Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

Compliance whitepaper | Insurance

State Insurance Data Security Laws: What Agencies Need to Know

A practical overview of the NAIC model law and similar requirements

  • Published October 26, 2024
  • 3 min read

The rules are catching up

Many states have adopted insurance data security laws based on the NAIC Insurance Data Security Model Law, and New York has its own cybersecurity regulation for financial services companies. Requirements vary by state and agency size, so confirm what applies to you with counsel.

Common requirements

  • A written information security program based on a risk assessment
  • A designated person responsible for the program
  • Access controls, including multi-factor authentication
  • Oversight of third-party service providers
  • An incident response plan and breach notification procedures

Start with a risk assessment

Inventory where client data lives, who can access it, and which vendors touch it. The findings become the basis for your written program.

Keep evidence current

Carriers and regulators may ask for proof. Keep policies, training records, and control documentation up to date.

How WEBIT helps

WEBIT implements and documents the technical safeguards these laws expect and supports your written program. Your compliance lead and counsel keep final say.

Talk to an owner

Want help putting this guide into practice? A 30-minute discovery call gets you honest advice for your environment.

Schedule a discovery call

Insurance IT services

See how WEBIT supports insurance organizations across Chicagoland.

Explore Insurance IT →

More Insurance whitepapers

Browse the full library of guides for your industry.

All Insurance whitepapers →

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.