As used in
this chapter, unless the context otherwise requires:
1. “Authorized individual” means an individual known to and screened by a licensee and determined to be necessary and appropriate to have access to
nonpublic information held by the licensee and the licensee’s information system.
2. “Commissioner” means the commissioner of insurance.
3. “Consumer” means an individual, including but not limited to an applicant, policyholder, insured, beneficiary, claimant, or certificate
holder, who is a resident of this state and whose nonpublic information is in a licensee’s possession, custody, or control.
4. “Cybersecurity event” means an event resulting in unauthorized access to, or the disruption or misuse of, an information system or of nonpublic
information stored on an information system. “Cybersecurity event” does not include any of the following: a. The unauthorized acquisition of encrypted nonpublic information if the encryption, process, or key is not also acquired, released,
or used without authorization.
b. An event for which a licensee has determined that the nonpublic information accessed by an unauthorized person has not been
used or released, and the nonpublic information has been returned or destroyed.
5. “Delivered by electronic means” means delivery to an electronic mail address at which a consumer has consented to receive notices or documents.
6. “Encrypted” means the transformation of data into a form that results in a low probability of assigning meaning to the data without the
use of a protective process or key.
7. “Gramm-Leach-Bliley Act” means the Gramm-Leach-Bliley Act of 1999, 15 U.S.C. §6801 et seq., including amendments thereto and regulations promulgated thereunder.
8. “Health Insurance Portability and Accountability Act” or “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, including amendments thereto and regulations promulgated thereunder.
10. “Information security program” means the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process,
protect, store, use, transmit, dispose of, or otherwise handle nonpublic information.
11. “Information system” means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing,
dissemination, or disposition of electronic nonpublic information, and any specialized system such as an industrial or process
controls system, a telephone switching and private branch exchange system, or an environmental control system.
13. “Licensee” means a person licensed, authorized to operate, or registered, or a person required to be licensed, authorized to operate,
or registered pursuant to the insurance laws of this state. “Licensee” does not include a purchasing group or a risk retention group chartered and licensed in a state other than this state, or
a person acting as an assuming insurer that is domiciled in another state or jurisdiction.
14. “Multi-factor authentication” means authentication through verification of at least two of the following types of authentication factors: a. A knowledge factor, such as a password.
b. A possession factor, such as a token or text message on a mobile phone.
c. An inherence factor, such as a biometric characteristic.
15. “Nonpublic information” means electronic information that is not publicly available information and that is any of the following: a. Business-related information of a licensee the tampering of which, or unauthorized disclosure, access, or use of which, will
cause a material adverse impact to the business, operations, or security of the licensee.
b. Information concerning a consumer which can be used to identify the consumer due to a name, number, personal mark, or other
identifier, used in combination with any one or more of the following data elements: (1) A social security number.
(2) A driver’s license number or a nondriver identification card number.
(3) A financial account number, a credit card number, or a debit card number.
(4) A security code, an access code, or a password that will permit access to a consumer’s financial accounts.
(5) A biometric record.
c. Information or data, except age or gender, in any form or medium created by or derived from a health care provider or a consumer,
and that relates to any of the following: (1) The past, present, or future physical, mental or behavioral health or condition of a consumer, or a member of the consumer’s
family.
(2) The provision of health care services to a consumer.
(3) Payment for the provision of health care services to a consumer.
16. “Person” means an individual or a nongovernmental entity, including but not limited to a nongovernmental partnership, corporation,
branch, agency, or association.
17. “Publicly available information” means information that a licensee has a reasonable basis to believe is lawfully made available to the general public from
federal, state, or local government records, by widely distributed media, or by disclosure to the general public as required
by federal, state, or local law. For purposes of this definition, a licensee has a reasonable basis to believe that information
is lawfully made available to the general public if the licensee has determined all of the following: a. That the information is of a type that is available to the general public.
b. That if a consumer may direct that the information not be made available to the general public, that the consumer has not
directed that the information not be made available to the general public.
19. “Third-party service provider” means a person that is not a licensee that contracts with a licensee to maintain, process, store, or is otherwise permitted
access to nonpublic information through the person’s provision of services to the licensee.
507F.4 Information security program.
1. a. Commensurate with the size and complexity of a licensee, the nature and scope of a licensee’s activities including the licensee’s
use of third-party service providers, and the sensitivity of nonpublic information used by the licensee or that is in the
licensee’s possession, custody, or control, the licensee shall develop, implement, and maintain a comprehensive written information
security program based on the licensee’s risk assessment conducted pursuant to subsection 3. b. This section shall not apply to any of the following: (1) A licensee that meets any of the following criteria: (a) Has fewer than twenty individuals on its workforce, including employees and independent contractors.
(b) Has less than five million dollars in gross annual revenue.
(c) Has less than ten million dollars in year-end total assets.
(2) An employee, agent, representative, or designee of a licensee, and the employee, agent, representative, or designee is also
a licensee, if the employee, agent, representative, or designee is covered by the information security program of the other
licensee.
c. A licensee shall have one hundred eighty calendar days from the date the licensee no longer qualifies for exemption under
paragraph “b” to comply with this section.
2. A licensee’s information security program must be designed to do all of the following: a. Protect the security and confidentiality of nonpublic information and the security of the licensee’s information system.
b. Protect against threats or hazards to the security or integrity of nonpublic information and the licensee’s information system.
c. Protect against unauthorized access to or the use of nonpublic information, and minimize the likelihood of harm to any consumer.
d. Define and periodically reevaluate a schedule for retention of nonpublic information and a mechanism for the destruction of
nonpublic information if retention is no longer necessary for the licensee’s business operations, or is no longer required
by applicable law.
3. A licensee shall conduct a risk assessment that accomplishes all of the following: a. Designates one or more employees, an affiliate, or an outside vendor to act on behalf of the licensee and that has responsibility
for the information security program.
b. Identifies reasonably foreseeable internal or external threats that may result in unauthorized access, transmission, disclosure,
misuse, alteration, or destruction of nonpublic information, including nonpublic information that is accessible to, or held
by, a third-party service provider.
c. Assesses the probability of, and the potential damage caused by, the threats identified in paragraph “b”, taking into consideration the sensitivity of nonpublic information.
d. Assesses the sufficiency of policies, procedures, information systems, and other safeguards in place to manage the threats
identified in paragraph “b”. This assessment must include consideration of threats identified in each relevant area of the licensee’s operations, including
all of the following: (1) Employee training and management.
(2) Information systems, including network and software design; and information classification, governance, processing, storage,
transmission, and disposal.
(3) Detection, prevention, and response to an attack, intrusion, or other system failure.
e. Implements information safeguards to manage threats identified in the licensee’s ongoing risk assessments and, at least annually,
assesses the effectiveness of the information safeguards’ key controls, systems, and procedures.
4. Based on the risk assessment conducted pursuant to subsection 3, a licensee shall do all of the following: a. Develop, implement, and maintain an information security program as described in subsections 1 and 2.
b. Determine which of the following security measures are appropriate and implement each appropriate security measure: (1) Place access controls on information systems, including controls to authenticate and permit access only to authorized individuals
to protect against the unauthorized acquisition of nonpublic information.
(2) Identify and manage the data, personnel, devices, systems, and facilities that enable the licensee to achieve its business
purposes in accordance with the data, personnel, devices, systems, and facilities relative importance to the licensee’s business
objectives and risk strategy.
(3) Restrict access of nonpublic information stored in or at physical locations to authorized individuals only.
(4) Protect by encryption or other appropriate means, all nonpublic information while the nonpublic information is transmitted
over an external network, and all nonpublic information that is stored on a laptop computer, a portable computing or storage
device, or portable computing or storage media.
(5) Adopt secure development practices for in-house developed applications utilized by the licensee, and procedures for evaluating,
assessing, and testing the security of externally developed applications utilized by the licensee.
(6) Modify information systems in accordance with the licensee’s information security program.
(7) Utilize effective controls, which may include multi-factor authentication procedures for authorized individuals accessing
nonpublic information.
(8) Regularly test and monitor systems and procedures to detect actual and attempted attacks on, or intrusions into, information
systems.
(9) Include audit trails within the information security program designed to detect and respond to cybersecurity events, and designed
to reconstruct material financial transactions sufficient to support the normal business operations and obligations of the
licensee.
(10) Implement measures to protect against the destruction, loss, or damage of nonpublic information due to environmental hazards,
natural disasters, catastrophes, or technological failures.
(11) Develop, implement, and maintain procedures for the secure disposal of nonpublic information that is contained in any format.
c. Include cybersecurity risks in the licensee’s enterprise-wide risk management process.
d. Maintain knowledge and understanding of emerging threats or vulnerabilities and utilize reasonable security measures, relative
to the character of the sharing and the type of information being shared, when sharing information.
e. Provide the licensee’s personnel with cybersecurity awareness training that is updated as necessary to reflect risks identified
by the licensee’s risk assessment.
5. a. If a licensee has a board of directors, the board or an appropriate committee of the board shall at a minimum require the
licensee’s executive management or the executive management’s delegates to: (1) Develop, implement, and maintain the licensee’s information security program.
(2) Provide a written report to the board, at least annually, that documents all of the following: (a) The overall status of the licensee’s information security program and the licensee’s compliance with this chapter.
(b) Material matters related to the licensee’s information security program including issues such as risk assessment; risk management
and control decisions; third-party service provider arrangements; results of testing, cybersecurity events, or violations;
management’s response to cybersecurity events or violations; and recommendations for changes in the licensee’s information
security program.
b. If a licensee’s executive management delegates any of its responsibilities under this section the executive management shall oversee the delegate’s development, implementation, and maintenance of the licensee’s information
security program, and shall require the delegate to submit an annual written report to executive management that contains
the information required under paragraph “a”, subparagraph (2). If the licensee has a board of directors, the executive management shall provide a copy of the report
to the board.
6. A licensee shall monitor, evaluate, and adjust the licensee’s information security program consistent with relevant changes
in technology, the sensitivity of the licensee’s nonpublic information, changes to the licensee’s information systems, internal
or external threats to the licensee’s nonpublic information, and the licensee’s changing business arrangements, including
but not limited to mergers and acquisitions, alliances and joint ventures, and outsourcing arrangements.
7. As part of a licensee’s information security program, a licensee shall establish a written incident response plan designed
to promptly respond to, and recover from, a cybersecurity event that compromises the confidentiality, integrity, or availability
of nonpublic information in the licensee’s possession, the licensee’s information systems, or the continuing functionality
of any aspect of the licensee’s operations. The written incident response plan must address all of the following: a. The licensee’s internal process for responding to a cybersecurity event.
b. The goals of the licensee’s incident response plan.
c. The assignment of clear roles, responsibilities, and levels of decision-making authority for the licensee’s personnel that
participate in the incident response plan.
d. External communications, internal communications, and information sharing related to a cybersecurity event.
e. The identification of remediation requirements for weaknesses identified in information systems and associated controls.
f. Documentation and reporting regarding cybersecurity events and related incident response activities.
g. The evaluation and revision of the incident response plan, as appropriate, following a cybersecurity event.
8. An insurer domiciled in this state shall annually submit to the commissioner on or before April 15 a written certification
that the insurer is in compliance with this section. Each insurer shall maintain all records, schedules, documentation, and data supporting the insurer’s certification for five
years. To the extent an insurer has identified an area, system, or process that requires material improvement, updating, or
redesign, the insurer shall document the process used to identify the area, system, or process, and the remediation that has
been implemented, or will be implemented, to address the area, system, or process. All records, schedules, documentation,
and data described in this subsection shall be made available for inspection by the commissioner, or the commissioner’s representative, upon request of the commissioner.
9. Licensees shall comply with this section no later than January 1, 2023.
507F.6 Cybersecurity event — investigation.
1. If a licensee discovers that a cybersecurity event has occurred, or that a cybersecurity event may have occurred, the licensee,
or the outside vendor or third-party service provider the licensee has designated to act on behalf of the licensee, shall
conduct a prompt investigation of the event.
2. During the investigation, the licensee, outside vendor, or third-party service provider the licensee has designated to act
on behalf of the licensee, shall, at a minimum, determine as much of the following as possible: a. Confirm that a cybersecurity event has occurred.
b. Assess the nature and scope of the cybersecurity event.
c. Identify all nonpublic information that may have been compromised by the cybersecurity event.
d. Perform or oversee reasonable measures to restore the security of any compromised information systems in order to prevent
further unauthorized acquisition, release, or use of nonpublic information that is in the licensee’s possession, custody,
or control.
3. If a licensee learns that a cybersecurity event has occurred, or may have occurred, in an information system maintained by
a third-party service provider of the licensee, the licensee shall complete an investigation in compliance with this section, or confirm and document that the third-party service provider has completed an investigation in compliance with this section.
4. A licensee shall maintain all records and documentation related to the licensee’s investigation of a cybersecurity event for
a minimum of five years from the date of the event, and shall produce the records and documentation upon demand of the commissioner.
507F.7 Cybersecurity event — notification and report to the commissioner.
1. A licensee shall notify the commissioner no later than three business days from the date of the licensee’s confirmation of
a cybersecurity event if any of the following conditions apply: a. The licensee is an insurer who is domiciled in this state, or is a producer whose home state is this state, and any of the
following apply: (1) The laws of this state or federal law requires that notice of the cybersecurity event be given by the licensee to a government
body, self-regulatory agency, or other supervisory body.
(2) The cybersecurity event has a reasonable likelihood of causing material harm to a material part of the normal business, operations,
or security of the licensee.
b. The licensee reasonably believes that nonpublic information compromised by the cybersecurity event involves two hundred fifty
or more consumers and either of the following apply: (1) State or federal law requires that notice of the cybersecurity event be given by the licensee to a government body, self-regulatory
agency, or other supervisory body.
(2) The cybersecurity event has a reasonable likelihood of causing material harm to a consumer, or to a material part of the normal
business, operations, or security of the licensee.
2. A licensee’s notification to the commissioner pursuant to subsection 1 shall provide, in the form and manner prescribed by the commissioner by rule, as much of the following information as is
available to the licensee at the time of the notification: a. The date and time of the cybersecurity event.
b. A description of how nonpublic information was exposed, lost, stolen, or breached, including the specific roles and responsibilities
of the licensee’s third-party service providers, if any.
c. How the licensee discovered or became aware of the cybersecurity event.
d. If any lost, stolen, or breached nonpublic information has been recovered and if so, how the recovery occurred.
e. The identity of the source of the cybersecurity event.
f. The identity of any regulatory, governmental, or law enforcement agencies the licensee has notified, and the date and time
of each notification.
g. A description of the specific types of nonpublic information that were lost, stolen, or breached.
h. The total number of consumers affected by the cybersecurity event. The licensee shall provide the best estimate of affected
consumers in the licensee’s initial report to the commissioner and shall update the estimate in each subsequent report to
the commissioner under subsection 3.
i. The results of any internal review conducted by the licensee that identified a lapse in the licensee’s automated controls
or internal procedures, or that confirmed the licensee’s compliance with all automated controls or internal procedures.
j. A description of the licensee’s efforts to remediate the circumstances that allowed the cybersecurity event.
k. A copy of the licensee’s privacy policy.
l. A statement outlining the steps the licensee is taking to identify and notify consumers affected by the cybersecurity event.
m. The contact information for the individual authorized to act on behalf of the licensee and who is also knowledgeable regarding
the cybersecurity event.
3. A licensee shall have a continuing obligation to update and supplement the licensee’s initial notification to the commissioner
as material changes to information previously provided to the commissioner occur.