DE Universally Applicable Bulletin No. 5

Delaware Insurance Data Security Act Requirements

Last amended: 2026Year: 2026Length: 912 wordsOfficial source
Note: This Bulletin is intended solely for informational purposes. It is not intended to set forth legal rights, duties, or privileges, nor is it intended to provide legal advice. Readers should consult applicable statutes and rules and contact the Delaware Department of Insurance if additional information is needed. ♦INSURANCE.DELAWARE.GOV♦ 1351 W. NORTH ST., SUITE 101, DOVER, DELAWARE 19904 (302) 674-7300 DOVER♦ (302) 259-7554 GEORGETOWN♦ (302) 577-5280 WILMINGTON TRINIDAD NAVARRO COMMISSIONER STATE OF DELAWARE DEPARTMENT OF INSURANCE UNIVERSALLY APPLICABLE BULLETIN NO. 5 (REISSUED) TO: ANYONE ENGAGED IN ANY ASPECT OF THE BUSINESS OF INSURANCE IN DELAWARE INCLUDING BUT NOT LIMITED TO INSURERS, INTERMEDIARIES INCLUDING PRODUCERS (AGENTS, BROKERS AND DIRECT WRITERS), AND UNDERWRITERS, AND ANY CONTRACTORS OF THESE ENTITIES RE: DELAWARE INSURANCE DATA SECURITY ACT REQUIREMENTS DATED: August 26, 2019 UPDATED: October 8, 2020 REISSUED: February ____, 2026 I. Purpose This Bulletin is being reissued as a reminder to all individuals and entities engaged in any aspect of the insurance business in Delaware of their obligations under the Delaware Insurance Data Security Act (the Act), including annual certification due by February 15. The original Bulletin, issued August 29, 2019, notified licensees that House Bill 174 (H.B. 174), the Delaware Insurance Data Security Act, was signed into law on July 31, 2019, and outlined the Act’s requirements. The subsequent October 2020 update revised the Department’s dedicated email address for reporting data breaches (see updated Section III) and established the requirement for an annual certification of compliance with the Act (see Section IV). II. Summary of the Act The Act is codified at 18 Del.C. Chapter 86, and requires licensees i to: • Implement information security programs and conduct risk assessments to try to prevent data breaches and compromising of consumers’ nonpublic information and personal data (must be implemented no later than August 1, 2020), including oversight of third party service providers (must be implemented no later than August 1, 2021); • Conduct thorough investigations to determine if a cybersecurity event may have occurred and whose data may have been compromised; 12 Page | 2 • Notify the Department within three (3) business days of determining that a cybersecurity event has occurred; • Notify all impacted consumers within sixty (60) days of the determination that their data has or may have been compromised; and • Offer free credit monitoring services for one year to consumers impacted by breaches. “Licensee” is defined in the Act as “a person who is licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered, under the insurance laws of this State,” but a “licensee” is neither of the following: • A purchasing group or risk retention group that is chartered and licensed in a state other than this State; or • A licensee that is acting as an assuming insurer that is domiciled in a state other than this State or another jurisdiction. The Act also empowers the Commissioner to investigate the affairs of any insurer to determine whether they have been engaged in any conduct in violation of this Act and take appropriate action. Accordingly, Universally Applicable Bulletin No. 3, entitled, “Department’s Request that the Department be Notified of a Data Breach or Other Disclosure of Confidential Consumer Information,” is hereby rescinded because it is now superseded by the Act. That said, licensees who mail information to their consumers should continue to do so in closed-faced envelopes. III. Notifying the Department of a data breach Licensees who are subject to the Act should submit the required data breach/cyber security event notification to the Department’s dedicated email box, doidatasecurity@delaware.gov. The notice should include the following information in the notice: • Date the breach was discovered; • Date the breach occurred; • Description of how the breach occurred; • What information was breached (or as soon as determined); • How many Delaware policyholders may be affected (or as soon as determined); • A list of the Delaware policyholders (or as soon as determined); and • A copy of the notification being sent to affected policyholders. IV. Annual Certification An insurer domiciled in this State who is subject to the Act shall annually submit the following to the Commissioner at doidatasecurity@delaware.gov, no later than February 15: • A written statement, certifying that the insurer is in compliance with the requirements of the Act; and • The affidavit attached to this reissued bulletin. Page | 3 Any questions, comments or requests for clarification about this bulletin should be emailed to doidatasecurity@delaware.gov. This Bulletin shall be effective immediately and shall remain in effect unless withdrawn or superseded by subsequent law, regulation or bulletin. ______________________________________ Trinidad Navarro Delaware Insurance Commissioner i HB 174 does not apply to either of the following: (1) A licensee with fewer than 15 employees is exempt from § 8604 of this chapter. (2) A licensee subject to the Health Insurance Portability and Accountability Act (P.L. 104-191, as amended) that has established and maintains an information security program under the statutes, rules, regulations, procedures, or guidelines established thereunder, is considered to meet the requirements of 18 Del.C. § 8604 if the licensee is compliant with, and submits a written statement certifying its compliance. Additionally, a licensee’s employee, agent, representative, or designee, who is also a licensee, is exempt from 18 Del.C. § 8604 and is not required to develop the employee’s, agent’s, representative’s, or designee’s own information security program to the extent that the employee, agent, representative or designee is covered by the other licensee’s information security program.
DE Universally Applicable Bulletin No. 5: Delaware Insurance Data Security Act Requirements | Justis AI