Illinois wrote its own insurance data security law rather than adopting the NAIC’s model law wholesale, which means agencies used to how things work in other states can’t assume the requirements translate directly.
The Illinois-Specific Statute
The Illinois Insurance Data Security Law (215 ILCS 215/) governs how insurers, agents, and other Department of Insurance licensees must protect nonpublic information. It requires covered licensees to develop, implement, and maintain a written information security program, investigate cybersecurity events, and notify the Illinois Department of Insurance when a qualifying event occurs.
Where Illinois Diverges From the NAIC Model
Two differences matter most for smaller agencies. First, the small-business exemption threshold: the NAIC Model Law exempts licensees with fewer than 10 employees from certain program requirements, while Illinois sets a much higher bar at fewer than 50 employees — meaning more small Illinois agencies fall outside the full program mandate than would in a state using the NAIC model directly. Second, notification timelines to the Commissioner differ from the NAIC’s 72-hour standard, so agencies should confirm current Illinois-specific deadlines rather than assuming a number they read about elsewhere applies here.
Exempt Doesn’t Mean Unprotected
Falling under the 50-employee exemption for certain program-building requirements doesn’t mean an agency has no security obligations, and it definitely doesn’t mean the underlying threats disappear. Exempt agencies still handle policyholder nonpublic information and face the same ransomware, business email compromise, and phishing risk as larger licensees. Many agencies build baseline protections regardless of the exemption, both for genuine risk reduction and because carriers and reinsurers increasingly expect it contractually even where the statute doesn’t strictly require it.
What a Real Program Includes
At minimum, a written program should address risk assessment covering how nonpublic information is collected, stored, and transmitted; access controls limiting who can reach sensitive systems; encryption; employee training; incident response procedures; and oversight of third-party vendors who touch the same data. The scale should match the agency’s size and complexity, but the categories apply regardless.
When You’re Required to Notify
A qualifying cybersecurity event — generally unauthorized access to or acquisition of nonpublic information with a reasonable likelihood of harming a consumer or the agency’s own operations — triggers a notification duty to the Department of Insurance. Because Illinois’ specific timeline and thresholds differ from the NAIC model’s 72-hour standard, confirm current requirements with counsel at the time of an actual event rather than relying on generic multi-state guidance you found online.
The Threats Agencies Actually Face
Business email compromise targeting premium payments and claims disbursements, phishing impersonating carriers or policyholders to extract credentials, and ransomware targeting agency management systems are the most frequently reported vectors. Agencies handling both personal and commercial lines are attractive targets because a single breach can expose data across many unrelated policyholder businesses simultaneously.
How CelereTech Helps
CelereTech builds and manages the technical components of an information security program — access controls, encryption, endpoint protection, monitored backups, and incident detection — and helps document the program in a form that supports Illinois compliance. We coordinate with your agency’s compliance counsel or E&O carrier on the legal and reporting requirements specific to insurance licensees.
Get your agency’s security program assessed against Illinois’ actual requirements, not generic multi-state guidance.