Does My State Have an Insurance Cybersecurity Law?
Whether your state has an insurance cybersecurity law depends on where you sell insurance. As of the NAIC’s most recent state legislative brief, 28 jurisdictions have adopted the underlying model law. It’s called NAIC Model #668. Illinois is one of them.
Model #668 requires insurers and agencies to run an information security program. It also requires risk assessments and breach reporting to state regulators. Not every state has adopted it. Some rely on older, separate rules instead. Others show no current activity on this specific model at all.
The table below shows where every state stands right now. It also covers Washington D.C. and Puerto Rico.
How to Read the Table Below
The NAIC’s own adoption chart sorts every jurisdiction into one of three buckets. Knowing the difference matters before you draw conclusions about your state.

- Adopted: the state passed a version of Model #668 that the NAIC’s Legal Division considers substantially similar to the current model, in its entirety.
- Related activity / older law: the state has its own separate insurance data-security regulation on the books instead of the NAIC model as written.
- No current activity: the NAIC’s brief does not list the state as having adopted the model or having comparable related activity.
One more status shows up once: Pending. Idaho had a pending adoption in progress as of the NAIC’s last update, so it doesn’t cleanly fit any of the three buckets above yet.
This is a snapshot, not a live feed. State legislatures introduce and pass bills year-round, and the NAIC updates its chart periodically rather than in real time.
Insurance Cybersecurity Law by State
Source: NAIC’s state-adoption chart (ST-668, Summer 2025) and its August 2025 state legislative brief. As of that update. If this decision matters right now, confirm your state’s current status with your state Department of Insurance before you act on it.
| State / Jurisdiction | Status | Note |
|---|---|---|
| Alabama | Adopted | NAIC ST-668 chart |
| Alaska | Adopted | NAIC ST-668 chart |
| Arizona | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Arkansas | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| California | Related activity / older law | Separate state regulation, not Model #668 |
| Colorado | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Connecticut | Adopted | NAIC ST-668 chart |
| Delaware | Adopted | NAIC ST-668 chart |
| District of Columbia | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Florida | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Georgia | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Hawaii | Adopted | NAIC ST-668 chart |
| Idaho | Pending | Adoption pending as of the Aug. 2025 brief |
| Illinois | Adopted | 215 ILCS 215 (2024) |
| Indiana | Adopted | NAIC ST-668 chart |
| Iowa | Adopted | NAIC ST-668 chart |
| Kansas | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Kentucky | Adopted | NAIC ST-668 chart |
| Louisiana | Adopted | NAIC ST-668 chart |
| Maine | Adopted | NAIC ST-668 chart |
| Maryland | Adopted | NAIC ST-668 chart |
| Massachusetts | Related activity / older law | Separate state regulation, not Model #668 |
| Michigan | Adopted | NAIC ST-668 chart |
| Minnesota | Adopted | NAIC ST-668 chart |
| Mississippi | Adopted | NAIC ST-668 chart |
| Missouri | Adopted | NAIC ST-668 chart |
| Montana | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Nebraska | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Nevada | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| New Hampshire | Adopted | NAIC ST-668 chart |
| New Jersey | Related activity / older law | Separate state regulation, not Model #668 |
| New Mexico | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| New York | Related activity / older law | Separate state regulation, not Model #668 |
| North Carolina | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| North Dakota | Adopted | NAIC ST-668 chart |
| Ohio | Adopted | NAIC ST-668 chart |
| Oklahoma | Adopted | NAIC ST-668 chart |
| Oregon | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Pennsylvania | Adopted | NAIC ST-668 chart |
| Puerto Rico | Adopted | NAIC ST-668 chart |
| Rhode Island | Adopted | NAIC ST-668 chart |
| South Carolina | Adopted | NAIC ST-668 chart |
| South Dakota | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Tennessee | Adopted | NAIC ST-668 chart |
| Texas | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Utah | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Vermont | Adopted | NAIC ST-668 chart |
| Virginia | Adopted | NAIC ST-668 chart |
| Washington | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| West Virginia | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
| Wisconsin | Adopted | NAIC ST-668 chart |
| Wyoming | No current activity confirmed in source | Not named as adopted or related in the Aug. 2025 brief |
A “no current activity confirmed in source” row does not mean your state definitely has no rule. It means the NAIC’s August 2025 brief did not name that state as adopted or as having related activity. Bills move fast. Check with your state DOI before treating this as final.
Illinois and Chicagoland: What This Means Right Now
Illinois adopted Model #668 in 2024. It’s codified at 215 ILCS 215. The law is already in effect, not pending.
If you’re an insurer, agency, or MGA licensed in Illinois, you’re already on the clock. This isn’t a “watch this space” state. It’s an “already law” state.
That means the full Section 4 requirement set applies to you:
LeadingIT is a managed IT and cybersecurity provider based in Woodstock and Manteno, Illinois.
Model #668’s technical controls map closely onto what a managed IT partner already builds:
- Access controls and multi-factor authentication
- Encryption of nonpublic information
- Ongoing monitoring and audit-trail logging
- A tested incident response plan
If your agency needs help getting there, see LeadingIT’s insurance/compliance IT services. Or book a call to talk through where you stand.
My State Isn’t on the Adopted List. Am I Off the Hook?
No. Here’s why:

- Exceptions are narrow, not automatic. Even in adopted states, only three groups qualify: licensees with fewer than 10 employees, licensees already compliant with HIPAA’s security rules, and employees already covered by another licensee’s program. – “No current activity” isn’t permanent. Illinois had no activity until 2024, then adopted the law outright. The NAIC’s own August 2025 brief lists Idaho as pending. State legislatures move on their own schedule. – Domicile can pull you in anyway. In an adopted state, the notification duty applies based on where an insurer is domiciled or where a producer’s home state is, not just where you happen to sell policies. Coverage is still partial today.
None of this tells you what compliance actually requires once your state reaches you. What NAIC Model Law 668 actually requires walks through it step by step. Or go straight to the full NAIC 668 compliance checklist for the requirement-by-requirement view.
See Where You Stand
Not sure exactly where your agency stands today? Answer 8 plain-English questions and get your compliance-readiness level, plus the specific gaps to close. No sign-up needed to see your result.
Take the free 2-minute NAIC 668 Risk-Check
Related Guides
- What Is NAIC Model Law 668? Insurance Data Security Explained
- NAIC 668 Compliance Checklist: Every Requirement, Plain English
Frequently Asked Questions
It sets standards for an information security program and for investigating and reporting a cybersecurity event to regulators. It’s a model, not a federal statute, so it only takes legal effect once a state’s legislature or insurance department adopts it.</p> </details>
Yes. Illinois adopted NAIC Model Law 668 in 2024, codified at 215 ILCS 215. Illinois-licensed insurers, agencies, and MGAs are already required to comply, not waiting on a future deadline.
You may still be reached by it. If you’re domiciled in an adopted state but sell in others, that state’s notification duty can still apply to you. State adoption also changes over time, so a state with no current activity today can adopt the law next year, the way Illinois did in 2024.
The law applies to “Licensees,” meaning anyone licensed, authorized, or required to be licensed under a state’s insurance laws in an adopting state. In practice that covers insurers, insurance producers and agents, and other NAIC-regulated entities. It excludes certain out-of-state purchasing groups, risk retention groups, and some out-of-state assuming insurers.
Only if they have fewer than 10 employees, including independent contractors. Two other narrow exceptions exist: licensees already compliant with HIPAA’s security rules, and employees already covered by another licensee’s program.<details> <summary>What is the penalty for violating Model 668?</summary> <p>The model law itself doesn’t set one fixed dollar penalty. It instructs each adopting state to insert its own general penalty statute, so the actual fine or sanction comes from that state’s insurance code, not a single nationwide number. Check your state’s specific penalty provisions rather than assuming a flat figure.
Licensees generally get one year from a state’s effective date to implement the core Information Security Program requirements. Third-party service provider oversight gets a longer runway, two years from the effective date, since vetting vendor relationships takes more time than standing up internal controls.
Get Help Meeting Your State’s Requirements
Model #668 compliance touches nearly every part of your IT environment. That includes access controls, encryption, monitoring, and incident response. LeadingIT builds and maintains that environment for insurance agencies and insurers across Chicagoland. See LeadingIT’s insurance/compliance IT services or book a call to talk through your state’s specific requirements.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
