RI Insurance Bulletin 2025-1

Implementation of Insurance Data Security Statute

Year: 2025Length: 834 wordsOfficial source
Department of Business Regulation Insurance Division 1511 Pontiac Avenue, Bldg. 69-2 Cranston, Rhode Island 02920 Insurance Bulletin Number 2025-1 Implementation of Insurance Data Security Statute The Rhode Island legislature enacted portions of the NAIC Insurance Data Security Model (model #668) effective January 1, 2025, which applies to foreign and domestic insurance companies. This bulletin is to memorialize the Department’s interpretation of Rhode Island 2024 Public Laws Chapters 354 & 355 to assist insurers with compliance. In accordance with R.I. General Laws § 27-1-46(i), domestic Rhode Island insurers should file a certificate by April 15, 2025, and annually thereafter. To meet this statutory requirement, they should email a PDF file of a letter on company letterhead, including the information required by R.I. General Laws § 27-1-46(i) and signed by the CTO, CIO, or other officer or executive with appropriate knowledge and responsibility for that information. That submission can be submitted to the Company’s financial analyst or, if that is not immediately known, it may be submitted to DBR.CompanyLicensing@dbr.ri.gov. As R.I. Gen. Laws § 27-1-46(i) does not apply to foreign insurers, foreign insurers are not required to file the annual certification discussed above. Rhode Island's insurance data security requirements are very similar to those in New York, Connecticut and numerous other jurisdictions. Insurers compliant in those states should not have any difficulties complying with the new Rhode Island requirements. R.I. Gen. Laws §§ 27-1-46 & 27-2-29 use the phrase “commensurate with the size and complexity of an insurer.” The Department understands that phrase to mean that the Information Security program implemented by the insurer will vary depending upon the specific characteristics of the insurer. Other things being equal, the program should be more robust for larger and more complex insurers and may be less robust for smaller and less complex insurers. The Department does not interpret the terms of § 27-1-46(d)(2) & 27-2-29(d)(2) to require that every insurer implement the entire list of security measures to achieve compliance. Rather, the list provides examples of measures that could be taken if the insurer determines during its own risk assessment that such measures are necessary to protect nonpublic information. R.I. Gen. Laws §§ 27-1-46(f) and 27-2-29(f) – These subsections only apply to Third-Party Service Providers to whom the insurer has provided nonpublic information. The corresponding notification requirements only apply if the compromised information is that of the insurer. The insurer’s obligation is to confirm that the Third-Party Service Provider has implemented measures to protect the nonpublic information. This can be done in any number of ways and does 2 not require direct confirmation by the Third-Party Service Provider to the individual insurer if the information can be obtained by other means. R.I. Gen. Laws § 27-1-47(a)(2) requires notification to the Department by a domestic insurer who experiences a “cybersecurity event that has a reasonable likelihood of materially harming” Rhode Island consumers. The Department does want to encourage its domestic insurers to regularly notify the Department of such events, but a formal notification need only be filed for breaches exceeding 50 consumers residing in Rhode Island. R.I. Gen. Laws §§ 27-1-47(b) & 27-2-30 require insurers to file notifications to the Department regarding breaches. These important notifications must include thirteen key items of information for the Department’s regulatory purposes. The statute allows insurers to claim exemptions from the Rhode Island Access to Public Records Act (“APRA”) in these notifications, but to ensure that there is no misunderstanding, the Department believes the public portions of such notices must include at least the following five key pieces of information in a method that can be made public. - Name of the insurer; - Timing of the breach (27-1-47(b)(1); - Number of impacted consumers (27-1-47(b)(9); - Type of information impacted by the breach (27-1-47(b)(7); and - Whether any third-party service providers were involved (27-1-47(b)(2). If necessary, a second filing may be made to address confidential items, citing specific provisions in APRA, such as the exemptions in R.I. Gen. Laws § 38-2-2. 27-2-29 requires foreign insurers licensed in Rhode Island to have an information security program commensurate with their size and complexity. If that foreign insurer has an information security program that is prepared for and in compliance with Pub. L. No. 104-191, 110 Stat. 1936, enacted August 21, 1996 (Health Insurance Portability and Accountability Act) and related privacy, security, and breach notification regulations pursuant to Code of Federal Regulations, Parts 160 and 164, and Pub. L. No. 111-5, 123 Stat. 226, enacted February 17, 2009 (Health Information Technology), then it will be considered to meet this requirement. It is expected that all insurers will continue to protect personal information of Rhode Island consumers, as is required by 230-RICR-20-60-7 (former Insurance Regulation 99 and 100), and 230-RICR-20-60-8 (formerly Insurance Regulation 107) and R.I. Gen. Laws § 11-49.3. The Division previously reminded companies of these requirements in Insurance Bulletin 2020-10. If insurers have questions or concerns with the above, please let the Department know at DBR.Insurance@dbr.ri.gov. Elizabeth Kelleher Dwyer Superintendent of Insurance April 11, 2025
RI Insurance Bulletin 2025-1: Implementation of Insurance Data Security Statute | Justis AI