Data Security Rules

The NAIC Insurance Data Security Model Law: What Model #668 Requires and How Eight States Rewrote It

Key Takeaways

  • Model #668 was adopted by the NAIC in the fourth quarter of 2017 and binds no one until a legislature enacts it; the NAIC's Summer 2026 chart places 28 jurisdictions in its Model Adoption column
  • The model requires a written, risk-based information security program, board oversight where a board exists, and a February 15 annual compliance certification from domestic insurers
  • Notice to the commissioner is due within 72 hours of determining a cybersecurity event occurred, where the state is the licensee's domicile or home state, or 250 or more resident consumers are involved and a further condition is met
  • Of eight enacted statutes reviewed here, only South Carolina keeps the 72-hour clock; Delaware, Iowa, New Hampshire, North Dakota, Ohio and Virginia use three business days and Minnesota five
  • The model exempts licensees with fewer than ten employees from the program requirement; the enacted versions reviewed use 15, 20 or 25 employees, revenue and asset tests, or no size test at all

A Model, Not a Statute

The Insurance Data Security Model Law, NAIC model #668, was adopted at the NAIC's Executive and Plenary level by conference call in the fourth quarter of 2017, according to its chronological summary, which also records a technical edit in 2025. As a model it imposes nothing by itself. It is written for enactment, with bracketed placeholders for the adopting state, its insurance regulator, its breach notification law and its general penalty statute.

Section 2 states the purpose as establishing "standards for data security and standards for the investigation of and notification to the Commissioner of a Cybersecurity Event applicable to Licensees," and provides that the Act may not be construed to create or imply a private cause of action, or to curtail one that would otherwise exist. A drafting note records the drafters' intent that a licensee in compliance with New York's cybersecurity regulation for financial services companies, 23 NYCRR Part 500, "effective March 1, 2017," is also in compliance with the model.

Who and What the Model Covers

A licensee is any person licensed, authorized to operate or registered, or required to be, under the state's insurance laws. The definition leaves out a purchasing group or risk retention group chartered and licensed in another state, and a licensee acting as an assuming insurer that is domiciled elsewhere. Person means an individual or a non-governmental entity.

Nonpublic information has three branches. The first is business information whose tampering or unauthorized disclosure, access or use would cause a material adverse impact to the licensee's business, operations or security. The second is information that identifies a consumer in combination with a Social Security number, driver's license or non-driver identification number, account or card number, a code or password permitting access to a financial account, or biometric records. The third is health information, other than age or gender, created by or derived from a health care provider or a consumer and relating to physical, mental or behavioral health, the provision of health care, or payment for it. A consumer is a resident of the adopting state whose nonpublic information the licensee holds.

A cybersecurity event is "an event resulting in unauthorized access to, disruption or misuse of, an Information System or information stored on such Information System." Two carve-outs follow. Acquisition of encrypted nonpublic information is not an event if the encryption, process or key is not also acquired, released or used without authorization, and neither is an event where the licensee has determined that the information accessed "has not been used or released and has been returned or destroyed."

The Information Security Program

Section 4A requires each licensee to "develop, implement, and maintain a comprehensive written Information Security Program based on the Licensee's Risk Assessment," commensurate with its size and complexity, the nature and scope of its activities including its use of third-party service providers, and the sensitivity of the information. Section 4B sets four objectives, the last of which is to define and periodically reevaluate a retention schedule for nonpublic information and a mechanism for destroying it.

The risk assessment in Section 4C involves designating one or more employees, an affiliate or an outside vendor responsible for the program; identifying reasonably foreseeable internal or external threats, including to information held by service providers; assessing their likelihood and potential damage; assessing the sufficiency of safeguards across employee training, information systems, and detection and response; and, no less than annually, assessing the effectiveness of key controls, systems and procedures.

Section 4D is where the model is most flexible. The licensee is to "[d]etermine which security measures listed below are appropriate and implement such security measures." The list runs from (a) to (k): access controls, management of data, personnel, devices and facilities, physical access restrictions, encryption or other appropriate protection of information sent over external networks and stored on laptops and portable devices, secure development practices, effective controls "which may include Multi-Factor Authentication procedures," regular testing and monitoring, audit trails, protection against environmental hazards, and secure disposal. The licensee also includes cybersecurity risks in its enterprise risk management process and provides awareness training updated to reflect the risk assessment.

Governance and documentation complete Section 4. Where the licensee has a board, Section 4E requires the board or a committee to require executive management to develop the program and to report in writing at least annually on its status and material matters. Section 4H requires a written incident response plan addressing seven areas, from internal response processes and decision-making authority to documentation and post-event revision. Section 4I requires each domestic insurer to submit a written statement to the commissioner by February 15 each year certifying compliance with Section 4, to keep supporting records for five years, and to document any areas identified as needing material improvement.

Third-Party Service Providers

A third-party service provider is a person, not otherwise a licensee, that contracts with a licensee to maintain, process or store nonpublic information, or is otherwise permitted access to it, through services provided to the licensee. Section 4F imposes two duties: due diligence in selecting the provider, and requiring the provider "to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information" it can access or holds. Section 13 gives licensees one year from the effective date to implement Section 4 generally and two years for Section 4F.

A provider's incidents stay with the licensee. Where an event occurs in a system a provider maintains, Section 5C requires the licensee to complete the investigation steps or to confirm and document that the provider has done so, and Section 6D requires the licensee to treat the event as it would under Section 6A. The licensee's deadlines begin on the day after the provider notifies it or it otherwise has actual knowledge, whichever is sooner. The model does not prevent an agreement under which another party performs the investigation or notice work.

Investigation and Notice of a Cybersecurity Event

When a licensee learns that a cybersecurity event has or may have occurred, Section 5 requires a prompt investigation that determines, as far as possible, whether an event occurred, its nature and scope, and the nonpublic information involved, and that restores the security of compromised systems. Records of all cybersecurity events are kept for at least five years and produced on the commissioner's demand.

Section 6A sets the clock: notice to the commissioner "as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred" when either of two criteria is met:

  • the state is the licensee's state of domicile, for an insurer, or its home state, for a producer; or
  • the licensee reasonably believes the nonpublic information of 250 or more consumers residing in the state is involved, and the event either must be reported to a government body, self-regulatory agency or other supervisory body under state or federal law, or has a reasonable likelihood of materially harming a resident consumer or any material part of the licensee's normal operations

Section 6B lists 13 items to provide as far as possible, among them the date of the event, how the information was exposed and the roles of any service providers, how it was discovered, whether information was recovered, the source of the event, the specific types of information acquired, the period of compromise, the number of resident consumers affected, the results of any internal review, remediation efforts, a copy of the privacy policy, and a contact person. The obligation to update and supplement the notice continues. Consumer notice is not written into the model: Section 6C points to the state's existing breach notification law and requires a copy of the consumer notice to go to the commissioner.

Two further duties run along the insurance chain. An assuming insurer without a direct contractual relationship with the affected consumers notifies its affected ceding insurers and its domiciliary commissioner within 72 hours, and the ceding insurers handle consumer notice. An insurer whose affected consumers came through independent producers notifies the producers of record as soon as practicable, as the commissioner directs. Section 8 makes much of what licensees submit confidential and privileged, exempt from open records law and subpoena, and not discoverable or admissible in private civil actions.

Exceptions and Penalties in the Model

Section 9A contains three exceptions, each directed at Section 4, the program requirement. A licensee with fewer than ten employees, including independent contractors, is exempt from Section 4. A licensee subject to HIPAA that maintains an information security program under it is considered to meet Section 4 if it is compliant and submits a written statement certifying that compliance. An employee, agent or designee who is itself a licensee need not build its own program where the other licensee's program covers it. None of the three reaches the investigation and notice duties in Sections 5 and 6. A licensee that stops qualifying has 180 days to comply, and Section 10 leaves penalties to the state's general penalty statute.

Which States Have Enacted It

The NAIC publishes a state page for each model. Its Summer 2026 chart sorts each jurisdiction's citations into Model Adoption, Previous Version and Related Activity columns, and describes the Model Adoption column as covering states that "adopted the most recent version of the NAIC model in a substantially similar manner." It lists citations in that column for 28 jurisdictions: Alabama, Alaska, Connecticut, Delaware, Hawaii, Illinois, Indiana, Iowa, Kentucky, Louisiana, Maine, Maryland, Michigan, Minnesota, Mississippi, Missouri, New Hampshire, North Dakota, Ohio, Oklahoma, Pennsylvania, Puerto Rico, Rhode Island, South Carolina, Tennessee (noted as "portions of model"), Vermont, Virginia and Wisconsin. New York appears only under Related Activity, citing 23 NYCRR Part 500 and General Business Law sections 899-aa and 899-bb.

That list is the NAIC's classification, and the chart itself cautions that the NAIC's interpretation "may or may not be shared by the individual states." The enacted statutes of eight of the listed states were read for this article: South Carolina, Ohio, Delaware, New Hampshire, Virginia, Minnesota, Iowa and North Dakota. The comparison below is limited to those eight, and nothing is inferred about the other twenty jurisdictions.

Where Enacted Versions Depart From the Model

The clearest divergence is the notice clock, followed by the size of licensee that is excused from building a program.

TextNotice to the commissionerSize-based exemption from the program requirement
NAIC Model #668No later than 72 hours from the determinationFewer than 10 employees, including independent contractors
South Carolina, S.C. Code 38-99-10 to 38-99-100No later than 72 hours after the determinationFewer than 10 employees, including independent contractors
Delaware, 18 Del. C. ch. 86No later than 3 business days from the determinationFewer than 15 employees (from section 8604)
Ohio, R.C. 3965.01 to 3965.11No later than 3 business days after the determinationFewer than 20 employees, less than $5 million gross annual revenue, or less than $10 million in assets (from section 3965.02)
New Hampshire, RSA 420-PWithin 3 business days of the determinationFewer than 20 employees, including independent contractors (from RSA 420-P:4)
Iowa, Iowa Code ch. 507FNo later than 3 business daysFewer than 20 individuals on the workforce, less than $5 million gross annual revenue, or less than $10 million year-end assets (from section 507F.4)
North Dakota, N.D.C.C. ch. 26.1-02.23 business days from the determinationNo headcount test; less than $5 million gross revenue or less than $10 million year-end assets (from subsections 2 through 10 of section 26.1-02.2-03)
Virginia, Va. Code 38.2-621 to 38.2-629No later than 3 business days from the determinationNone; the exceptions in section 38.2-629 cover HIPAA licensees, licensees covered by another licensee's program, and affiliates of depository institutions
Minnesota, Minn. Stat. 60A.985 to 60A.9857No later than 5 business days, to the commissioner of commerce or of health, whichever regulates the licenseeFewer than 25 employees (from sections 60A.9851 and 60A.9852)

Certification dates move too. South Carolina and Delaware keep the February 15 date. Minnesota and North Dakota use April 15, and Iowa requires the certification before April 15.

HIPAA is handled with different wording and effect. Ohio section 3965.07(B)(1) deems a licensee subject to and in compliance with 45 CFR parts 160 and 164 to meet the chapter "except those pertaining to notification under section 3965.04," so the three-business-day notice still applies to it. Virginia section 38.2-629 adds a condition that the licensee certify it will protect nonpublic information not subject to HIPAA in the same manner, and treats a licensee that investigates and notifies consumers under HIPAA as compliant with sections 38.2-624 and 38.2-626. North Dakota requires the licensee to maintain consumer nonpublic information in the same manner as protected health information. Minnesota section 60A.9856 treats a certifying HIPAA-compliant licensee as complying with the program sections and with subdivisions 3 to 5 of its notice section, and New Hampshire titles its provision, RSA 420-P:10, a safe harbor for HIPAA compliance.

Other departures are structural. Minnesota's domicile criterion is narrower than the model's, applying only where the event also "has a reasonable likelihood of materially harming" a resident consumer or the licensee's normal operations, and Minnesota writes a consumer notice duty into its insurance statute rather than relying only on the general breach law. Virginia's second trigger reaches an event involving 250 or more resident consumers or any event of which the licensee must give notice to a government body under federal law or another state's law. Minnesota and Virginia both add an exception for affiliates of depository institutions whose programs satisfy the federal interagency safeguarding guidelines.

Ohio adds provisions with no counterpart in the model. Section 3965.08 gives a licensee that satisfies the chapter an affirmative defense to tort claims alleging that a failure to implement reasonable information security controls resulted in a data breach, and section 3965.09 makes the chapter the exclusive state standards for licensees on cybersecurity events, data security and notice to the superintendent. Virginia section 38.2-627 is likewise titled as establishing exclusive state standards. New Hampshire's RSA 420-P:11, a safe harbor for New York regulatory compliance, treats a licensee compliant with Part 500 as effective March 1, 2017 that certifies that compliance as meeting the chapter, but expressly keeps such a licensee subject to the investigation, commissioner notice and consumer notice requirements.

Part 500, the Model's Reference Point

The New York regulation the drafting note names has since changed. The Department of Financial Services' second amendment to 23 NYCRR Part 500 rewrote section 500.17(a) so that a covered entity notifies the superintendent "as promptly as possible but in no event later than 72 hours after determining that a cybersecurity incident has occurred at the covered entity, its affiliates, or a third-party service provider," deleting the earlier list of qualifying events. The annual filing is due April 15 and may be either a certification of material compliance or a written acknowledgment of material noncompliance that identifies the sections involved.

Its limited exemption in section 500.19(a) now reaches covered entities with fewer than 20 employees and independent contractors, less than $7,500,000 in gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets, and it removes only listed sections of the regulation rather than the whole program. Both the model's drafting note and New Hampshire's safe harbor identify Part 500 by its March 1, 2017 effective date, not by the amended text.

Background

For the underlying law rather than this development: Financial Services privacy law.

Frequently Asked Questions

Is the NAIC Insurance Data Security Model Law binding on insurers?
Not by itself. Model #668 is a template the NAIC adopted in 2017, and it applies only as enacted by a state legislature, often with changes. The NAIC's Summer 2026 state page lists 28 jurisdictions in its Model Adoption column, a classification the chart says states may not share.
How quickly does the model require an insurance licensee to notify the commissioner?
Section 6A requires notice as promptly as possible and no later than 72 hours from a determination that a cybersecurity event occurred, where the state is the licensee's domicile or home state, or 250 or more resident consumers are involved and a further condition is met. Of the eight enacted statutes reviewed here, six use three business days and Minnesota uses five.
Does the insurance data security model law require encryption or multi-factor authentication?
Not in absolute terms. Section 4D(2) has the licensee determine which listed measures are appropriate based on its risk assessment. The list includes encryption or other appropriate protection for information sent over external networks or stored on portable devices, and effective controls that may include multi-factor authentication.
Are small insurance agencies exempt from the model's security program requirement?
The model exempts licensees with fewer than ten employees, including independent contractors, from Section 4, but not from investigation and notice. Enacted versions differ: Delaware uses 15 employees, Ohio, Iowa and New Hampshire 20, Minnesota 25, Ohio and Iowa add revenue and asset tests, North Dakota uses only revenue and asset tests, and Virginia's exceptions contain no size test.
How does the model treat a cybersecurity event at a vendor?
Section 4F requires due diligence in selecting third-party service providers and requiring them to implement appropriate safeguards. If an event occurs in a provider's system, Sections 5C and 6D keep the investigation and notice duties with the licensee, with deadlines running from the day after the provider notifies it or it otherwise has actual knowledge, whichever is sooner.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.