Multi-factor authentication is not stated for access to insurer data
You have not said whether multi-factor authentication is enforced for everyone who can reach insurer data. Section 500.12 requires the carrier to have it for any access to nonpublic information, and the carrier cannot answer that question for its own examiner while a vendor holding the same data cannot. A reviewer treats silence here as a no, because every vendor that has it says so in the first sentence.
To fix: Enforce a second factor for every account, including administrators, service accounts that a person can use, and any third party with access. Then say so, with the mechanism named, in the security section of the profile.