Florida Rule 69O-128.032 Explained: What Insurance Agencies Actually Need to Know

Florida's Office of Insurance Regulation (OIR) has raised the bar on cybersecurity for insurance licensees, and Rule 69O-128.032 is at the center of it. If you run an insurance agency in Florida, this rule affects you directly — not just carriers and MGAs. Here's a plain-English breakdown of what it requires and how to actually comply, rather than just check a box.

What the Rule Is About

Rule 69O-128.032 implements Florida's information security requirements for insurance licensees, built on the framework of the NAIC Insurance Data Security Model Law. In short: if you're a licensed insurance entity in Florida — including agencies — you're required to develop, implement, and maintain a written Information Security Program (ISP) that's appropriate for the size and complexity of your business, the sensitivity of the data you handle, and the risks you actually face.

This isn't a suggestion or best-practice guide. It's a regulatory requirement, and the OIR has enforcement authority behind it.

The Core Requirements

At a high level, the rule expects licensees to do four things.

First, conduct a risk assessment. You need to identify reasonably foreseeable internal and external threats to the security, confidentiality, and integrity of nonpublic information — things like client Social Security numbers, financial account details, and health information — and assess the likelihood and potential damage of those threats.

Second, implement safeguards based on that assessment. That typically includes access controls, encryption of nonpublic information in transit and at rest, multi-factor authentication for remote access, employee training, and a written incident response plan.

Third, oversee third-party service providers. If a vendor — like an IT provider, a claims processor, or a software platform — has access to your nonpublic information, you're expected to exercise due diligence in selecting them and to require them to maintain appropriate safeguards.

Fourth, report cybersecurity events. If your agency experiences a qualifying cybersecurity event, the rule sets specific notification timelines to the OIR Commissioner — and missing that window is its own compliance failure, separate from the incident itself.

Where Agencies Get Tripped Up

The most common mistake isn't ignoring the rule entirely — it's treating it as an IT-only problem. An Information Security Program that lives solely in your managed service provider's head, with nothing documented and no executive sign-off, doesn't satisfy the requirement. The rule expects governance: a written program, a designated person or team responsible for it, and regular review as your business and its risks change.

The second common gap is vendor oversight. Agencies often assume that because their IT provider or software vendors are "secure," they've satisfied the third-party requirement. In reality, the rule expects you to have actually evaluated that, documented it, and built it into your vendor contracts where appropriate.

What Compliance Looks Like in Practice

A defensible Information Security Program generally includes a documented risk assessment that's been reviewed within the past year, written policies covering access control, encryption, and data handling, a named individual responsible for the program, MFA enforced on remote access and sensitive systems, an incident response plan that's actually been tested, and a vendor management process that includes security expectations in writing.

None of this needs to be built from scratch with expensive custom tooling. For most agencies, it's a matter of formalizing practices that may already exist informally and closing the gaps a proper risk assessment reveals.

Where to Start

If your agency doesn't have a written Information Security Program today, the right first step is a risk assessment — not a policy template pulled off the internet. The assessment tells you what actually needs to be in the program; the documentation follows from there.

Contact Us

If you're not sure whether your agency's current security practices would hold up under Rule 69O-128.032, Main Event Managed Services can walk through a risk assessment with you and help build an Information Security Program that actually fits your agency. Reach out to get started.

Previous
Previous

Why Your Small Business Needs a Password Manager (Sticky Notes Are Not a Backup Plan)

Next
Next

Cyber Insurance Renewals Are Changing: What Tampa Bay Agencies Need to Know