Insurance became the cyber-attack and regulatory epicenter of the last two years. New York alone extracted .5 million across ten insurers for exactly the pattern small agencies now build with AI tools: insecure online quoting tools and agent portals. 28 jurisdictions have enacted the NAIC Insurance Data Security Model Law, which reaches agents and brokers, not just carriers.
Free Insurance App Scan → Talk to UsQuote tools, agent portals, and claims intake all touch driver's license numbers, health data, and property information at once. Here is where AI-built insurance apps create regulatory exposure.
Pre-fill features that auto-populate DL numbers and dates of birth from data-broker feeds were the exact vulnerability behind New York's .2 million settlement with eight auto insurers and its earlier .3 million GEICO/Travelers settlement — .5 million combined, all traced to stolen data used for fraudulent unemployment claims.
A single First Notice of Loss record can hold a Social Security number, bodily-injury or disability details, an address, and photos. Aflac's June 2025 breach exposed claims and health information for at least 13.9 million people, and health-line claims data can make an agency a HIPAA business associate on top of everything else.
Landmark Admin, a third-party administrator, exposed 1.61 million records, and AssuranceAmerica, an MGA, was breached through a single phished employee across multiple retail agents' records. The NAIC Model Law makes licensees responsible for overseeing service providers — including whatever platform hosts your AI-built app.
Both the NAIC Model Law and NY DFS require notifying the commissioner within 72 hours of a breach. Healthplex was fined million by NYDFS partly for notifying four months late. AI-built apps typically ship with no logging, so a licensee often can't even tell when that 72-hour clock started.
Insurance leads account for 28% of all TCPA lawsuits, the largest single category, out of roughly 3,200 federal suits filed in 2025. An AI-built lead form without documented, compliant consent is worth to per text or call — American Income Life settled one such case for million.
Lovable's CVE-2025-48757 left 170+ apps with no row-level security, meaning any user could query every policy row in the database. Veracode found 45% of AI-generated code fails security checks, with an 86% failure rate on XSS defenses specifically.
| What you built | Hidden risk |
|---|---|
| Quote / rating tool with pre-fill | Auto-populated DL numbers and DOB from data-broker feeds — the exact NY .5M pattern |
| Agent / producer portal | No MFA by default; a breached portal exposed 116,000 New Yorkers' DL numbers |
| Claims intake / FNOL app | Mixes SSNs with health and property data under a 72-hour notification duty |
| Policyholder self-service dashboard | Missing row-level security lets any anonymous request read entire policyholder tables |
| Lead-gen / comparison-quote site with SMS follow-up | 28% of all TCPA lawsuits come from insurance leads |
| AI chatbot / CSR assistant | Undocumented "shadow AI" adds roughly K to average breach cost |
| Regulation | Triggers when… | Penalty |
|---|---|---|
| NAIC Insurance Data Security Model Law #668 | Any DOI licensee (insurer, agent, broker, MGA) handling nonpublic info; 28 jurisdictions enacted | Varies by state; e.g., CT up to /violation |
| NY DFS Cybersecurity Regulation (23 NYCRR 500) | Insurers, agents, or brokers licensed in NY | Up to /day willful; .3M in DFS penalties 2024–2025 |
| GLBA via NAIC Model #672 | Licensees collecting financial or health info, in every state | Per state insurance code, up to license suspension or revocation |
| CCPA / CPRA | Website, marketing, B2B, or employee data outside the GLBA entity-level exemption | Up to /violation intentional |
| TCPA | Marketing calls or texts to leads without prior express written consent | – per call or text, uncapped class exposure |
| HIPAA (health, dental, disability lines) | Health plans as covered entities; brokers/TPAs handling PHI as business associates | –/violation category |
Yes, in any of the 28 jurisdictions that have enacted it, if you're a licensed insurer, agent, broker, or MGA handling nonpublic information. It requires a written information security program, third-party oversight, and notifying the commissioner within 72 hours of a breach.
The NY AG fined ten auto insurers a combined .5 million across two settlements for quoting tools that auto-populated driver's license numbers and dates of birth from data-broker feeds, which criminals then used for fraudulent unemployment claims. It's the exact pattern many AI-built pre-fill quote tools recreate.
Possibly, if it lacks multi-factor authentication. The breached GEICO/Travelers quoting tool and agent portal had no MFA and exposed 116,000 New Yorkers' driver's license numbers, resulting in an .3 million combined NY AG/DFS settlement.
Yes. NY DFS Part 500 requires it directly, and missing MFA has been cited in multiple settlements, including Healthplex's million penalty. AI app builders don't enforce MFA or session controls by default, so it has to be added and verified separately.
Insurance leads generate 28% of all TCPA lawsuits, the largest category by far. Any automated call or text sent without prior express written consent risks to in statutory damages per message, with no cap on class-action exposure.
We check MFA on agent and producer portals, database access controls on claims and policyholder data, TCPA consent capture on lead-gen forms, your 72-hour breach-notification readiness, and third-party/vendor oversight documentation. You get a plain-English report ranked by risk.
Get a free, no-obligation scan of your agency's app — MFA, database access, and 72-hour readiness, in plain English.
Start With a Free Scan →