Compliance research

What Insurance Data Security Laws Require of Third-Party Service Providers

A sourced desk review of the NAIC Insurance Data Security Model Law and two state enactments, focused on due diligence, contractual safeguards, and oversight of third-party service providers such as virtual assistants.

Published: September 17, 2026 · InsuranceYo Research

What Insurance Data Security Laws Require of Third-Party Service Providers research illustration

Research question

What do state insurance data security laws based on the NAIC Insurance Data Security Model Law require of a licensed insurance entity that uses a third-party service provider, and what specifically does that mean for an agency delegating work to a virtual assistant that can access nonpublic information?

This is a desk review of public legal sources. It is not legal advice and does not determine the obligations of any particular agency or state.

Method

The method was to read the NAIC's regulator-authored overview and two enacted state statutes that follow the model law's structure:

  1. The NAIC's public Cybersecurity topic page, which describes the model law and the regulatory context.
  2. The Ohio Revised Code, Chapter 3965, "Cybersecurity Requirements for Insurance Companies," read in the relevant sections including definitions, the information security program requirements, and the third-party service provider provision.
  3. Minnesota Statutes sections 60A.985 (definitions) and 60A.9851 (information security program), which include a dedicated subdivision on oversight of third-party service provider arrangements.

The NAIC model law text itself was not used because the published PDF could not be read reliably in this environment; instead, two state enactments that track its structure were read directly. This is a limitation discussed below. No survey, interview, or agency data was collected.

Evidence

The NAIC overview

The NAIC states that it adopted the Insurance Data Security Model Law (#668), which it says "requires insurers and other entities licensed by state insurance departments to develop, implement and maintain an information security program; investigate any cybersecurity events; and notify the state insurance commissioner of such events." (NAIC, Cybersecurity).

Source fact: The model law applies to entities licensed by state insurance departments, requires a program and event investigation, and requires notification to the commissioner.

Ohio's enactment

Ohio Revised Code Chapter 3965 defines a "third-party service provider" as a person other than a licensee that contracts with a licensee to maintain, process, or store nonpublic information through its provision of services, or that is otherwise permitted access to nonpublic information through its provision of services (Ohio Revised Code § 3965.01(R)).

The statute requires each licensee to develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment, commensurate with the size and complexity of the licensee, the nature and scope of its activities "including its use of third-party service providers," and the sensitivity of the nonpublic information (Ohio Revised Code § 3965.02(A)).

The program must define and periodically reevaluate a retention schedule and destruction mechanism, identify reasonably foreseeable threats including those to systems accessible to or held by third-party service providers, assess the sufficiency of safeguards, implement safeguards, and at least annually assess the effectiveness of key controls (Ohio Revised Code § 3965.02(B)–(C)).

On service providers specifically, the statute states:

"A licensee shall exercise due diligence in selecting its third-party service provider." and "A licensee shall require a third-party service provider to implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information that are accessible to, or held by, the third-party service provider." (Ohio Revised Code § 3965.02(F))

Ohio also requires a written incident response plan, permits the board to require annual written reports that address third-party service provider arrangements, and requires notification of cybersecurity events, including when the event occurs in a system maintained by a third-party service provider, with deadlines beginning when the provider notifies the licensee or the licensee has actual knowledge, whichever is sooner (Ohio Revised Code §§ 3965.02(H), 3965.02(E), 3965.04(D)).

Minnesota's enactment

Minnesota defines "third-party service provider" in similar terms: a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, or store nonpublic information, or is otherwise permitted access to nonpublic information through its provision of services (Minnesota Statutes § 60A.985, subd. 15).

Minnesota requires each licensee to develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment, commensurate with its size and complexity and "the nature and scope of the licensee's activities, including its use of third-party service providers" (Minnesota Statutes § 60A.9851, subd. 2).

Minnesota contains a dedicated subdivision titled "Oversight of third-party service provider arrangements," which states that a licensee shall exercise due diligence in selecting its third-party service provider and shall require the provider to implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information accessible to or held by the provider (Minnesota Statutes § 60A.9851, subd. 6).

Findings

Finding 1: The laws follow a common template. The NAIC model law and the two enactments reviewed share a structure: definitions, a written risk-based information security program, an incident response plan, third-party oversight, and event notification to the commissioner. This uniformity is the model law's purpose.

Finding 2: Third-party oversight has two explicit parts. In both states, the licensee must (a) exercise due diligence in selecting the provider and (b) require the provider to implement appropriate administrative, technical, and physical safeguards. These are separate obligations.

Finding 3: The program's required scope accounts for providers. Both statutes require the program to be commensurate with the nature and scope of activities, including the entity's use of third-party service providers, and to consider threats to information accessible to or held by those providers.

Finding 4: The licensee remains responsible for third-party-caused events. Ohio's notification provisions treat a cybersecurity event in a provider's system as the licensee's event for notification purposes, with the clock starting when the provider notifies the licensee or the licensee has actual knowledge.

Finding 5: Board reporting reaches provider arrangements. Both states require reporting that can address third-party service provider arrangements, which puts provider oversight on the governance agenda rather than only on the IT agenda.

Interpretation: what this suggests for using a virtual assistant

The following is the author's interpretation, not statutory text:

  • A virtual assistant arrangement that permits access to nonpublic information fits the statutory definition of a third-party service provider in both states reviewed.
  • "Due diligence" and "require appropriate measures" imply both a selection process and a contractual safeguard requirement, plus the ability to demonstrate that both occurred.
  • Because the program must account for provider-held information, a VA relationship is a planning input, not just a procurement detail.
  • Incident notification duties can be triggered by a provider's event, so the agency needs a notification path from the provider to the agency that is fast enough to meet the statutory clock.

Operational implications

Proposed steps derived from the source obligations, not themselves a statutory checklist:

  1. Map provider access. List every provider, including virtual assistants, that can access nonpublic information, and the systems involved.
  2. Document due diligence. Record how the provider was selected and what safeguards were evaluated.
  3. Put safeguards in the contract. Require administrative, technical, and physical measures, confidentiality, and cooperation with investigations.
  4. Require prompt breach notification. Make the provider's obligation to notify the agency explicit and fast enough to meet the agency's own regulatory deadlines.
  5. Include providers in the risk assessment and program. Assess threats to provider-held data and set appropriate controls.
  6. Control and review access. Limit access to what the role needs and review it periodically, consistent with the program's access-control requirements.
  7. Address provider arrangements in governance reporting. Include them in the annual report described by the statutes.
  8. Confirm the applicable state. Adoption status and details vary; confirm the current law in each state where the agency operates.

Limitations

  • Not legal advice. This paper summarizes public sources and does not determine any agency's obligations.
  • Two states, not fifty. Only Ohio and Minnesota were read in depth. Their enactments illustrate the model's structure but do not represent every jurisdiction.
  • Model law text not read directly. The NAIC model law PDF was not reliably readable in this environment, so the review relies on the NAIC overview and two enactments. The enactments may differ from the model in detail.
  • Federal and other overlays not analyzed. The FTC Safeguards Rule, the Gramm-Leach-Bliley Act, and state breach-notification statutes may apply alongside these laws. See related InsuranceYo research on the FTC Safeguards Rule.
  • Definitions matter. Exemptions and thresholds, such as small-licensee provisions, were not fully reviewed.

Practical conclusion

The state laws reviewed take a consistent approach: the licensed entity owns the information security program, and using a third-party service provider does not transfer that responsibility. A virtual assistant placement that can reach nonpublic information is a provider arrangement, which triggers due diligence, a contractual safeguard obligation, and inclusion in the program's risk assessment and governance reporting. An agency can meet the spirit of these requirements with a mapped inventory, a documented selection rationale, a safeguards clause, a fast notification path, and a periodic access review, while confirming the specifics with counsel for each state it operates in.

Sources

  1. National Association of Insurance Commissioners — Insurance Topics: Cybersecurity (including Insurance Data Security Model Law #668). https://content.naic.org/insurance-topics/cybersecurity
  2. Ohio Revised Code, Chapter 3965 — Cybersecurity Requirements for Insurance Companies. https://codes.ohio.gov/ohio-revised-code/chapter-3965
  3. Minnesota Statutes § 60A.985 — Definitions. https://www.revisor.mn.gov/statutes/cite/60A.985
  4. Minnesota Statutes § 60A.9851 — Information security program. https://www.revisor.mn.gov/statutes/cite/60A.9851

Related research