Skip to main content
Category: Regulatory & Privacy Compliance

Insurance Data Security Model Law

Also known as: Model Law #668, NAIC Model #668
Simply put

The Insurance Data Security Model Law is a template law developed by the National Association of Insurance Commissioners (NAIC) that sets standards for how insurers and other entities licensed by state insurance departments protect consumer data and respond to security incidents. Because it is a model law rather than a binding federal statute, it takes legal effect only when an individual state adopts it, and states may modify its provisions when they do. It addresses cybersecurity obligations for regulated insurance entities, including investigating incidents and notifying the state insurance commissioner.

Formal definition

Model #668 is an NAIC model law establishing standards for data security and for the investigation of, and notification to, the insurance Commissioner regarding cybersecurity events affecting licensees of state insurance departments. As a model law, it has no independent legal force; its requirements bind regulated entities only in states that enact it into their own statutes, and enacted versions may diverge from the NAIC text (for example, South Carolina codified its version in Title 38, Chapter 99 of the South Carolina Code of Laws). Adoption and pending action vary by state over time. The law imposes regulatory obligations on covered entities and should not be conflated with cyber insurance policy coverage terms; it governs the security and incident-notification duties of licensed insurers and related entities rather than defining what losses a policy pays. The precise scope, thresholds, and exemptions depend on each adopting state's enacting language.

Why it matters

For insurers, brokers, and other entities licensed by state insurance departments, the Insurance Data Security Model Law (#668) represents a shift from voluntary data-protection practices to enforceable regulatory obligations wherever a state has enacted it. Because it is a model law rather than a binding federal statute, its practical significance depends entirely on state-level adoption: a licensee operating across multiple states may face different requirements, thresholds, and exemptions depending on how each adopting state codified its version. This patchwork means compliance teams cannot assume a single national standard applies, and must track adoption and pending action state by state over time.

The law matters because it imposes affirmative duties on regulated entities to maintain data security and to investigate and notify the insurance Commissioner of cybersecurity events. These are regulatory compliance obligations, not insurance coverage terms. A common and consequential error is to conflate the two: satisfying Model #668's security and notification requirements does not determine whether a cyber insurance policy will pay a given loss, and holding a cyber policy does not discharge a licensee's statutory duties under an adopting state's version of the law. Whether an incident triggers a notification duty to the Commissioner is governed by the enacting statute; whether it triggers coverage is governed by the specific policy wording, endorsements, exclusions, and conditions.

Because enacted versions may diverge from the NAIC text, organizations should treat the model law as a baseline template rather than as the operative legal requirement in any particular jurisdiction. South Carolina, for example, codified its version in Title 38, Chapter 99 of the South Carolina Code of Laws. Risk managers and compliance professionals should confirm the precise scope, thresholds, and exemptions in each state where a licensee operates rather than relying on the NAIC template alone.

Who it's relevant to

Compliance and legal professionals at insurers
Because the law binds licensees only in states that have enacted it, and enacted versions may differ from the NAIC template, compliance and legal teams must track adoption and pending action state by state and confirm the specific scope, thresholds, exemptions, and notification requirements in each jurisdiction where the entity is licensed. Reliance on the model text alone is insufficient where a state has modified it.
Chief information security officers and incident responders
In adopting states, the law creates affirmative duties to maintain data security and to investigate and notify the state insurance Commissioner of cybersecurity events. CISOs and incident response teams should build these regulatory investigation and notification obligations into their incident response processes, recognizing that these are compliance duties distinct from any internal security framework or resilience program.
Risk managers and cyber insurance buyers
The model law imposes regulatory obligations and should not be conflated with cyber insurance coverage. Satisfying the law's security and notification duties does not determine whether a policy responds to a loss, and purchasing cover does not satisfy the statutory duties. Risk managers should treat the two as separate workstreams, coordinating regulatory notification to the Commissioner with any notice obligations under their policy.
State insurance regulators
The NAIC maintains a map of state action and pending action on Model #668, reflecting that adoption varies by state over time. Regulators considering adoption or amendment work from the model as a template, with authority to modify its provisions, thresholds, and exemptions when codifying it into state law.

Inside Insurance Data Security Model Law

Information Security Program Requirement
A core element requiring covered entities (typically insurers, agents, and other licensees) to develop, implement, and maintain a written information security program based on a risk assessment. The program is generally expected to be commensurate with the size and complexity of the entity, the nature of its activities, and the sensitivity of the information it handles. This is a security and governance obligation, not an insurance coverage term.
Risk Assessment Obligation
A requirement to identify reasonably foreseeable internal and external threats, assess the likelihood and potential damage of those threats, and evaluate the sufficiency of existing safeguards. This is a risk mitigation and governance concept distinct from risk transfer through insurance.
Board and Governance Oversight
Provisions typically calling for oversight of the information security program at a senior or board level, and in many versions assignment of responsibility for the program. This addresses accountability and governance rather than coverage entitlement.
Third-Party Service Provider Oversight
A component addressing due diligence over vendors and service providers that have access to nonpublic information, including contractual expectations that providers maintain appropriate safeguards. This is a supply-chain risk management element, not a liability coverage grant.
Cybersecurity Event Investigation and Notification
Duties to investigate suspected or confirmed cybersecurity events and, where thresholds are met, to notify the state insurance commissioner and affected consumers within specified timeframes. Notification triggers and definitions of a 'cybersecurity event' are set by the adopting jurisdiction's wording and should not be assumed uniform across states.
Incident Response Planning
An expectation that covered entities establish a written incident response plan to address and recover from cybersecurity events. Incident response here refers to the operational handling of a security event and is distinct from crisis management and from insurance claims processes.
State-by-State Adoption
The Model Law is a template developed for state adoption and only carries legal force in jurisdictions that enact it, potentially with modifications. Its scope, definitions, and thresholds can therefore differ by jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Insurance Data Security Model Law.

Does adopting the Insurance Data Security Model Law mean an organization is protected against cyber losses?
No. The model law is a regulatory framework establishing information security program requirements for licensed insurance entities; it is a compliance and risk-mitigation instrument, not a source of financial recovery. Complying with it does not transfer the financial consequences of a cyber incident the way a cyber insurance policy might, and it does not by itself constitute resilience. Whether any resulting loss is recoverable depends entirely on the terms of a separate insurance policy. Compliance may influence underwriting or the availability of certain coverage, but the two are distinct concepts and should not be conflated.
Is the Insurance Data Security Model Law a nationally uniform requirement that applies the same way everywhere?
Not necessarily. A model law is a template proposed for adoption; it takes legal effect only when a given jurisdiction enacts it, and jurisdictions may adopt it with modifications, on different timelines, or not at all. As a result, the specific obligations, definitions, exemption thresholds, and enforcement provisions that actually apply depend on the enacting jurisdiction's version rather than a single national standard. Organizations operating across multiple jurisdictions should not assume the requirements are identical everywhere.
Who is typically subject to the requirements once a jurisdiction adopts the model law?
The framework is generally directed at persons and entities licensed or authorized under a jurisdiction's insurance laws, subject to the specific scope language the jurisdiction enacts. Many versions include exemptions for smaller entities based on defined thresholds and may address the treatment of third-party service providers. Because scope and exemptions can vary by enacting jurisdiction, organizations should confirm applicability against the precise wording of the version in force where they operate rather than relying on the general model.
What are the core components an information security program is expected to address under this framework?
Enacted versions commonly call for a written information security program based on a risk assessment, designation of responsibility for the program, safeguards proportionate to identified risks, oversight of third-party service providers, and an incident response plan, subject to the specific wording adopted. These are governance and security control expectations rather than insurance policy terms. Note that an incident response plan under this framework is distinct from crisis management and from broader business continuity or disaster recovery planning, which the law does not necessarily prescribe.
How do the notification obligations under the model law relate to obligations under other regimes?
Enacted versions typically impose obligations to investigate cybersecurity events and to notify a regulator within a defined timeframe when specified criteria are met, subject to the jurisdiction's exact wording. These obligations are separate from, and may operate alongside, other breach-notification duties arising under general privacy or data-breach statutes, contractual terms, or an insurer's own claim-notice conditions. Because a single event can trigger multiple, differently defined notification duties, organizations should map each applicable regime rather than assuming one notice satisfies all.
How should compliance with this framework be coordinated with a cyber insurance program?
The two should be managed as complementary but distinct. The framework addresses regulatory obligations and security program governance (risk mitigation), while a cyber policy addresses financial risk transfer, subject to its wording, endorsements, exclusions, and conditions. Insurers may inquire into an applicant's security program during underwriting, and gaps between represented and actual practices can have coverage consequences depending on policy conditions and applicable exclusions, such as failure-to-maintain-standards provisions. Organizations should align documentation, incident response planning, and notification workflows so that regulatory duties and any policy notice conditions are both satisfied, recognizing that meeting one does not automatically satisfy the other.

Common misconceptions

Complying with the Insurance Data Security Model Law means an entity's cyber losses will be covered by insurance.
The Model Law is a regulatory security and governance standard imposing obligations on covered entities; it is not an insurance policy and does not itself provide first-party or third-party coverage. Whether any resulting loss is covered depends entirely on the wording, endorsements, exclusions, and conditions of a separate cyber insurance policy, which is a matter of risk transfer rather than regulatory compliance.
The Model Law applies uniformly across the United States.
It is a model template intended for adoption by individual states, and it only has legal effect where enacted. Adopting states may modify definitions, notification thresholds, and timeframes, so requirements can vary by jurisdiction rather than being a single national standard.
Meeting the Model Law's information security program requirements makes an organization resilient.
The Model Law establishes governance, risk assessment, and incident response obligations, but satisfying a compliance baseline does not by itself constitute resilience. Resilience involves distinct operational capabilities such as business continuity and disaster recovery with defined recovery objectives, which are separate concepts from a mandated security program.

Best practices

Confirm which specific state versions of the Model Law apply to your operations, since adopting jurisdictions may modify definitions, notification thresholds, and timeframes rather than mirroring the template exactly.
Maintain the written information security program and supporting risk assessment as living documents, updating them as the entity's size, activities, and threat environment change.
Treat Model Law compliance and cyber insurance as complementary but separate workstreams, and review policy wording, endorsements, and exclusions independently to understand what regulatory notification and remediation costs may or may not be covered.
Establish and periodically test a written incident response plan, and keep it distinct from crisis management and from the insurance claims notification process so each is understood and exercised by the right owners.
Implement documented third-party service provider due diligence and contractual safeguards for vendors with access to nonpublic information, aligned to the oversight expectations in the applicable statute.
Assign clear senior or board-level accountability for the information security program so governance obligations are demonstrably met and evidenced for potential regulatory examination.
Promotional banner for the Pentest Readiness checklist download