By Joseph Boyd, MBA, Founder and Principal Advisor at Infosec CheckLast verified
Direct answer
Virginia's insurance data-security provisions require covered insurance licensees to develop, implement, and maintain a written information security program appropriate to the organization's size, complexity, activities, vendors, and risks. Va. Code 38.2-623 Virginia enacted these provisions in a framework that reflects the NAIC Insurance Data Security Model Law, but Virginia's enacted statute and official guidance control.
The program is not limited to software. It includes governance, access controls, cybersecurity awareness training, vendor oversight, incident response, documentation, and continuing review.
Written by Joseph Boyd, MBA, Founder and Principal Advisor at Infosec Check
Published · Last reviewed
Scope: Virginia insurance data-security provisions and the NAIC Insurance Data Security Model Law framework · Jurisdiction: Commonwealth of Virginia
General educational and informational content. Not legal, insurance, or coverage advice. Requirements depend on your facts, contracts, policy language, and applicable law.
Why this responsibility sits with management
Insurance agencies hold information that can affect a person's finances, identity, health, property, and ability to recover after a loss. That responsibility does not disappear because an agency uses cloud software, outsources technology, or has a small staff.
Many agency leaders know they need cybersecurity, but they are unsure which duties belong to management, the agency's IT provider, a software vendor, an insurance professional, or legal counsel. Infosec Check helps executives understand the governance and insurance-readiness side of that responsibility, beginning with practical cybersecurity awareness training through Ante Up and expanding into regulatory and risk guidance as the agency's needs require.
What Virginia's law requires
Virginia's insurance data-security provisions appear in Title 38.2, Chapter 6, Article 7.1 of the Code of Virginia. The statutory definitions and scope begin with Va. Code 38.2-621.
The law requires a covered licensee to maintain a comprehensive written information security program based on an assessment of the organization's risks. The program must be commensurate with:
- The size and complexity of the licensee
- The nature and scope of its activities
- Its use of third-party service providers
- The sensitivity of the nonpublic information it handles
The program is intended to protect the security and confidentiality of nonpublic information, address reasonably foreseeable threats, restrict unauthorized access, reduce the likelihood of harm to consumers, and establish retention and destruction practices.
Important program components
Virginia's statutory framework addresses several areas that agency leadership should be able to explain and document:
- A designated person, affiliate, or outside vendor responsible for the information security program
- Administrative, technical, and physical safeguards
- Access controls and authentication
- Physical access restrictions where nonpublic information is held
- Protection against destruction, loss, damage, environmental hazards, and technology failure
- Secure disposal procedures
- Awareness of emerging threats and reasonable measures when information is shared
- Cybersecurity awareness training for personnel
- Executive management or board oversight when applicable
- Due diligence in selecting third-party service providers
- Appropriate safeguards required of third-party service providers
- Ongoing monitoring, evaluation, and adjustment
- A written incident-response plan
The statute is risk-based. It does not mean that every agency must purchase the same products, use the same architecture, or follow a one-size-fits-all technology stack.
What happens after a cybersecurity event
Virginia's law also addresses investigation, regulator notice, consumer notice, and record retention. These provisions should not be reduced to a generic statement that an agency must report a breach. The duties depend on the facts, the type of licensee, the information involved, the number of affected Virginia consumers, and other notice obligations.
If a licensee learns that a cybersecurity event has or may have occurred, the licensee or an investigator must conduct a prompt investigation. The investigation must determine, as much as possible, whether an event occurred, its nature and scope, the nonpublic information involved, and reasonable measures to restore the security of compromised information systems. Records concerning cybersecurity events must be maintained for at least five years. Va. Code 38.2-624
Notice to the Commissioner is not a universal three-business-day reporting rule for every agency. Virginia Code 38.2-625 establishes specific conditions, including rules for domestic insurers, Virginia-home-state producers when the event meets applicable thresholds and requirements, events involving 250 or more Virginia consumers, and events that require notice to a government or supervisory body under federal law or another state's law. When the section applies, notice is due as promptly as possible and no later than three business days after the determination. Va. Code 38.2-625
Consumer notice is governed separately. A licensee that maintains consumers' nonpublic information must notify affected consumers without unreasonable delay when the statutory access, acquisition, identity-theft, or fraud conditions are met. Law-enforcement coordination may delay notice in the circumstances described by the statute. Va. Code 38.2-626
Incident-response decisions involving notice, privilege, law enforcement, consumers, regulators, and insurance carriers should be coordinated with qualified counsel and the organization's appropriate technical and insurance professionals. This page does not determine whether a particular event triggers a particular notice duty.
Virginia exceptions are narrow and fact-specific
Virginia provides specific exceptions, including certain HIPAA-covered licensees, certain employees, agents, representatives, or designees who are themselves licensees and are covered by another licensee's program and obligations, and certain licensees affiliated with a depository institution that maintains a qualifying information security program.
These are not a general small-agency exemption. Whether an exception applies depends on the organization's exact status, relationships, program, certifications, and facts. A licensee that ceases to qualify for an exception has 180 days to comply with the article. Va. Code 38.2-629
Annual certification applies differently to insurers
Beginning in 2023 and annually thereafter, each insurer domiciled in Virginia must submit a written compliance certification to the Commissioner by February 15 and retain supporting records for five years. This provision applies to insurers domiciled in the Commonwealth and should not be casually presented as a universal annual certification requirement for every independent producer or agency. Va. Code 38.2-623(H)
Why cybersecurity awareness training comes first
Technology can reduce risk, but people still make decisions involving email, passwords, payment instructions, client information, documents, links, and account access.
Ante Up is Infosec Check's introductory cybersecurity awareness training program. It is designed to help individuals understand practical cybersecurity behavior before an organization moves into more formal governance, compliance, or insurance-readiness work.
Ante Up is not a compliance certification, regulatory determination, legal opinion, employer completion-tracking system, or complete organizational security-awareness program. It is a practical starting point.
For a regulation-by-regulation view of where training obligations appear, see cybersecurity awareness training requirements by regulation.
An IT provider is not the entire information security program
An MSP, MSSP, cybersecurity technician, software provider, or cloud platform may support important safeguards. That technical support is valuable, but it does not automatically establish executive accountability or complete the organization's written information security program.
Management still needs to understand:
- What information the agency holds
- Which systems and vendors have access to it
- Who is responsible for the program
- How employees receive awareness training
- How vendors are evaluated
- What happens if an incident occurs
- Which decisions require legal or insurance input
- What unresolved risks remain
- How the program will be reviewed as the agency changes
Infosec Check does not operate the agency's systems or replace its technical providers. The role is governance, regulatory applicability, executive guidance, and insurance-readiness coordination.
The role of an outside vendor under Virginia's framework
Virginia permits the person responsible for the information security program to be an employee, affiliate, or outside vendor designated to act on behalf of the licensee.
That does not mean an outside advisor assumes every legal duty of the licensee. The agency remains responsible for its own business decisions, representations, vendor relationships, policy requirements, and regulatory obligations. Any engagement should clearly define responsibilities, access, confidentiality, data handling, deliverables, exclusions, and coordination with counsel and technical providers.
Does compliance guarantee cyber-insurance coverage?
No.
A written program does not guarantee that a cyber-liability claim will be covered. Coverage depends on the policy language, representations, conditions, exclusions, security requirements, and facts of the loss.
An agency that cannot explain its security decisions, employee training, vendor oversight, or incident response may face more difficult questions during renewal, examination, or claim review. That is a reason to build a defensible governance process, not a promise that a particular process controls an insurer's decision. Our cyber insurance readiness guide explains what executives are usually asked to show.
What an agency leader should do next
Start with a management-level conversation:
- Identify the information and systems the agency relies upon.
- Determine who is responsible for the information security program.
- Confirm that personnel receive meaningful cybersecurity awareness training.
- Review vendors and service providers with access to nonpublic information.
- Confirm that an incident-response plan exists and can be used under pressure.
- Document unresolved risks and management's response to them.
- Coordinate legal, technical, regulatory, and insurance questions with the appropriate professionals.
- Revisit the program when the agency, technology, vendors, or threat environment changes.
The objective is not paperwork for its own sake. The objective is to create a reasonable and defensible process for protecting the agency, its personnel, its clients, and its ability to operate after a disruptive event.
What Infosec Check does
Infosec Check helps insurance agencies and other regulated businesses understand cybersecurity governance, regulatory applicability, executive accountability, and cyber-insurance readiness.
The work may include education, governance guidance, responsibility mapping, vendor and risk discussions, documentation guidance, insurance-readiness questions, and coordination with the organization's existing professionals. Regulatory duties may exist independently of whether an organization purchases Infosec Check services.
Infosec Check does not replace qualified legal counsel, an MSP, MSSP, managed security provider, software vendor, carrier, broker, forensic investigator, or incident-response firm.
Start with Ante Up
The first practical step for many organizations is cybersecurity awareness training. Ante Up helps individuals begin building better cybersecurity habits before an organization undertakes more formal compliance and governance work.
Frequently asked questions
What is the NAIC Insurance Data Security Model Law?
It is a model framework developed for state insurance cybersecurity and information security requirements. A state model law is not automatically binding everywhere. The state's enacted statute, regulations, official guidance, and effective dates control.
Does Virginia have an insurance-specific cybersecurity law?
Yes. Virginia has insurance data-security requirements in Title 38.2, Chapter 6, Article 7.1 of the Code of Virginia. The provisions establish requirements for covered licensees, including a written information security program and related safeguards. Whether a particular organization is covered depends on its legal status and facts.
Does Virginia require cybersecurity awareness training?
Virginia Code 38.2-623 requires each licensee's information security program to provide personnel with cybersecurity awareness training. The specific program should be appropriate to the organization's size, complexity, activities, and risks.
Does having an MSP mean an agency is compliant?
No. An MSP may support technical safeguards, but management remains responsible for understanding its information security program, assigning responsibility, overseeing vendors, training personnel, and making documented risk decisions.
Does Infosec Check replace an IT provider or lawyer?
No. Infosec Check provides governance, regulatory-applicability, executive, and insurance-readiness guidance. Technical implementation, legal advice, incident legal decisions, forensic work, and insurance coverage determinations belong with the appropriate qualified professionals.
Does the law guarantee that a cyber-insurance claim will be paid?
No. Coverage depends on the policy language, representations, conditions, exclusions, security requirements, and facts of the loss. A governance program may improve preparedness and documentation, but it does not control an insurer's coverage decision.
Where should an agency begin?
Begin with practical cybersecurity awareness training, assignment of responsibility, identification of nonpublic information, a review of vendors and access, and confirmation that an incident-response plan exists. Ante Up is Infosec Check's introductory cybersecurity awareness training starting point.
Legal and educational disclaimer
This page provides general educational information and is not legal advice, an insurance coverage opinion, a compliance certification, or a guarantee of claim payment. Laws, regulations, regulatory interpretations, contracts, and insurance policies may change or apply differently to different organizations. Consult qualified legal counsel, the appropriate regulator, and the organization's insurance and technology professionals regarding a specific situation.
Authoritative sources
- Virginia Code 38.2-621, Definitions
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: Statutory definitions and scope of Virginia's insurance data-security provisions.
- Virginia Code 38.2-622, Private cause of action
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: Statutory treatment of private causes of action under the article.
- Virginia Code 38.2-623, Information security program
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: The written information security program requirement, program components, cybersecurity awareness training, and the annual certification for insurers domiciled in Virginia.
- Virginia Code 38.2-624, Investigation of a cybersecurity event
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: Investigation duties and the five-year record retention requirement.
- Virginia Code 38.2-625, Notice to the Commissioner
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: The conditions under which notice to the Commissioner is required and the three-business-day timeframe when the section applies.
- Virginia Code 38.2-626, Notice to consumers
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: Consumer notice conditions and law-enforcement delay provisions.
- Virginia Code 38.2-629, Exceptions
Issuer: Code of Virginia, Virginia Legislative Information System
Supports: The statutory exceptions and the 180-day period after an exception ceases to apply.
- NAIC Cybersecurity, including Insurance Data Security Model Law #668
Issuer: National Association of Insurance Commissioners
Supports: The NAIC description of the Insurance Data Security Model Law framework.
Primary sources are cited for the specific point noted. They do not determine how a rule, contract, or policy applies to a particular organization.
