When you earned your insurance license, the curriculum covered products, markets, and regulations. Nobody explained that collecting client information in the course of normal business creates a legal data protection obligation.
Several states have enacted requirements modeled on NAIC guidelines, with enforceable obligations around access management, encryption, employee training, and annual risk assessments.
Most agents have never seen these requirements written out.
Most do not know they apply to their practice.
Medicare, life insurance and health benefits are regulated under HIPAA, and the fines per record exposed have started at $50 and up gone as high as $1.5 MM per incident a year.
If you get hit and get your records exposed, what amount will you pay?
For some people, “reasonable” looks like:
Endpoint Security and Protection
Antivirus
Managed SOC and SIEM
Zero-Cost Remediation
For others, the list might be even longer, requiring additional services:
Email Threat Protection
VPN
Email Encryption
Encrypted Backups
Compliance and Data Breach Support
The best way to know what the right tools are for you is through an assessment. You can get a free assessment here and take the first step to secure your operations.
- Daniel
A Cyber Assessment identifies gaps before they turn into incidents. Get one with our experts. We make it simple for you.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.