you may know, I am quite serious about data privacy, so I decided to try and put the whole story in perspective. This is a story 12 (or more) years in the making, it really does read like a novel, but my aim is to help think about data security/confidentiality then and now.

I hope the infographic above is readable, it wasn’t easy trying to fit so much information into 1 single page.





  1. The story starts in 2007 with Mr Brochez and Dr Ler meeting online, liking each other’s internet personalities
  2. Mr Brochez moved to Singapore in January 2008; as part of the requirements for an employment pass required for foreigners to work in Singapore, he was required to submit to an HIV test. People who are found to have HIV positive would not be allowed to work in Singapore.
  3. Mr Brochez first took the HIV test in march 2008, at the Singapore Anti Tuberculosis Association clinic using a fake Bahamian passport. He tests HIV positive.
  4. Dr Ler draws his own blood, Mr Brochez turns up at the “My family clinic” in Commonwealth where Dr Ler is working, and Dr Ler submits his own blood as that of Mr Brochez for testing. This sample test HIV negative and Mr Brochez is granted the employment pass (EP). He works in private practice.
  5. In September 2008, Mr Brochez applies to teach at Temasek Poly and is hired.
  6. On Jan 1 2010, The New Paper publishes an article on Mr Brochez, where he explains his genius, how he was brought up by his famous doctor mother, was the youngest in Princeton (at 13) went to Vanderbilt (where he obtained 2 Masters) among other claims. At a later stage these were all shown to be fake.
  7. In February 2011, Mr Brochez is granted a Personal Employment Pass (PEP) by the Ministry of Manpower (MoM)
  8. In March 2012, Dr Ler starts his stint as Head of the National Public Health at the MoH.
  9. In November 2012, Mr Brochez informs an MoH Director that Dr Ler showed him screenshots of the database of people who have tested HIV positive, and informed someone else he was HIV positive. MoH launches an investigation, but Mr Brochez subsequently does not cooperate.
  10. Dr Ler’s role as head of National Public Health at MoH ends in May 2013.
  11. In October 2013, MoM receives information that Mr Brochez is HIV positive, and asks him to cancel his PEP by 8 November 2013. Mr Brochez replies that he will prove that he is HIV negative.
  12. On November 22 2013, Dr Ler again passes off his blood as that of Mr Brochez for him to retain his PEP.
  13. Dr Ler and Mr Brochez deny again that the blood tested was not that of Mr Brochez.
  14. Dr Ler resigns from MoH in January 2014.
  15. Mr Brochez and Dr Ler get married in April 2014 in New York.
  16. In May 2016, Mr Brochez is found in possession of 'Ketaminised Cannabis'. During the search his education certificates were also found, and they were found to be forged.
  17. In May 2016 he MoH also makes a police report against Mr Brochez after learning he has a list of people who tested HIV positive in Singapore and their contacts.
  18. Dr Ler admits he used his own blood to substitute that of Mr Brochez in the HIV tests that were negative.
  19. In June 2016, Mr Brochez is remanded for numerous fraud charges including lying about his HIV status, and drug related charges.
  20. Dr Ler is charged under the Penal Code and the Official Secrets Act; for OSA the charge was relating to not keeping possession of a thumb drive with details of the HIV registry.
  21. In July 2017, the government disables the use of non-authorised portable storage devices as part of a government wide tightening of security.
  22. In April 2018, Mr Brochez finishes his sentence and is deported.
  23. In May 2018, MoH makes a police report after learning that Mr Brochez still has a copy of the registry.
  24. On January 22 2019, the police informs MoH that a list of people who tested HIV positive in Singapore and their contacts has be leaked online.
  25. On January 24 2019, the MoH confirms that the data was for the registry as at January 2013.
  26. MoH and the police work to disable access to the information leaked online
  27. MoH confirms the leak to the public on January 28 2019.


What do you think of the case?\

First of all this case is very different from the SingHealth case where people hacking was involved, and the first response was to sweep things under the carpet and not even report the breach. In this case, I feel, the first priority of MoH was to inform the people affected and provide them with the support they need. This must be a very traumatic time for them.
Secondly, I think this is a story of official blindness or stupidity.


  1. The unnamed private practice that employed Mr Brochez in 2008 must have reviewed his education certificates before deciding to hire him.
  2. The MoM too must have checked his education certificates in 2008; Vanderbilt does not have millions of Masters Graduates.
  3. Temasek Poly also reviewed the education certificates in September 2008, and must have interviewed Mr Brochez thoroughly; as a lecturer he would have the power to help mould the minds of many young people.
  4. The New paper also swallowed the stories of Mr Brochez hook, line and sinker.



Ok, now to the elephant in the room…

  1. MoH was told since November 2012 that Dr Ler had, in his possession screenshots of the HIV registry. While it has been argued by the MoH that people in Dr Ler’s role needed to be able to download the data (more on that later), I fail to see why screen shots shown to people who are not authorized to see the database do not set alarm bells ringing.Yes, Mr Brochez decided not to cooperate with the enquiry, but in view of the risk (the damage caused to people on the registry if their details were leaked), a more serious and sustained effort should have been made.But then, that brings up the point; if data is protected by the Official Secrets Act, and that data relates to peoples personal details and contact details, what legitimate use can one really have to mass download the records? Wasn’t the usage of the database tracked?
  2. In May 2016, when presumably a copy of the list was discovered when searching the apartment, why didn’t the authorities consider that there may have been copies not on-site? At the least, couldn’t the sentencing of Mr Brochez be subject to his having relinquished all the copies and undertaking not to use them? 
  3. Why did the MoH not institute increased protection for the database and wait until the government-wide initiative to do so? MoH had already known for sure of the issues since at worse June 2016; Dr Ler was charged with regards to OSA, but still the disabling of downloads to unauthorized storage only happened in July 2017.

  

In sum

I think MoH did the right thing in focusing in the potential fall-out of the leak and worked to disable access to the information and counselling the people potentially directly impacted. However, the whole saga revealed a very loose approach to data security: allowing and even justifying mass download of the database (I actually think the intent would be much much worse if it was downloaded 1 record at a time) by saying it was required by the role Dr Ler was playing as Head of National Public Health, to me, shows that the people who created and thought of the use of the database did not take into account the risks.

On the other hand, I find it really interesting that the original employer of Mr Brochez who sponsored his original EP (unless this was an organization somehow linked to Dr Ler – this is something I could not find out), the MoM, Temasek Poly, all failed to see that his academic credentials were forged.

Latest Development 
In a latest development, Mr Brochez has also made available a list of 13 HIV positive people who were due for medical check-up at Changi Prison on March 28 2018 (15). Mr Brochez finished his sentence and was deported in April 2018.

Whether it is the prison service, Parkway Shenton (who is contracted to carry out the tests), it is really amazing how little consideration they give to the data they are guardians of. How can a person, who is in prison, have access to a list of fellow patients, their identities and identity card numbers…

In a facebook post over the weekend (16), Mr Brochez also maintained that he has tried to inform the authorities of the leaks since 2012, and claims that neither he, not Dr Ler, were the ones who copied the information, but rather a lawyer in Singapore with whom his husband was having an affair.

The police and prison service responded (17).

Needless to say that this saga is not likely to end so soon, but what I hope had ended is data leaks due to bad (allowing mass download) or lax policies (not verifying educational certs, not tightening procedures immediately after leaks found).



  1. https://www.tnp.sg/news/singapore/doctor-jailed-switching-hiv-positive-blood-his-own
  2. https://www.moh.gov.sg/news-highlights/details/unauthorised-possession-and-disclosure-of-information-from-hiv-registry
  3. https://www.channelnewsasia.com/news/singapore/hiv-positive-records-leaked-online-singapore-mikhy-brochez-11175718
  4. https://www.channelnewsasia.com/news/singapore/hiv-data-leak-what-we-know-about-mikhy-farrera-brochez-11175940
  5. https://mothership.sg/2019/01/14200-moh-hiv-leak/
  6. http://news.asiaone.com/News/Education/Story/A1Story20091228-188488.html
  7. https://www.todayonline.com/singapore/doctor-accused-helping-hiv-positive-boyfriend-deceive-mom
  8. https://coconuts.co/singapore/news/american-conman-deported-singapore-leaked-information-14-2k-people-diagnosed-hiv/
  9. https://www.tnp.sg/news/singapore/doctor-jailed-switching-hiv-positive-blood-his-own
  10. https://www.straitstimes.com/singapore/courts-crime/fake-american-professor-who-used-boyfriends-blood-for-hiv-test-jailed-28
  11. https://www.channelnewsasia.com/news/singapore/public-servants-barred-from-using-unauthorised-usb-drives-9031718
  12. https://www.straitstimes.com/singapore/suspicions-about-leak-emerged-as-early-as-in-2012
  13. https://www.straitstimes.com/singapore/health/how-the-hiv-data-leak-was-handled
  14. https://www.businessinsider.sg/parliament-9-questions-on-hiv-registry-data-leak-addressed-by-singapores-health-minister-gan-kim-yong/
  15. https://www.channelnewsasia.com/news/singapore/hiv-data-leak-mikhy-brochez-singapore-prison-service-11251244
  1. https://www.singaporenewsgazette.com/joint-spf-sps-statement-in-response-to-allegations-made-in-mikhy-brochezs-facebook-post-2/