RI Insurance Bulletin 2020-10

Reminder of Data Breach Notice Requirement

Year: 2020Length: 336 wordsOfficial source
Department of Business Regulation Insurance Division 1511 Pontiac Avenue, Bldg. 69-2 Cranston, Rhode Island 02920 Insurance Bulletin 2020-10 Reminder of Data Breach Notice Requirement Insurers, producers, third party administrators, managing general agents and other licensees, as well as their vendors and contractors, are entrusted with an important role in protecting confidential consumer information, including confidential health and financial information. Unfortunately, data breaches are an inescapable part of modern life and bad actors are able to occasionally gain access to confidential consumer information. The Insurance Division wants to remind all licensees and their vendors that Rhode Island has a Data Breach Notice requirement. For more than fifteen years Rhode Island has required insurers and other licensees to notify the Insurance Division in the event of a “breach of the security of computerized unencrypted data that poses a significant risk of identity theft.” See 230-RICR-20-60-8.11 and R.I. Gen. Laws Chapter 11-49.3 and their predecessors. This Bulletin is to serve as a reminder of these requirements in case of a breach. • Notices sent to the Department should be delivered to DBR.Insurance@dbr.ri.gov. Please do NOT mail these reports and use the email method of delivery instead. • Notices shall be made in the most expedient time possible and without unreasonable delay. • Notices must include a basic explanation of the breach, identify the number of Rhode Islanders impacted (or potentially impacted), as well as any notice the insurer or licensee anticipates sending to Rhode Island consumers. • Notices to the Department MUST identify all licensees involved. • Notices to the Department and the Consumer MUST identify the breach BUT ALSO INCLUDE the relationship between the notifying party and the consumer. o For instance, if a TPA provides a data breach notice to a consumer, they must identify the insurer or other entity that maintains the relationship with the consumer. • Notices that fail to provide the information required above will be deemed noncompliant. Any questions should be directed to DBR.Insurance@dbr.ri.gov Elizabeth Kelleher Dwyer Superintendent of Insurance November 16, 2020
RI Insurance Bulletin 2020-10: Reminder of Data Breach Notice Requirement | Justis AI