Insurance Data Security Model Law
The Insurance Data Security Model Law is a template law developed by the National Association of Insurance Commissioners (NAIC) that sets standards for how insurers and other entities licensed by state insurance departments protect consumer data and respond to security incidents. Because it is a model law rather than a binding federal statute, it takes legal effect only when an individual state adopts it, and states may modify its provisions when they do. It addresses cybersecurity obligations for regulated insurance entities, including investigating incidents and notifying the state insurance commissioner.
Model #668 is an NAIC model law establishing standards for data security and for the investigation of, and notification to, the insurance Commissioner regarding cybersecurity events affecting licensees of state insurance departments. As a model law, it has no independent legal force; its requirements bind regulated entities only in states that enact it into their own statutes, and enacted versions may diverge from the NAIC text (for example, South Carolina codified its version in Title 38, Chapter 99 of the South Carolina Code of Laws). Adoption and pending action vary by state over time. The law imposes regulatory obligations on covered entities and should not be conflated with cyber insurance policy coverage terms; it governs the security and incident-notification duties of licensed insurers and related entities rather than defining what losses a policy pays. The precise scope, thresholds, and exemptions depend on each adopting state's enacting language.
Why it matters
For insurers, brokers, and other entities licensed by state insurance departments, the Insurance Data Security Model Law (#668) represents a shift from voluntary data-protection practices to enforceable regulatory obligations wherever a state has enacted it. Because it is a model law rather than a binding federal statute, its practical significance depends entirely on state-level adoption: a licensee operating across multiple states may face different requirements, thresholds, and exemptions depending on how each adopting state codified its version. This patchwork means compliance teams cannot assume a single national standard applies, and must track adoption and pending action state by state over time.
The law matters because it imposes affirmative duties on regulated entities to maintain data security and to investigate and notify the insurance Commissioner of cybersecurity events. These are regulatory compliance obligations, not insurance coverage terms. A common and consequential error is to conflate the two: satisfying Model #668's security and notification requirements does not determine whether a cyber insurance policy will pay a given loss, and holding a cyber policy does not discharge a licensee's statutory duties under an adopting state's version of the law. Whether an incident triggers a notification duty to the Commissioner is governed by the enacting statute; whether it triggers coverage is governed by the specific policy wording, endorsements, exclusions, and conditions.
Because enacted versions may diverge from the NAIC text, organizations should treat the model law as a baseline template rather than as the operative legal requirement in any particular jurisdiction. South Carolina, for example, codified its version in Title 38, Chapter 99 of the South Carolina Code of Laws. Risk managers and compliance professionals should confirm the precise scope, thresholds, and exemptions in each state where a licensee operates rather than relying on the NAIC template alone.
Who it's relevant to
Inside Insurance Data Security Model Law
Common questions
Answers to the questions practitioners most commonly ask about Insurance Data Security Model Law.
