MI DIFS Bulletin 2010-21-INS

Safeguarding Customer Information

Year: 2010Length: 419 wordsOfficial source
STATE OF MICHIGAN DEPARTMENT OF ENERGY, LABOR & ECONOMIC GROWTH OFFICE OF FINANCIAL AND INSURANCE REGULATION Bulletin 2010-21-INS In the matter of Safeguarding Customer Information I Issued and entered this 29th day of December 2010 by Ken Ross Commissioner SAFEGUARDING CUSTOMER INFORMATION Michigan resident and non-resident insurance producers are required under Section 500.547 of the Insurance Code to "adopt policies and procedures for administrative, technical, and physical safeguards for the protection ofcustomer records and information." The intent ofthis bulletin is to emphasize the imp01tance of protecting customers' nonpublic personal financial info1mation. Under administrative rnle R 500.553, producers must implement a comprehensive written information security program for the protection of customer information. Standards for developing and implementing safeguards to protect the security, confidentiality, and integrity of customer information are found in administrative rules R 500.555 - R 500.560. Failure to have in place an appropriate security program to protect customer info1mation and prevent unauthorized access to or use ofthat information is "an unfair or deceptive act or practice in the business of insurance" under Section 500.2013 that may subject a producer to disciplinary action. The Office of Financial and Insurance Regulation makes the following recommendations to producers: • Never just throw away old records or leave them in an abandoned office. Documents containing customer information that are discarded in trash containers create the potential for identity theft. Customer information is especially vulnerable to inadve1tent disclosure when producers change office locations and records are simply discarded. • Consult with insurance companies. Every insurance company has guidelines on how to store customer records and methods for properly disposing ofthose records (shredding, offsite storage, etc.). I • Periodically review your information security program and make adjustments in light of new circumstances ( changes in technology, changes in the sensitivity of the customer information, new internal or external threats, etc.). Train office staffin the elements of your information security program and emphasize the need to safeguard customer information. Producers are also reminded that a breach ofthe security ofa database containing personal customer information may subject them to penalties under the Identity Theft Protection Act, MCL Section 445.61 et seq. The sections of the Insurance Code, the administrative rules referenced in this bulletin, and additional information on producers' responsibilities to safeguard customer information, can be found at www.michigan.gov/ofir. Any questions regarding this bulletin should be directed to: Office ofFinancial and Insurance Regulation Consumer Services Division Market Conduct Section 611 West Ottawa Street P.O. Box 30220 Lansing, Michigan 48909-7720 Toll Free: (866-999-6442 Ken Ross Commissioner 2
MI DIFS Bulletin 2010-21-INS: Safeguarding Customer Information | Justis AI