State Requirements Translated Into Proof

STATE CYBER & BREACH REQUIREMENTS

See What Each State Expects, and What Proof to Keep Ready

Select a state to see:

  • Breach notification basics
  • Insurance-specific cybersecurity requirements where they apply
  • Federal requirements, including FTC Safeguards / GLBA
  • The evidence you should be able to produce on demand

Use the state summary to confirm timing, who must be notified, any industry-specific requirements, and the proof a reviewer will expect.

Not legal advice. Use this to scope work and keep records, then confirm specifics with counsel.

Select Your State

One core program can support work across multiple states. Select each state where you operate to map deadlines, notice thresholds, recipients, and any industry-specific requirements into one evidence set.

Filter by Industry

Filters the view below. Requirements don't change — this only highlights what's most relevant to your industry.

Interactive map
State-specific insurance cybersecurity statutes NAIC model-law baseline states Related insurance activity

Use Tab to focus a state. Press Enter or Space to select it. You can also select a state from the searchable list below.

NAIC model-law baseline states
State-specific insurance cybersecurity statutes
No dedicated insurance cybersecurity statute

The map highlights insurance cybersecurity overlays. Breach notification laws apply in every state; exact timing, recipients, thresholds, and insurance classifications still vary by jurisdiction.

* Puerto Rico: Puerto Rico appears in the adopted category on the NAIC Model 668 map dated March 3, 2026. Because Borealis presents a 50-state table and the Summer 2025 NAIC state page still showed Puerto Rico under related activity, Borealis tracks Puerto Rico separately instead of folding it into the 50-state list.

Borealis planning baseline
Book a 30-Minute Program Review

Borealis planning baseline

What applies and what to keep ready

Showing general baseline requirements common to every state. Select your state above (or visit its dedicated page) for state-specific timing and requirements.

Applies to
If you store or process personal information for Borealis planning baseline residents, these notice rules can apply even outside regulated industries.
Trigger
A reportable breach trigger varies by state and may be based on unauthorized access, unauthorized acquisition, or other misuse-based standards. Use the jurisdiction-specific law for the exact trigger.
Covered Data
Covered data is state-specific and can include name plus Social Security number, driver’s license/state ID number, financial account or payment credential data, medical/health information, health-insurance information, biometric data, tax information, login credentials, and other categories specified by the state law. Use the jurisdiction-specific rule to determine coverage.
Consumer Notice
Jurisdiction-specific
Consumer notice timing is jurisdiction-specific. Some states use a qualitative standard such as without unreasonable delay; many states also impose an outer deadline such as 30, 45, or 60 days. Use the state-specific row for the exact deadline.
Third-Party to Owner/Licensee
Jurisdiction-specific
Processor-to-owner or vendor-to-licensee notice timing is also jurisdiction-specific. Use the state-specific rule to determine the exact timing and recipient.
AG / State Agency
Varies by jurisdiction
Attorney General or state-agency notice is not universal. Recipient, threshold, timing, and applicability vary by jurisdiction and sometimes by entity type. Use the state-specific row for the exact rule.
Response priorities to review live

Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.

  • Preserve logs and evidence (do not "clean up" yet)
  • Open an incident ticket and assign an owner
  • Start the decision log and incident timeline
  • Notify counsel and your cyber insurer

Key Obligations

Written Program
Risk Assessment
MFA and Encryption
Vendor Oversight
Incident Response

Who You Notify

Primary
  • Affected Borealis planning baseline residents - if covered personal information was accessed, acquired, or otherwise triggers the jurisdiction-specific notice rule
Conditional
  • State regulator / Attorney General - when the jurisdiction-specific recipient, threshold, and entity-type rule applies
  • Consumer reporting agencies - if required for large-scale incidents
Coordination
  • Law enforcement - coordinate if an investigative delay is requested

What to Keep Ready

Prepare Now
  • Incident Response Plan - roles, escalation, outside counsel and insurer contacts
  • Incident Contact Matrix - IT/MSP, insurer, key vendors, regulator/AG contacts
  • Notice Templates - resident and regulator notice drafts reviewed with counsel
  • Baseline Control Evidence - MFA, access reviews, backup/restore testing, vendor oversight
During an Incident
  • Notification Decision Log - why notice is or is not required, who approved, and when
  • Incident Timeline - key events, containment steps, and decision points
  • Delivery & Submission Records - notices sent, confirmations, and regulator submissions

Review-Ready Evidence

Incident RecordDecision log, timeline, approval trail
Control EvidenceMFA config, backup test proof, access attestations
Notification RecordsNotices sent, delivery confirmations, regulator receipts
No state insurance cybersecurity statute. Carriers and examiners still expect a defensible program: written security plan, risk decisions, vendor oversight, MFA, and incident readiness - with evidence that stays current and reviewable.

What Examiners Still Expect

  • Written Information Security Program - approved, dated, with a documented review cadence
  • Risk Assessment - current, with remediation tracking
  • MFA Evidence - remote access, admin accounts, email
  • Vendor Oversight - inventory, due diligence, contract clauses
  • Incident Response Plan - tested (tabletop exercise records)
Applies to
Applicability depends on whether the entity is a covered financial institution under FTC jurisdiction. Common examples can include tax return preparers, tax professional firms, accounting firms, and some financial advisors.
Authority
FTC Safeguards Rule (16 CFR 314) under the Gramm-Leach-Bliley Act.
FTC Notification
At least 500 consumers / 30 days outer limit
For a notification event involving at least 500 consumers' unencrypted customer information, covered institutions must notify the FTC as soon as possible and no later than 30 days after discovery.
IRS Stakeholder Liaison
Immediately / as soon as possible
IRS guidance says tax professionals should report client data theft immediately / as soon as possible to the local IRS stakeholder liaison.
Response priorities to review live

Operational guidance to stabilize an incident and document decisions. It is not a statutory deadline.

  • Preserve logs and evidence (do not "clean up" yet)
  • Open an incident ticket and assign an owner
  • Start the decision log and incident timeline
  • Notify counsel and your cyber insurer

Key Obligations

Written Program
Risk Assessment
MFA and Encryption
Vendor Oversight
Incident Response

What to Keep Ready

Prepare Now
  • Tax-Focused WISP - written security plan for taxpayer data, access controls, and encryption approach
  • MFA Evidence - email, portal, admin accounts configuration
  • Encryption Documentation - secure storage approach for SSNs and return data
  • Vendor Inventory - tax software, DMS, e-sign, portal, payroll providers
During an Incident
  • Notification Decision Log - why notice is/isn't required, who approved, when
  • Incident Timeline - key events, containment steps, decision points
  • Submission Records - FTC notification, IRS liaison report (if applicable)

Review-Ready Evidence

Written Program Signed, dated, with current security controls
Control Evidence MFA/encryption config, access review attestations
Vendor Oversight Inventory, due diligence, contract clauses
Incident Record Timeline, notification records, FTC/IRS receipts
AL NAIC 668

Alabama

Alabama Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

AK SB 134

Alaska

Alaska Insurance Data Security Act

State-specific insurance cybersecurity requirements mapped to actions and evidence.

AZ Related

Arizona

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

AR Baseline

Arkansas

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

CA Related

California

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

CO Related

Colorado

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

CT NAIC 668

Connecticut

Connecticut Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

DE Ch. 86

Delaware

Delaware Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

FL Baseline

Florida

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

GA Baseline

Georgia

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

HI NAIC 668

Hawaii

Hawaii Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

ID Baseline

Idaho

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

IL NAIC 668

Illinois

Illinois Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

IN NAIC 668

Indiana

Indiana Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

IA Ch. 507F

Iowa

Iowa Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

KS Baseline

Kansas

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

KY NAIC 668

Kentucky

Kentucky Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

LA NAIC 668

Louisiana

Louisiana Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

ME NAIC 668

Maine

Maine Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

MD NAIC 668

Maryland

Maryland Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

MA Baseline

Massachusetts

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

MI NAIC 668

Michigan

Michigan Data Security in the Insurance Sector Act

NAIC 668-style insurance requirements mapped to actions and evidence.

MN NAIC 668

Minnesota

Minnesota Insurance Data Security Model Law

NAIC 668-style insurance requirements mapped to actions and evidence.

MS NAIC 668

Mississippi

Mississippi Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

MO NAIC 668

Missouri

Missouri Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

MT Related

Montana

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

NE Related

Nebraska

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

NV Baseline

Nevada

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

NH NAIC 668

New Hampshire

New Hampshire Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

NJ Related

New Jersey

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

NM Related

New Mexico

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

NY NYDFS

New York

NYDFS Cybersecurity Regulation

State-specific insurance cybersecurity requirements mapped to actions and evidence.

NC Related

North Carolina

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

ND NAIC 668

North Dakota

North Dakota Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

OH NAIC 668

Ohio

Ohio Data Protection Act (Insurance)

NAIC 668-style insurance requirements mapped to actions and evidence.

OK NAIC 668

Oklahoma

Oklahoma Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

OR Related

Oregon

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

PA NAIC 668

Pennsylvania

Pennsylvania Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

RI NAIC 668

Rhode Island

Rhode Island Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

SC NAIC 668

South Carolina

South Carolina Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

SD Related

South Dakota

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

TN NAIC 668

Tennessee

Tennessee Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

TX Baseline

Texas

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

UT Related

Utah

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

VT NAIC 668

Vermont

Vermont Insurance Data Security Law

NAIC 668-style insurance requirements mapped to actions and evidence.

VA NAIC 668

Virginia

Virginia Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

WA Baseline

Washington

Borealis baseline for regulated firms

No dedicated insurance cybersecurity statute. General security, vendor, MFA, and incident expectations still apply.

WV Related

West Virginia

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

WI NAIC 668

Wisconsin

Wisconsin Insurance Data Security Act

NAIC 668-style insurance requirements mapped to actions and evidence.

WY Related

Wyoming

Related insurance activity (not Model 668 adoption)

Related insurance authority exists, but this is not treated here as a current Model 668 adoption. Confirm applicability with counsel and the DOI.

Program Review

Work Through State Requirements With Borealis

Use the state summary to frame the work, then book a short program review to map deadlines, reviewer expectations, and next actions with us.

Breach Notification Review

Walk through timing, recipients, thresholds, and the decisions to document before notices go out.

Book a review call

Incident Readiness Review

Pressure-test the first 72 hours, ownership decisions, and evidence handling before an incident happens.

Book a review call

Reviewer Evidence Review

Walk through the control crosswalk and the evidence reviewers usually expect to see.

Book a review call

Not legal advice. Borealis does not provide standalone download packs; we review your situation with you.

Ready to Map Your Requirements?

Get a prioritized review plan: what you have, what’s missing, and what evidence to organize next. Then book a short program review to confirm scope, state deltas, and what to prep for audit, renewal, and diligence requests.

Educational guidance, not legal advice. Always confirm requirements with your counsel and relevant regulators.