Insurers face privacy scrutiny from an unusual angle, since the external data feeding underwriting models is regulated as much as the policyholder data itself. This hub covers both, plus coverage disputes over privacy claims.
Data Security Rules
September 14, 2026
The NAIC adopted its Insurance Data Security Model Law in late 2017 as a template for state legislatures. It asks insurance licensees to run a written information security program, oversee vendors, investigate cybersecurity events and notify the insurance commissioner within 72 hours. This walks through the model's text and compares it with eight enacted state versions.
Read more →
FCRA
September 7, 2026
The Fair Credit Reporting Act does not have one adverse action notice. It has a notice owed before a decision that only employers owe, and a notice owed after any adverse action taken on a consumer report by anyone. The two sit in different sections, carry different contents, and answer to different silences in the statute.
Read more →
HIPAA
August 12, 2026
HIPAA is three interlocking rules rather than one, and they apply to a defined set of organizations rather than to health information generally. This guide covers who is covered, what the Privacy Rule permits without authorization, what the Security Rule requires, how business associate liability works, and the mechanics of breach notification.
Read more →