Data Security Checklist

Annual cybersecurity and data privacy compliance review for an insurance carrier, MGA, or agency. Covers NYDFS Part 500 / NAIC Insurance Data Security Model Law controls, GLBA Safeguards Rule obligations, vendor risk, and breach response readiness.

5 sections 21 steps Collects data
1

Security Program Governance

  1. Confirm CISO designation under Part 500
    • NYDFS 23 NYCRR 500.4 requires a designated CISO accountable for the cybersecurity program; the role can be in-house or a qualified third party but accountability stays with the Covered Entity. Confirm the named CISO and whether a written delegation exists if outsourced to an MSSP or virtual CISO.

  2. Refresh the written information security program
    • The GLBA Safeguards Rule and the NAIC Insurance Data Security Model Law each require a written program covering administrative, technical, and physical safeguards over NPI. Pull the current WISP, mark redlines for the past year's material changes (new products, acquisitions, vendor swaps), and route for executive approval.

    Collects file
  3. Conduct the annual risk assessment
    • NYDFS Part 500.9 expects a risk assessment that drives the controls in the program; HIPAA Security Rule expects the same on the PHI side for stop-loss and group health writers. Re-run if there has been a material change mid-year — biennial-only programs after a new product launch or major vendor swap fail exam.

  4. Document board reporting and sign-off
    • Part 500.4(c) requires the CISO to deliver a written annual report to the board or senior governing body. Capture meeting minutes referencing the report and the board's review of material risks, control gaps, and the prior year's incidents.

2

Technical Controls Review

  1. Verify MFA on all external access
    • Part 500.12(b) requires MFA for any individual accessing internal networks from an external network — including TPAs, wholesalers, and IT contractors with VPN credentials. Pull the IdP report (Okta, Entra, Duo) and reconcile against the contractor roster; treating MFA as employee-only is a common finding.

    Collects paragraph
  2. Confirm encryption of NPI in transit and at rest
    • Part 500.15 requires encryption of NPI in transit over external networks and at rest, or a CISO-approved compensating control. Spot-check the AMS database, document repositories (ImageRight, ePolicy), claim-file shares, and any SFTP feeds to wholesalers and reinsurers.

  3. Schedule annual penetration test
    • Part 500.5 requires annual penetration testing and bi-annual vulnerability assessments based on the risk assessment. Confirm scope covers PolicyCenter, ClaimCenter, the AMS, and any insured-facing portals. Pen-tests scoped only to the corporate network miss the policy and claims surface.

  4. Validate audit-trail and logging coverage
    • Part 500.6 requires audit trails sufficient to detect and respond to a cybersecurity event, retained for at least three years for material events and five years for financial transactions. Confirm SIEM ingestion from the AMS, policy admin, claims, and email gateway.

  5. Review user access against least privilege
    • Pull the access review for producers, CSRs, adjusters, and underwriters in Applied Epic or AMS360. Common gotchas: terminated producers still appointed in NIPR but with active AMS logins; adjusters with all-claim visibility when scope should be book-of-business limited.

3

Privacy and Data Handling

  1. Refresh the GLBA annual privacy notice
    • The GLBA Privacy Rule requires an annual notice with opt-out for non-affiliate sharing. Vermont requires opt-in; California personal-lines insureds need CCPA/CPRA-aligned disclosures. Don't reuse a national form letter without state overlays.

  2. Confirm data classification and retention schedule
    • Most states require 5–7 years of policy and claim file retention; workers comp often 10+ years given lifetime medical on occurrence-based coverage. Premature destruction creates discoverable spoliation risk; over-retention expands breach exposure. Reconcile the schedule against ImageRight and any legacy archive.

  3. Audit OFAC screening at issuance and payment
    • Many carriers screen at policy issuance but not at every claim payment, missing names added to the SDN list mid-policy. Pull a sample of recent claim payments and confirm each was OFAC-cleared at disbursement, not just at FNOL.

  4. Update the third-party service provider inventory
    • Part 500.11 vendor risk scope includes TPAs, claims vendors, document destruction firms, mailhouses printing claim packets — anyone touching NPI, not just IT vendors. Capture the current vendor list with the data they handle and the date of their most recent SOC 2 Type II.

    Collects file Collects paragraph
4

Workforce Training

  1. Deliver annual cybersecurity awareness training
    • Part 500.14 requires regular cybersecurity awareness training for all personnel, updated to reflect risks identified in the risk assessment. Cover phishing, social engineering targeted at producers (fake binding requests), and recorded-statement consent rules for adjusters.

    Collects file
  2. Run a phishing simulation
    • Use KnowBe4, Proofpoint, or equivalent. Tailor lures to the agency's actual workflow — fake ACORD 25 requests, spoofed wholesaler emails, fake premium-finance notices. Track click and report rates by team.

  3. Verify producer CE includes ethics and data security
    • Pull the NIPR roster and confirm CE compliance per resident state, including any ethics or cybersecurity-specific hours. Lapsed CE means lapsed license means no authority to bind — and it shows up at the next market conduct exam.

5

Incident Response Readiness

  1. Refresh the incident response plan
    • Plan must address the NAIC Insurance Data Security Model Law 72-hour DOI notification window — shorter than HIPAA's 60 days and shorter than most state breach laws. Many IR plans default to the longest window and miss the DOI clock. Name the DOI contact in every state of operation.

  2. Test the breach notification workflow
    • Walk through who drafts the DOI notice, who signs it, and how it gets filed in each state's portal. Confirm parallel tracks for state attorneys general, affected individuals, and HHS for any health-insurance lines. Capture timing benchmarks against the 72-hour clock.

  3. Run a tabletop exercise
    • Scenario should hit a realistic insurance-specific vector: ransomware on the AMS, BEC against a producer binding an account, or NPI exfiltration from a TPA. Include underwriting, claims, IT, legal, and the CISO.

    Collects list
  4. Document remediation plan for identified gaps
    • For each gap, name an owner, a target date, and the control framework reference (Part 500 section, NAIC Model section, or NIST CSF subcategory). Route to the CISO and capture in the next board report.

    Collects file Collects signature
  5. File the annual Part 500 certification
    • Covered Entities must file a Notice of Compliance or an acknowledgement of non-compliance with NYDFS by April 15 each year via the DFS Cybersecurity Portal. Confirm the CISO and a senior officer have both reviewed before submission.

Use this template

Copy it to your account, customize the steps, and run it with your team in minutes.


Sections 5
Steps 21
Category Insurance
Price Free to start
Need a different process

Browse hundreds of free templates across every team and industry.

Back to template library

Run Data Security Checklist with your team

Customize the steps, assign roles, set a schedule, and keep a complete record for every run.