NAIC MDL-668FinancialUnited States (State)Insurance

NAIC Insurance Data Security Model Law

Model law adopted by most US states requiring insurance companies to implement comprehensive information security programs with annual certification requirements.

Get a Gap Assessment
The Mapping

What your auditor cites,
and what produces the evidence

The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.

NAIC MDL-668Section 4DAssessment backed by evidence

Risk Assessment

Licensees MUST design information security program to identify risks to nonpublic information and assess safeguards.

An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.

NAIC MDL-668Section 4FLeast privilege and privileged use

Access Controls

REQUIRES implementation of access controls including monitoring of access to nonpublic information.

Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.

NAIC MDL-668Section 6A record of access

Investigation

Licensees MUST conduct investigation of cybersecurity events and determine scope, affected individuals, and root cause.

A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.

NAIC MDL-668Section 8Patching, hardening, and exposureA record of access

Annual Certification

Insurers MUST annually certify in writing that they maintain a compliant information security program.

Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.

What NAIC MDL-668 covers

Model Law 668, Sec. 3 — nonpublic information

A three-part definition: business information whose disclosure would harm the licensee, plus consumer information by identifier, plus health information.

In scope

  • Business information whose unauthorised disclosure would materially harm the licensee
  • Consumer information linked to a name, number, personal mark or other identifier
  • Information about physical or mental health, health care provision, or payment for it

What falls outside

Information lawfully obtained from publicly available sources.

The definition is enacted state by state and the enacted texts differ, so the operative wording is the one in your state of licensure rather than the model.

NAIC Insurance Data Security Model Law · as at 2026-08

How NAIC MDL-668 is enforced

Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The insurance commissioner of each state that has enacted a version of the model.

A model law. It binds only where a state has enacted its own version.

Published maximumChargedAs at
USD 500per violation, to a USD 10,000 cap, as the model suggests — each state sets its own2026-08
USD 10,000per violation, to a USD 50,000 cap, for breaching a commissioner cease-and-desist order2026-08

Model Law 668 deliberately does not fix a national penalty. Section 10 defers to each state general insurance code, so the answer to what it costs is genuinely which state. The suggested figures rise to USD 10,000 per violation, capped at USD 50,000, where a commissioner cease-and-desist order is breached.

Around 28 jurisdictions have enacted some version, and the enacted texts differ. Only the version adopted in your states of licensure binds you.

Uncapped exposure that sits outside this instrument

These come from company law rather than from NAIC MDL-668, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.

Duty of oversight

Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.

Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.

Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.

This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.

In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).

Enforcement data reviewed August 2026. Several figures are indexed annually and move.

Ships With It

Built for NAIC MDL-668,
not configured for it afterwards

Policy Template

Insurance Data Monitoring

Track access to policyholder nonpublic information

Report

NAIC Annual Certification Report

DAM system evidence for annual certification filing

Classification

Insurance Data Patterns

Detect policy numbers, claims data, and beneficiary information

Alert

Cybersecurity Event Detection

Alert on events requiring investigation per Section 6

Other Financial frameworks

Walk into the NAIC MDL-668 audit knowing the answer

228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.

Get a Gap Assessment