Two Other States Adopt Model Data Security Law for Insurance Industry

Sheppard Mullin Richter & Hampton LLP
Contact

Sheppard Mullin Richter & Hampton LLP

Maine and North Dakota recently adopted the National Association of Insurance Commissioners (NAIC) data security model law. They join at least 11 others states who have already adopted the model law. The model law applies to insurers, insurance agents and other entities licensed by the state department of insurance.

As we wrote about in our insurance certifications round-up, among other requirements, the model law requires organizations subject to the law to have:

  • A comprehensive written information security program commensurate with the company’s size and complexity
  • A written incident response plan
  • Employee training
  • Appropriate oversight by the company’s board of directors

Neither law will take effect right away. Maine’s Model Law is not effective until January 1, 2022, with one section regarding compliance with third-party service provider arrangements effective January 1, 2023. The North Dakota law takes effect later, on August 1, 2022, with one section regarding the obligation to document and report cybersecurity events and related incident response activities effective August 1, 2023.

Putting it Into Practice: We anticipate more states will continue to adopt the NAIC model security law. Those in the insurance field should keep these security obligations in mind when assessing the sufficiency of their practices.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Sheppard Mullin Richter & Hampton LLP | Attorney Advertising

Written by:

Sheppard Mullin Richter & Hampton LLP
Contact
more
less

Sheppard Mullin Richter & Hampton LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide