NAIC Insurance Data Security Model Law
A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.
Model #668 · National Association of Insurance Commissioners
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
NAIC Insurance Data Security Model Law is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
The model law itself is a state-legislative product; once enacted by a given state it is public law and freely ingestible verbatim per that state's statute. Ingest per-state enacted text, not the NAIC drafting PDF.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Information security program · Investigation of a cybersecurity event · Notification of a cybersecurity event · Third-party service provider oversight
- Applies to
- insurance · healthcare · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- Roughly 25-28 states had adopted a version of Model #668 as of 2026. A 2026 amendment draft addresses AI and third-party data; it has not been finalized.Expected: 2026 amendment draft not yet finalized
03Version ledger
| Model #668 | Current edition | date not published |
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
- ARC-AMPEv1.02
Also applies to healthcare · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.
- CMS Enhanced Direct EnrollmentYear 9 (PY 2026–PY 2027)
Also applies to healthcare · The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.
- Shared Assessments SIG2026 annual release
Also applies to healthcare · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.