1-844-366-6700

Insurance agencies run on email. Policy documents, claims correspondence, premium payment details, and carrier communications all move through the inbox every day, and most of it qualifies as nonpublic personal information under state and federal law. That combination, high message volume plus high-sensitivity data, makes an email platform migration a very different project for an insurance agency than it is for a typical small business.

Move a mailbox carelessly and you’re not just risking a bounced email. You’re risking a reportable cybersecurity event under a state insurance data security law, a lapsed carrier appointment, or a wire transfer sent to a fraudster impersonating a client. This guide walks through what independent agencies and brokerages need to know before switching between Microsoft 365 and Google Workspace, or moving off a legacy hosted email system, without creating a compliance or security gap along the way.

Why Insurance Agencies Face a Different Migration Calculus

Three things set insurance agencies apart from most other small businesses migrating email:

Regulatory exposure is now standardized across most states. The NAIC Insurance Data Security Model Law (MDL-668) has been adopted in some form by at least 28 jurisdictions as of early 2026, and agencies operating across state lines have to satisfy the most restrictive version of the law among every state where they hold an appointment or license. That means a written information security program, an annual risk assessment, and a breach notification clock, typically 72 hours from discovery, are not optional extras. They’re baseline requirements that your email environment has to support before, during, and after a migration.

You don’t control your own tech stack in isolation. Agency management systems like AMS360, Applied Epic, EZLynx, and HawkSoft sync contacts, attachments, and communication history with your email platform, and carrier portals like IVANS Exchange often assume a specific email configuration. A migration that breaks that sync doesn’t just create an inconvenience; it can interrupt certificate issuance, renewal notices, and carrier download connections.

Premium fraud and impersonation scams target the exact workflow email migration touches. Business email compromise schemes that redirect premium payments or client funds follow the same playbook seen in real estate and title fraud: attackers monitor a mailbox, then send a spoofed payment instruction at the moment of highest trust. Our real estate agency migration guide covers the wire-fraud mechanics in detail; the same risk window opens for insurance agencies handling premium finance payments and claims settlements.

The Compliance Landscape: What Your Email Platform Needs to Support

NAIC Model Law (MDL-668)

Under the Model Law, licensees, which generally includes agencies, agents, brokers, and public adjusters, must maintain a written information security program appropriate to their size and complexity, encrypt nonpublic information in transit and at rest, and be able to investigate and report cybersecurity events on a defined timeline. The NAIC’s 2026 regulatory agenda has also begun extending the law’s reach into AI governance and third-party vendor management, which means the vendors touching your email environment, including your migration provider, fall under the same scrutiny as your internal systems.

Practically, this means your new email platform needs, at minimum:

  • Encryption for data in transit and at rest (both Microsoft 365 and Google Workspace support this natively on business-tier plans)
  • Multi-factor authentication enforced agency-wide
  • Audit logging sufficient to support a breach investigation
  • A documented data retention and disposal policy that survives the platform switch

GLBA Safeguards Rule

Because insurance is regulated at the state level, the FTC’s Safeguards Rule generally defers to state insurance departments for enforcement rather than applying directly, but the underlying GLBA obligation to protect consumers’ nonpublic personal information still runs through state insurance regulators, who are responsible for enforcement through their own state laws. In practice, most state versions of the NAIC Model Law mirror the Safeguards Rule’s administrative, technical, and physical safeguard requirements closely enough that agencies should treat them as functionally equivalent.

Carrier Appointment Requirements

Beyond regulators, your carriers set their own bar. Major carriers increasingly condition agency appointments on demonstrated cybersecurity controls, including MFA, endpoint detection, and a documented incident response plan. A poorly executed migration that leaves MFA misconfigured or disables logging even temporarily can put appointment renewals at risk, independent of any regulatory exposure.

Microsoft 365 vs. Google Workspace for Insurance Agencies

Both platforms meet the baseline compliance requirements above on their business and enterprise tiers. The deciding factor for most agencies comes down to how well the platform integrates with the agency management system and carrier tools already running the business.

Factor Microsoft 365 Google Workspace
AMS integration Deepest native support; most major AMS platforms (AMS360, Applied Epic, EZLynx) build first for Outlook contact, calendar, and attachment sync Generally requires middleware or manual workarounds for deep AMS sync
ACORD form handling Strong, since most agencies still work in Word/Excel-based ACORD templates Workable via Google Docs/Sheets converters, but adds friction
Carrier portal compatibility Broadest compatibility; most carrier download tools were built assuming an Exchange/Outlook environment Improving, but still the less common configuration among agencies
Compliance/eDiscovery tooling Microsoft Purview offers granular retention, legal hold, and audit tools well-suited to state DOI recordkeeping requirements Google Vault covers the basics but with less regulatory-specific tooling
Cost (per user/month, 2026) Business Basic ~$6, Business Standard ~$12.50, Business Premium ~$22 Business Starter ~$7, Business Standard ~$14, Business Plus ~$22
Best fit Agencies on AMS360 or Applied Epic, or with heavy carrier portal dependencies Agencies that are Google-native already, or smaller shops with lighter AMS integration needs

For a full platform-by-platform breakdown outside the insurance context, see our Microsoft 365 vs. Google Workspace comparison.

In our experience, the majority of independent agencies land on Microsoft 365, largely because agency management systems overwhelmingly build their tightest integrations around Outlook for contact syncing, attachment access, and calendar coordination. Agencies on EZLynx or a lighter-weight AMS have more flexibility, since EZLynx’s own integration ecosystem is less tightly coupled to a single email platform.

Security Risks During Migration

Insurance agencies are attractive targets because a single compromised mailbox can expose policy numbers, Social Security numbers, payment records, and claims histories all at once, and a migration window is exactly when attackers look for gaps. A few risks specific to this industry:

Premium payment redirection fraud. Attackers who gain visibility into a mailbox during migration can time a spoofed payment instruction to a client who’s expecting a legitimate premium invoice. The financial fraud playbook has cost companies billions globally through impersonation schemes that trick organizations into redirecting funds to fraudulent accounts, and insurance agencies handling premium finance are a natural target.

Carrier impersonation. A spoofed email appearing to come from a carrier or MGA, requesting updated banking details or login credentials, is a common variant that specifically exploits the high volume of legitimate carrier correspondence agencies receive.

Vendor and third-party exposure. Since MDL-668 makes clear that agencies can’t outsource their liability for vendor security, any migration provider or AMS integration partner touching your email data during the transition needs contractual security commitments in place before the project starts, not after.

For broader phishing and BEC context across small businesses, see our email phishing and security statistics guide.

Step-by-Step Migration Framework for Insurance Agencies

1. Pre-Migration Compliance and Discovery

Before touching a single mailbox, document your current data map: which mailboxes contain nonpublic personal information, which are shared or resource mailboxes tied to specific carrier relationships, and which archived mailboxes from former employees need to carry over for recordkeeping. Confirm your state DOI’s specific retention requirements, since some states mandate longer retention for claims-related correspondence than general business email.

2. AMS and Carrier Portal Inventory

Map every system that syncs with your current email platform: your AMS (AMS360, Applied Epic, EZLynx, HawkSoft, or another), IVANS Exchange or other carrier download connections, e-signature tools, and any comparative rater. Contact your AMS vendor before migration day to confirm the correct sequence for repointing integrations to the new platform, since most AMS platforms sync contacts and attachments through a live connection that will break if the email platform changes without reconfiguration.

3. Security Configuration First, Migration Second

Configure MFA, conditional access policies, and audit logging in the destination platform before migrating a single mailbox, not after. This closes the gap attackers look for during transition windows and keeps you continuously compliant with NAIC Model Law safeguards rather than exposed during the switch.

4. Staged or Cutover Migration

Most independent agencies with fewer than 50 users are well-suited to a cutover migration completed over a weekend. Larger multi-location agencies, or those with complex carrier integrations, often benefit from a staged approach that migrates one office or department at a time to limit the blast radius of any integration issue. Our detailed cutover vs. staged migration comparison covers the tradeoffs in more depth.

5. Reconnect AMS and Carrier Integrations

Immediately after cutover, reconnect and test every AMS sync point and carrier portal connection. Verify that contact sync, attachment access, and calendar integration are functioning correctly, and confirm IVANS Exchange or other carrier download connections are authenticated against the new platform.

6. Validate and Document

Confirm zero data loss across mailboxes, test MFA and security policies, and document the completed migration as part of your information security program’s ongoing recordkeeping. This documentation matters if a state DOI or carrier ever requests evidence of your security controls.

For platform-specific walkthroughs, see our step-by-step guides: migrating from Google Workspace to Microsoft 365 or migrating from Microsoft 365 to Google Workspace.

Frequently Asked Questions

Does the NAIC Model Law require a specific email platform? No. The Model Law is platform-agnostic. It requires administrative, technical, and physical safeguards, which both Microsoft 365 and Google Workspace can satisfy on their business tiers, but it doesn’t mandate one platform over another.

Do we need to notify our state insurance commissioner if something goes wrong during migration? If a migration error results in unauthorized access to or exposure of nonpublic personal information, it may qualify as a reportable cybersecurity event under your state’s version of the Model Law, typically requiring notification within 72 hours of discovery. This is one of the strongest reasons to use a migration provider with insurance industry experience rather than attempting a DIY switch.

Will migrating email platforms affect our carrier appointments? Not if security controls, especially MFA and audit logging, are configured correctly on the new platform before go-live. Some carriers periodically verify agency security posture as part of appointment renewal, so document your migration and updated controls for that purpose.

Can our AMS sync with either Microsoft 365 or Google Workspace? Most agency management systems support both, but the depth of integration varies significantly. AMS360 and Applied Epic have historically built their deepest integrations around Outlook and Microsoft 365. Confirm your specific AMS vendor’s current integration support before finalizing a platform decision.

How long does an insurance agency email migration typically take? For a single-location agency under 50 mailboxes, a well-planned cutover migration can be completed over a weekend. Multi-location agencies or those with complex carrier integrations should budget for a staged migration over one to two weeks to allow time for testing each integration point.

What happens to our archived mailboxes from former employees? These typically need to migrate as well, since claims-related correspondence often carries longer retention requirements under state insurance recordkeeping rules than general business email. Confirm your state’s specific requirements and make sure your migration scope includes every archived mailbox, not just active users.


Ready to migrate your agency’s email without disrupting carrier connections or compliance posture? Get in touch with EMNMS for a migration assessment built around insurance industry requirements.