STATE CYBER & BREACH REQUIREMENTS
See What Each State Expects, and What Proof to Keep Ready
Select a state to see:
- Breach notification basics
- Insurance-specific cybersecurity requirements where they apply
- Federal requirements, including FTC Safeguards / GLBA
- The evidence you should be able to produce on demand
Use the state summary to confirm timing, who must be notified, any industry-specific requirements, and the proof a reviewer will expect.
Not legal advice. Use this to scope work and keep records, then confirm specifics with counsel.
Select Your State
One core program can support work across multiple states. Select each state where you operate to map deadlines, notice thresholds, recipients, and any industry-specific requirements into one evidence set.
Use Tab to focus a state. Press Enter or Space to select it. You can also select a state from the searchable list below.
The map highlights insurance cybersecurity overlays. Breach notification laws apply in every state; exact timing, recipients, thresholds, and insurance classifications still vary by jurisdiction.
* Puerto Rico: Puerto Rico appears in the adopted category on the NAIC Model 668 map dated March 3, 2026. Because Borealis presents a 50-state table and the Summer 2025 NAIC state page still showed Puerto Rico under related activity, Borealis tracks Puerto Rico separately instead of folding it into the 50-state list.
Borealis planning baseline
What applies and what to keep ready
Showing general baseline requirements common to every state. Select your state above (or visit its dedicated page) for state-specific timing and requirements.
Response priorities to review live
Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.
- Preserve logs and evidence (do not "clean up" yet)
- Open an incident ticket and assign an owner
- Start the decision log and incident timeline
- Notify counsel and your cyber insurer
Key Obligations
Who You Notify
Primary
- Affected Borealis planning baseline residents - if covered personal information was accessed, acquired, or otherwise triggers the jurisdiction-specific notice rule
Conditional
- State regulator / Attorney General - when the jurisdiction-specific recipient, threshold, and entity-type rule applies
- Consumer reporting agencies - if required for large-scale incidents
Coordination
- Law enforcement - coordinate if an investigative delay is requested
What to Keep Ready
Prepare Now
- Incident Response Plan - roles, escalation, outside counsel and insurer contacts
- Incident Contact Matrix - IT/MSP, insurer, key vendors, regulator/AG contacts
- Notice Templates - resident and regulator notice drafts reviewed with counsel
- Baseline Control Evidence - MFA, access reviews, backup/restore testing, vendor oversight
During an Incident
- Notification Decision Log - why notice is or is not required, who approved, and when
- Incident Timeline - key events, containment steps, and decision points
- Delivery & Submission Records - notices sent, confirmations, and regulator submissions
Review-Ready Evidence
Keep a clean incident record: decision log, timeline, control evidence, and delivery records your team can review with counsel, carriers, and regulators.
What Examiners Still Expect
- Written Information Security Program - approved, dated, with a documented review cadence
- Risk Assessment - current, with remediation tracking
- MFA Evidence - remote access, admin accounts, email
- Vendor Oversight - inventory, due diligence, contract clauses
- Incident Response Plan - tested (tabletop exercise records)
Response priorities to review live
Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.
- Preserve logs and evidence (do not "clean up" yet)
- Open an incident ticket and assign an owner
- Start the decision log and incident timeline
- Notify counsel and your cyber insurer
Key Obligations
What to Keep Ready
Prepare Now
- Tax-Focused WISP - written security plan for taxpayer data, access controls, and encryption approach
- MFA Evidence - email, portal, admin accounts configuration
- Encryption Documentation - secure storage approach for SSNs and return data
- Vendor Inventory - tax software, DMS, e-sign, portal, payroll providers
During an Incident
- Notification Decision Log - why notice is/isn't required, who approved, when
- Incident Timeline - key events, containment steps, decision points
- Submission Records - FTC notification, IRS liaison report (if applicable)
Review-Ready Evidence
Keep a clean incident record: decision log, timeline, control evidence, and delivery records your team can review with counsel, carriers, and regulators.
Borealis planning baseline
Borealis baseline for regulated firms
Use this as a Borealis planning baseline. Breach notification rules, recipients, thresholds, and state or federal overlays still vary by jurisdiction.
Alabama
Alabama Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Alaska
Alaska Insurance Data Security Act
State-specific insurance cybersecurity requirements mapped to actions and evidence.
Arizona
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Arkansas
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
California
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Colorado
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Connecticut
Connecticut Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Delaware
Delaware Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Florida
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Georgia
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Hawaii
Hawaii Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Idaho
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Illinois
Illinois Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Indiana
Indiana Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Iowa
Iowa Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Kansas
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Kentucky
Kentucky Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Louisiana
Louisiana Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Maine
Maine Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Maryland
Maryland Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Massachusetts
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Michigan
Michigan Data Security in the Insurance Sector Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Minnesota
Minnesota Insurance Data Security Model Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Mississippi
Mississippi Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Missouri
Missouri Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Montana
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Nebraska
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Nevada
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
New Hampshire
New Hampshire Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
New Jersey
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
New Mexico
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
New York
NYDFS Cybersecurity Regulation
State-specific insurance cybersecurity requirements mapped to actions and evidence.
North Carolina
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
North Dakota
North Dakota Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Ohio
Ohio Data Protection Act (Insurance)
NAIC 668-style insurance requirements mapped to actions and evidence.
Oklahoma
Oklahoma Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Oregon
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Pennsylvania
Pennsylvania Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Rhode Island
Rhode Island Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
South Carolina
South Carolina Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
South Dakota
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Tennessee
Tennessee Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Texas
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
Utah
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Vermont
Vermont Insurance Data Security Law
NAIC 668-style insurance requirements mapped to actions and evidence.
Virginia
Virginia Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Washington
Borealis baseline for regulated firms
No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.
West Virginia
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Wisconsin
Wisconsin Insurance Data Security Act
NAIC 668-style insurance requirements mapped to actions and evidence.
Wyoming
Related insurance activity (not Model 668 adoption)
Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.
Program Review
Work Through State Requirements With Borealis
Use the state summary to frame the work, then book a short program review to map deadlines, reviewer expectations, and next actions with us.
Breach Notification Review
Walk through timing, recipients, thresholds, and the decisions to document before notices go out.
Book a review callIncident Readiness Review
Pressure-test the first 72 hours, ownership decisions, and evidence handling before an incident happens.
Book a review callReviewer Evidence Review
Walk through the control crosswalk and the evidence reviewers usually expect to see.
Book a review callNot legal advice. Borealis does not provide standalone download packs; we review your situation with you.
Ready to Map Your Requirements?
Get a prioritized review plan: what you have, what’s missing, and what evidence to organize next. Then book a short program review to confirm scope, state deltas, and what to prep for audit, renewal, and diligence requests.