DE Universally Applicable Bulletin No. 5
Delaware Insurance Data Security Act Requirements
Note: This Bulletin is intended solely for informational purposes. It is not intended to set forth legal rights, duties, or privileges, nor is it
intended to provide legal advice. Readers should consult applicable statutes and rules and contact the Delaware Department of Insurance if
additional information is needed.
♦INSURANCE.DELAWARE.GOV♦
1351 W. NORTH ST., SUITE 101, DOVER, DELAWARE 19904
(302) 674-7300 DOVER♦ (302) 259-7554 GEORGETOWN♦ (302) 577-5280 WILMINGTON
TRINIDAD NAVARRO
COMMISSIONER
STATE OF DELAWARE
DEPARTMENT OF INSURANCE
UNIVERSALLY APPLICABLE BULLETIN NO. 5 (REISSUED)
TO:
ANYONE ENGAGED IN ANY ASPECT OF THE BUSINESS OF
INSURANCE IN DELAWARE INCLUDING BUT NOT LIMITED TO
INSURERS, INTERMEDIARIES INCLUDING PRODUCERS (AGENTS,
BROKERS AND DIRECT WRITERS), AND UNDERWRITERS, AND
ANY CONTRACTORS OF THESE ENTITIES
RE:
DELAWARE INSURANCE DATA SECURITY ACT REQUIREMENTS
DATED:
August 26, 2019
UPDATED: October 8, 2020
REISSUED: February ____, 2026
I.
Purpose
This Bulletin is being reissued as a reminder to all individuals and entities engaged in any aspect
of the insurance business in Delaware of their obligations under the Delaware Insurance Data
Security Act (the Act), including annual certification due by February 15.
The original Bulletin, issued August 29, 2019, notified licensees that House Bill 174 (H.B. 174),
the Delaware Insurance Data Security Act, was signed into law on July 31, 2019, and outlined
the Act’s requirements.
The subsequent October 2020 update revised the Department’s dedicated email address for
reporting data breaches (see updated Section III) and established the requirement for an annual
certification of compliance with the Act (see Section IV).
II.
Summary of the Act
The Act is codified at 18 Del.C. Chapter 86, and requires licensees
i to:
• Implement information security programs and conduct risk assessments to try to prevent
data breaches and compromising of consumers’ nonpublic information and personal data
(must be implemented no later than August 1, 2020), including oversight of third party
service providers (must be implemented no later than August 1, 2021);
• Conduct thorough investigations to determine if a cybersecurity event may have occurred
and whose data may have been compromised;
12
Page | 2
• Notify the Department within three (3) business days of determining that a
cybersecurity event has occurred;
• Notify all impacted consumers within sixty (60) days of the determination that their data
has or may have been compromised; and
• Offer free credit monitoring services for one year to consumers impacted by breaches.
“Licensee” is defined in the Act as “a person who is licensed, authorized to operate, or
registered, or required to be licensed, authorized, or registered, under the insurance laws of this
State,” but a “licensee” is neither of the following:
• A purchasing group or risk retention group that is chartered and licensed in a state other
than this State; or
• A licensee that is acting as an assuming insurer that is domiciled in a state other than this
State or another jurisdiction.
The Act also empowers the Commissioner to investigate the affairs of any insurer to determine
whether they have been engaged in any conduct in violation of this Act and take appropriate
action.
Accordingly, Universally Applicable Bulletin No. 3, entitled, “Department’s Request that the
Department be Notified of a Data Breach or Other Disclosure of Confidential Consumer
Information,” is hereby rescinded because it is now superseded by the Act. That said, licensees
who mail information to their consumers should continue to do so in closed-faced envelopes.
III.
Notifying the Department of a data breach
Licensees who are subject to the Act should submit the required data breach/cyber security event
notification to the Department’s dedicated email box, doidatasecurity@delaware.gov. The notice
should include the following information in the notice:
• Date the breach was discovered;
• Date the breach occurred;
• Description of how the breach occurred;
• What information was breached (or as soon as determined);
• How many Delaware policyholders may be affected (or as soon as determined);
• A list of the Delaware policyholders (or as soon as determined); and
• A copy of the notification being sent to affected policyholders.
IV.
Annual Certification
An insurer domiciled in this State who is subject to the Act shall annually submit the following
to the Commissioner at doidatasecurity@delaware.gov, no later than February 15:
• A written statement, certifying that the insurer is in compliance with the requirements of
the Act; and
• The affidavit attached to this reissued bulletin.
Page | 3
Any questions, comments or requests for clarification about this bulletin should be emailed to
doidatasecurity@delaware.gov.
This Bulletin shall be effective immediately and shall remain in effect unless withdrawn or
superseded by subsequent law, regulation or bulletin.
______________________________________
Trinidad Navarro
Delaware Insurance Commissioner
i HB 174 does not apply to either of the following:
(1) A licensee with fewer than 15 employees is exempt from § 8604 of this chapter.
(2) A licensee subject to the Health Insurance Portability and Accountability Act (P.L. 104-191, as amended) that
has established and maintains an information security program under the statutes, rules, regulations, procedures,
or guidelines established thereunder, is considered to meet the requirements of 18 Del.C. § 8604 if the licensee is
compliant with, and submits a written statement certifying its compliance.
Additionally, a licensee’s employee, agent, representative, or designee, who is also a licensee, is exempt from 18
Del.C. § 8604 and is not required to develop the employee’s, agent’s, representative’s, or designee’s own
information security program to the extent that the employee, agent, representative or designee is covered by the
other licensee’s information security program.