Insurance cybersecurity requirements vary by state. Pick yours to see who you must notify after a data breach, how fast, and the security controls regulators and carriers now expect.
A documented plan scaled to your size, with a named owner.
Find where client data lives and put safeguards in place — MFA, encryption, EDR.
A written, rehearsed playbook built before a breach, not during it.
Vet the tech providers who touch your data and put security terms in their contracts.
Notify regulators on a clock — often 72 hours — and certify compliance yearly.
| State | Insurance data-security law | Report cyber event to | Notify residents within | Also notify (verified) |
|---|---|---|---|---|
| Alabama | Adopted (#668) | Dept. of Insurance | 45 days | AG + credit bureaus if 1,000+ residents |
| Alaska | Adopted (#668) | Division of Insurance | Without undue delay | AG + credit bureaus if 1,000+ residents |
| Arizona | Older / partial | — | 45 days | — |
| Arkansas | Breach law only | — | Without undue delay | No AG/regulator filing required |
| California | Older / partial | — | 30 days | AG if 500+ residents; AG filing within 15 days |
| Colorado | Older / partial | — | 30 days | AG if 500+ residents |
| Connecticut | Adopted (#668) | Insurance Dept. | 60 days | AG notice required |
| Delaware | Adopted (#668) | Dept. of Insurance | 60 days | — |
| District of Columbia | Older / partial | — | Without undue delay | — |
| Florida | Breach law only | — | 30 days | AG if 500+ residents |
| Georgia | Breach law only | — | Without undue delay | Credit bureaus if 10,000+; no AG filing |
| Hawaii | Adopted (#668) | Insurance Division | Without undue delay | Consumer Protection + bureaus if 1,000+ |
| Idaho | Breach law only | — | Without undue delay | Agencies notify AG within 24 hrs |
| Illinois | Adopted (#668) | Dept. of Insurance | Without undue delay | AG if 500+ residents |
| Indiana | Adopted (#668) | Dept. of Insurance | 45 days | AG + credit bureaus required |
| Iowa | Adopted (#668) | Insurance Division | Without undue delay | — |
| Kansas | Breach law only | — | Without undue delay | — |
| Kentucky | Adopted (#668) | Dept. of Insurance | Without undue delay | — |
| Louisiana | Adopted (#668) | Dept. of Insurance | 60 days | — |
| Maine | Adopted (#668) | Bureau of Insurance | 30 days | — |
| Maryland | Adopted (#668) | Insurance Administration | Without undue delay | — |
| Massachusetts | Breach law only | — | Without undue delay | — |
| Michigan | Adopted (#668) | DIFS | Without undue delay | — |
| Minnesota | Adopted (#668) | Dept. of Commerce | Without undue delay | — |
| Mississippi | Adopted (#668) | Dept. of Insurance | Without undue delay | — |
| Missouri | Older / partial | — | Without undue delay | — |
| Montana | Older / partial | — | Without undue delay | — |
| Nebraska | Older / partial | — | Without undue delay | — |
| Nevada | Breach law only | — | Without undue delay | — |
| New Hampshire | Adopted (#668) | Insurance Dept. | Without undue delay | — |
| New Jersey | Older / partial | — | Without undue delay | — |
| New Mexico | Older / partial | — | 45 days | — |
| New York | NY 23 NYCRR 500 | Dept. of Financial Services (portal) | Without undue delay | AG + state agencies required |
| North Carolina | Older / partial | — | Without undue delay | — |
| North Dakota | Adopted (#668) | Insurance Dept. | Without undue delay | — |
| Ohio | Adopted (#668) | Dept. of Insurance | 45 days | — |
| Oklahoma | Adopted (#668) | Insurance Dept. | Without undue delay | Breach law amended 2026 — verify |
| Oregon | Adopted (#668) | DCBS / Insurance Division | 45 days | — |
| Pennsylvania | Adopted (#668) | Insurance Dept. | Without undue delay | — |
| Rhode Island | Adopted (#668) | Insurance Division | 45 days | — |
| South Carolina | Adopted (#668) | Dept. of Insurance (form) | Without undue delay | — |
| South Dakota | Older / partial | — | 60 days | — |
| Tennessee | Adopted (#668) | Dept. of Commerce & Insurance | 45 days | Credit bureaus if 1,000+ residents |
| Texas | Breach law only | — | 60 days | AG notice required (250+ residents) |
| Utah | Adopted (#668) | Insurance Dept. | Without undue delay | — |
| Vermont | Adopted (#668) | Dept. of Financial Regulation | 45 days | — |
| Virginia | Adopted (#668) | Bureau of Insurance | Without undue delay | — |
| Washington | Breach law only | — | 30 days | AG if 500+ residents |
| West Virginia | Older / partial | — | Without undue delay | — |
| Wisconsin | Adopted (#668) | OCI | 45 days | — |
| Wyoming | Adopted (#668) | Insurance Dept. | Without undue delay | — |
Trinity Solutions makes Triad insurance agencies audit-ready — security programs, MFA, EDR, 24/7 monitoring, and a rehearsed incident-response plan.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy.