insuranceagencyvirtualassistant.com

Missouri's insurance data security law, for small agencies

Every Missouri insurance agency, whatever its size, must report a qualifying cybersecurity event to the Department of Commerce and Insurance within four business days. Agencies with 10 or more people also need a written information security program by 1 January 2027. Agencies with fewer than 10 are exempt from the program, not from the report. This is general information, not legal advice.

Download the one-page PDF (US Letter) for your files or your E&O carrier. Section numbers below are from the statute at revisor.mo.gov, checked on 3 October 2026.

The law

The Insurance Data Security Act, RSMo 375.1400 to 375.1427 (2025 H.B. 974), in effect since 1 January 2026 (375.1427). It covers every "licensee": anyone licensed, authorized or registered under Missouri insurance law, so every agency and every producer (375.1402(10)).

What every agency must do, whatever its size

Not an event: stolen data that was encrypted, if the key wasn't taken too; or data you've confirmed was not used or released and was returned or destroyed (375.1402(3)).

Agencies with 10 or more people

Counting employees and independent contractors, they must also:

Agencies with fewer than 10 people

They are exempt from 375.1405 (375.1417.1(1)), but not from investigating, reporting to the Director or telling clients. An agency that grows to 10 or more has 180 days to comply (375.1417.2).

One unclear line

375.1417.1(4) also lists "Producers that have fewer than fifty employees; less than five million dollars in gross annual revenue; or less than ten million dollars in year-end total assets" as an exception, without saying what they are excepted from. DCI's bulletins don't explain it. Until DCI or your attorney says otherwise, plan as if the four-day report applies to you.

Questions to ask anyone who touches your client data

A VA, an outsourcing firm or an AI tool:

  1. Where does our client data live, and who can see it?
  2. What can you do in our systems, and what can't you do?
  3. Is there a log of what was done, and by whom?
  4. If something goes wrong on your side, how fast will you tell us? It needs to be well inside our four business days.
  5. When we stop working together, what happens to our data and our logins?

How Cirlet's AI assistant answers them

  1. It runs on a computer the agency owns, in its office, with its own logins that the agency controls. The text it works on is sent to the AI model provider, a vendor the agency records like any other.
  2. It drafts and asks before it sends, submits or spends anything. It never binds coverage or gives advice.
  3. Every draft and approval is logged.
  4. Cirlet tells the agency about any incident within 24 hours.
  5. When the agency leaves, the computer, accounts and setup stay with it.

Sources: RSMo 375.1400 to 375.1427 and RSMo 407.1500 at revisor.mo.gov; DCI Insurance Bulletin 26-01 (5 January 2026).