RI Insurance Bulletin 2025-1
Implementation of Insurance Data Security Statute
Department of Business Regulation
Insurance Division
1511 Pontiac Avenue, Bldg. 69-2
Cranston, Rhode Island 02920
Insurance Bulletin Number 2025-1
Implementation of Insurance Data Security Statute
The Rhode Island legislature enacted portions of the NAIC Insurance Data Security Model
(model #668) effective January 1, 2025, which applies to foreign and domestic insurance
companies. This bulletin is to memorialize the Department’s interpretation of Rhode Island 2024
Public Laws Chapters 354 & 355 to assist insurers with compliance.
In accordance with R.I. General Laws § 27-1-46(i), domestic Rhode Island insurers should file a
certificate by April 15, 2025, and annually thereafter. To meet this statutory requirement, they
should email a PDF file of a letter on company letterhead, including the information required by
R.I. General Laws § 27-1-46(i) and signed by the CTO, CIO, or other officer or executive with
appropriate knowledge and responsibility for that information. That submission can be submitted
to the Company’s financial analyst or, if that is not immediately known, it may be submitted to
DBR.CompanyLicensing@dbr.ri.gov.
As R.I. Gen. Laws § 27-1-46(i) does not apply to foreign insurers, foreign insurers are not
required to file the annual certification discussed above.
Rhode Island's insurance data security requirements are very similar to those in New York,
Connecticut and numerous other jurisdictions. Insurers compliant in those states should not have
any difficulties complying with the new Rhode Island requirements.
R.I. Gen. Laws §§ 27-1-46 & 27-2-29 use the phrase “commensurate with the size and
complexity of an insurer.” The Department understands that phrase to mean that the Information
Security program implemented by the insurer will vary depending upon the specific
characteristics of the insurer. Other things being equal, the program should be more robust for
larger and more complex insurers and may be less robust for smaller and less complex insurers.
The Department does not interpret the terms of § 27-1-46(d)(2) & 27-2-29(d)(2) to require that
every insurer implement the entire list of security measures to achieve compliance. Rather, the
list provides examples of measures that could be taken if the insurer determines during its own
risk assessment that such measures are necessary to protect nonpublic information.
R.I. Gen. Laws §§ 27-1-46(f) and 27-2-29(f) – These subsections only apply to Third-Party
Service Providers to whom the insurer has provided nonpublic information. The corresponding
notification requirements only apply if the compromised information is that of the insurer. The
insurer’s obligation is to confirm that the Third-Party Service Provider has implemented
measures to protect the nonpublic information. This can be done in any number of ways and does
2
not require direct confirmation by the Third-Party Service Provider to the individual insurer if
the information can be obtained by other means.
R.I. Gen. Laws § 27-1-47(a)(2) requires notification to the Department by a domestic insurer
who experiences a “cybersecurity event that has a reasonable likelihood of materially harming”
Rhode Island consumers. The Department does want to encourage its domestic insurers to
regularly notify the Department of such events, but a formal notification need only be filed for
breaches exceeding 50 consumers residing in Rhode Island.
R.I. Gen. Laws §§ 27-1-47(b) & 27-2-30 require insurers to file notifications to the Department
regarding breaches. These important notifications must include thirteen key items of information
for the Department’s regulatory purposes. The statute allows insurers to claim exemptions from
the Rhode Island Access to Public Records Act (“APRA”) in these notifications, but to ensure
that there is no misunderstanding, the Department believes the public portions of such notices
must include at least the following five key pieces of information in a method that can be made
public.
-
Name of the insurer;
-
Timing of the breach (27-1-47(b)(1);
-
Number of impacted consumers (27-1-47(b)(9);
-
Type of information impacted by the breach (27-1-47(b)(7); and
-
Whether any third-party service providers were involved (27-1-47(b)(2).
If necessary, a second filing may be made to address confidential items, citing specific
provisions in APRA, such as the exemptions in R.I. Gen. Laws § 38-2-2.
27-2-29 requires foreign insurers licensed in Rhode Island to have an information security
program commensurate with their size and complexity. If that foreign insurer has an information
security program that is prepared for and in compliance with Pub. L. No. 104-191, 110 Stat.
1936, enacted August 21, 1996 (Health Insurance Portability and Accountability Act) and related
privacy, security, and breach notification regulations pursuant to Code of Federal Regulations,
Parts 160 and 164, and Pub. L. No. 111-5, 123 Stat. 226, enacted February 17, 2009 (Health
Information Technology), then it will be considered to meet this requirement.
It is expected that all insurers will continue to protect personal information of Rhode Island
consumers, as is required by 230-RICR-20-60-7 (former Insurance Regulation 99 and 100), and
230-RICR-20-60-8 (formerly Insurance Regulation 107) and R.I. Gen. Laws § 11-49.3. The
Division previously reminded companies of these requirements in Insurance Bulletin 2020-10.
If insurers have questions or concerns with the above, please let the Department know at
DBR.Insurance@dbr.ri.gov.
Elizabeth Kelleher Dwyer
Superintendent of Insurance
April 11, 2025