The NAIC Insurance Data Security Model Law, Explained

The NAIC Insurance Data Security Model Law stops being guidance once a state enacts it: the 72-hour notice, and who has it.

In this article

For Compliance, security, and legal staff at insurers, agencies, and other licensed entities placing the data security law alongside their AI work.

Read if AI governance duties finally make sense, but a separate data security law keeps surfacing in vendor reviews and exams, and no one has explained how the two connect.

By Simon Li · Published JUL 28, 2026 · Updated SEP 4, 2026 · 13 min read

Engraved cover illustration: The NAIC Insurance Data Security Model Law, Explained
Ask AI

You can get a long way into insurance AI governance before anyone mentions the data security law. Then it arrives all at once: inside the vendor questionnaire, inside the incident-response plan, inside the exam letter asking for your third-party inventory. That law is the NAIC Insurance Data Security Model Law, and if your company holds insurance licenses across much of the country, it is already one of the statutes you answer to.

It sits one layer below the AI conversation. AI governance asks what your models do. This law asks what happens to the data underneath all of it, and what you do when something goes wrong. The two overlap more than most programs admit, which is why it pays to read them together.

What the model law is

The Insurance Data Security Model Law, NAIC model number 668, is a template statute published in the NAIC’s model-law compendium in the fourth quarter of 2017 for state legislatures to enact as binding law.1 Per the NAIC’s own description, it requires insurers and other licensed entities to develop, implement, and maintain an information security program, investigate cybersecurity events, and notify the state insurance commissioner when one occurs.2 By our own count of the enacting texts, 27 states and Puerto Rico have a version of it on the books as of September 4, 2026, which makes it the nearest thing to a nationwide data security baseline the industry has.3 If the state-by-state structure that produced that result is unfamiliar, how U.S. insurance regulation actually works is the layer underneath this one.

Two features of that sentence deserve a second look. First, like every NAIC product, the model text binds no one by itself. It takes a state to enact it, and states modify as they enact, the same adoption mechanics covered in what the NAIC is and is not. Second, once enacted, this is not guidance. A model law becomes a statute with penalties, which puts it in a different weight class from the AI bulletin most compliance teams have spent the last two years reading.

The reach is also wider than the word “insurer” suggests. The law speaks to licensees: carriers, yes, but also producers, agencies, and other entities holding a state insurance license. An agency with a book of customer data is inside the same statute as the carrier whose paper it sells. The model’s one size break is narrower than it sounds: a licensee with fewer than ten employees, independent contractors included, is exempt from Section 4, the information security program itself, and from nothing else. The duties to investigate a cybersecurity event and to notify the commissioner still run.1 And in states that adopted the certification provision, an insurer domiciled there owes its commissioner a written statement by February 15 each year certifying compliance with that program section, with the records behind it kept five years for examination.1 That turns the security program from a document into a recurring sworn statement.

The four duties at its core

Stripped to the load-bearing parts, the law asks for four things.

A written information security program. Not a policy binder, but a program scaled to the licensee’s size, complexity, and the nature of the data it holds, and built on a risk assessment. The assessment is the foundation document: an examiner who wants to know whether your program is real starts by asking what risks it was built against.

Third-party oversight. A licensee answers for the service providers it lets near nonpublic information. That means due diligence before engagement, contracts that require protection of the data, and attention afterward. The vendor’s breach is legally your notification problem, a point that stopped being theoretical when the NAIC’s own PeopleSoft incident put a central industry data repository in the breach conversation.

Investigation of cybersecurity events. When something happens, the licensee must determine whether a cybersecurity event occurred and what nonpublic information it touched.1 Everything downstream keys off that determination, including the clock.

Notification to the commissioner. Section 6 gives the licensee 72 hours from that determination, and the clock does not run to every state at once. It runs in a state if that state is the licensee’s domicile or home state, or if the licensee reasonably believes the event involved the nonpublic information of 250 or more consumers residing there and the event either triggers notice to some other government or regulatory body or is reasonably likely to cause material harm.1 Read both gates before anyone drafts a fifty-state notification runbook. An NAIC committee has approved a project for a centralized breach-notification portal, but none has been built: as of September 2026 the association’s Executive (EX) Committee has not taken the project up, and a security review stands in front of that step. If one arrives, a single filing would reach every adopting state, which raises the stakes on the internal moment of determination: slow once, late everywhere.

Which states have enacted the insurance data security model law

Adoption is what turns the model text into binding law, so the only list that matters is the one below: 27 states and Puerto Rico with a version of Model Law 668 in force as of September 4, 2026.3 The District of Columbia is marked pending on the NAIC’s map and is not counted.4 New York is not on this list either, because it regulates insurance data security through an instrument of its own, 23 NYCRR Part 500, rather than through the model. Puerto Rico is on the list by a different route from everywhere else: its Commissioner of Insurance adopted the model as Rule 108, a regulation, where the 27 states each passed a bill.3

Jurisdictions with a version of Model Law 668 in force, with the enacting instrument and primary source
JurisdictionInstrumentIn force sinceNotice to the regulatorStatute
AlabamaInsurance Data Security Law (Act 2019-98)May 1, 20193 business daysAla. Code § 27-62-1 et seq.
AlaskaInsurance Data Security (AS 21.23, art. 2)January 1, 20253 business daysAlaska Stat. §§ 21.23.240–21.23.399
ConnecticutInsurance Data Security Law (P.A. 19-117 § 230)October 1, 20203 business daysConn. Gen. Stat. § 38a-38
DelawareInsurance Data Security Act (82 Del. Laws c. 176)July 31, 20193 business days18 Del. C. § 8601 et seq.
HawaiiInsurance Data Security Law (Act 112, SLH 2021)July 1, 20213 business daysHaw. Rev. Stat. § 431:3B-101 et seq.
IllinoisInsurance Data Security Law (P.A. 103-0142)January 1, 20243 business days215 ILCS 215/1 et seq.
IndianaInsurance Data Security (IC 27-2-27)July 1, 20213 business daysInd. Code § 27-2-27-1 et seq.
IowaInsurance Data Security Act (2021 Iowa Acts ch. 79)January 1, 20223 business daysIowa Code ch. 507F
KentuckyInsurance data security (2022 Ky. Acts ch. 149)January 1, 20233 business daysKy. Rev. Stat. §§ 304.3-750 to 304.3-768
LouisianaInsurance Data Security Law (Act No. 283 of 2020)August 1, 20203 business daysLa. R.S. 22:2501–22:2511
MaineMaine Insurance Data Security ActJanuary 1, 20223 business days24-A M.R.S. §§ 2261–2272
MarylandInsurance Data Security, Title 33 (Ch. 231 of 2022)October 1, 20223 business daysMd. Code Ann., Ins. §§ 33-101 to 33-109
MichiganData Security, Insurance Code ch. 5A (P.A. 690 of 2018)January 20, 202110 business daysMCL 500.550–500.565
MinnesotaInsurance data security (Laws 2021 1st Spec. Sess. ch. 4, art. 3)August 1, 20215 business daysMinn. Stat. §§ 60A.985–60A.9858
MississippiInsurance Data Security LawJuly 1, 20193 business daysMiss. Code Ann. §§ 83-5-801 to 83-5-825
MissouriInsurance Data Security ActJanuary 1, 20264 business daysMo. Rev. Stat. §§ 375.1400–375.1427
New HampshireInsurance Data Security LawJanuary 1, 20203 business daysN.H. RSA ch. 420-P
North DakotaInsurance Data Security (N.D.C.C. ch. 26.1-02.2)August 1, 20213 business daysN.D. Cent. Code ch. 26.1-02.2
OhioCybersecurity Requirements for Insurance Companies (O.R.C. ch. 3965)March 20, 20193 business daysOhio Rev. Code §§ 3965.01–3965.11
OklahomaInsurance Data Security ActJuly 1, 20243 business days36 O.S. §§ 670–679
PennsylvaniaInsurance Data Security (40 Pa.C.S. ch. 45)December 11, 20235 business days40 Pa.C.S. §§ 4501–4536
Puerto RicoRule 108, Cybersecurity Standards for the Insurance IndustryOctober 10, 202472 hoursRegla Núm. 108, Reglamento del Código de Seguros de Puerto Rico
Rhode IslandInsurance data security amendments (P.L. 2024 ch. 354 and 355)January 1, 20253 business daysR.I. Gen. Laws §§ 27-1-46, 27-1-47, 27-2-29, 27-2-30
South CarolinaSouth Carolina Insurance Data Security ActJanuary 1, 201972 hoursS.C. Code Ann. §§ 38-99-10 to 38-99-100
TennesseeInsurance Data Security LawJuly 1, 20213 business daysTenn. Code Ann. §§ 56-2-1001 to 56-2-1011
VermontVermont Insurance Data Security LawJanuary 1, 2023None in the insurance law8 V.S.A. § 4728
VirginiaInsurance Data Security ActJuly 1, 20203 business daysVa. Code §§ 38.2-621 to 38.2-629
WisconsinInsurance Data Security (Wis. Stat. ch. 601, subch. IX)November 1, 20213 business daysWis. Stat. §§ 601.95–601.956

The notice column is the reason to read a state’s own text rather than the model. Two jurisdictions kept the model’s 72 hours, South Carolina and Puerto Rico, and Puerto Rico gates it on 250 affected consumers. Everywhere else the clock was rewritten in business days, which run longer than they look across a weekend: three in most states, four in Missouri, five in Minnesota and Pennsylvania, ten in Michigan. Vermont has no notification provision in its insurance law at all, and routes breach notice through the Security Breach Notice Act instead.

Two more departures matter before you assume the model describes your obligation. The first is who is covered: Rhode Island reaches only domestic and foreign insurance companies, and Maryland only carriers, a category running from insurers through managed general agents to third-party administrators but stopping short of the producers and agencies the model covers. The second is the small-licensee break. Virginia and Rhode Island dropped it altogether, so the ten-employee exemption in the model text does not exist there at all; most states kept one but raised it, to 15, 20, 25 or 50 employees; and North Dakota and Oklahoma replaced the headcount with revenue or asset tests. The model’s ten is a poor guide to whether any particular licensee is exempt.

One caution about the dates in the table: they are the day the chapter took effect. Most of these states then phased the security program in over a year and third-party oversight over two, so the deadline a licensee actually worked to fell later than the column shows.

Where GLBA fits

Underneath the model law sits a federal statute. Since 1999 the Gramm-Leach-Bliley Act has placed every financial institution, insurers included, under a continuing obligation to protect the security and confidentiality of customer information. It does not spell out what that takes. It tells each institution’s own regulator to set the safeguards standards.5

The piece most people miss is who that regulator is. For anyone engaged in providing insurance, GLBA names the state insurance authority of the licensee’s domicile, and directs it to implement the safeguards standards by rule.5 The FTC gets only the financial institutions no other agency covers, which is why its Safeguards Rule reaches other non-bank companies and stops short of insurers.5

Model Law 668 is how the states carry that federal duty. Read the two together and the structure is simple: GLBA supplies the obligation and the allocation, the states supply the teeth, and 668 is the tooth shape most of them chose. GLBA’s privacy-notice requirements run on a separate track. The model law is the security side of the same federal floor.

How the federal duty reaches an insurance licensee: GLBA, in force since 1999, imposes a federal duty to protect customer information and leaves the safeguards standards to each institution's own regulator. One branch runs to the FTC Safeguards Rule, which governs other non-bank firms and does not reach insurers. The other branch runs to state insurance regulators, who carry the duty through Model Law 668, which lands on the licensee: carriers, producers, and agencies.GLBA (1999)federal duty to protectcustomer informationFTC SAFEGUARDSRULEother non-bank firmsNOT INSURERSSTATE INSURANCEREGULATORSGLBA hands them thisMODEL LAW 668how the states carrythe federal dutyTHE LICENSEEcarriers, producers, agencies
FIG. 1: GLBA HANDS INSURANCE DATA SECURITY TO THE STATES

Where it meets your AI program

This is the connection few write down, and the reason this piece exists.

Start with the inventory. The third parties your AI governance program tracks, the vendors whose models score, draft, or triage, are in almost every case also third-party service providers under the data security law, because they touch nonpublic information to do their work. One vendor, two regulatory lenses, same underlying spreadsheet. Programs that run these as separate lists discover the mismatch during an exam, which is the worst time to discover it.

Then the records. A security program that documents its risk assessments and vendor oversight is producing the same species of evidence an AI governance program produces, and examiners read both with the same skepticism: a document dated last week reads like it was written last week. The disciplines compound. So do the gaps.

Finally, the incident chain. A breach at an AI vendor is a cybersecurity event under this law exactly as it is a vendor-oversight failure under your AI framework. The notification duty, the investigation duty, and the contract question about who tells you what, and how fast, are one problem wearing two labels. If your AI vendor risk assessment does not already ask about breach-notification timelines, the data security law is the reason it should.

What to check

Three lookups cover most of the practical exposure. Which of your license states have enacted the law, and with what modifications, is the first: the table above names the enacting statute in each of them, and only the state’s own enacted text shows what it changed on the way in. Our state tracker maps the AI rules, not this one. Whether your security program’s third-party list and your AI vendor inventory describe the same population is the second. Who inside your company has the authority to declare that a determination has been made, and how quickly that declaration can happen on a weekend, is the third, because that answer defines your real notification timeline.

None of these duties lands on the NAIC, on the vendor, or on the model text. They land on the licensee whose name is on the filing. Where the notification gates are met, the clock belongs to the enacting state rather than to the model, and in most of the country it runs in business days from the moment the licensee determines a cybersecurity event occurred. That makes the most consequential sentence in the whole incident-response plan the one that defines when a determination happens. Companies that treat data security as an IT topic discover this in the wrong order. The law is aimed at whoever holds the license, and it prices the delay accordingly.

FAQ

Is a breach inside a vendor’s system a cybersecurity event under the model law? Yes, if the licensee learns that an event has or may have occurred in a system a third-party service provider maintains. Section 5.C requires the licensee to complete the Section 5.B investigation itself or to confirm and document that the provider completed it. The 72-hour clocks in Section 6 start at different points, the licensee’s own determination under 6.A and receipt of the provider’s notice for an assuming insurer under 6.C, so the incident plan needs to name which one applies.1

Does every unauthorized access count as a cybersecurity event? No. Section 3.D excludes the acquisition of encrypted nonpublic information when the key or process was not also taken, and an event where the licensee has determined that the information was not used or released and has been returned or destroyed. Records concerning every cybersecurity event still have to be kept for at least five years and produced to the commissioner on demand under Section 5.D.1

What penalty does a violation carry? The model leaves it blank. Under its Section 10 a licensee “may be penalized in accordance with [insert general penalty statute],” so each enacting state fills in its own insurance-code penalty, and the exposure differs by license state.1

Footnotes

  1. NAIC Insurance Data Security Model Law (MDL-668), published in NAIC Model Laws, Regulations, Guidelines and Other Resources, 4th Quarter 2017. Section 4.A (program “commensurate with the size and complexity of the Licensee” and based on its Risk Assessment); Section 4.F (due diligence in selecting a Third-Party Service Provider, and requiring it to implement safeguards); Section 4.I (annual written certification of Section 4 compliance by February 15 from insurers domiciled in the state, records kept five years); Section 5.B (investigate and determine whether a cybersecurity event occurred and what nonpublic information was involved); Section 6.A (notice “as promptly as possible but in no event later than 72 hours from a determination that a Cybersecurity Event has occurred when either of the following criteria has been met,” the two criteria being domicile or home state, or 250 or more affected consumers residing in the state combined with other-agency notice or a reasonable likelihood of material harm); Section 9.A(1) (licensees with fewer than ten employees, including independent contractors, exempt from Section 4); Section 3.D (the two exclusions from the definition of Cybersecurity Event: encrypted nonpublic information where the key or process was not also taken, and information the licensee has determined was not used or released and has been returned or destroyed); Section 5.C (an event in a system maintained by a Third-Party Service Provider: the licensee completes the Section 5.B steps or confirms and documents that the provider completed them); Section 5.D (records concerning all Cybersecurity Events kept for at least five years and produced on the Commissioner’s demand); Section 6.C(1)(a) and 6.C(2)(a) (an assuming insurer’s 72 hours run from its own determination, or from receiving notice from its Third-Party Service Provider); Section 10 (“a Licensee may be penalized in accordance with [insert general penalty statute]”). https://content.naic.org/sites/default/files/model-law-668.pdf ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  2. NAIC, cybersecurity topic page (last updated May 9, 2024): the NAIC “adopted the new Insurance Data Security Model Law (#668) which requires insurers and other entities licensed by state insurance departments to develop, implement and maintain an information security program; investigate any cybersecurity events; and notify the state insurance commissioner of such events.” The same page’s adoption figure (“21 states”) is older than the working group’s April 2026 map cited at 4. https://content.naic.org/insurance-topics/cybersecurity ↩

  3. This count is InsureAI Wire’s own, taken from each jurisdiction’s own text as linked in the table above rather than from the NAIC’s adoption map. It covers the same set the map marks adopted as of April 1, 2026, which the map totals as 28 jurisdictions and this piece writes out as 27 states plus Puerto Rico. We opened and cited each one because the map disclaims any determination about whether a given enactment contains all elements of the model, and because secondary trackers disagree with the official record on the bill number, the year, or both for a majority of these jurisdictions. ↩ ↩2 ↩3

  4. NAIC Cybersecurity (H) Working Group, “Implementation of Model Act #668, Insurance Data Security Model Law,” state adoption map, status as of April 1, 2026: the legend counts 28 jurisdictions as Adopted (27 states plus Puerto Rico), 1 pending, and New York separately under “Other Insurance Data Security Provisions.” The map itself cautions that it “does not reflect a determination as to whether the pending or enacted legislation contains all elements of the model,” and published counts differ by tracker for that reason, which is why the count in this piece is taken from each jurisdiction’s own text rather than from the map. https://content.naic.org/sites/default/files/cmte-h-cybersecurity-wg-state-adoption-map-model-668.pdf ↩ ↩2

  5. Gramm-Leach-Bliley Act, Pub. L. 106-102 (Nov. 12, 1999). 15 U.S.C. § 6801(a) declares the continuing obligation of every financial institution “to protect the security and confidentiality of those customers’ nonpublic personal information,” and § 6801(b) directs each agency or authority listed in § 6805(a) to “establish appropriate standards” for administrative, technical, and physical safeguards. Section 6805(a)(6) assigns that role, “in the case of any person engaged in providing insurance,” to “the applicable State insurance authority of the State in which the person is domiciled,” and § 6805(b)(2) requires those authorities to implement the standards by rule. Section 6805(a)(7) gives the FTC only financial institutions not covered by paragraphs (1) through (6), which is why the FTC’s Safeguards Rule (16 C.F.R. Part 314) does not reach state-licensed insurers. https://www.law.cornell.edu/uscode/text/15/6805 ↩ ↩2 ↩3

The Bottom Line

  • Model Law 668 is a statute template, not guidance. Where a state has enacted it, the security program, the vendor oversight and the breach investigation are legal duties with penalties behind them, and it is on the books in 27 states and Puerto Rico.
  • It reaches every insurance licensee, not just carriers. Producers and agencies are in scope under the model, though Rhode Island and Maryland cut theirs down to insurers and carriers; the model's one size break exempts licensees under ten employees from the program section, and from nothing else.
  • GLBA is the federal layer underneath. It hands insurance data security to state regulators, 668 is how the states carry it, and the FTC rule you read about elsewhere does not cover insurers.
  • Your AI vendor inventory and your security-law third-party list are the same spreadsheet. Treat them as one and both programs get easier.

Recommended next

How Insurers Assess AI Vendor Risk

A NAIC-aligned AI vendor risk assessment checklist: a twenty-question due-diligence questionnaire, contract clauses, and the monitoring that stays with the insurer.

Continue →
Engraved portrait of Simon Li

Written by

Simon Li · Founding Editor

I write InsureAI Wire and maintain its 51-jurisdiction tracker. Most of the work is reading: NAIC working group papers, state bulletins, bills, court filings, and public comment letters. Every claim on the site carries the document it came from, so you never have to take my word for it.

Contact or report a correction →

Related reading

Information aggregation and analysis, not legal advice. See our disclaimer.