If a licensee experiences a cybersecurity incident, they must conduct a prompt investigation, determine the nature and scope of the event, what information was involved, and restore the security of the information systems. If the event occurred in a system maintained by a third party, the licensee should ensure that the provider takes the necessary steps and documents them. All records concerning cybersecurity events should be kept for at least five years and must be handed over to the insurance commissioner if requested.
The NAIC Model Law also recommends that each licensee notifies their state insurance commissioner within 72 hours of discovering a cybersecurity event, and the commissioner of any other state where 250 or more individuals were affected by the event. Licensees should also notify affected parties within the time required by their state’s data breach notification laws. If the cybersecurity event occurred in a system maintained by a third party, the licensee should carry out the same notification process.
Under the NAIC Model Law, the regulations apply to insurers with ten or more employees, although some states have altered that number based on their own adoption of the laws.
The Insurance Data Security Model Law has been adopted in several states as of January 2023: including Alabama, Connecticut, Delaware, Georgia, Illinois, Indiana, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nevada, New Hampshire, New Jersey, New York, North Dakota, Ohio, Oklahoma, Oregon, Rhode Island, South Carolina, Tennessee, Texas, Vermont, Virginia, and Wyoming.
Compliance with the NAIC’s cybersecurity regulations is critical for insurance companies. Not only is it required by law, but it is also important for protecting the sensitive information of their customers. Cyber threats are becoming more sophisticated and frequent, and companies that do not take the necessary steps to protect themselves and their customers are putting themselves at risk of significant financial losses and damage to their reputation. Therefore, it is vital for insurance companies to prioritize cybersecurity.
With over 25 years of experience, we at Motiva Networks can help you plan and see if your data has been compromised with a Free Confidential Cybersecurity Risk Assessment courtesy of the Big “I” NY. Or you can schedule a quick 10-minute call with me directly to discuss any questions you might have HERE.