Missouri's insurance data security law, for small agencies
Every Missouri insurance agency, whatever its size, must report a qualifying cybersecurity event to the Department of Commerce and Insurance within four business days. Agencies with 10 or more people also need a written information security program by 1 January 2027. Agencies with fewer than 10 are exempt from the program, not from the report. This is general information, not legal advice.
Download the one-page PDF (US Letter) for your files or your E&O carrier. Section numbers below are from the statute at revisor.mo.gov, checked on 3 October 2026.
The law
The Insurance Data Security Act, RSMo 375.1400 to 375.1427 (2025 H.B. 974), in effect since 1 January 2026 (375.1427). It covers every "licensee": anyone licensed, authorized or registered under Missouri insurance law, so every agency and every producer (375.1402(10)).
What every agency must do, whatever its size
- Investigate promptly if a cybersecurity event has or may have happened, and keep records of every event for at least 3 years (375.1407).
- Report it to the Director of the Department of Commerce and Insurance "as promptly as practicable, but in no event later than four business days" after determining it happened, when either: (a) Missouri is your home state and the event is reasonably likely to materially harm a Missouri consumer or your normal operations; or (b) it involves the nonpublic information of 250 or more Missouri consumers and either must be reported to another regulator or is reasonably likely to cause that harm (375.1410.1). Use DCI's online form, apps.dci.mo.gov/forms/CybersecurityEventNotification (Bulletin 26-01), and update the report as you learn more (375.1410.2).
- Tell affected clients under Missouri's general breach law, "without unreasonable delay", and send the Director a copy of that notice (375.1410.3, 407.1500).
- Vendor events count too. An event in a system run by a vendor that handles your nonpublic information (a "third-party service provider") is treated as your own once you know about it. The four days start the day after the vendor tells you or you otherwise find out, whichever is sooner (375.1410.4).
Not an event: stolen data that was encrypted, if the key wasn't taken too; or data you've confirmed was not used or released and was returned or destroyed (375.1402(3)).
Agencies with 10 or more people
Counting employees and independent contractors, they must also:
- have a written information security program, based on a risk assessment and including an incident response plan (375.1405), by 1 January 2027;
- check their vendors' security (375.1405.6) by 1 January 2028 (375.1427).
Agencies with fewer than 10 people
They are exempt from 375.1405 (375.1417.1(1)), but not from investigating, reporting to the Director or telling clients. An agency that grows to 10 or more has 180 days to comply (375.1417.2).
One unclear line
375.1417.1(4) also lists "Producers that have fewer than fifty employees; less than five million dollars in gross annual revenue; or less than ten million dollars in year-end total assets" as an exception, without saying what they are excepted from. DCI's bulletins don't explain it. Until DCI or your attorney says otherwise, plan as if the four-day report applies to you.
Questions to ask anyone who touches your client data
A VA, an outsourcing firm or an AI tool:
- Where does our client data live, and who can see it?
- What can you do in our systems, and what can't you do?
- Is there a log of what was done, and by whom?
- If something goes wrong on your side, how fast will you tell us? It needs to be well inside our four business days.
- When we stop working together, what happens to our data and our logins?
How Cirlet's AI assistant answers them
- It runs on a computer the agency owns, in its office, with its own logins that the agency controls. The text it works on is sent to the AI model provider, a vendor the agency records like any other.
- It drafts and asks before it sends, submits or spends anything. It never binds coverage or gives advice.
- Every draft and approval is logged.
- Cirlet tells the agency about any incident within 24 hours.
- When the agency leaves, the computer, accounts and setup stay with it.
Sources: RSMo 375.1400 to 375.1427 and RSMo 407.1500 at revisor.mo.gov; DCI Insurance Bulletin 26-01 (5 January 2026).