Skip to main content

Missouri's HB 974 Insurance Data Security Law: What Small Agencies Must Do Before January 1, 2026

8 min readMike ThriftMike Thrift
Missouri's HB 974 Insurance Data Security Law: What Small Agencies Must Do Before January 1, 2026

If you run a two-person insurance agency out of a strip mall in Springfield or Cape Girardeau, you probably think cybersecurity laws are written for the Allstates and Progressives of the world. Starting January 1, 2026, Missouri law says otherwise. House Bill 974, the state's new Insurance Data Security Act, puts a formal cybersecurity compliance obligation on almost every entity licensed to sell, service, or adjust insurance in Missouri — and the clock is already running.

Missouri isn't inventing something new here. It's adopting a model law that a majority of states have already put on the books, which means agencies operating across state lines may already be under similar rules elsewhere and just didn't realize Missouri was about to join the list. Here's what actually changed, who has to comply, and what a small agency needs to do between now and the deadline.

What HB 974 Actually Does

Missouri Governor Mike Kehoe signed HB 974 on July 2, 2025, making Missouri roughly the 33rd state (plus Puerto Rico) to adopt the National Association of Insurance Commissioners' Insurance Data Security Model Law. The Missouri version takes effect January 1, 2026, and creates the Insurance Data Security Act inside the state's insurance code.

The law applies to any entity that is, or is required to be, licensed, authorized, or registered under Missouri's insurance statutes. That's a broad net: carriers, third-party administrators, managing general agents, and — critically for most readers of this article — independent insurance agencies and individual producers.

This is separate from Missouri's general data breach notification law. Insurance licensees now have to comply with both: the general consumer-notification statute that applies to any Missouri business, and this insurance-specific regime with its own definitions, its own timeline, and its own regulator (the Missouri Department of Commerce and Insurance, rather than the Attorney General).

The Four Things Every Licensee Must Build

Strip away the legal language and HB 974 asks licensees to build four concrete things.

1. A written information security program

The law requires a documented program "tailored to the licensee's size, complexity, and use of third-party providers," built on a documented risk assessment. In practice, that means you can't just buy antivirus software and call it done — you need a written document that identifies what data you hold, what could go wrong, and what safeguards you have in place to prevent it. Administrative, technical, and physical safeguards all have to be addressed: things like access controls, encryption of sensitive data, multi-factor authentication, audit trails, and secure disposal of records you no longer need.

2. Annual risk assessment and testing

A one-time policy binder isn't compliance. The law expects ongoing testing of key controls — periodically confirming that your safeguards still work, not just that they existed when you wrote the policy. For a small shop, this is usually the step that gets skipped, because "annual testing" sounds like something only an IT department has time for. It doesn't have to be elaborate: a documented review of who has access to client files, whether old accounts were deactivated, and whether backups actually restore, done once a year and written down, goes a long way.

3. An incident response plan

Before anything goes wrong, licensees must have a documented plan that spells out who does what during a cybersecurity event — who investigates, who communicates with regulators and affected consumers, and who handles remediation. Writing this down in advance matters because the notification clock, described below, starts ticking the moment you discover an incident. An agency scrambling to figure out its own escalation procedure in the middle of a breach loses precious hours it doesn't have.

4. Vendor oversight

If a third-party vendor — your agency management system, your email provider, a cloud file-storage tool — has access to consumer data and gets breached, that's treated as your incident, not just theirs. HB 974 requires due diligence in selecting vendors and contractual security requirements built into those relationships. Reviewing your vendor contracts for security language before January 1 is a reasonable use of the next several months.

The Notification Clock: Four Business Days

The headline number in HB 974 is speed. Once a licensee discovers a cybersecurity event, it must promptly investigate the scope and impact, and if the event affects 250 or more Missouri consumers or could materially harm Missouri residents or operations, the licensee must notify the Missouri Department of Commerce and Insurance within four business days.

Four business days is fast. Most general state breach-notification laws give businesses 30, 45, or even 60 days to notify affected consumers after discovery. The insurance-specific timeline compresses that dramatically — which is exactly why having an incident response plan already written, rather than improvised, is not optional in any practical sense.

Does a Small Agency Get an Exemption?

The NAIC's model law includes an exemption for licensees with fewer than 10 employees, agents of a licensee, and entities already compliant with HIPAA — but only from Section 4, the information-security-program build-out requirement. States that adopt the model law don't always keep that threshold as written; some have lowered it, some have raised it to 25 employees, and a few have dropped the exemption for agents while keeping it for carriers.

The practical takeaway: don't assume a "small business exemption" protects you without confirming Missouri's specific text applies to your headcount and license type. Even a licensee that qualifies for the Section 4 exemption is still subject to the breach-investigation and notification requirements — the exemption reduces the paperwork burden, it doesn't opt you out of the law. If your agency is close to the line, this is worth a conversation with an insurance-focused attorney or your state agents' association before assuming you're covered.

Why Independent Agencies Are the Ones Most at Risk

Carriers already run mature cybersecurity programs, largely because they've been subject to similar rules in other states for years and because they have the budget for dedicated security staff. The compliance gap opens at the independent agency level — the two- or three-person shop juggling client policies, renewals, and commission statements on a laptop, an agency management system, and a Gmail account.

That's also, unfortunately, where a lot of the actual risk sits. Insurance agencies hold exactly the kind of data attackers want: names, addresses, dates of birth, Social Security numbers, driver's license numbers, sometimes medical information tied to health or life policies, and banking details for premium payments. A single phishing email that compromises an agency's email account can expose client data across dozens of policies at once — and now triggers a four-business-day clock most agencies have never had to run against before.

What to Do Before January 1

  1. Confirm whether your agency is exempt under Missouri's specific employee threshold, and don't assume the general 10-employee NAIC default applies without checking the enacted text.
  2. Inventory what consumer data you actually hold — which systems have it, who can access it, and whether any of it is stored somewhere it doesn't need to be.
  3. Write the information security program, even if it's a few pages long for a small shop. It needs to exist and be tailored to your actual size and setup, not copied wholesale from a carrier's 40-page template.
  4. Draft an incident response plan with names, not just roles — who calls the Department of Commerce and Insurance, who calls affected clients, who calls your errors-and-omissions carrier.
  5. Review vendor contracts for your agency management system, email provider, and any cloud storage tool, and confirm they include security commitments you can point to.
  6. Calendar the annual review. Set a recurring reminder now, so "annual testing" doesn't quietly become "the thing we did once in 2025 and never revisited."

Where Bookkeeping Fits Into Compliance

Data security and financial recordkeeping might seem like separate problems, but for an insurance agency they overlap more than you'd expect. Commission statements, premium trust accounts, and producer 1099s all involve the same client-linked financial data that HB 974 is trying to protect — which means the systems you use to track money are part of your data-security surface area, not separate from it.

Agencies that keep financial records in an opaque, proprietary system often can't answer a basic compliance question quickly: which vendor has access to which financial data, and where does a given number actually come from? Plain-text accounting sidesteps that ambiguity. Every transaction lives in a version-controlled, human-readable ledger file you fully own — no vendor lock-in, no black-box database that becomes its own audit liability if it's ever breached.

Keep Your Financial Records as Transparent as Your Security Program

As your agency builds out the written policies HB 974 requires, it's worth applying the same transparency standard to your books. Beancount.io offers plain-text accounting that gives you complete visibility and control over your financial data — every entry auditable, every change tracked, with none of the opacity that makes vendor incidents harder to investigate. Get started for free and see why finance-minded small businesses are moving to plain-text accounting.

Share this article