Industry guide

Managed IT diligence for insurance agencies.

Agencies hold applications, claims, health and financial details across every household the agency serves. A majority of states have adopted versions of the NAIC insurance data security model, which puts a written security program, vendor oversight, and breach duties on licensees, meaning the agency answers to its regulator for its IT vendor's work.

What binds you

The frameworks

NAIC Insurance Data Security Model LawThe frameworkState-adopted requirements for licensee security programs and breach handling.
GLBA safeguardsThe frameworkFinancial-privacy obligations reaching insurance activities.

The industry question

Will your documentation satisfy my state insurance regulator's security-program requirements?

It belongs on the checklist, in writing, next to the other 18.

Your state

Insurance Agencies, state by state

The same diligence with your state's verification layer: the breach statute, the entity search, the regulator.

Educational reference, not legal advice. Frameworks are summarized at the framework level; confirm specifics for your situation with counsel or the primary source.