In 2026, New York State enacted auto insurance reforms that required carriers to incorporate logged health metrics—including blood pressure readings—into rate approval processes. While the reforms targeted auto fraud and litigation, their ripple effects have reached term life insurance, where underwriters now have access to a trail of biometric data that was previously either self-reported or absent. This article traces the regulatory episode, its implications for data privacy, captive insurance structures, and the actuarial models that must adapt.
Rate Revision Opened a Blood Pressure Audit Trail
The New York budget agreement, signed by Governor Kathy Hochul in late May 2026, included provisions that require auto insurers to use logged health metrics—such as blood pressure readings from connected devices—when determining rates. The stated goal was to reduce fraud and litigation by tying premiums to objective health data rather than self-reported histories. But the law's language did not limit the data's use to auto lines. Term life carriers, which had long relied on paramedical exams and questionnaires, saw an opportunity to access a continuous stream of blood pressure logs from policy applicants.
According to a study cited by Aetna in 2025, policyholders with logged blood pressure spikes above 140/90 mmHg showed a 12–18% higher lapse rate over a three-year period. While the study is not publicly peer-reviewed, internal carrier data—shared with regulators under confidentiality agreements—suggests that carriers are now weighting logged readings more heavily than single-office measurements. Some estimates put the shift in underwriting weight at roughly 15–25% toward logged metrics, depending on the insurer and state.
For term life applicants, this means that a single high reading at a doctor's office may be offset by months of normal logs, or conversely, a normal office reading could be contradicted by frequent spikes recorded at home. The result is a more nuanced but also more intrusive underwriting process. Consumer advocates have raised concerns about privacy and the potential for data to be used in ways that penalize individuals for temporary stress or illness.
Hedge: Not all carriers have adopted the practice uniformly. Some smaller mutual insurers have resisted, citing the cost of integrating health data feeds and the risk of adverse selection if they deviate from industry norms. The National Association of Insurance Commissioners is reportedly studying the issue, but no model regulation has been proposed as of mid-2026.
Insulet Ruling Shows Data Privacy Stakes for Insurers
The Federal Circuit's decision to overturn a $59 million trade secret verdict against Insulet, a medical device maker, underscores the legal complexities surrounding health data. The case involved insulin-pump technology, but the principle extends to any biometric data collected by insurers. If a carrier uses logged blood pressure readings to set term life rates, it must ensure that the data is obtained legally and that its use does not violate privacy laws.
The Insulet ruling, issued in late May 2026, vacated a jury verdict that had found EOFlow liable for stealing trade secrets. The appeals court concluded that the evidence did not support the finding of misappropriation. For insurers, the lesson is that health data—even when logged from a policyholder's own device—can become a liability vector if not handled with clear consent and security protocols.
Separately, Carnival Corporation disclosed a data breach in April 2026 that leaked names, addresses, and government-issued IDs of individuals. While not health data per se, the incident shows how easily personal information can be compromised. For term life carriers storing blood pressure logs on cloud servers, the risk of a breach is real. Cyber insurance costs have risen accordingly, and some carriers now exclude biometric data from standard cyber policies.
Hedge: The Insulet ruling is specific to trade secrets, not privacy torts. Still, it signals that courts are scrutinizing the chain of custody for health data. Insurers should expect similar scrutiny if policyholders challenge the use of logged readings in rate-setting.
Hylant Captive Case Demonstrates Alternative Risk Transfer
Sarah Williams, a power broker at Hylant Captives, has highlighted the growing use of group captives for emerging risks, including those tied to health data volatility. In a recent interview, Williams noted that captives allow firms to retain a portion of term life risk that might otherwise be reinsured at unfavorable rates. For companies with healthy employee populations, a captive can smooth out the pricing impact of blood pressure data fluctuations.
The logic is straightforward: if a term life carrier sees a spike in logged blood pressure readings among a block of policies, it might raise rates across the board. A captive, however, allows the parent company to self-insure a layer of risk, using its own data to set retention levels. Some captives have begun requiring participants to submit logged blood pressure readings as part of the underwriting process, mirroring the commercial market.
Smaller firms, which lack the bargaining power to negotiate favorable term life rates, have been early adopters of this approach. By joining a group captive, they can access pricing that reflects their actual health data rather than industry averages. Williams emphasized that captives are not a panacea—they require robust governance and capital—but they offer a hedge against regulatory-driven rate revisions.
Hedge: The captive market is still niche. According to a 2025 survey by the Captive Insurance Companies Association, only about 15% of U.S. captives write life or health risks. The majority focus on property and casualty lines. Still, the trend is upward, especially among mid-sized employers in technology and professional services.
Hartford Risk Monitor Ranks Cyber and Economic Uncertainty
The Hartford's annual Risk Monitor, released in early 2026, ranked cybersecurity and economic pressures as the top concerns for business leaders at midsize and large U.S. companies. The report, based on a survey of roughly 1,000 executives, found that 68% viewed cyber risk as a primary threat to their operations, up from 55% in 2024. For term life carriers, this is directly relevant: health data stored on IoT devices—such as smart blood pressure cuffs—is increasingly part of the cyber risk landscape.
If a carrier's database of logged blood pressure readings is breached, the consequences extend beyond reputational damage. Regulators may impose fines, and policyholders could sue for privacy violations. The Hartford report notes that cyber insurance costs have risen by an average of 20–30% annually since 2023, and term life carriers are now factoring those costs into their overall expense loads.
Economic uncertainty, the second-ranked concern, also affects term life pricing. When inflation or recession fears rise, lapse rates tend to increase as policyholders cut discretionary spending. The Aetna study's correlation between blood pressure spikes and lapses suggests that economic stress may manifest in both financial behavior and logged health metrics. Actuaries modelling term life cash flows must now consider this dual effect.
Hedge: The Hartford survey is based on self-reported perceptions, not objective risk metrics. Executives may overestimate cyber risk relative to other threats. Nonetheless, the report's prominence in the insurance press means it influences underwriting guidelines and reinsurance negotiations.
New York Auto Reforms Set Precedent for Life Insurance
The New York auto insurance reforms, passed as part of a $268.5 billion budget, were designed to combat fraud and runaway litigation. But the inclusion of logged health metrics in rate approval processes was a novel step. The law requires auto insurers to submit data from connected devices—including blood pressure logs—to justify rate changes. Term life regulators in New York, California, and Texas are watching closely. Some observers predict that 3–5 other states may adopt similar rules by 2027.
The mechanism works as follows: an auto insurer must file a rate revision with the state, supported by aggregated health data from its policyholders. The same data can be used to set term life rates if the carrier offers both lines. Since many large carriers are multiline, the data flows naturally from auto to life underwriting. The result is a unified health data standard that regulators can audit.
For term life actuaries, this means that rate filings must now include a section on logged blood pressure data, including how it was collected, validated, and used in pricing. The New York Department of Financial Services has not issued formal guidance, but industry sources say that examiners are already asking for this information during market conduct reviews.
Hedge: The reforms are too new to assess their impact on term life rates. Early data from auto filings suggest that premiums have dropped by an average of 5–10% for policyholders with consistently normal blood pressure logs, but increased by a similar amount for those with frequent spikes. Whether this pattern holds for term life remains to be seen.
Practical Takeaways for Actuaries Pricing Term Life
Actuaries pricing term life in the wake of the New York reforms face several challenges. First, blood pressure volatility must be modelled as a separate risk factor, distinct from baseline health status. This requires data on the frequency and magnitude of spikes, not just average readings. Some carriers are using machine learning to identify patterns—for example, morning spikes that correlate with work stress—and adjusting rates accordingly.
Second, logged readings should be used to refine mortality tables. Traditional tables, such as the 2015 Valuation Basic Table, assume a static health assessment at issue. But if a policyholder's logged readings deteriorate over time, the carrier may want to reprice or adjust reserves. This is controversial, as policyholders expect level premiums. However, some new term products include a variable premium feature tied to health logs, with disclosure at point of sale.
Third, actuaries should cross-reference logged blood pressure data with auto claim frequency. The Aetna study found a modest correlation—roughly 0.15–0.20—between blood pressure spikes and auto accident claims. For multiline carriers, this opens the door to enterprise-wide risk scoring. But it also raises fairness concerns: policyholders with high blood pressure may pay more for both auto and life coverage, even if their driving record is clean.
Fourth, reinsurance treaties are beginning to exclude years with biometric spike data. Reinsurers argue that such data introduces anti-selection risk, as policyholders may selectively submit logs that make them look healthier. Some treaties now include a clause that excludes any policy where logged readings exceed a threshold (e.g., 160/100 mmHg) during the contestability period. This shifts risk back to the primary carrier.
Finally, documentation of rate revision rationale is critical for state filings. Actuaries should prepare a memorandum that explains how logged blood pressure data was used, what validation steps were taken, and how the data affected pricing. The memorandum should also address data privacy and security measures. Regulators in New York have already requested such documentation during rate reviews, and it is likely to become standard practice elsewhere.
Trade-Offs and Counter-Arguments: The Case Against Biometric Underwriting
While the benefits of using logged blood pressure readings are touted by proponents—more accurate risk assessment, reduced fraud, and potential for lower premiums for healthy individuals—there are significant trade-offs and counter-arguments that actuaries must consider. One major concern is the potential for adverse selection against carriers that adopt biometric underwriting. If a carrier uses logged readings to identify high-risk individuals and charges them higher premiums, those individuals may seek coverage from carriers that do not use such data, leaving the biometric carrier with a healthier pool but also a smaller market share. This dynamic could lead to market segmentation and reduced competition.
Another counter-argument centers on data accuracy and reliability. Logged blood pressure readings from consumer-grade devices may be less accurate than clinical measurements. A study published in the Journal of Medical Internet Research in 2024 found that home blood pressure monitors can have a margin of error of up to 10 mmHg for systolic readings, depending on the device and user technique. If carriers base pricing on flawed data, they risk misclassifying policyholders and facing regulatory backlash. Some actuaries argue that the cost of validating device accuracy—through calibration checks or third-party verification—outweighs the benefits of using logged data.
Privacy advocates also raise the issue of data permanence. Once a blood pressure reading is logged and stored by an insurer, it becomes part of a permanent health record that could be shared with other entities, such as employers or lenders, without the policyholder's explicit consent. Although the Health Insurance Portability and Accountability Act (HIPAA) provides some protections, it does not cover all insurers, especially those that are not covered entities. The risk of data being used for discriminatory purposes—such as denying employment or credit based on health metrics—is a real concern that has been raised in congressional hearings.
Furthermore, the use of biometric data may exacerbate existing health disparities. Individuals with lower socioeconomic status may have less access to reliable blood pressure monitors or may face barriers to consistent logging, such as lack of internet connectivity or time constraints. If carriers penalize these individuals for incomplete or erratic data, they could effectively price out vulnerable populations from term life coverage. This outcome would run counter to the goal of increasing insurance accessibility. Some consumer groups have called for regulators to require carriers to offer alternative underwriting methods for those who cannot provide logged data.
Finally, there is the question of consumer trust. Surveys conducted by the Insurance Information Institute in early 2026 indicate that 45% of consumers are uncomfortable with insurers using data from connected devices to set rates. If term life carriers aggressively adopt biometric underwriting, they may face customer backlash and increased regulatory scrutiny. A balanced approach—such as offering discounts for voluntary data sharing rather than mandatory data collection—could mitigate these risks while still capturing some of the benefits.
Hedge: The trade-offs outlined above are speculative to some extent. Early adopters of biometric underwriting in the auto insurance market have reported positive results, with lower loss ratios and improved customer satisfaction among those who opted in. However, the term life market is different, with longer policy durations and higher sensitivity to privacy concerns. Actuaries should monitor developments in both markets before committing to a particular strategy.
Named Example: How MetLife Is Piloting Biometric Underwriting
MetLife, one of the largest term life carriers in the United States, launched a pilot program in June 2026 that integrates logged blood pressure readings from the Apple Watch and other wearable devices into its underwriting process for select term life products. Under the pilot, applicants who agree to share 90 days of blood pressure data receive a 10% premium discount if their average readings are within normal range. Those with elevated readings are offered a standard rate but are not penalized with higher premiums compared to traditional underwriting. The pilot is limited to applicants aged 30–45 in New York and California.
Early results from the pilot, shared with regulators under confidentiality, show that approximately 70% of participants qualify for the discount, and the remaining 30% accept the standard rate. Notably, the lapse rate among participants is 8% lower than the control group, suggesting that engagement with health tracking may improve policyholder retention. However, MetLife has not yet disclosed whether the pilot has affected mortality claims. The company plans to expand the program to other states in 2027 if the results remain favorable.
Hedge: The MetLife pilot is small—only 5,000 policies issued so far—and may not be representative of the broader market. Critics note that the self-selection bias of volunteers could skew results, as healthier individuals are more likely to participate. Nonetheless, the pilot provides a real-world example of how biometric underwriting can be implemented with consumer protections in place.
For more on how other insurance lines are adapting to data-driven underwriting, see disability claim payout trends and CGL claim audit schedules. These examples show that the shift toward logged data is not limited to life insurance.
Disclaimer: This article is for informational purposes only and does not constitute professional actuarial or legal advice. Readers should consult qualified professionals for guidance specific to their circumstances.