State insurance data security laws · NAIC Model #668 · HIPAA §164.308(a)(7)

72 hours to notify. Longer than that to explain why you couldn't.

More than half the states have now enacted insurance data security laws built on the NAIC model — and if you're licensed in several, the strictest version is effectively your program. The clock starts when you determine a cybersecurity event has occurred, not when you've contained it. Most plans can respond. Fewer can prove when they knew, who decided, and what they did next.

Sound familiar?

The obligations don't scale down with your headcount.

Your incident response plan is a document, not a decision structure

The model law is unusually specific about what an incident response (IR) plan must contain: defined internal processes, named roles and responsibilities — who can authorize taking a system offline, who communicates with the public, who informs executive management. Most plans name a team. Few answer those questions under pressure, at 2 a.m., without improvising.

You're licensed in more than one state

The core obligations are consistent across adopting states; the thresholds, timelines and exemptions are not. In practice, a multi-state licensee complies with the most restrictive version it's subject to — which means maintaining one program against a moving patchwork.

Your biggest exposure may not be your own systems

Change Healthcare wasn't a breach of a health plan — it was a breach of something health plans depended on, and it stopped claims, eligibility and payment across the industry. Third-party service provider oversight is a named obligation now, not diligence you did once at onboarding.

The stakes

The clock doesn't wait for your org chart.

In February 2024, Change Healthcare went down and took much of the payment infrastructure of American healthcare with it — 192.7 million people affected and billions in industry impact, with providers unable to submit claims or verify eligibility for weeks.

For every plan watching, the question wasn't only "could this happen to us." It was: if it did, who here decides it's a reportable event — and could we prove, afterward, exactly when we knew?

Obligation → capability

What you're accountable for, and where Resilis meets it.

What you're accountable for What a regulator expects to see What Resilis offers
Written information security program (WISP) A program proportionate to your size and complexity, maintained and exercised — not a document written once A living program tied to your actual operations — with scenario-based tabletop exercises you can run against it, each producing a dated record
Incident response plan — with prescribed content Defined internal processes: who, what and when. Named roles and authorities — including who can take a system offline, who speaks externally, who informs executive management Roles, authorities and escalation defined in advance — plus generated reflex cards: one-page action aids per role and scenario, so each responder has a direct answer to "what do I do right now"
72-hour notification to your insurance commissioner, from determination A defensible record of when you determined an event occurred and when notice went out A timestamped determination log — the moment the clock started, recorded as it happens rather than reconstructed
Annual risk assessment Evidence the assessment happened and drove something Assessment findings tracked to remediation and closure, with dates and owners
Third-party service provider oversight Due diligence and ongoing monitoring, with evidence A dependency and vendor map where each critical provider carries its own oversight evidence — available on demand
Evaluate and revise following an event A documented post-event review that improved the program After-action findings captured and turned into suggested plan updates — surfaced for your team's review and validation. Nothing changes without human sign-off
HIPAA §164.308(a)(7) — contingency plan, as a covered entity Data backup, disaster recovery and emergency mode operation plans — all three Required Emergency mode procedures maintained and tested in the same cycle as the rest of the program

Abbreviations: NAIC — National Association of Insurance Commissioners; HIPAA — Health Insurance Portability and Accountability Act; WISP — written information security program; IR — incident response.

State adoptions vary in thresholds, timelines and exemptions — see the NAIC state adoption map and state-by-state citations. Resilis holds one program against the strictest applicable version rather than one per state.

Binder vs. living system

A plan that names a team, or one that decides under pressure.

Before

  • One IR plan document, last revised at the previous audit.
  • The multi-state requirements matrix lives in a spreadsheet one person maintains.
  • Determination happens on a call. Nobody writes down when.
  • Vendor oversight was diligence at onboarding and a questionnaire since.
  • The post-event review happens — and changes nothing in the plan.

With Resilis

  • The plan is a decision structure with named authorities — and reflex cards in responders' hands.
  • One program, held against the strictest state requirement you're subject to.
  • The determination is timestamped as it's made — your clock, provable.
  • Each critical vendor carries live oversight evidence.
  • After-action findings become suggested updates, validated by your team before anything changes.
Trust

No protected health information. By design.

No PHI. By design.

Resilis coordinates your response — it does not hold member records. The platform works from system dependencies, recovery objectives, and aggregate impact figures. Not clinical data, not identifiers. Bringing Resilis in doesn't widen the surface your privacy and security teams have to defend.

And we'll sign a BAA anyway

Where your contracting requires it, we execute a Business Associate Agreement.

Security posture, stated plainly

Infrastructure certified to ISO 27001 and PCI-DSS. SOC 2 is underway — the controls are in place today; the report formalizes what US buyers expect. If HITRUST is a requirement in your vendor program, tell us early and we'll discuss it honestly rather than imply we have it. Hosting and residency are addressed at onboarding: US-region hosting for US clients.

ISO 27001 PCI-DSS SOC 2 · underway

Priced for regional plans

The enterprise resilience platforms are built and priced for national carriers. The obligations don't scale down. The price should.

Who's behind it

Regulated-industry discipline, real crisis experience, and health data.

Julien Puaux spent a decade on crisis assignments for major institutions and served on the emergency desk at Médecins Sans Frontières (MSF). Hugues Lajoie ran operational risk and business continuity inside a regulated bank, then led Deeplink Medical as Chief Executive Officer, building health technology certified as a medical device. Alongside them, the independent advisors who support Resilis's US expansion bring years inside the Chief Operating Officer (COO) offices of regulated financial institutions — running regulatory change and remediation, and assembling the evidence when an examiner or auditor arrived.

Regulated-industry operating discipline, real crisis experience, and health data. The tooling reflects all three.

Twenty minutes on what your commissioner would actually ask.

Your first conversation isn't with an SDR — it's with an independent advisor who works alongside Resilis on its US expansion. It's a working session, not a pitch: we map where your program stands, where the evidence may be thin, what wouldn't hold up if your commissioner asked, and how your team would actually run the response if it happened tomorrow.

Book a 20-minute review