# The NAIC Insurance Data Security Model Law, Explained

> NAIC Model Law 668 binds where a state enacts it: a written security program, third-party oversight, breach investigation, and notice to the insurance commissioner.

- Source: https://insureaiwire.com/insurance-data-security-model-law/
- Publication: InsureAI Wire
- Author: Simon Li
- Updated: 2026-07-28

---
You can get a long way into insurance AI governance before anyone mentions the data security law. Then it arrives all at once: inside the vendor questionnaire, inside the incident-response plan, inside the exam letter asking for your third-party inventory. That law is the NAIC Insurance Data Security Model Law, and if your company holds insurance licenses across much of the country, it is already one of the statutes you answer to.

It sits one layer below the AI conversation. [AI governance](/ai-governance-in-insurance/) asks what your models do. This law asks what happens to the data underneath all of it, and what you do when something goes wrong. The two overlap more than most programs admit, which is why it pays to read them together.

## What the model law is

The Insurance Data Security Model Law, NAIC model number 668, is a template statute published in the NAIC's model-law compendium in the fourth quarter of 2017 for state legislatures to enact as binding law.[^3] Per the NAIC's own description, it requires insurers and other licensed entities to develop, implement, and maintain an information security program, investigate cybersecurity events, and notify the state insurance commissioner when one occurs.[^1] More than two dozen jurisdictions have adopted it in some form, per the NAIC's own implementation map, which makes it the nearest thing to a nationwide data security baseline the industry has.[^2] If the state-by-state structure that produced that result is unfamiliar, [how U.S. insurance regulation actually works](/where-to-begin/) is the layer underneath this one.

Two features of that sentence deserve a second look. First, like every NAIC product, the model text binds no one by itself. It takes a state to enact it, and states modify as they enact, the same adoption mechanics covered in [what the NAIC is and is not](/what-is-the-naic/). Second, once enacted, this is not guidance. A [model law](/glossary/model-law/) becomes a statute with penalties, which puts it in a different weight class from the AI bulletin most compliance teams have spent the last two years reading.

The reach is also wider than the word "insurer" suggests. The law speaks to licensees: carriers, yes, but also producers, agencies, and other entities holding a state insurance license. An agency with a book of customer data is inside the same statute as the carrier whose paper it sells. The model's one size break is narrower than it sounds: a licensee with fewer than ten employees, independent contractors included, is exempt from Section 4, the information security program itself, and from nothing else. The duties to investigate a cybersecurity event and to notify the commissioner still run.[^3] And in states that adopted the certification provision, an insurer domiciled there owes its commissioner a written statement by February 15 each year certifying compliance with that program section, with the records behind it kept five years for examination.[^3] That turns the security program from a document into a recurring sworn statement.

## The four duties at its core

Stripped to the load-bearing parts, the law asks for four things.

**A written information security program.** Not a policy binder, but a program scaled to the licensee's size, complexity, and the nature of the data it holds, and built on a risk assessment. The assessment is the foundation document: an examiner who wants to know whether your program is real starts by asking what risks it was built against.

**Third-party oversight.** A licensee answers for the service providers it lets near nonpublic information. That means due diligence before engagement, contracts that require protection of the data, and attention afterward. The vendor's breach is legally your notification problem, a point that stopped being theoretical when the [NAIC's own PeopleSoft incident](/news/naic-peoplesoft-breach/) put a central industry data repository in the breach conversation.

**Investigation of cybersecurity events.** When something happens, the licensee must determine whether a cybersecurity event occurred and what nonpublic information it touched.[^3] Everything downstream keys off that determination, including the clock.

**Notification to the commissioner.** Section 6 gives the licensee 72 hours from that determination, and the clock does not run to every state at once. It runs in a state if that state is the licensee's domicile or home state, or if the licensee reasonably believes the event involved the nonpublic information of 250 or more consumers residing there and the event either triggers notice to some other government or regulatory body or is reasonably likely to cause material harm.[^3] Read both gates before anyone drafts a fifty-state notification runbook. The NAIC is now building a [centralized breach-notification portal](/news/naic-cybersecurity-event-notification-portal/) that would let one filing reach every adopting state, which raises the stakes on the internal moment of determination: slow once, late everywhere.

## Where GLBA fits

Underneath the model law sits a federal statute. Since 1999 the [Gramm-Leach-Bliley Act](/glossary/gramm-leach-bliley-act/) has placed every financial institution, insurers included, under a continuing obligation to protect the security and confidentiality of customer information. It does not spell out what that takes. It tells each institution's own regulator to set the safeguards standards.[^4]

The piece most people miss is who that regulator is. For anyone engaged in providing insurance, GLBA names the state insurance authority of the licensee's domicile, and directs it to implement the safeguards standards by rule.[^4] The FTC gets only the financial institutions no other agency covers, which is why its Safeguards Rule reaches other non-bank companies and stops short of insurers.[^4]

Model Law 668 is how the states carry that federal duty. Read the two together and the structure is simple: GLBA supplies the obligation and the allocation, the states supply the teeth, and 668 is the tooth shape most of them chose. GLBA's privacy-notice requirements run on a separate track. The model law is the security side of the same federal floor.

<figure class="figure">
<svg viewBox="0 0 460 434" width="460" role="img"><title>How the federal duty reaches an insurance licensee: GLBA, in force since 1999, imposes a federal duty to protect customer information and leaves the safeguards standards to each institution's own regulator. One branch runs to the FTC Safeguards Rule, which governs other non-bank firms and does not reach insurers. The other branch runs to state insurance regulators, who carry the duty through Model Law 668, which lands on the licensee: carriers, producers, and agencies.</title><rect x="110" y="8" width="240" height="76" fill="none" class="s-ink" stroke-width="2"/><text x="124" y="34" class="t-label f-ink" font-size="15">GLBA (1999)</text><text x="124" y="56" class="t-note f-soft" font-size="14">federal duty to protect</text><text x="124" y="74" class="t-note f-soft" font-size="14">customer information</text><line x1="230" y1="84" x2="230" y2="108" class="s-ink" stroke-width="2"/><line x1="96" y1="108" x2="364" y2="108" class="s-ink" stroke-width="2"/><line x1="96" y1="108" x2="96" y2="126" class="s-ink" stroke-width="2"/><polygon points="92,126 100,126 96,134" class="f-ink"/><line x1="364" y1="108" x2="364" y2="126" class="s-ink" stroke-width="2"/><polygon points="360,126 368,126 364,134" class="f-ink"/><rect x="8" y="136" width="176" height="80" fill="none" class="s-soft" stroke-width="1"/><text x="20" y="162" class="t-label f-soft" font-size="14">FTC SAFEGUARDS</text><text x="20" y="180" class="t-label f-soft" font-size="14">RULE</text><text x="20" y="204" class="t-note f-soft" font-size="14">other non-bank firms</text><line x1="96" y1="216" x2="96" y2="226" class="s-red" stroke-width="2"/><line x1="88" y1="234" x2="104" y2="250" class="s-red" stroke-width="2"/><line x1="104" y1="234" x2="88" y2="250" class="s-red" stroke-width="2"/><text x="96" y="276" text-anchor="middle" class="t-label f-red" font-size="14">NOT INSURERS</text><rect x="276" y="136" width="176" height="80" fill="none" class="s-ink" stroke-width="2"/><text x="288" y="162" class="t-label f-ink" font-size="14">STATE INSURANCE</text><text x="288" y="180" class="t-label f-ink" font-size="14">REGULATORS</text><text x="288" y="204" class="t-note f-soft" font-size="14">GLBA hands them this</text><line x1="364" y1="216" x2="364" y2="240" class="s-ink" stroke-width="2"/><polygon points="360,240 368,240 364,248" class="f-ink"/><rect x="276" y="250" width="176" height="80" fill="none" class="s-ink" stroke-width="2"/><text x="288" y="276" class="t-label f-ink" font-size="15">MODEL LAW 668</text><text x="288" y="300" class="t-note f-soft" font-size="14">how the states carry</text><text x="288" y="318" class="t-note f-soft" font-size="14">the federal duty</text><line x1="364" y1="330" x2="364" y2="348" class="s-ink" stroke-width="2"/><polygon points="360,348 368,348 364,356" class="f-ink"/><rect x="138" y="358" width="314" height="68" fill="none" class="s-ink" stroke-width="2"/><text x="152" y="384" class="t-label f-ink" font-size="15">THE LICENSEE</text><text x="152" y="408" class="t-note f-soft" font-size="14">carriers, producers, agencies</text></svg>
<figcaption>FIG. 1: GLBA HANDS INSURANCE DATA SECURITY TO THE STATES</figcaption>
</figure>

## Where it meets your AI program

This is the connection few write down, and the reason this piece exists.

Start with the inventory. The third parties your AI governance program tracks, the vendors whose models score, draft, or triage, are in almost every case also third-party service providers under the data security law, because they touch nonpublic information to do their work. One vendor, two regulatory lenses, same underlying spreadsheet. Programs that run these as separate lists discover the mismatch during an exam, which is the worst time to discover it.

Then the records. A security program that documents its risk assessments and vendor oversight is producing the same species of evidence an AI governance program produces, and examiners read both with the same skepticism: a document dated last week reads like it was written last week. The disciplines compound. So do the gaps.

Finally, the incident chain. A breach at an AI vendor is a cybersecurity event under this law exactly as it is a vendor-oversight failure under your AI framework. The notification duty, the investigation duty, and the contract question about who tells you what, and how fast, are one problem wearing two labels. If your [AI vendor risk assessment](/ai-vendor-risk-assessment/) does not already ask about breach-notification timelines, the data security law is the reason it should.

## What to check

Three lookups cover most of the practical exposure. Which of your license states have enacted the law, and with what modifications, is the first: the [NAIC working group's Model #668 adoption map](https://content.naic.org/sites/default/files/cmte-h-cybersecurity-wg-state-adoption-map-model-668.pdf) shows who has acted, and only the state's own enacted text shows what it changed on the way in. Our [state tracker](/states/) maps the AI rules, not this one. Whether your security program's third-party list and your AI vendor inventory describe the same population is the second. Who inside your company has the authority to declare that a determination has been made, and how quickly that declaration can happen on a weekend, is the third, because that answer defines your real notification timeline.

<!-- CLOSING: 代价型 (cost lands on a specific party) -->
None of these duties lands on the NAIC, on the vendor, or on the model text. They land on the licensee whose name is on the filing. Where the notification gates are met, the statute gives that licensee 72 hours from the moment it determines a cybersecurity event occurred, which makes the most consequential sentence in the whole incident-response plan the one that defines when a determination happens. Companies that treat data security as an IT topic discover this in the wrong order. The law is aimed at whoever holds the license, and it prices the delay accordingly.

[^2]: NAIC Cybersecurity (H) Working Group, "Implementation of Model Act #668, Insurance Data Security Model Law," state adoption map, status as of April 1, 2026: the legend counts 28 jurisdictions as Adopted (27 states plus Puerto Rico), 1 pending, and New York separately under "Other Insurance Data Security Provisions." The map itself cautions that it "does not reflect a determination as to whether the pending or enacted legislation contains all elements of the model," and published counts differ by tracker for that reason, so this piece keeps the figure hedged. https://content.naic.org/sites/default/files/cmte-h-cybersecurity-wg-state-adoption-map-model-668.pdf

[^3]: NAIC Insurance Data Security Model Law (MDL-668), published in NAIC Model Laws, Regulations, Guidelines and Other Resources, 4th Quarter 2017. Section 4.A (program "commensurate with the size and complexity of the Licensee" and based on its Risk Assessment); Section 4.F (due diligence in selecting a Third-Party Service Provider, and requiring it to implement safeguards); Section 4.I (annual written certification of Section 4 compliance by February 15 from insurers domiciled in the state, records kept five years); Section 5.B (investigate and determine whether a cybersecurity event occurred and what nonpublic information was involved); Section 6.A (notice "as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred when either of the following criteria has been met," the two criteria being domicile or home state, or 250 or more affected consumers residing in the state combined with other-agency notice or a reasonable likelihood of material harm); Section 9.A(1) (licensees with fewer than ten employees, including independent contractors, exempt from Section 4). https://content.naic.org/sites/default/files/model-law-668.pdf

[^4]: Gramm-Leach-Bliley Act, Pub. L. 106-102 (Nov. 12, 1999). 15 U.S.C. § 6801(a) declares the continuing obligation of every financial institution "to protect the security and confidentiality of those customers' nonpublic personal information," and § 6801(b) directs each agency or authority listed in § 6805(a) to "establish appropriate standards" for administrative, technical, and physical safeguards. Section 6805(a)(6) assigns that role, "in the case of any person engaged in providing insurance," to "the applicable State insurance authority of the State in which the person is domiciled," and § 6805(b)(2) requires those authorities to implement the standards by rule. Section 6805(a)(7) gives the FTC only financial institutions not covered by paragraphs (1) through (6), which is why the FTC's Safeguards Rule (16 C.F.R. Part 314) does not reach state-licensed insurers. https://www.law.cornell.edu/uscode/text/15/6805

[^1]: NAIC, cybersecurity topic page (last updated May 9, 2024): the NAIC "adopted the new Insurance Data Security Model Law (#668) which requires insurers and other entities licensed by state insurance departments to develop, implement and maintain an information security program; investigate any cybersecurity events; and notify the state insurance commissioner of such events." The same page's adoption figure ("21 states") is older than the working group's April 2026 map cited at [^2]. https://content.naic.org/insurance-topics/cybersecurity