State insurance regulators are enforcing cybersecurity requirements that add governance, risk management and third-party oversight obligations to what health insurers already manage under HIPAA. The NAIC Insurance Data Security Model Law, now adopted in more than half of U.S. states, establishes accountabilities that extend beyond IT implementation to strategic risk decisions, board reporting and regulatory examination readiness.

For health plan executives, compliance directors and risk officers, the business problem is clear: leadership is accountable for a security outcome without necessarily having a clear owner, a defined sequence or a practical way to measure progress toward regulatory expectations.

What the NAIC Model Law Requires

The NAIC Insurance Data Security Model Law imposes four principal requirements on state-regulated insurers, including health plans and third-party administrators:

  • **Written cybersecurity program**: A documented program based on a risk assessment, designed to protect nonpublic information and the insurer's information systems
  • **Annual risk assessment**: A documented evaluation of internal and external cybersecurity risks to the insurer's information systems and nonpublic information
  • **Third-party service provider oversight**: Written policies and procedures governing the security of information accessible to or held by vendors, including due diligence, contractual protections and monitoring
  • **Incident response plan**: A documented plan to respond to and recover from cybersecurity events, with specific notification timelines to the state insurance commissioner

These requirements apply to licensed insurers and are subject to examination by state insurance departments. Compliance timelines vary by state, but enforcement is active where the law has been adopted.

Which States Have Adopted the Model Law

As of this writing, more than 25 states have enacted legislation substantially based on the NAIC model. These include states with significant health insurance markets. Because state insurance regulation follows the location of the insurer's domicile and the states where it is licensed, a single health plan may be subject to multiple state versions of the law, each with variation in scope, timelines and examination authority.

The sources provided for this article do not include a current state-by-state adoption list. Organizations should consult their state insurance department or regulatory counsel to confirm applicability and effective dates.

How the NAIC Requirements Differ From HIPAA

Health insurers already operate under HIPAA Security Rule obligations. The NAIC model does not replace HIPAA, but it establishes distinct and overlapping requirements administered by a different regulator. Key differences include:

  • **Regulatory authority**: HIPAA is enforced by the U.S. Department of Health and Human Services Office for Civil Rights. The NAIC model is enforced by state insurance commissioners with examination authority over the insurer
  • **Governance focus**: The NAIC model explicitly requires a risk-based cybersecurity program approved and overseen by senior management or the board. HIPAA does not prescribe board involvement
  • **Annual risk assessment**: The NAIC model mandates a documented annual risk assessment. HIPAA requires periodic risk analysis but does not specify annual cycles or documentation standards
  • **Third-party oversight program**: The NAIC model requires written policies and procedures for vendor oversight, including due diligence and contractual requirements. HIPAA requires business associate agreements but does not prescribe a vendor risk management program
  • **Incident notification**: The NAIC model requires notification to the state insurance commissioner within 72 hours of determining that a cybersecurity event has occurred or is reasonably likely to materially harm the insurer or its policyholders. HIPAA breach notification timelines and triggers differ

The result is that health insurers must demonstrate compliance to two regulatory frameworks with different expectations, documentation standards and examination processes.

Governance and Board-Level Accountability

The NAIC model places explicit accountability on the board of directors or an appropriate committee for overseeing the cybersecurity program. This is a governance requirement, not an IT requirement. Boards must be prepared to demonstrate to examiners that they have:

  • Received regular reporting on the organization's cybersecurity risks and program effectiveness
  • Approved the cybersecurity program and material changes to it
  • Overseen management's implementation of the program
  • Been briefed on the results of the annual risk assessment

This shifts cybersecurity from a technical function to a fiduciary and strategic responsibility. The board's effectiveness is measured not by technical fluency but by the quality of information it receives, the questions it asks and the decisions it makes about resource allocation and acceptable risk.

The Annual Risk Assessment Requirement

The annual risk assessment is the foundation of the NAIC cybersecurity program. It must be documented and must inform both the design of the cybersecurity program and the board's oversight. The risk assessment should address:

  • Criteria for evaluating and categorizing identified security risks or threats
  • Criteria for assessing the confidentiality, integrity and availability of information systems and nonpublic information
  • Requirements describing how identified risks will be mitigated or accepted, and how the cybersecurity program will address those risks

This is not a penetration test or vulnerability scan. It is a business risk evaluation that considers both technical vulnerabilities and operational, third-party and business continuity risks. The output must be sufficiently detailed to support regulatory examination and board decisions about resource allocation.

Third-Party Service Provider Oversight

The NAIC model requires insurers to establish written policies and procedures for managing the security risks posed by third-party service providers. This includes vendors that have access to, transmit, process or store nonpublic information, as well as those whose failure could materially disrupt the insurer's operations.

The program must include:

  • Identification and risk assessment of third-party service providers
  • Minimum cybersecurity practices required of providers, defined contractually
  • Due diligence processes for evaluating providers before engagement and periodically thereafter
  • Monitoring and oversight of provider compliance with contractual security obligations

This requirement often exposes a gap in accountability. IT teams may manage vendor technical security assessments. Procurement may manage contracts. Compliance may track business associate agreements. But the integrated vendor risk program the NAIC model requires—spanning due diligence, contracting, monitoring and remediation—often has no single owner.

For more on how strategic oversight clarifies accountability in [third-party vendor risk management](/vciso/#third-party-risk), see Heights' discussion of virtual CISO services.

Incident Response and Regulatory Notification

The NAIC model requires a written incident response plan that addresses detection, response, recovery and notification. The plan must include procedures for:

  • Internal escalation and decision-making during a cybersecurity event
  • Assessment of the event's scope and impact
  • Containment and remediation
  • Notification to the state insurance commissioner, policyholders, law enforcement and others as required

The notification requirement is specific: insurers must notify the commissioner of their state of domicile within 72 hours of determining that a cybersecurity event has occurred or is reasonably likely to materially harm normal operations, policyholders or the insurer itself. Determining when that threshold is met is a judgment call that requires both technical assessment and business context.

This places a premium on clarity about who makes the determination, what information they rely on and how quickly leadership can assemble that information during an event.

Who Owns Compliance and What Adequate Ownership Looks Like

The NAIC model does not prescribe an organizational structure, but it makes clear that cybersecurity is a board and executive responsibility, not solely an IT responsibility. Adequate ownership includes:

  • An executive accountable for the cybersecurity program who reports regularly to the board or a designated committee
  • Coordination across IT, legal, compliance, risk and operations to ensure the program addresses technical, contractual, regulatory and operational risks
  • A documented governance structure that makes clear who assesses risk, who decides how to address it, who monitors program effectiveness and who reports to regulators and the board
  • Regular board-level reporting that translates technical risks into business consequences and resource decisions

For organizations without a full-time chief information security officer, or where the CISO role is IT-focused rather than governance-focused, [virtual CISO leadership](/vciso/) can provide the strategic ownership, regulatory fluency and board reporting that the NAIC model requires.

What Leadership Should Do Next

If your organization is subject to the NAIC Insurance Data Security Model Law, the following steps will clarify your regulatory position and close gaps in accountability:

  • **Confirm applicability**: Determine which state versions of the NAIC model apply to your organization based on domicile and licensure. Confirm effective dates and examination timelines.
  • **Assess current state**: Compare your existing cybersecurity program, risk assessment practices, third-party oversight and incident response plan against NAIC requirements. Identify documentation gaps.
  • **Clarify ownership**: Decide who is accountable for the cybersecurity program, who reports to the board, who coordinates across functions and who makes risk acceptance decisions. Document this in governance materials.
  • **Establish board reporting**: Develop a regular reporting cadence to the board or appropriate committee that addresses the annual risk assessment, program effectiveness, third-party risk and material incidents.
  • **Document the annual risk assessment**: Ensure the risk assessment is documented, covers the scope required by the NAIC model and informs both the cybersecurity program and board decisions.
  • **Formalize third-party oversight**: Establish written policies and procedures for vendor due diligence, contractual security requirements and ongoing monitoring. Assign ownership for the program.
  • **Test incident response**: Conduct a tabletop exercise that includes the 72-hour notification requirement and the decision-making process for determining materiality.
  • **Prepare for examination**: Organize evidence that demonstrates board oversight, annual risk assessments, third-party oversight and incident response readiness. Regulatory examiners will expect to see documentation, not assertions.

If these steps surface gaps in executive ownership, strategic direction or regulatory reporting, a confidential consultation with Heights can clarify how [virtual CISO services](/vciso/) provide the governance, coordination and regulatory fluency that health insurers need to meet NAIC requirements without expanding permanent staff. To explore whether this approach fits your organization, contact Heights directly for a confidential discussion.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Vendor, MSP and Third-Party Oversight

Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.

Read about Vendor, MSP and Third-Party Oversight