Skip to main content
Framework library
Framework module · naic-insurance-data-security-668

NAIC Insurance Data Security Model Law

A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.

Model #668 · National Association of Insurance Commissioners

Standing today
Directory entry

00Answer

from the registry record
What is NAIC Insurance Data Security Model Law?
A model law for insurance-sector information security programs, incident response, and breach notification, adopted individually by roughly 25-28 US states as of 2026. It becomes enforceable law only where a state has enacted its own version — the requirements can vary state to state.
Who does NAIC Insurance Data Security Model Law apply to?
NAIC Insurance Data Security Model Law applies to insurance, healthcare, US, per National Association of Insurance Commissioners.
What is the current version of NAIC Insurance Data Security Model Law?
The current edition is Model #668, issued by National Association of Insurance Commissioners. Source: https://content.naic.org/insurance-topics/cybersecurity.
What does an assessment under NAIC Insurance Data Security Model Law require?
No control catalog has been ingested for NAIC Insurance Data Security Model Law yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NAIC Insurance Data Security Model Law is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

The model law itself is a state-legislative product; once enacted by a given state it is public law and freely ingestible verbatim per that state's statute. Ingest per-state enacted text, not the NAIC drafting PDF.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Information security program · Investigation of a cybersecurity event · Notification of a cybersecurity event · Third-party service provider oversight
Applies to
insurance · healthcare · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
Roughly 25-28 states had adopted a version of Model #668 as of 2026. A 2026 amendment draft addresses AI and third-party data; it has not been finalized.Expected: 2026 amendment draft not yet finalized

03Version ledger

1 edition
Model #668Current editiondate not published

06Related frameworks

scored from registry facts
  1. Also applies to healthcare · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

  2. Also applies to healthcare · CMS's NIST-aligned security and privacy framework for ACA administering entities and applicable partner entities. Volume II supplies tailored control baselines and system security and privacy plan templates; applicability depends on entity type, law, regulation, or contract.

  3. CMS Enhanced Direct EnrollmentYear 9 (PY 2026–PY 2027)

    Also applies to healthcare · The pathway that lets a web broker or issuer run the whole ACA enrollment experience on its own site instead of handing the consumer off to HealthCare.gov.

  4. Shared Assessments SIG2026 annual release

    Also applies to healthcare · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

NAIC Insurance Data Security Model Law | ControlFrame