Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Does My State Have an Insurance Cybersecurity Law?

August 11, 2026
hero-does-my-state-have-insurance-cybersecurity-law-1.png

Whether your state has an insurance cybersecurity law depends on where you sell insurance. As of the NAIC’s most recent state legislative brief, 28 jurisdictions have adopted the underlying model law. It’s called NAIC Model #668. Illinois is one of them.

Model #668 requires insurers and agencies to run an information security program. It also requires risk assessments and breach reporting to state regulators. Not every state has adopted it. Some rely on older, separate rules instead. Others show no current activity on this specific model at all.

The table below shows where every state stands right now. It also covers Washington D.C. and Puerto Rico.

How to Read the Table Below

The NAIC’s own adoption chart sorts every jurisdiction into one of three buckets. Knowing the difference matters before you draw conclusions about your state.

NAIC Adoption Status Key
  • Adopted: the state passed a version of Model #668 that the NAIC’s Legal Division considers substantially similar to the current model, in its entirety.
  • Related activity / older law: the state has its own separate insurance data-security regulation on the books instead of the NAIC model as written.
  • No current activity: the NAIC’s brief does not list the state as having adopted the model or having comparable related activity.

One more status shows up once: Pending. Idaho had a pending adoption in progress as of the NAIC’s last update, so it doesn’t cleanly fit any of the three buckets above yet.

This is a snapshot, not a live feed. State legislatures introduce and pass bills year-round, and the NAIC updates its chart periodically rather than in real time.

Insurance Cybersecurity Law by State

Source: NAIC’s state-adoption chart (ST-668, Summer 2025) and its August 2025 state legislative brief. As of that update. If this decision matters right now, confirm your state’s current status with your state Department of Insurance before you act on it.

State / JurisdictionStatusNote
AlabamaAdoptedNAIC ST-668 chart
AlaskaAdoptedNAIC ST-668 chart
ArizonaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
ArkansasNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
CaliforniaRelated activity / older lawSeparate state regulation, not Model #668
ColoradoNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
ConnecticutAdoptedNAIC ST-668 chart
DelawareAdoptedNAIC ST-668 chart
District of ColumbiaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
FloridaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
GeorgiaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
HawaiiAdoptedNAIC ST-668 chart
IdahoPendingAdoption pending as of the Aug. 2025 brief
IllinoisAdopted215 ILCS 215 (2024)
IndianaAdoptedNAIC ST-668 chart
IowaAdoptedNAIC ST-668 chart
KansasNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
KentuckyAdoptedNAIC ST-668 chart
LouisianaAdoptedNAIC ST-668 chart
MaineAdoptedNAIC ST-668 chart
MarylandAdoptedNAIC ST-668 chart
MassachusettsRelated activity / older lawSeparate state regulation, not Model #668
MichiganAdoptedNAIC ST-668 chart
MinnesotaAdoptedNAIC ST-668 chart
MississippiAdoptedNAIC ST-668 chart
MissouriAdoptedNAIC ST-668 chart
MontanaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
NebraskaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
NevadaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
New HampshireAdoptedNAIC ST-668 chart
New JerseyRelated activity / older lawSeparate state regulation, not Model #668
New MexicoNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
New YorkRelated activity / older lawSeparate state regulation, not Model #668
North CarolinaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
North DakotaAdoptedNAIC ST-668 chart
OhioAdoptedNAIC ST-668 chart
OklahomaAdoptedNAIC ST-668 chart
OregonNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
PennsylvaniaAdoptedNAIC ST-668 chart
Puerto RicoAdoptedNAIC ST-668 chart
Rhode IslandAdoptedNAIC ST-668 chart
South CarolinaAdoptedNAIC ST-668 chart
South DakotaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
TennesseeAdoptedNAIC ST-668 chart
TexasNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
UtahNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
VermontAdoptedNAIC ST-668 chart
VirginiaAdoptedNAIC ST-668 chart
WashingtonNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
West VirginiaNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief
WisconsinAdoptedNAIC ST-668 chart
WyomingNo current activity confirmed in sourceNot named as adopted or related in the Aug. 2025 brief

A “no current activity confirmed in source” row does not mean your state definitely has no rule. It means the NAIC’s August 2025 brief did not name that state as adopted or as having related activity. Bills move fast. Check with your state DOI before treating this as final.

Illinois and Chicagoland: What This Means Right Now

Illinois adopted Model #668 in 2024. It’s codified at 215 ILCS 215. The law is already in effect, not pending.

If you’re an insurer, agency, or MGA licensed in Illinois, you’re already on the clock. This isn’t a “watch this space” state. It’s an “already law” state.

That means the full Section 4 requirement set applies to you:

LeadingIT is a managed IT and cybersecurity provider based in Woodstock and Manteno, Illinois.

Model #668’s technical controls map closely onto what a managed IT partner already builds:

  • Access controls and multi-factor authentication
  • Encryption of nonpublic information
  • Ongoing monitoring and audit-trail logging
  • A tested incident response plan

If your agency needs help getting there, see LeadingIT’s insurance/compliance IT services. Or book a call to talk through where you stand.

My State Isn’t on the Adopted List. Am I Off the Hook?

No. Here’s why:

The three narrow exceptions to NAIC Model 668 compliance: businesses with fewer than 10 employees, businesses already compliant with HIPAA's security rules, and employees already covered by another licensee's program.
  • Exceptions are narrow, not automatic. Even in adopted states, only three groups qualify: licensees with fewer than 10 employees, licensees already compliant with HIPAA’s security rules, and employees already covered by another licensee’s program. – “No current activity” isn’t permanent. Illinois had no activity until 2024, then adopted the law outright. The NAIC’s own August 2025 brief lists Idaho as pending. State legislatures move on their own schedule. – Domicile can pull you in anyway. In an adopted state, the notification duty applies based on where an insurer is domiciled or where a producer’s home state is, not just where you happen to sell policies. Coverage is still partial today.

None of this tells you what compliance actually requires once your state reaches you. What NAIC Model Law 668 actually requires walks through it step by step. Or go straight to the full NAIC 668 compliance checklist for the requirement-by-requirement view.

See Where You Stand

Not sure exactly where your agency stands today? Answer 8 plain-English questions and get your compliance-readiness level, plus the specific gaps to close. No sign-up needed to see your result.

Take the free 2-minute NAIC 668 Risk-Check

Frequently Asked Questions

It sets standards for an information security program and for investigating and reporting a cybersecurity event to regulators. It’s a model, not a federal statute, so it only takes legal effect once a state’s legislature or insurance department adopts it.</p> </details>

Yes. Illinois adopted NAIC Model Law 668 in 2024, codified at 215 ILCS 215. Illinois-licensed insurers, agencies, and MGAs are already required to comply, not waiting on a future deadline.

You may still be reached by it. If you’re domiciled in an adopted state but sell in others, that state’s notification duty can still apply to you. State adoption also changes over time, so a state with no current activity today can adopt the law next year, the way Illinois did in 2024.

The law applies to “Licensees,” meaning anyone licensed, authorized, or required to be licensed under a state’s insurance laws in an adopting state. In practice that covers insurers, insurance producers and agents, and other NAIC-regulated entities. It excludes certain out-of-state purchasing groups, risk retention groups, and some out-of-state assuming insurers.

Only if they have fewer than 10 employees, including independent contractors. Two other narrow exceptions exist: licensees already compliant with HIPAA’s security rules, and employees already covered by another licensee’s program.<details> <summary>What is the penalty for violating Model 668?</summary> <p>The model law itself doesn’t set one fixed dollar penalty. It instructs each adopting state to insert its own general penalty statute, so the actual fine or sanction comes from that state’s insurance code, not a single nationwide number. Check your state’s specific penalty provisions rather than assuming a flat figure.

Licensees generally get one year from a state’s effective date to implement the core Information Security Program requirements. Third-party service provider oversight gets a longer runway, two years from the effective date, since vetting vendor relationships takes more time than standing up internal controls.

Get Help Meeting Your State’s Requirements

Model #668 compliance touches nearly every part of your IT environment. That includes access controls, encryption, monitoring, and incident response. LeadingIT builds and maintains that environment for insurance agencies and insurers across Chicagoland. See LeadingIT’s insurance/compliance IT services or book a call to talk through your state’s specific requirements.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.