What you are legally obligated to protect and what happens when something goes wrong.
When you earned your insurance license, the curriculum covered products, markets, and regulations. Nobody explained that collecting client information in the course of normal business creates a legal data protection obligation.
Several states have enacted requirements modeled on NAIC guidelines, with enforceable obligations around access management, encryption, employee training, and annual risk assessments.
Most agents have never seen these requirements written out. Most do not know they apply to their practice.

Medicare, life insurance, and health benefits are regulated under HIPAA, and the fines per record exposed have started at $50 and up gone as high as $1.5 MM per incident.
If you get hit and get your records exposed, what amount will you pay?
For some people, “reasonable” looks like:
For others, the list might be even longer, requiring additional services:
The best way to know what the right tools are for you is through an assessment. You can get a free assessment here and take the first step to secure your operations.
State laws modeled on NAIC guidelines expect agents to manage access, encrypt data, train employees, and assess risk; obligations most agents have never seen written out. A Cyber Assessment is a short review of your agency’s current security controls measured against what regulators and carriers expect, showing exactly where you fall short.