Data Protection & Privacy
DETAIL

NAIC Insurance Data Security Model Law (MDL-668)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

The NAIC Insurance Data Security Model Law (MDL-668) is a regulatory framework that establishes data security requirements for insurance companies and related entities to protect consumer information and reduce cybersecurity risks. Its purpose is to drive adoption of effective cybersecurity programs and incident response processes within the insurance sector.

Published by the National Association of Insurance Commissioners (NAIC), this model law is adopted by U.S. state insurance regulators seeking to enhance data protection, risk management, and regulatory compliance across insurers, agents, and other licensees. The law addresses areas including cybersecurity controls, risk assessments, oversight of third-party service providers, breach notification, and ongoing compliance obligations.

Insurance organizations implement the NAIC Model Law by developing written information security programs, conducting regular risk assessments, monitoring internal controls, training staff, and reporting security incidents when required. The law aligns with broader U.S. data protection and cybersecurity frameworks, helping insurers strengthen compliance, reduce regulatory risk, and build customer trust.

Why it Matters

The NAIC Insurance Data Security Model Law establishes consistentstandards to help insurers safeguard consumer data and reduceevolving cybersecurity risks.

Key benefits include:

  • Strengthen information security governance

Drive adoption ofdocumented cybersecurity programs, oversight, and risk managementacross insurance organizations and their third-party serviceproviders.

  • Enhance regulatory compliance

Facilitateadherence to state-level data security obligations, reducingregulatory risk and streamlining compliance reporting to insuranceregulators.

  • Improve breach response capabilities

Establishincident response practices and notification procedures, enablingprompt detection, containment, and reporting of security breaches.

  • Protect consumer information

Mandate securitycontrols that reduce the risk of data compromise, helping safeguardsensitive personal and financial data entrusted to insurers.

  • Increase audit and readiness

Require regularrisk assessments and documentation, supporting better audit outcomesand organizational readiness for evolving cybersecurity threats.

How it Works

The NAIC Insurance Data Security Model Law (MDL-668) establishes astructured approach for safeguarding sensitive insurance data througha set of regulatory requirements and security safeguards. It outlinesrequirements for risk assessment, development of comprehensiveinformation security programs, and implementation of administrative,technical, and physical security controls. The framework also setsout governance responsibilities, incident response procedures,ongoing monitoring, and regulator notification obligations, providinga lifecycle-based structure for ongoing data protection andcompliance.

In operational practice, insurance companies and relatedorganizations conduct risk assessments to identify threats tononpublic information and then implement security controls alignedwith the Model Law’s provisions. They regularly review and updatetheir cybersecurity policies, provide employee training, monitorsystems for unauthorized activity, and prepare incident responseplans. Periodic compliance assessments and required notifications tostate insurance regulators ensure that governance and compliancestandards are maintained.

Using SmartSuite, organizations can operationalize the NAIC Model Lawby leveraging integrated control libraries, maintaining a riskregister, and tracking policy governance across business units.SmartSuite supports evidence collection, compliance monitoring, auditreadiness, and remediation workflows. Reporting dashboards providereal-time visibility into control effectiveness and regulatorycompliance for ongoing data security management.

Key Elements

  • Information Security Program Requirements

Specifiescriteria for comprehensive, written cybersecurity programs tailoredto the organization’s business and risk environment.

  • Risk Assessment Processes

Describesprocedures for evaluating internal and external cyber threats,vulnerabilities, and business impact.

  • Third-Party Service Provider Oversight

Outlinesexpectations for managing and reviewing the security practices ofexternal vendors and business partners.

  • Incident Response Planning

Definesstructural requirements for preparing, detecting, and responding tocybersecurity incidents that affect sensitive information.

  • Ongoing Compliance and Reporting

Establishesobligations for routine monitoring, staff training, and reporting ofcyber events to regulatory authorities.

  • Access and Data Controls

Organizescontrols around restricting access, managing authentication, andsafeguarding protected data assets.

Framework Scope

The NAIC Insurance Data Security Model Law (MDL-668) is adopted byinsurance companies, agents, and third-party service providersmanaging consumer information. It governs information securityprograms, breach response processes, and oversight of data systems,typically when organizations are meeting state-level regulatoryrequirements and strengthening cybersecurity risk management andongoing compliance programs.

Framework Objectives

The NAIC Insurance Data Security Model Law (MDL-668) establishesfoundational requirements to advance cybersecurity, risk management,and regulatory compliance in the insurance industry.

Safeguard sensitive consumer data through robust security controlsand oversight

Strengthen cybersecurity risk management and reduce exposure toemerging threats

Promote effective governance across insurance organizations andlicensed entities

Support ongoing regulatory compliance and readiness for auditprocesses

Enhance operational resilience and incident response capabilities

Ensure comprehensive oversight of third-party service providersecurity practices The NAIC Insurance Data Security Model Law(MDL-668) aligns closely with frameworks like NIST CybersecurityFramework, GLBA, and the FFIEC IT Examination Handbook. Insuranceorganizations typically implement this model law to meet regulatorydata protection obligations, ensure robust cybersecurity practices,and harmonize risk management efforts with broader industrystandards.

Framework in Context

The NAIC InsuranceData Security Model Law (MDL-668) aligns closely with frameworks likeNIST Cybersecurity Framework, GLBA, and the FFIEC IT ExaminationHandbook. Insurance organizations typically implement this model lawto meet regulatory data protection obligations, ensure robustcybersecurity practices, and harmonize risk management efforts withbroader industry standards.

Common Framework Mappings

NAIC Insurance Data Security Model Law is often mapped to otherwell-established cybersecurity and data protection frameworks tosupport regulatory harmonization, facilitate risk management, andstreamline audit processes across jurisdictions.

Mapped frameworks include:

CIS Critical Security Controls

Digital Operational Resilience Act (DORA)

FFIEC IT Examination Handbook

Gramm-Leach-Bliley Act (GLBA)

ISO/IEC 27001

NIST Cybersecurity Framework

NIST SP 800-53

SOC 2 / AICPA Trust Services Criteria

At a Glance
NAIC Insurance Data Security Model Law MDL-668 (2017)
  • checklist
    Classification
    Category
    info
    Data Protection & Privacy
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Framework
    Legal Instrument
    info
    Law
    Sector
    info
    Financial Sector
    Industry
    info
    Insurance
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    National Association of Insurance Commissioners (NAIC)
  • published_with_changes
    Versioning
    Version
    info
    NAIC Model Law 668
    Effective Date
    info
    2017
    Issue Date
    info
    December 2017
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The NAIC Insurance Data Security Model Law is publicly available through the National Association of Insurance Commissioners.

Official Resources
NAIC Insurance Data Security Model Law (MDL-668)
Defines data security requirements for insurance entities to protect consumer information.
chevron_forward
NAIC Cybersecurity Guidance
Provides implementation guidance for achieving compliance with the NAIC Cybersecurity Model Law.
chevron_forward
SMARTSUITE

How SmartSuite Supports NAIC Insurance Data Security Model Law (MDL-668)

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Security Program Requirements Library

Organize governance, risk assessment, safeguards, and oversight requirements.

Risk Assessments and Treatment Plans

Run periodic risk assessments and track mitigation actions through closure.

Vendor Due Diligence and Contract Management

Manage vendor due diligence, contract requirements, and ongoing monitoring.

Incident Response and Notification Workflow

Track cybersecurity events, escalation decisions, and reporting readiness.

Evidence and Examination Readiness

Centralize policies, training, testing, and operating evidence tied to requirements.

Board and Leadership Reporting

Provide program status, open issues, and risk posture reporting for governance.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
GLBA Safeguards Rule (16 CFR Part 314)

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27701

ISO/IEC 27701 extends ISO/IEC 27001 to help organizations manage privacy and protect personally identifiable information.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For NAIC Insurance Data Security Model Law (MDL-668)

What is the NAIC Insurance Data Security Model Law (MDL-668) used for?

The NAIC Insurance Data Security Model Law is designed to establish data security standards for insurance companies and related entities. Its primary purpose is to protect consumer information and mitigate cybersecurity risks within the insurance sector by mandating robust data protection programs and incident response processes.

Is compliance with the NAIC Insurance Data Security Model Law (MDL-668) mandatory?

Compliance becomes mandatory when a U.S. state adopts the NAIC Model Law into its own insurance regulations. Insurers, agents, and other licensed entities operating in those states must adhere to the specific requirements set forth by the adopted version of the law.

Who does the NAIC Insurance Data Security Model Law apply to?

The law applies to all insurance licensees, including insurers, agents, brokers, and certain third-party service providers that handle nonpublic consumer information. Its scope covers any entity regulated by state insurance departments that has access to sensitive customer data.

What are the key requirements of the NAIC Insurance Data Security Model Law?

Key requirements include developing and maintaining a written information security program, conducting periodic risk assessments, implementing appropriate cybersecurity controls, managing third-party risk, and establishing breach notification processes. Assigning clear governance responsibilities to senior leadership is also required.

How should insurance organizations implement the NAIC Insurance Data Security Model Law?

Organizations should start by conducting a comprehensive risk assessment to identify cybersecurity threats and vulnerabilities. Based on this assessment, they must implement appropriate safeguards, train personnel, monitor controls, update policies regularly, and prepare formal incident response and notification procedures.

How does the NAIC Insurance Data Security Model Law relate to other cybersecurity frameworks?

The NAIC Model Law aligns with broader U.S. data protection standards, such as those outlined by NIST and state-level privacy laws, but is tailored specifically for the insurance industry. It complements existing frameworks by focusing on regulatory oversight, sector-specific requirements, and integration with state insurance regulations.

What ongoing compliance activities are required under the NAIC Insurance Data Security Model Law?

Ongoing compliance requires regular review and updating of the information security program, continuous risk assessment, staff training, monitoring of internal and third-party controls, and timely incident reporting to regulators. Organizations must maintain documentation as evidence of their ongoing adherence to the law.

How would SmartSuite support NAIC Insurance Data Security Model Law (MDL-668) compliance?

SmartSuite helps organizations operationalize NAIC MDL-668 by mapping legal requirements to policies and controls, managing and tracking cybersecurity risk assessments, monitoring vendor risk, collecting compliance evidence, and automating reporting. These capabilities support audit readiness and streamline ongoing compliance management for insurance organizations.

Operationalize NAIC MDL-668 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward