Landmark Admin — a Texas-based TPA — suffered ransomware in October 2024 that exposed 800,000+ claimant records: SSNs, policy numbers, health conditions, and financial data in a single breach. Globe Life's data exposure earlier that year put investor scrutiny and TDI enforcement on the entire sector. Texas insurance entities face TIC Chapter 601 compliance (the NAIC Model Law), TDI 72-hour cybersecurity event reporting, GLBA Safeguards Rule, HIPAA for health lines, TDPSA consumer data obligations, and SOC 2 requirements from carrier vendor programs. CoreRecon delivers NAIC Model Law-mapped SOC, claims-data DLP, BEC defense for premium and claim wire workflows, and 30-min incident response SLA — at $89–$129/endpoint.
Texas insurance entities operate under more regulatory layers than most sectors realize. TIC Chapter 601 is just the floor — carriers handling health lines face HIPAA, fintech-adjacent MGAs face GLBA, any entity collecting consumer data faces TDPSA, and carrier vendor programs require SOC 2. Here is the full compliance stack mapped to CoreRecon coverage.
| Framework | Who's in Scope | Key Requirements | Penalty / Consequence | CoreRecon Coverage |
|---|---|---|---|---|
| NAIC Model Law — Texas Insurance Code Chapter 601 | All Texas-licensed insurers, agents, MGAs, surplus lines licensees, and TPAs that access, maintain, or transmit nonpublic personal information of policyholders or claimants | Written information security program (WISP); designated Information Security Coordinator; annual risk assessment; third-party vendor oversight and contractual security requirements; incident response plan; cybersecurity event reporting to TDI within 72 hours; board/senior management oversight; annual reporting to board of directors | License action (suspension or revocation); TDI enforcement orders and administrative penalties; failure to report timely creates standalone regulatory exposure separate from underlying breach. Reputational damage in TDI examination process | Sentinel WISP development, security coordinator function, annual risk assessment. Fortress Third-party vendor security oversight, IRP development and annual testing, TDI 72-hour notification runbook. Command Board-level reporting, NAIC Model Law gap assessment, full audit evidence package |
| GLBA Safeguards Rule (FTC) | All insurance entities that qualify as "financial institutions" under GLBA: insurers, agents, premium finance companies, and entities that provide financial products or services to consumers. Amended 2023 requirements apply | Written information security program; designated qualified individual; annual risk assessment; encryption of customer information in transit and at rest; MFA for systems with customer data; continuous monitoring or annual penetration testing; incident response plan; 30-day breach notification to FTC (500+ customers). 2023 amendments added encryption, MFA, and access controls as explicit requirements | FTC enforcement; civil penalties up to $100K per violation per day for entities; criminal penalties for officers. No private right of action, but state AGs may enforce on FTC's behalf. Texas AG has active GLBA enforcement posture | Sentinel Encryption enforcement, MFA deployment, continuous monitoring. Fortress Penetration testing annually, access log review, qualified individual function, FTC 30-day notification workflow |
| HIPAA Security Rule & Breach Notification | Health insurance carriers (Covered Entities); TPAs and service providers handling PHI on behalf of health carriers (Business Associates). Dental carriers, vision carriers, life carriers with accelerated death benefit riders tied to health conditions | HIPAA Security Rule: administrative, physical, and technical safeguards for electronic PHI (ePHI); risk analysis; access controls; audit logging; transmission security. Breach Notification Rule: notification to HHS/OCR within 60 days for 500+ individual breaches; immediate state attorney general notification in some cases; annual summary for sub-500 breaches | OCR penalties: $100–$50,000 per violation per category, up to $1.9M annually per violation category. Wall of Shame (HHS breach portal) for 500+ record breaches is a permanent public record and creates reputational harm. Texas AG may bring enforcement under state law. Class action exposure for large breaches | Fortress ePHI-aware DLP, access control enforcement, HIPAA Security Rule audit logging, dual-clock incident management (HIPAA + TIC 601 simultaneous clocks). Command OCR breach notification workflow, annual HIPAA risk analysis, BAA review for TPAs |
| Texas Data Privacy and Security Act (TDPSA — Tex. Bus. & Com. Code Ch. 541) | Insurance entities that process personal data of Texas consumers above statutory thresholds: 100K+ data subjects annually, or 25K+ data subjects if data is sold or revenue derived from processing. Practically all carriers, large MGAs, and TPAs meet thresholds | Consumer rights: access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling; privacy notice obligations; sensitive data consent (health conditions, financial data, precise geolocation); Data Protection Assessments for high-risk processing; controller-processor contracts; data minimization; reasonable security; universal opt-out/GPC recognition (§541.056, effective Jan 1, 2025) | Texas AG enforcement only; civil penalties up to $7,500 per violation (higher for intentional or knowing violations). Cure period for non-intentional violations. No private right of action. Insurance entities process high-sensitivity data categories that trigger mandatory DPAs and consent obligations | Fortress TDPSA-relevant data mapping, privacy notice alignment, sensitive data handling controls. Use TDPSA Readiness Quiz → |
| TDI Cybersecurity Event Reporting (TIC §601.052) | All entities subject to TIC Chapter 601; carriers and large agencies must additionally notify TDI when a cybersecurity event involves 250+ Texas residents' nonpublic personal information | 72-hour notification to TDI upon determining a cybersecurity event has occurred; notification must include: nature of event, data categories affected, estimated affected individual count, initial response steps taken. Post-incident: updated notification as investigation develops; cooperation with TDI examinations | Late or deficient notification is an independent regulatory violation from the underlying breach. TDI examiners now specifically inquire about cybersecurity programs during market conduct exams. Failure to notify timely creates multiplied penalty exposure | Command Pre-built TDI 72-hour notification runbook, analyst-assisted timeline documentation, templated TDI disclosure forms, post-incident examination support |
| SOC 2 Type II (Carrier Vendor Requirements) | MGAs, TPAs, insurtech platforms, and service providers whose carrier appointments require SOC 2 Type II certification as a vendor security condition. Increasingly standard for any entity handling carrier systems or policyholder data | Trust Services Criteria evaluation over 12-month observation period: Security (CC series), Availability, Processing Integrity, Confidentiality, Privacy. Requires continuous monitoring, access control logging, incident response, change management, and vendor management evidence | Loss of carrier appointment or agency contract; inability to expand market access; competitive disadvantage in E&S and specialty lines where sophisticated counterparties require SOC 2. Not a regulatory mandate, but a commercial condition | Fortress Continuous monitoring evidence, access logging, IRP documentation — the evidentiary foundation for a clean SOC 2 Type II audit. Formatted evidence packages provided for your auditor's Type II observation period |
Insurance companies carry the most valuable data combination in any sector: PII, PHI (health lines), financial records, and claims data — all in one system. That creates a uniquely attractive target for ransomware, BEC, and account takeover. Here are the five threat patterns CoreRecon is positioned to detect and contain.
Globe Life, Inc. (McKinney, Texas) disclosed in 2024 that it had received a communication claiming access to consumer and policyholder data. The subsequent investigation and disclosure triggered investor scrutiny, regulatory inquiry, and significant reputational damage to one of Texas's largest publicly traded insurers. While the full TDI enforcement picture remains ongoing, the Globe Life timeline demonstrates how data exposure events in the insurance sector cascade: investor calls, regulatory examinations, third-party litigation exposure, and sustained reputational harm in a sector where trust is the product.
The operational lesson: Insurance entities cannot absorb a breach quietly. TIC Chapter 601 makes non-disclosure a regulatory violation. The question is not whether to report — it's whether you have the detection capability to know a breach occurred within 72 hours, and the response program to satisfy TDI's examination requirements afterward. CoreRecon provides both.
Texas is the second-largest insurance market in the United States. The Dallas-Plano-Frisco corridor alone hosts Globe Life HQ (McKinney), USAA satellite offices (Plano/Irving), Higginbotham HQ (Fort Worth), and hundreds of MGA and specialty broker operations. Houston hosts energy-line specialty carriers, Lloyd's of London syndicates, and E&S capacity for Texas's outsized energy sector risk. TDI is one of the most active state regulators in the US.
Standard MSSPs monitor Windows events and EDR. Insurance requires claims-aware DLP, producer portal anomaly detection, BEC playbooks tuned to premium and claim wire workflows, and regulatory runbooks that activate the moment an incident is detected. Here's what each tier includes.
10-endpoint minimum. Month-to-month. Designed for retail agencies and small MGAs without dedicated security staff — and scaled to full TIC Chapter 601 + HIPAA + SOC 2 requirements for carriers and TPAs handling 100K+ claimant records. Use the breach cost calculator to model your specific risk exposure.
Pricing is per staff and admin endpoint. Claims system server monitoring and producer portal integration are scoped separately during the free assessment. See full pricing page → for endpoint slider and total cost modeling. SDVOSB contracting available for federally-related insurance work.
Yes. Texas Insurance Code Chapter 601 applies to all licensees — not just carriers. That includes individual agents, agencies, MGAs, surplus lines licensees, and TPAs that access, maintain, or transmit nonpublic personal information (NPPI) of policyholders or claimants. The compliance obligation scales with the size and complexity of the entity — a small agency with fewer than 10 employees and no revenue from services is exempt, but any entity of meaningful size that handles customer data is in scope.
The core obligations apply to all in-scope licensees: a written information security program appropriate to the size, complexity, and activities of the licensee; designation of a security coordinator; annual risk assessment; and incident response plan. The 72-hour TDI reporting obligation applies when a cybersecurity event involves 250+ Texas residents' NPPI. CoreRecon's Sentinel tier handles these requirements for retail agencies and small brokers at $89/endpoint/month.
TIC Chapter 601 requires that you have a contractual right to audit and review your TPA's security program, and that your TPA maintains security controls appropriate to the sensitivity of the data they access on your behalf. When your TPA is breached, you are responsible for the regulatory response — including TDI 72-hour notification if the breach involves 250+ Texas residents' NPPI.
The 72-hour clock starts when you determine that a cybersecurity event has occurred — not when your TPA tells you, and not when the investigation is complete. This means you need independent detection capability, not just reliance on your TPA's incident disclosure. CoreRecon Fortress and Command tiers include third-party vendor security oversight documentation and carrier-side monitoring that doesn't depend on the TPA's own alerting.
Carriers should also maintain a vendor security inventory that documents which TPAs have access to which data categories, the contractual security requirements imposed, and annual review evidence — all of which TDI examiners now request under Chapter 601.
HIPAA applies specifically to health plans, health care clearinghouses, and health care providers — and to Business Associates that handle PHI on their behalf. For insurance purposes, HIPAA directly applies to:
Property-casualty carriers generally are not Covered Entities — but if they handle workers' compensation claims that include medical records, the HIPAA analysis gets more nuanced. CoreRecon performs a HIPAA applicability assessment during onboarding for any insurance entity that handles health-related data.
The FTC Safeguards Rule (16 C.F.R. Part 314) applies to "financial institutions" under GLBA, which includes insurance companies that provide financial products or services to consumers. The amended 2023 Safeguards Rule (effective June 9, 2023) added specific technical requirements that many insurance entities haven't yet implemented:
These requirements are not new conceptually — but the 2023 amendments made MFA and encryption explicit requirements rather than implicit best practices. CoreRecon Sentinel tier handles MFA enforcement, encryption, and continuous monitoring. Fortress tier adds the penetration testing documentation and FTC breach notification workflow.
SOC 2 Type II certification requires demonstrating that your security controls operated effectively over a 12-month observation period. The auditor reviews evidence of continuous monitoring, access logging, incident response, change management, and vendor management throughout the observation period — not just a point-in-time snapshot.
CoreRecon Fortress tier provides the operational foundation: 24/7 continuous monitoring with full logging retention, access control review and documentation, documented incident response for any security events during the period, and change management logging. We generate formatted evidence packages aligned to the SOC 2 Trust Services Criteria (CC series) for your auditor's review.
CoreRecon works alongside your SOC 2 auditor — we don't perform the audit ourselves. What we provide is the operational program that the auditor evaluates, plus the evidentiary documentation that makes the Type II observation period straightforward rather than a scramble to reconstruct. Command tier includes a dedicated compliance manager who coordinates with your auditor directly.
CoreRecon's insurance assessment maps your claims-data attack surface, reviews your NAIC Model Law compliance program, evaluates producer portal security, analyzes your BEC exposure on premium and claim wire workflows, and assesses your TPA vendor oversight documentation. No credit card. No commitment. Delivered in 14 days.
Request your free $2,500 assessment →Delivered within 14 days • TIC Chapter 601 gap review included • SDVOSB-certified team • No commitment