Managed IT and Cybersecurity for Columbus Insurance Agencies
Your agency management system holds a full financial profile for every household and business you write: Social Security numbers, dates of birth, driver’s license numbers, bank details, and in benefits work, health information. That book sits behind a handful of logins, a comparative rater, an e-signature tool and a carrier portal for every appointment you hold. Ohio Revised Code Chapter 3965 has been in effect since March 20, 2019, and it is written to reach agents, not only carriers.
What does Ohio Revised Code Chapter 3965 require of your agency?
Ohio adopted a version of the NAIC Insurance Data Security Model Law as Senate Bill 273 of the 132nd General Assembly. It took effect March 20, 2019. The chapter binds a “licensee,” and section 3965.01(M) defines that term broadly: any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered, pursuant to the insurance laws of this state. That is the sentence that puts your agency inside the chapter, and it covers captive and independent agencies alike. This is not a carrier-only law.
One phrase trips agencies up. Section 3965.04 uses a narrower term in one of its reporting triggers: whether “this state is the licensee’s home state, in the case of an independent insurance agent.” Do not read that as the test for everyone. “Independent insurance agent” is a defined term, not a casual one, and section 3965.01(I) takes its meaning from section 3905.49, which turns on how your contract with the carrier is written. A captive or exclusive agency is unlikely to meet it. It is still a licensee either way, and the 250-consumer trigger in section 3965.04(A)(2) applies to every licensee regardless of home state. If which side of that line you sit on matters to you, read the definition or ask us to walk your carrier contract through it.
The core duty in section 3965.02 is a comprehensive written information security program based on your own risk assessment, sized to your agency and to the sensitivity of what you hold. Division (D) is not a menu to browse. It says that based on that risk assessment you determine which of the listed security measures are appropriate, and then implement them.
Those measures include access controls that authenticate and permit access only to authorized individuals; encryption or other appropriate protection of nonpublic information both while it is transmitted over an external network and while it is stored on a laptop computer or other portable computing or storage device or media, which is the full requirement in division (D)(2)(d); restricted physical access; effective controls “which may include multifactor authentication procedures for accessing nonpublic information”; regular testing and monitoring to detect actual and attempted attacks; audit trails; and secure disposal of nonpublic information in any format. Division (D)(5) requires cybersecurity awareness training updated to reflect the risks your assessment identified. Division (H) requires a written incident response plan.
Read the encryption line twice. The half about laptops and portable media is the one that drives a purchasing decision. Division (D)(2)(d) names portable devices and media on their own terms, alongside transmission over an external network, so an agency whose producers carry client files on the road should expect that hardware to be inside the program rather than beside it.
Does the under-twenty-employee exemption get your agency off the hook?
Partly, and less than most owners assume. Section 3965.07(A) exempts a licensee from section 3965.02 if it meets any one of three criteria: fewer than twenty employees, less than five million dollars in gross annual revenue, or less than ten million dollars in assets at the close of its fiscal year. Plenty of Central Ohio agencies clear one of those. But the section 3965.07(A) exemption is written against section 3965.02 and nothing else.
Section 3965.07(C) is a second route out of section 3965.02, shaped differently. It covers a licensee that is an employee, agent, representative, independent contractor or designee of another licensee, and exempts it from section 3965.02 to the extent it is covered by that other licensee’s information security program. Appointed and captive agents running under a carrier’s program should check whether that describes them, and should be able to show which parts of the carrier program actually cover them.
If you write benefits, section 3965.07(B) is a different animal. A licensee that is subject to HIPAA and in compliance with the privacy and security regulations at 45 C.F.R. Parts 160 and 164 is deemed to meet the requirements of this chapter, except those pertaining to notification under section 3965.04, which you still owe. That route carries conditions in the same division: a written statement to the superintendent certifying that compliance, supporting records kept available for examination for five years, and compliance with the requirements of any subsequent amendments to HIPAA within the timeframes those amendments establish. Read section 3965.07(B) before you rely on it, or ask us to check whether your benefits book actually puts you there.
What does your agency have to do after a cybersecurity event?
The duties in sections 3965.03 and 3965.04 survive the exemptions in section 3965.07(A) and (C), because both of those are written against section 3965.02 and nothing else. The HIPAA route in section 3965.07(B) is the one exception worth knowing: it is deemed to satisfy the chapter apart from section 3965.04 notification, which it does not touch.
On learning that a cybersecurity event has or may have occurred, you must conduct a prompt investigation: determine whether an event occurred, assess its nature and scope, identify the nonpublic information involved, and perform or oversee reasonable measures to restore the security of your systems. Section 3965.03(A) lets an outside vendor or service provider designated to act on your behalf do that work, which matters for a small agency with no internal security staff. It does not let the work go undone. If the event happened in a system a third-party service provider maintains, section 3965.03(C) requires you to take those steps or make reasonable efforts to confirm and document that the provider did. You must keep records of all cybersecurity events for at least five years from the date of the event and produce them on the superintendent’s demand.
Notice to the superintendent is due as promptly as possible and no later than three business days after you determine that a cybersecurity event occurred. Whether you owe it turns on either of two tests in section 3965.04(A), and each test pairs a scope condition with a harm condition that both have to be true. One runs on Ohio being your home state as an independent insurance agent. The other runs on nonpublic information relating to 250 or more consumers residing in Ohio. A bare headcount is not the trigger by itself. Read section 3965.04(A), or call us during the event and we will walk it through with you.
The superintendent filing is not the end of it, and this is the step agencies miss. When you owe notice to the superintendent under section 3965.04(A), section 3965.04(C) also requires you to comply with section 1349.19 of the Revised Code as applicable, and to give the superintendent a copy of the notice you send to consumers. Under section 1349.19(B)(2), notice to affected consumers is due in the most expedient time possible and no later than forty-five days following your discovery of the breach or notification of it. Section 1349.19 also carries qualifiers and carve-outs that can change that answer: the deadline is subject to the legitimate needs of law enforcement, and the section does not apply at all to a HIPAA covered entity, which runs HIPAA’s own sixty-day breach notification clock at 45 C.F.R. 164.404. Do not read that onto yourself too quickly: an agency writing benefits is usually a business associate of the plan or carrier rather than a covered entity itself, and the exclusion is written for covered entities. It also does not reach or to certain federally examined financial institutions already required to notify customers. Read the section, or ask us to walk your situation through it.
Watch the two clocks, because they do not start on the same day. The three-business-day superintendent deadline runs from determination. The forty-five-day consumer deadline runs from discovery. An agency can file with the superintendent on time and still blow the consumer deadline, and still fail to send the superintendent the required copy. None of this is waived by the section 3965.07(A) exemption.
One more threshold rides along with section 1349.19. If a breach requires you to notify more than one thousand Ohio residents in a single occurrence, section 1349.19(G) requires you to also notify all nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution and content of the notices sent to residents. That step may not be used to delay the forty-five-day resident deadline. One thousand is the highest count on this page rather than the first line you cross — consumer notice under section 1349.19 can be owed over a single affected Ohio resident, and 250 Ohio consumers can put you in front of the superintendent — but an agency with a large book crosses one thousand easily, so plan for the step instead of discovering it mid-week.
Section 3965.11 directs the superintendent to consider the nature, scale and complexity of licensees, so a small agency is measured as a small agency. But none of these duties are achievable without logging, retained backups and written procedure you put in place before the bad week.
Why do attackers go after insurance agencies specifically?
Because you aggregate. One agency file carries what an attacker needs for identity theft, account takeover and follow-on fraud, and your book concentrates hundreds or thousands of those files in one system. On June 16, 2025, John Hultquist, chief analyst at Google’s Threat Intelligence Group, warned that the crew tracked as Scattered Spider had turned to the US insurance sector after a run at retail, and said the industry should be on high alert “especially for social engineering schemes which target their help desks and call centers.”
That is the realistic shape of the threat. Not an exotic exploit, but a convincing caller talking someone into a password reset or a fresh MFA enrollment, a lookalike domain on a renewal thread, or a carrier portal password reused from a personal account. The countermeasures are unglamorous and they work: phishing-resistant multifactor authentication, a verification script your staff follows before any credential change, conditional access on email and the agency management system, and alerting that catches a sign-in from a place your team has never worked.
How do the third-party rules apply when your whole agency runs on someone else’s software?
Section 3965.02(F) requires a licensee to exercise due diligence in selecting its third-party service provider, and to require that provider to implement appropriate administrative, technical and physical measures to protect the information systems and nonpublic information accessible to or held by it. Note where that division sits. It is inside section 3965.02, so an agency exempt under section 3965.07(A) is not bound by it as a matter of statute.
The duty that survives that exemption is section 3965.03(C). For any event on a provider’s systems, you must take the division (B) investigation steps yourself or make reasonable efforts to confirm and document that the provider took them. You cannot confirm and document what a vendor did if you never established what the vendor was supposed to do. Vendor diligence is the practical way to meet that duty either way. For an agency that means the management system, the rater, the e-signature platform, the document repository, cloud email and every carrier portal belong inside your planning, not outside it.
In practice that is an inventory of every vendor touching client data, evidence you assessed each one before signing, contract language that obliges them, and a named owner who reviews it on a schedule. TTS Cyber’s Virtual CISO and IT Strategy work is built to produce that record, and managed IT and cloud services keep the accounts, devices and backups in a state where the record is true. If you want a defensible starting point, the Security Analysis at https://outreach.ttscyber.com/analysis is a $349 independent assessment mapped to 38 compliance frameworks that tells you where your agency actually stands. You pay for it because it is a diagnostic rather than a sales call, and the findings are yours either way.
Start here
Find out where you actually stand
The Security Analysis is a fixed-scope review of your environment, run independently and mapped to 38 compliance frameworks. It is the fastest way to replace an assumption about your posture with a finding.
Questions we get asked
Does the February 15 certification filing apply to our agency?
Not the one in section 3965.02(I)(1). That division sets a February 15 annual deadline for a written statement certifying compliance, and it is written for each insurer domiciled in this state. Division (I)(2) gives an insurer domiciled here and licensed exclusively to do business in Ohio an alternative: certify as part of its corporate governance annual disclosure under section 3901.073, which is a June 1 filing. Either way it is a carrier obligation. An Ohio agency or agent is a licensee under section 3965.01(M), so the security program, investigation and notification duties reach you, but that annual certification does not. Do not read the absence of that filing deadline as an absence of duty. And note one separate filing that can apply to you: if you rely on the HIPAA route in section 3965.07(B), that route only works if you submit a written statement to the superintendent certifying your compliance with 45 C.F.R. Parts 160 and 164 and keep supporting records for five years.
Is there anything to gain from compliance beyond staying out of trouble with the department?
Yes, and Ohio put it in the statute. Section 3965.08 gives a licensee that satisfies the provisions of the chapter an affirmative defense to any cause of action sounding in tort brought under Ohio law or in Ohio courts alleging that a failure to implement reasonable information security controls resulted in a data breach concerning nonpublic information, and it does not limit any other affirmative defense available to you. That defense runs on evidence. A risk assessment with a date on it, a written program, training records and incident logs are what turn compliance into something your attorney can hold up.
Our agency is about to pass twenty employees. How long do we have to build the program?
Section 3965.07(D) gives a licensee that ceases to qualify for an exemption one hundred eighty days from the date it ceases to qualify to come into compliance. That is enough time to do it properly and not much more, because the risk assessment has to come first and every control in section 3965.02 is scaled to it. Start with the assessment, then multifactor authentication on email and the agency management system, encryption on every laptop and portable drive that leaves the office, no shared logins, an offboarding checklist that truly kills carrier portal access, and backups you have restored from at least once.