The NAIC Insurance Data Security Model Law, Explained
NAIC Model Law 668 binds where a state enacts it: a written security program, third-party oversight, breach investigation, and notice to the insurance commissioner.
For Compliance, security, and legal staff at insurers, agencies, and other licensed entities placing the data security law alongside their AI work.
Read if AI governance duties finally make sense, but a separate data security law keeps surfacing in vendor reviews and exams, and no one has explained how the two connect.
You can get a long way into insurance AI governance before anyone mentions the data security law. Then it arrives all at once: inside the vendor questionnaire, inside the incident-response plan, inside the exam letter asking for your third-party inventory. That law is the NAIC Insurance Data Security Model Law, and if your company holds insurance licenses across much of the country, it is already one of the statutes you answer to.
It sits one layer below the AI conversation. AI governance asks what your models do. This law asks what happens to the data underneath all of it, and what you do when something goes wrong. The two overlap more than most programs admit, which is why it pays to read them together.
What the model law is
The Insurance Data Security Model Law, NAIC model number 668, is a template statute published in the NAIC’s model-law compendium in the fourth quarter of 2017 for state legislatures to enact as binding law.1 Per the NAIC’s own description, it requires insurers and other licensed entities to develop, implement, and maintain an information security program, investigate cybersecurity events, and notify the state insurance commissioner when one occurs.2 More than two dozen jurisdictions have adopted it in some form, per the NAIC’s own implementation map, which makes it the nearest thing to a nationwide data security baseline the industry has.3 If the state-by-state structure that produced that result is unfamiliar, how U.S. insurance regulation actually works is the layer underneath this one.
Two features of that sentence deserve a second look. First, like every NAIC product, the model text binds no one by itself. It takes a state to enact it, and states modify as they enact, the same adoption mechanics covered in what the NAIC is and is not. Second, once enacted, this is not guidance. A model law becomes a statute with penalties, which puts it in a different weight class from the AI bulletin most compliance teams have spent the last two years reading.
The reach is also wider than the word “insurer” suggests. The law speaks to licensees: carriers, yes, but also producers, agencies, and other entities holding a state insurance license. An agency with a book of customer data is inside the same statute as the carrier whose paper it sells. The model’s one size break is narrower than it sounds: a licensee with fewer than ten employees, independent contractors included, is exempt from Section 4, the information security program itself, and from nothing else. The duties to investigate a cybersecurity event and to notify the commissioner still run.1 And in states that adopted the certification provision, an insurer domiciled there owes its commissioner a written statement by February 15 each year certifying compliance with that program section, with the records behind it kept five years for examination.1 That turns the security program from a document into a recurring sworn statement.
The four duties at its core
Stripped to the load-bearing parts, the law asks for four things.
A written information security program. Not a policy binder, but a program scaled to the licensee’s size, complexity, and the nature of the data it holds, and built on a risk assessment. The assessment is the foundation document: an examiner who wants to know whether your program is real starts by asking what risks it was built against.
Third-party oversight. A licensee answers for the service providers it lets near nonpublic information. That means due diligence before engagement, contracts that require protection of the data, and attention afterward. The vendor’s breach is legally your notification problem, a point that stopped being theoretical when the NAIC’s own PeopleSoft incident put a central industry data repository in the breach conversation.
Investigation of cybersecurity events. When something happens, the licensee must determine whether a cybersecurity event occurred and what nonpublic information it touched.1 Everything downstream keys off that determination, including the clock.
Notification to the commissioner. Section 6 gives the licensee 72 hours from that determination, and the clock does not run to every state at once. It runs in a state if that state is the licensee’s domicile or home state, or if the licensee reasonably believes the event involved the nonpublic information of 250 or more consumers residing there and the event either triggers notice to some other government or regulatory body or is reasonably likely to cause material harm.1 Read both gates before anyone drafts a fifty-state notification runbook. The NAIC is now building a centralized breach-notification portal that would let one filing reach every adopting state, which raises the stakes on the internal moment of determination: slow once, late everywhere.
Where GLBA fits
Underneath the model law sits a federal statute. Since 1999 the Gramm-Leach-Bliley Act has placed every financial institution, insurers included, under a continuing obligation to protect the security and confidentiality of customer information. It does not spell out what that takes. It tells each institution’s own regulator to set the safeguards standards.4
The piece most people miss is who that regulator is. For anyone engaged in providing insurance, GLBA names the state insurance authority of the licensee’s domicile, and directs it to implement the safeguards standards by rule.4 The FTC gets only the financial institutions no other agency covers, which is why its Safeguards Rule reaches other non-bank companies and stops short of insurers.4
Model Law 668 is how the states carry that federal duty. Read the two together and the structure is simple: GLBA supplies the obligation and the allocation, the states supply the teeth, and 668 is the tooth shape most of them chose. GLBA’s privacy-notice requirements run on a separate track. The model law is the security side of the same federal floor.
Where it meets your AI program
This is the connection few write down, and the reason this piece exists.
Start with the inventory. The third parties your AI governance program tracks, the vendors whose models score, draft, or triage, are in almost every case also third-party service providers under the data security law, because they touch nonpublic information to do their work. One vendor, two regulatory lenses, same underlying spreadsheet. Programs that run these as separate lists discover the mismatch during an exam, which is the worst time to discover it.
Then the records. A security program that documents its risk assessments and vendor oversight is producing the same species of evidence an AI governance program produces, and examiners read both with the same skepticism: a document dated last week reads like it was written last week. The disciplines compound. So do the gaps.
Finally, the incident chain. A breach at an AI vendor is a cybersecurity event under this law exactly as it is a vendor-oversight failure under your AI framework. The notification duty, the investigation duty, and the contract question about who tells you what, and how fast, are one problem wearing two labels. If your AI vendor risk assessment does not already ask about breach-notification timelines, the data security law is the reason it should.
What to check
Three lookups cover most of the practical exposure. Which of your license states have enacted the law, and with what modifications, is the first: the NAIC working group’s Model #668 adoption map shows who has acted, and only the state’s own enacted text shows what it changed on the way in. Our state tracker maps the AI rules, not this one. Whether your security program’s third-party list and your AI vendor inventory describe the same population is the second. Who inside your company has the authority to declare that a determination has been made, and how quickly that declaration can happen on a weekend, is the third, because that answer defines your real notification timeline.
None of these duties lands on the NAIC, on the vendor, or on the model text. They land on the licensee whose name is on the filing. Where the notification gates are met, the statute gives that licensee 72 hours from the moment it determines a cybersecurity event occurred, which makes the most consequential sentence in the whole incident-response plan the one that defines when a determination happens. Companies that treat data security as an IT topic discover this in the wrong order. The law is aimed at whoever holds the license, and it prices the delay accordingly.
Footnotes
-
NAIC Insurance Data Security Model Law (MDL-668), published in NAIC Model Laws, Regulations, Guidelines and Other Resources, 4th Quarter 2017. Section 4.A (program “commensurate with the size and complexity of the Licensee” and based on its Risk Assessment); Section 4.F (due diligence in selecting a Third-Party Service Provider, and requiring it to implement safeguards); Section 4.I (annual written certification of Section 4 compliance by February 15 from insurers domiciled in the state, records kept five years); Section 5.B (investigate and determine whether a cybersecurity event occurred and what nonpublic information was involved); Section 6.A (notice “as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred when either of the following criteria has been met,” the two criteria being domicile or home state, or 250 or more affected consumers residing in the state combined with other-agency notice or a reasonable likelihood of material harm); Section 9.A(1) (licensees with fewer than ten employees, including independent contractors, exempt from Section 4). https://content.naic.org/sites/default/files/model-law-668.pdf ↩ ↩2 ↩3 ↩4 ↩5
-
NAIC, cybersecurity topic page (last updated May 9, 2024): the NAIC “adopted the new Insurance Data Security Model Law (#668) which requires insurers and other entities licensed by state insurance departments to develop, implement and maintain an information security program; investigate any cybersecurity events; and notify the state insurance commissioner of such events.” The same page’s adoption figure (“21 states”) is older than the working group’s April 2026 map cited at 3. https://content.naic.org/insurance-topics/cybersecurity ↩
-
NAIC Cybersecurity (H) Working Group, “Implementation of Model Act #668, Insurance Data Security Model Law,” state adoption map, status as of April 1, 2026: the legend counts 28 jurisdictions as Adopted (27 states plus Puerto Rico), 1 pending, and New York separately under “Other Insurance Data Security Provisions.” The map itself cautions that it “does not reflect a determination as to whether the pending or enacted legislation contains all elements of the model,” and published counts differ by tracker for that reason, so this piece keeps the figure hedged. https://content.naic.org/sites/default/files/cmte-h-cybersecurity-wg-state-adoption-map-model-668.pdf ↩ ↩2
-
Gramm-Leach-Bliley Act, Pub. L. 106-102 (Nov. 12, 1999). 15 U.S.C. § 6801(a) declares the continuing obligation of every financial institution “to protect the security and confidentiality of those customers’ nonpublic personal information,” and § 6801(b) directs each agency or authority listed in § 6805(a) to “establish appropriate standards” for administrative, technical, and physical safeguards. Section 6805(a)(6) assigns that role, “in the case of any person engaged in providing insurance,” to “the applicable State insurance authority of the State in which the person is domiciled,” and § 6805(b)(2) requires those authorities to implement the standards by rule. Section 6805(a)(7) gives the FTC only financial institutions not covered by paragraphs (1) through (6), which is why the FTC’s Safeguards Rule (16 C.F.R. Part 314) does not reach state-licensed insurers. https://www.law.cornell.edu/uscode/text/15/6805 ↩ ↩2 ↩3
The Bottom Line
- Model Law 668 is a statute template, not guidance. Where a state has enacted it, the security program, the vendor oversight and the breach investigation are legal duties with penalties behind them, and it is on the books in more than two dozen.
- It reaches every insurance licensee, not just carriers. Producers and agencies are in scope; the model's one size break exempts licensees under ten employees from the program section, and from nothing else.
- GLBA is the federal layer underneath. It hands insurance data security to state regulators, 668 is how the states carry it, and the FTC rule you read about elsewhere does not cover insurers.
- Your AI vendor inventory and your security-law third-party list are the same spreadsheet. Treat them as one and both programs get easier.
How Insurers Assess AI Vendor Risk
A practical NAIC-aligned checklist for AI vendor risk assessment: due-diligence questions, contract clauses, and the ongoing monitoring that stays with the insurer.
Continue →
Simon Li · Founding Editor
Much of his time goes into reading NAIC meeting papers, state bulletins, bills, court filings, and public comments. He also keeps the site's 51-jurisdiction tracker up to date.
Free · Weekly
Track these developments weekly
Get the InsureAI Wire dispatch in your inbox. Free, sourced, no spam.
Free weekly · No spam · Unsubscribe anytime
Related reading
AI Governance Documents to Prepare for a Market Conduct Exam
The insurance AI exam documentation to have ready for a market conduct exam: an insurer-built readiness file of eight evidence categories, and how to record a gap.
AI Model Monitoring After the Model Goes Live
A playbook for insurers on AI model monitoring, validation, drift detection, and retesting records that satisfy NAIC Model Bulletin and Exhibit C expectations.
Does AI Insurance Regulation Apply to You? A Plain-Language Self-Check
Five questions that flag when the AI regulations for insurance companies may reach your business, and what to review before treating the answer as settled.
Market Conduct Examinations, Explained
A market conduct exam is how state regulators inspect how insurers treat consumers: what triggers one, what examiners ask for, and how it differs from a financial exam.
Information aggregation and analysis, not legal advice. See our disclaimer.