The NAIC Insurance Data Security Model Law 668 State Adoption Map: Which States Have Adopted NAIC Model Law 668
The NAIC 668 state adoption map shows which states have adopted this insurance cybersecurity law. As of the NAIC’s August 2025 legislative brief, 28 of the NAIC’s 56 U.S. jurisdictions have adopted Model #668. Idaho’s adoption was pending at that time. That means fewer than half of all states and territories have this specific law on the books.
If you run an insurance agency, MGA, or carrier, this patchwork matters. Coverage differs sharply by state. This page gives you the national picture. It shows how many jurisdictions have adopted Model #668. It also explains why the map still isn’t finished.
Want your own state’s exact citation and effective date instead? Use the state-by-state lookup page. This page is the reference map. That page is the personal lookup.
Key Takeaways
- 28 of 56 NAIC jurisdictions have adopted Model #668 as of August 2025. Idaho’s adoption was pending.
- “Adopted” means the NAIC Legal Division found a state’s law substantially similar to the current model text, not identical word for word.
- Illinois adopted the law in 2024, codified at 215 ILCS 215. Illinois-licensed insurers are already covered.
- States missing from the list aren’t automatically unregulated. New York, New Jersey, California, and Massachusetts run their own separate insurance cybersecurity rules instead.
- The U.S. Treasury pushed for full state adoption within five years of the 2017 model and floated federal preemption if states fell short. That five-year mark has already passed.
What “Adopted” Actually Means on This Map
Model #668 is the NAIC’s Insurance Data Security Law. The National Association of Insurance Commissioners finalized it in October 2017, after nearly two years of drafting.

It’s a model law, not a federal statute. It only takes legal effect once a state’s legislature or insurance department passes it into that state’s own law. That’s why requirements and citations differ from state to state.
“Adopted” has a narrow, specific meaning here. It means the NAIC’s Legal Division reviewed a state’s version of the bill. It found that version substantially similar to the current model text. That’s not the same as word for word identical.
A state can pass related cybersecurity rules and still miss this list. If the language diverges too much from the model, it doesn’t count on this map.
Who the law actually covers:
- Insurers licensed in an adopting state
- Insurance producers and agents
- Other entities that state licenses under its insurance laws
The model law calls these entities “Licensees.” It excludes purchasing groups and risk retention groups chartered in another state, along with certain out-of-state assuming insurers.
For your state’s exact citation and effective date, see the state-by-state lookup page linked above. This page covers the whole national map at once.
The 28 Adopted Jurisdictions
Here is the compact list. It’s current as of the NAIC’s own state-adoption map, published by its Cybersecurity (H) Working Group.
| Alabama | Alaska | Connecticut | Delaware |
| Hawaii | Illinois | Indiana | Iowa |
| Kentucky | Louisiana | Maine | Maryland |
| Michigan | Minnesota | Mississippi | Missouri |
| New Hampshire | North Dakota | Ohio | Oklahoma |
| Pennsylvania | Puerto Rico | Rhode Island | South Carolina |
| Tennessee | Vermont | Virginia | Wisconsin |
As of the NAIC’s August 2025 state legislative brief, 28 of the NAIC’s 56 U.S. jurisdictions have adopted Model #668, with Idaho’s adoption pending.
This is a snapshot, not a live feed. State legislatures move on their own schedule. A bill can pass between one NAIC update and the next.
If you’re reading this well after August 2025, confirm your state’s current status. Check directly with the NAIC or your state’s Department of Insurance before you act on it.
This list is deliberately compact. It’s built for the national picture, not citation-level research. That kind of detail lives on the state-by-state lookup page instead.
Illinois and Chicagoland: Adopted in 2024
Illinois adopted Model #668 in 2024. It’s codified at 215 ILCS 215, the state’s Insurance Data Security Law.

The NAIC lists Illinois in its Model Adoption column. That means the Legal Division found Illinois’s version substantially similar to the current model in its entirety.
Illinois-licensed insurers, agencies, and MGAs are already on the clock. Here’s what that means in practice:
- A written security program. Every Licensee needs administrative, technical, and physical safeguards for policyholder data and the systems that hold it. – An annual risk assessment. Someone has to own it, identify realistic threats, and test whether current safeguards actually hold up. – A tested incident response plan. It has to define roles, communication steps, and how you document and fix what broke.
Small Licensees get some relief. A business with fewer than 10 employees, including independent contractors, is exempt from building the full program. So is a Licensee already compliant with HIPAA’s security rules, if it certifies that in writing.
There’s no single nationwide dollar penalty for violating this law. Illinois’s own insurance code sets the penalty for noncompliance, the same as every other adopting state.
Want the plain-English breakdown of every requirement? Start with what NAIC 668 actually requires. Want someone to build and maintain that documentation for you? That’s LeadingIT’s insurance compliance IT service.
States Not on the List Aren’t Necessarily Off the Hook
Missing from this list doesn’t mean a state has no rules at all. Several states run their own separate insurance cybersecurity regulations instead. These predate or diverge from the NAIC model, so they don’t earn a spot on this specific map.
States known to regulate this area on their own, outside Model #668:
- New York
- New Jersey
- California
- Massachusetts
New York’s framework is the best known of the four. It isn’t Model #668. It’s its own standalone rule, built on its own timeline and its own definitions. Read the NY DFS 500 explainer for the clearest side-by-side example of a state that regulates this differently rather than not at all.
Don’t assume a state is unregulated just because it’s missing here. Check what that specific state actually requires. Then draw your conclusion from that, not from this list alone.
Why the Map Still Isn’t Finished
Model #668 was finalized in 2017. That October, the U.S. Treasury pushed for adoption within five years. It warned that federal preemption could follow if states fell short.
That five-year mark has already passed. Adoption sits at 28 of 56 jurisdictions as of August 2025. No federal preemption bill looks imminent right now.
Even the NAIC’s own systems aren’t immune to the risk this law targets.
The agency confirmed personal information, banking details, and policyholder data were not accessed.
That incident didn’t touch consumer data. It isn’t a knock on the model itself. It’s a reminder that data security is an ongoing job, not a box you check once and forget.
This is why the map matters as its own reference. It isn’t a finished rollout you can assume is complete. It’s an ongoing, state-by-state process, moving slower than Treasury originally wanted.
How to Use This Map
Work through these steps in order. Where you land depends on where your business operates and licenses.
- Find your state in the list above. This map only tells you adopted or not adopted. For the exact bill citation, section numbers, and effective date, check the state-by-state lookup page linked earlier in this article.
- If your state adopted the model, you have real, dated obligations ahead of you. The hub page linked above walks through the specific sections, deadlines, and board-reporting duties that apply to your license type.
- Once you understand the requirements, look at your current program honestly. Most agencies already have pieces of this in place, just not documented the way an examiner expects. The full NAIC 668 compliance checklist walks through every section item by item.
- If your state isn’t on the list, don’t assume you’re unregulated. A handful of states run their own separate cybersecurity law instead of this model, New York being the clearest case, covered earlier in this article.
See Where You Stand
Not sure how close your program is to what Model #668 requires? Answer eight plain-English questions. See your compliance-readiness level and the specific gaps to fix. No sign-up needed to see your result.
Take the free 2-minute NAIC 668 Risk-Check
Related Guides
- Does My State Have an Insurance Cybersecurity Law? (State-by-State Lookup)
- What Is NAIC Model Law 668? Insurance Data Security Explained
- NAIC 668 Compliance Checklist: Every Requirement, Plain English
- What Is NY DFS 500?
Frequently Asked Questions
As of the NAIC’s August 2025 state legislative brief, 28 of 56 NAIC jurisdictions had adopted the model. Idaho’s adoption was pending at that time. This is a dated snapshot, not a live count. Confirm current status with the NAIC or your state’s Department of Insurance if you’re checking this well after August 2025.
It means the NAIC’s Legal Division reviewed that state’s law and found it substantially similar to the current model text. That doesn’t require word for word identical language. A state can have related cybersecurity rules that still don’t count here, if they diverge too far from the model.
Yes. Illinois adopted the model in 2024, codified at 215 ILCS 215. The NAIC lists Illinois as a full model adoption. Illinois-licensed insurers, agencies, and MGAs are already required to comply.
No. New York is not on the list of jurisdictions that adopted Model #668. It regulates insurance cybersecurity under its own separate framework instead, commonly known as NY DFS 500. New Jersey, California, and Massachusetts also rely on their own separate rules rather than the NAIC model.
The model was finalized in 2017. The U.S. Treasury pushed for full state adoption within five years and warned federal preemption could follow if states didn’t act. That five-year window has passed, and adoption is still only 28 of 56 jurisdictions. State legislatures move at different speeds, and some states chose to regulate this area their own way instead.
Both, in an adopting state. The model law covers “Licensees,” which includes insurers, insurance producers and agents, and other NAIC-regulated entities. It excludes purchasing groups and certain out-of-state assuming insurers. Size still matters: a Licensee with fewer than 10 employees is exempt from the full program requirement.
Use the state-by-state lookup page for your specific state’s citation, effective date, and adoption status. This page is built for the national overview. The lookup page carries the per-state detail this one leaves out.
Not Sure Where Your Program Stands?
Every adopting state’s law works a little differently. The underlying work looks the same almost everywhere. That means a documented security program, a real risk assessment, and a tested incident response plan.
LeadingIT helps Illinois-licensed insurers, agencies, and MGAs build and maintain that documentation. Check out LeadingIT’s insurance compliance IT services for the done-for-you path. Or book a call to talk through your specific situation.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
