Insurance carriers, brokers, MGAs, and third-party administrators handle some of the most sensitive nonpublic personal information (NPI) in the financial services sector — Social Security numbers, driver's license records, health information tied to underwriting, banking and ACH details, claims histories, and beneficiary data. Every retired laptop, underwriting workstation, claims server, and contact-center desktop in an insurance environment is a high-value target, and improper disposal is one of the most commonly cited control failures in state insurance department market-conduct exams.
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, as updated by the FTC in 2021 and effective in 2023, explicitly requires financial institutions — including most insurance entities — to develop, implement, and maintain a written information security program covering the disposal of customer information. The NAIC Insurance Data Security Model Law (Model #668), adopted in a growing number of states including New York's 23 NYCRR 500 framework, layers additional requirements: documented secure-disposal procedures, third-party service-provider oversight, and incident-response readiness for any device that handled NPI.
Phoenix ITAD's insurance program is engineered to satisfy GLBA, NAIC Model #668, 23 NYCRR 500, and HIPAA where health-related underwriting data is involved. Every engagement includes a written confidentiality agreement, NAID AAA certified data destruction, serialized Certificates of Destruction, and reporting formatted directly to the artifacts requested in state insurance department examinations and acquirer audits.