Don't forget that there's lots of gray hat / black hat hackers out there as well, who will begin with an email similar to this, add a bitcoin address for the "bug bounty" in the next, and will end with escalating the price of the "bounty" for the "service" of deleting the data they harvested. It's hard even for tech-savvy managers to figure out which of these you're dealing with. Now put yourself into the shoes of the average insurance company middle manager.
For completeness, I don't think this company's behavior is excusable. I'm just saying that maybe also the security community should iterate a bit more on the nuances of the "standard practice" vulnerability reporting process, with the explicit goal of not freaking people out so bad.