What exactly would a request for biometric data from an insurance provider pertain to and how confidential is the information retrieved?
Biometric data serves only one purpose: to verify someone's identity. An insurance provider is probably requesting it to verify the identity of someone either applying for a policy or filing a claim. Before delving into the confidentiality of biometric data, let's take a quick look at biometrics to get a better understanding of what the insurance provider is probably doing.
Biometrics is a factor of authentication that is a physical characteristic, like a fingerprint, face pattern or the sound of someone's voice.
Because physical characteristics are difficult, if not impossible, to spoof in most cases, they're considered the strongest authentication factor. There are ways to copy fingerprints onto a gel or mold to fool a scanner, but such cases are rare.
In addition, biometric data is analog and has to be converted into digital data so computer systems can read and process it. This digital data has to be protected from being sniffed in transit or stolen from identity stores. Though rare and difficult to carry out, attacks with compromised biometrics data can be used to gain malicious access to systems.
The other issue to consider with biometric data is that once compromised, it's difficult to replace. A lost or stolen user ID and password can be reset, but a lost fingerprint or iris scan can't. Biometric credentials are set in stone. One way around this problem with fingerprints, for example, is to take only partial fingerprints. If the prints on file are stolen, more prints can be taken from other fingers or other parts of fingers.
Unfortunately, biometric data, like other authentication credentials, is considered just that -- authentication credentials and not confidential customer data to be protected. Just like other authentication credentials, biometric data should be securely collected, transmitted and stored, and that means encryption during the whole process.
It's wise to ask the insurance provider some questions about its handling of biometrics data before handing it over. But, first, ask the purpose for collecting the data. Is it to verify a claimant's identity, or for some other reason? How is the data collected and stored? Will it be encrypted?
If the company gives unsatisfactory answers, think twice before handing over any biometric information.
- Terrorist attack spurs discussion of the implications of biometric surveillance.
- Learn more about the military's use of biometrics.
- What are the possible benefits of implanted microchips and RFID tags for remote employees?
Dig Deeper on Biometric technology
Related Q&A from Joel Dubin
Ensuring authenticity of online communications is critical to conduct business. Learn how to use a public key and private key in digital signatures ... Continue Reading
Learn about the purpose of CAPTCHA challenges that enable websites to differentiate bots from authentic users to stop spammers from hijacking forums ... Continue Reading
Proper planning is at the top of the list for single sign-on best practices, but it's important to get enterprise SSO implementations off to a good ... Continue Reading