NAIC Data Law Runs into Jumble of Opposition
State regulators and insurance industry groups have filed an avalanche of comment letters â 186 pages worth â asking for still more revisions to a proposed regulation governing agent liability in connection with data security.
The model law, the Insurance Data Security Model Law, was proposed by the National Association of Insurance Commissioners, and is on its second discussion-phase draft.
It is designed to offer state legislatures a roadmap for how insurers and distributors ought to proceed in the face of costly and potentially devastating data theft and the subsequent liability incurred by parties deemed responsible.
But a coalition of insurers, distributors and even other state regulators have called on the NAIC to rethink several passages within the draft proposal because it does not go far enough in pre-empting a patchwork of state laws governing data theft.
Trade groups have also taken issue with proposed notification procedures, definitions of what constitutes âpersonal information,â whether the model law is workable, procedures regarding post-breach investigations and harm thresholds.
Model laws drafted by the NAIC, which lacks enforcement powers, are not binding but serve as a guide for state insurance regulators and state lawmakers.
The first draft of the Insurance Data Security Model Law was issued in March and the second draft in August.
NAIC-level discussion around the data security model law is a sign that top-level leaders are beginning to take data breaches seriously. States like New York are also beginning to move aggressively with a modern data security framework.
Indeed, the NAICâs draft appears to place a heavier onus on insurance licensees for the oversight of third-party service provider arrangements than state laws, said James R. Woods, co-leader of Mayer Brownâs Global Insurance Industry Group in New York.
NAIC commissioners began to address data breach issues in earnest last fall with the release of its Cybersecurity Bill of Rights. The document, while lacking any legal authority, gives policyholders some recourse when their data have been compromised.
With the introduction of the model law in March, the NAIC signaled to the industry that it is ready to undertake the heavy lifting in connection with a new data security framework.
The public comment period on the Insurance Data Security Model Law draft ended last month and NAIC officials are expected to discuss the model law once more at their fall national meeting in Miami, Dec. 10-13.
Industry Groups Want Sole Applicable Law
In a letter to North Dakota Insurance Commissioner Adam Hamm, chair of the NAIC Cybersecurity Task Force, representatives for 14 life, property and health insurers and distributors said they want the model law to be the âsole data security and breach notification law applicable in a state.â
The comments, co-signed by representatives of 14 trade organizations, urge the NAIC to modify the draft of the model law.
Changes are necessary to ensure uniformity among state data security and breach notification rules, and to ensure âworkabilityâ of the model law, the representatives wrote.
Industry representatives also see the Insurance Data Security Model Law draft as imposing strict liability on insurance licensees â an agent or advisor for example â for any failure by a third-party such as a data vendor or a custodian firm. For instance, if they fail to protect personal information provided by an insurance agent or financial advisor.
Such âpotentially open-ended liabilityâ isnât something that insurance and financial advisors can accept, wrote Gary A. Sanders, counsel and vice president of government relations with the National Association of Insurance and Financial Advisors.
Furthermore, leaving out the âharm trigger,â or the threshold at which a data loss causes harm, âraises significant âworkabilityâ concerns,â and may be neither practical in âreal world applications,â nor of much help to consumers, Sanders wrote.
Agents and brokers are already subject to data breach requirements and 47 states have enacted data breach investigation and notification laws, wrote Wesley Bissett, senior counsel for Government Affairs with the Independent Insurance Agents & Brokers of America.
Regulators Raise Their Voices
State regulators who often clash with industry positions on regulation appeared to join the industry in this case citing costs, regulatory burdens on small agencies and the general legislative environment opposed to more rules.
In Georgia, the model law is already dead.
âLegislators and interested parties have expressed their dissatisfaction with the proposed model as it exists today,â wrote Sarah U. Crittenden, an attorney with the Legal Division of the Georgia Department of Insurance.
Arkansas Attorney General Leslie Rutledge likened the model law to the sweep of the Health Insurance Portability and Accountability Actâs data security and breach requirements by simply transposing them onto the rest of the insurance industry.
âSome members of the insurance industry, such as small-town independent agents, are too small to absorb the costs inherent in the modelâs requirements,â said Rutledge in a two-page comment.
While the model lawâs security program is designed to be tailored to the size and complexity of individual licensees, âall licensees regardless of size will have to undergo a risk analysis and have a written security program,â she wrote.
Arkansasâ breach notification law contains a harm threshold, which if not met does not require agents or insurers to notify consumers. In Arkansas, a premium invoice sent by an agent to the wrong address by mistake, for example, does not meet the threshold.
Under the NAICâs proposed model law, a misdirected invoice would trigger the threshold and require notice requirements, Rutledge said.
Patrick M. McPharlin, director of the Michigan Department of Insurance and Financial Services, also called on the NAIC to back off the strict liability assigned to insurance licensees under the draft of the data security model law.
Making agents responsible or liable for security outside their control is simply unfair.
âIt is unreasonable to make licensees strictly liable for third parties, irrespective of the standards of care they undertake in safeguarding the data,â he wrote.
InsuranceNewsNet Senior Writer Cyril Tuohy has covered the financial services industry for more than 15 years. Cyril may be reached at [email protected].
© Entire contents copyright 2016 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.
Cyril Tuohy is a writer based in Pennsylvania. He has covered the financial services industry for more than 15 years. He can be reached at [email protected].



Should Financial Advisors Re-Assess Brexit In Their Clients’ Portfolios?
IMOs Dance With DOL On Fiduciary Rule Deadline
Advisor News
- Most Americans optimistic about a financial ‘resolution rebound’ in 2026
- Mitigating recession-based client anxiety
- Terri Kallsen begins board chair role at CFP Board
- Advisors underestimate demand for steady, guaranteed income, survey shows
- D.C. Digest: 'One Big Beautiful Bill' rebranded 'Working Families Tax Cut'
More Advisor NewsAnnuity News
- MetLife Declares First Quarter 2026 Common Stock Dividend
- Using annuities as a legacy tool: The ROP feature
- Jackson Financial Inc. and TPG Inc. Announce Long-Term Strategic Partnership
- An Application for the Trademark âEMPOWER PERSONAL WEALTHâ Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
- Talcott Financial Group Launches Three New Fixed Annuity Products to Meet Growing Retail Demand for Secure Retirement Income
More Annuity NewsHealth/Employee Benefits News
- CT set aside $120 million to help cover residentsâ health insurance costs. How to get help
- ARE SLEEP STUDIES COVERED BY INSURANCE?
- ACADEMYHEALTH'S SITUATION REPORT: CRITICAL POLICY DEVELOPMENTS WE'RE WATCHING IN 2026
- NM fills gap after Congress lets ACA tax credits expire
- Congress takes up health care again â and impatient voters shouldnât hold their breath for a cure
More Health/Employee Benefits NewsProperty and Casualty News
- U.S. News & World Report Announces the 2026 Best Travel Insurance Companies
- Are home warranties replacing home insurance for some customers?
- IL House speaker signals insurance regulation described as 'ill-advised'
- Homeowners insurance and earthquake coverage: Which states offer protection?
- PHILADELPHIA'S ACCEPTANCE INTO FEMA COMMUNITY RATING SYSTEM OPENS DOORS FOR DISCOUNTS ON FLOOD INSURANCE POLICIES
More Property and Casualty News