NAIC Insurance Data Security Model Law (MDL-668)
The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (Model 668) establishes data security standards for the insurance industry. Adopted by NAIC in 2017, it has been enacted by over 20 US states. It requires insurers and other licensed entities to develop comprehensive information security programs, conduct risk assessments, and notify regulators of cybersecurity events.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Definitions and Scope
Sections 5-10: Key definitions and covered entities
| Code | Title |
|---|---|
| 7012(a) | Definitions |
| 7012(b)(1) | Covered Defence Information Identification |
| 7012(b)(2) | Scope of Protected Systems |
| 7012(b)(3) | COTS Exclusion |
| BIPA-SEC5-1 | Biometric Identifier Definition |
| BIPA-SEC5-2 | Biometric Information Definition |
| BIPA-SEC5-3 | Private Entity Definition |
| CTDPA-1 | Definitions |
| CTDPA-2 | Applicability Thresholds |
| MSA-5 | Definition of Modern Slavery |
| MSA-Commonwealth | Commonwealth Entities |
| MSA-Threshold | Revenue Threshold |
| NAIC-668-1 | Title and Purpose |
| NAIC-668-3 | Definitions |
| NAIC-668-9 | Exemptions |
Enforcement and Administration
Sections 7-8, 10: Commissioner powers, confidentiality, and penalties
| Code | Title |
|---|---|
| NAIC-668-10 | Penalties |
| NAIC-668-7 | Power of Commissioner |
| NAIC-668-8 | Confidentiality |
Governance and Oversight
KISO governance and statutory framework
| Code | Title |
|---|---|
| Art. 17 | Governance Structure |
| Art. 18 | Central Bank Supervision |
| Art. 19 | Consent Management Controls |
| Art. 20 | Executive Accountability |
| DMF-1.1 | Data Governance Structure |
| DMF-1.2 | Roles and Responsibilities |
| DMF-1.3 | Executive Sponsorship |
Information Security Program
Security program requirements for licensees
| Code | Title |
|---|---|
| NAIC-668-4A | ISP Implementation |
| NAIC-668-4B | ISP Objectives |
| NAIC-668-4C | Risk Assessment |
| NAIC-668-4D1 | Access Controls |
| NAIC-668-4D2 | Physical Access Restrictions |
| NAIC-668-4D3 | Encryption |
| NAIC-668-4D4 | Secure Development |
| NAIC-668-4D5 | Audit Trails |
| NAIC-668-4D6 | Multi-Factor Authentication |
| NAIC-668-4D7 | Secure Disposal |
| NAIC-668-4D8 | Incident Detection and Response |
| NAIC-668-4D9 | Testing and Monitoring |
| NAIC-ISP-01 | Written Information Security Program |
| NAIC-ISP-02 | Risk Assessment |
| NAIC-ISP-03 | Security Measures |
| NAIC-ISP-04 | Board Oversight |
Investigation and Notification
Sections 5-6: Incident investigation and regulatory/consumer notification
| Code | Title |
|---|---|
| NAIC-668-5A | Investigation Requirement |
| NAIC-668-5B | Investigation Scope |
| NAIC-668-6A | Notification to Commissioner |
| NAIC-668-6B | Notification Content |
| NAIC-668-6C | Consumer Notification |
Third-Party and Incident Management
Third-party oversight and cybersecurity event notification
| Code | Title |
|---|---|
| NAIC-TPM-01 | Third-Party Service Provider Oversight |
| NAIC-TPM-02 | Cybersecurity Event Investigation |
| NAIC-TPM-03 | Commissioner Notification |
Maps to 640 other frameworks
Frequently Asked Questions
What is NAIC Insurance Data Security Model Law (MDL-668)?
NAIC Insurance Data Security Model Law (MDL-668) is a compliance framework from United States (NAIC) with 6 domains and 49 controls. The National Association of Insurance Commissioners (NAIC) Insurance Data Security Model Law (Model 668) establishes data security standards for the insurance industry. Adopted by NAIC in 2017, it has been enacted by over 20 US states. It requires insurers and other licensed entities to develop comprehensive information security programs, conduct risk assessments, and notify regulators of cybersecurity events. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NAIC Insurance Data Security Model Law (MDL-668) have?
NAIC Insurance Data Security Model Law (MDL-668) has 49 controls organised across 6 domains. The largest domains are Information Security Program (16 controls), Definitions and Scope (15 controls), Governance and Oversight (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NAIC Insurance Data Security Model Law (MDL-668) map to?
NAIC Insurance Data Security Model Law (MDL-668) maps to 640 other compliance frameworks. The top mapping partners are CSA STAR (Security, Trust, Assurance, and Risk) (39% coverage), FedRAMP Rev 5 (39% coverage), TISAX — Trusted Information Security Assessment Exchange (39% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NAIC Insurance Data Security Model Law (MDL-668) compliance?
Start your NAIC Insurance Data Security Model Law (MDL-668) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NAIC Insurance Data Security Model Law (MDL-668) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required