Title
This chapter may be cited as the “Insurance Data Security Act”.
Iowa · statute · Iowa Code ch. 507F · 16 active provisions
This chapter may be cited as the “Insurance Data Security Act”.
1. Notwithstanding any provision of law to the contrary, this chapter establishes the exclusive state standards for data security, and the investigation and notification of cybersecurity events, applicable to licensees. 2. This chapter shall not be construed to create or imply a private cause of action for a violation…
As used in this chapter, unless the context otherwise requires: 1. “Authorized individual” means an individual known to and screened by a licensee and determined to be necessary and appropriate to have access to nonpublic information held by the licensee and the licensee’s information system. 2. “Commissioner” means th…
1. a. Commensurate with the size and complexity of a licensee, the nature and scope of a licensee’s activities including the licensee’s use of third-party service providers, and the sensitivity of nonpublic information used by the licensee or that is in the licensee’s possession, custody, or control, the licensee shall…
1. A licensee shall exercise due diligence in the selection of third-party service providers, conduct oversight of all third-party service provider arrangements, and require all third-party service providers to implement appropriate administrative, technical, and physical measures to protect and secure the information…
1. If a licensee discovers that a cybersecurity event has occurred, or that a cybersecurity event may have occurred, the licensee, or the outside vendor or third-party service provider the licensee has designated to act on behalf of the licensee, shall conduct a prompt investigation of the event. 2. During the investig…
1. A licensee shall notify the commissioner no later than three business days from the date of the licensee’s confirmation of a cybersecurity event if any of the following conditions apply: a. The licensee is an insurer who is domiciled in this state, or is a producer whose home state is this state, and any of the foll…
1. In the event of a cybersecurity event involving nonpublic information a licensee shall comply with the notification requirements pursuant to section 715C.2, and all other applicable notification requirements pursuant to federal or state law. 2. If a licensee is required to provide notice of a cybersecurity event to…
1. If a licensee becomes aware of a cybersecurity event in an information system maintained by a third-party service provider of the licensee, the licensee shall comply with section 507F.7, or the licensee may obtain a written certification from the third-party service provider that the provider is in compliance with s…
1. If a cybersecurity event involves nonpublic information used by, or that is in the possession, custody, or control of, a licensee that is acting as an assuming insurer and that does not have a direct contractual relationship with consumers affected by the cybersecurity event, the assuming insurer shall notify each o…
If a cybersecurity event involves nonpublic information that is in the possession, custody, or control of a licensee that is an insurer, or in the possession, custody, or control of the insurer’s third-party service provider, and for which a consumer accessed the insurer’s services through an independent insurance prod…
1. Documents, materials, and other information in the control or possession of the commissioner that are furnished by a licensee, or by an employee or agent of the licensee acting on behalf of the licensee, or that are obtained by the commissioner in an investigation or examination, shall be confidential by law and pri…
1. This chapter shall not apply to a licensee that is subject to, and in compliance with, the Health Insurance Portability and Accountability Act. The licensee shall annually submit to the commissioner a written certification of the licensee’s compliance with HIPAA. 2. This chapter shall not apply to a licensee that is…
A licensee that violates this chapter shall be subject to penalties pursuant to section 505.7A and chapter 507B.
1. The commissioner may adopt rules pursuant to chapter 17A as necessary to administer this chapter. 2. The commissioner may take any enforcement action under the commissioner’s authority to enforce compliance with this chapter.
If any provision of this chapter or its application to any person or circumstance is held invalid, the invalidity shall not affect other provisions or applications of this chapter which can be given effect without the invalid provision or application, and to this end the provisions of this chapter are severable.