Insurers face privacy scrutiny from an unusual angle, since the external data feeding underwriting models is regulated as much as the policyholder data itself. This hub covers both, plus coverage disputes over privacy claims.

Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

September 14, 2026

The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.

Read more →
HIPAA

HIPAA in Practice: The Privacy, Security and Breach Notification Rules

August 12, 2026

HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.

Read more →