NAIC Insurance Data Security Model Law
Model law adopted by most US states requiring insurance companies to implement comprehensive information security programs with annual certification requirements.
What NAIC MDL-668 draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Risk Assessment
Licensees MUST design information security program to identify risks to nonpublic information and assess safeguards.
An assessment is only defensible if the findings in it are observed rather than asserted. Discovery supplies what regulated data exists and where, scanning supplies the configuration and exposure posture, and the audit trail supplies who has actually been reaching it — so the assessment describes the estate as measured. Our advisory engagements then map each finding to the specific mandate it touches and sequence the remediation.
Access Controls
REQUIRES implementation of access controls including monitoring of access to nonpublic information.
Authorisation is configured in the database; proving it holds is what this requirement actually needs. Vulnerability scanning surfaces excessive privilege and role sprawl, default and weak credentials, and stale or orphaned accounts — including privilege inherited through nested roles, which is where least-privilege reviews usually go wrong. Real-time SQL auditing then shows which of those grants were exercised, so an access review reflects observed use rather than intent.
Investigation
Licensees MUST conduct investigation of cybersecurity events and determine scope, affected individuals, and root cause.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Annual Certification
Insurers MUST annually certify in writing that they maintain a compliant information security program.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
What NAIC MDL-668 covers
Model Law 668, Sec. 3 — nonpublic information
A three-part definition: business information whose disclosure would harm the licensee, plus consumer information by identifier, plus health information.
In scope
- Business information whose unauthorised disclosure would materially harm the licensee
- Consumer information linked to a name, number, personal mark or other identifier
- Information about physical or mental health, health care provision, or payment for it
What falls outside
Information lawfully obtained from publicly available sources.
The definition is enacted state by state and the enacted texts differ, so the operative wording is the one in your state of licensure rather than the model.
NAIC Insurance Data Security Model Law · as at 2026-08
How NAIC MDL-668 is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The insurance commissioner of each state that has enacted a version of the model.
A model law. It binds only where a state has enacted its own version.
| Published maximum | Charged | As at |
|---|---|---|
| USD 500 | per violation, to a USD 10,000 cap, as the model suggests — each state sets its own | 2026-08 |
| USD 10,000 | per violation, to a USD 50,000 cap, for breaching a commissioner cease-and-desist order | 2026-08 |
Model Law 668 deliberately does not fix a national penalty. Section 10 defers to each state general insurance code, so the answer to what it costs is genuinely which state. The suggested figures rise to USD 10,000 per violation, capped at USD 50,000, where a commissioner cease-and-desist order is breached.
Around 28 jurisdictions have enacted some version, and the enacted texts differ. Only the version adopted in your states of licensure binds you.
Uncapped exposure that sits outside this instrument
These come from company law rather than from NAIC MDL-668, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for NAIC MDL-668,
not configured for it afterwards
Insurance Data Monitoring
Track access to policyholder nonpublic information
NAIC Annual Certification Report
DAM system evidence for annual certification filing
Insurance Data Patterns
Detect policy numbers, claims data, and beneficiary information
Cybersecurity Event Detection
Alert on events requiring investigation per Section 6
Other Financial frameworks
Walk into the NAIC MDL-668 audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.