NAIC Insurance Data Security Model Law #668, Explained
NAIC Model Law #668 is a set of cybersecurity rules for the insurance industry. The National Association of Insurance Commissioners wrote it. Its formal name is the Insurance Data Security Law. It tells insurers, agents, and other licensed businesses how to build a security program, investigate cybersecurity events, and notify regulators. But it’s a model law, not a federal statute. On its own, it has no legal force. It only becomes real law once your state adopts it, which is why the exact rules differ from state to state.
If you run an insurance agency, work as a producer, or hold any license from a state Department of Insurance, this law may already apply to you. Illinois adopted its own version in 2024. Below, we cover who counts as a “Licensee,” whether your state has adopted the law, and the four things it actually requires.
Who Has to Comply With NAIC 668?

The law covers anyone it calls a “Licensee.” That sounds technical, but the definition is simple. A Licensee is anyone licensed, authorized, or required to be licensed under your state’s insurance laws.
In practice, that means:

- Insurance companies (insurers)
- Insurance producers and agents
- Other entities regulated under your state’s insurance code
A couple of narrow groups are carved out. Purchasing groups and risk retention groups chartered in another state don’t count. Neither do certain out-of-state assuming insurers. For almost every Chicagoland agency, agent, or small insurer, though, “Licensee” means you.
Who’s exempt from building a full program?
Section 9 of the model law excludes three specific groups from the Section 4 program-building requirements:

- Licensees with fewer than 10 employees, including independent contractors
- Licensees already compliant with HIPAA’s security rules, if they certify that compliance in writing
- Employees, agents, or designees already covered under another Licensee’s existing Information Security Program
One catch worth flagging: these exemptions aren’t permanent.
Does My State Even Have This Law?
Short answer: maybe. Model #668 isn’t automatically the law everywhere. It only applies in states that have formally adopted it. And where it has been adopted, the fine print (deadlines, penalties, exact citations) can vary.
As of the NAIC’s August 2025 legislative brief, 28 of the NAIC’s 56 member jurisdictions have adopted a version close enough to the current model to count. Illinois is one of them. Illinois adopted its version in 2024, codified at 215 ILCS 215.
Licensed somewhere other than Illinois, or licensed in multiple states? Check our state-by-state adoption guide before you assume the law does or doesn’t apply to you.
The Four Things NAIC 668 Actually Requires
Strip away the legal language, and Model #668 boils down to four concrete obligations.

- Build a written Information Security Program. You need a written Information Security Program covering administrative, technical, and physical safeguards. It has to be scaled to your size, complexity, and the sensitivity of the data you hold. There’s no single template that fits every Licensee.
- Investigate cybersecurity events when they happen. A documented process for figuring out what happened, what was affected, and how bad it is.
- Notify the Commissioner fast. You must report a Cybersecurity Event under the 72-hour Commissioner notification rule, once you determine one occurred and it meets the law’s reporting triggers.
- Certify compliance every year. Insurers domiciled in an adopting state must submit a statement by the February 15 certification deadline confirming they’ve met Section 4’s requirements.
None of these four are optional add-ons. They’re the core of what “complying with NAIC 668” actually means in practice, and each one shows up again in the controls breakdown below.
What the Program Actually Has to Cover
Section 4 doesn’t just say “have security.” It lists specific controls. It also requires an annual reassessment of your safeguards, not a one-time setup.
Here’s what that breaks down to in practice:
| Control area | What Section 4 requires | What this looks like day to day |
|---|---|---|
| Access controls & MFA | Access to Nonpublic Information limited to Authorized Individuals, with effective controls that may include Multi-Factor Authentication | Role-based logins, MFA on email and core systems, no shared passwords |
| Encryption | Nonpublic Information encrypted in transit over external networks and at rest on portable devices | Encrypted laptops and phones, encrypted email for client data |
| Testing & monitoring | Regular testing and monitoring for intrusions and system vulnerabilities | Ongoing network monitoring, periodic vulnerability scans |
| Audit trails | Logs able to detect and reconstruct a Cybersecurity Event | System and access logs kept and reviewed, not just collected |
| Secure disposal | Documented procedures for disposing of Nonpublic Information | A written policy for wiping drives and shredding files, not “someone handles it” |
| Board oversight | If you have a board, it must require management to build the program and report on it at least annually | A yearly written report to ownership or the board covering risk, incidents, and vendor arrangements |
| Vendor (third-party) oversight | Due diligence in selecting vendors, and a requirement that they protect the data they can access | Vendor security questionnaires and contract language before you hand over data access |
| Incident response plan | A written plan covering roles, communications, remediation, and post-event review | A document your team can actually follow at 2 a.m., not a binder nobody’s read |
Two of these get extra runway. Board oversight and the other core controls get one year to implement after your state’s law takes effect. Vendor oversight gets two years, since re-papering every vendor contract takes longer than fixing your own systems.
What Happens If You Don’t Comply?
The Commissioner’s office can investigate. Under Section 7, that includes examining your records directly.
Here’s the part that surprises people: Model #668 doesn’t set one nationwide fine. Section 10 leaves the actual penalty amount to each state’s own general insurance-code penalty rules. There’s no single number to quote here, and any resource that gives you one for “NAIC 668 penalties” nationwide is oversimplifying.
One more thing worth knowing if you’re evaluating your exposure. The model law explicitly gives you no private right to sue. A data breach victim can’t use this specific statute to bring a lawsuit against you. That doesn’t mean you’re off the hook. Your state’s separate breach-notification law, your contracts, and plain old negligence claims can still expose you. NAIC 668 just isn’t the vehicle for that particular kind of suit.
Why This Matters for a Chicagoland Agency Right Now
If you’re licensed in Illinois, this isn’t hypothetical. Illinois adopted this law in 2024.
The U.S. That window has already passed, with adoption still partial nationwide.
That gap is exactly why coverage varies so much state to state, and why “I’ll deal with it later” is a riskier bet than it used to be. Regulators write model laws slowly, then enforce them for years.
There’s also a plainer reason to take this seriously: nobody is immune, not even the regulators. Publicly available reporting data was exposed, not policyholder or banking information, but it’s a reminder that the risk this law addresses is real and current, not theoretical.
For a small or mid-size agency, the practical challenge is usually documentation. You may already run backups, MFA, and monitoring. What examiners actually want to see is the paper trail behind those controls. LeadingIT helps Illinois-licensed agencies build that: access controls and MFA, encryption, monitoring, audit logging, secure disposal, and a tested incident response plan, plus the documentation your annual board report and February certification depend on.
Before you tackle all of Section 4 at once, it helps to know exactly where the gaps are. Our NAIC 668 compliance checklist walks through every requirement in plain English. The next step is figuring out exactly where your agency stands today.
See Where You Stand
Answer 8 plain-English questions and get your compliance-readiness level, plus the specific gaps to fix. No sign-up required to see your result.
Take the free 2-minute NAIC 668 Risk-Check
Related Guides
- Does My State Have an Insurance Cybersecurity Law?
- NAIC 668 Compliance Checklist: Every Requirement, Plain English
Frequently Asked Questions
Both. The law covers anyone it defines as a Licensee, which means anyone licensed, authorized, or required to be licensed under your state’s insurance laws. That includes insurers, insurance producers, and agents, not just carriers.
Yes. Illinois adopted its own version of the law in 2024, codified in the Illinois Compiled Statutes. It’s one of 28 NAIC jurisdictions the association considers substantially similar to the current model as of its August 2025 update.
Generally one year from your state’s effective date for most of Section 4. Vendor and third-party oversight gets two years, since vetting and re-papering vendor contracts takes longer than fixing internal controls.
No. The model law explicitly does not create a private right to sue. That protection is specific to this statute though. Your state’s separate breach-notification law and your contracts can still create liability.
The state Department of Insurance can investigate and examine your records. Penalties aren’t set by the model law itself. Each state applies its own general insurance-code penalty rules, so the consequences vary by state.
Not always. Licensees with fewer than 10 employees, including independent contractors, are exempt from building a full Section 4 program. So are Licensees already compliant with HIPAA’s security rules, if they certify that in writing.<details> <summary>Do I have to certify compliance every year?</summary> <p>Yes, if you’re an insurer domiciled in an adopting state. You must submit a written statement to the Commissioner by February 15 each year certifying you’ve met Section 4’s requirements, and keep supporting records for five years.
Ready to Get Ahead of This?
Whether you’re already licensed in an adopting state or watching to see if yours is next, waiting until an exam letter arrives is the expensive way to find gaps. LeadingIT builds and documents the controls NAIC 668 asks for, so you’re ready before anyone asks.
See our insurance compliance IT services, book a call, or contact us to talk through where your agency stands.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
