Short title
Short title. This Act may be cited as the Insurance Data Security Law.(Source: P.A. 103-142, eff. 1-1-24.)
Illinois · statute · 215 ILCS 215 · 14 active provisions
Short title. This Act may be cited as the Insurance Data Security Law.(Source: P.A. 103-142, eff. 1-1-24.)
Purpose and intent. (a) The purpose and intent of this Act is to establish standards for data security and standards for the investigation of and notification to the Director of a cybersecurity event applicable to licensees. (b) This Act shall not be construed to create or imply a private cause of action for a violatio…
Definitions. As used in this Act: "Authorized individual" means an individual known to and screened by the licensee and determined to be necessary and appropriate to have access to the nonpublic information held by the licensee and its information systems. "Consumer" means an individual, including, but not limited to,…
Information security program. (a) Commensurate with the size and complexity of the licensee, the nature and scope of the licensee's activities, including its use of third-party service providers, and the sensitivity of the nonpublic information used by the licensee or in the licensee's possession, custody, or control,…
Investigation of a cybersecurity event. (a) If the licensee learns that a cybersecurity event has occurred or may have occurred, the licensee, or an outside vendor or service provider designated to act on behalf of the licensee, shall conduct a prompt investigation. (b) During the investigation the licensee, or an outs…
Notification of a cybersecurity event. (a) A licensee shall notify the Director as promptly as possible but no later than 3 business days after a determination that a cybersecurity event has occurred when either of the following criteria has been met: (1) this State is the licensee's state of domicile, in the case of a…
Power of Director. (a) The Director shall have power to examine and investigate the affairs of any licensee to determine whether the licensee has been or is engaged in any conduct in violation of this Act. This power is in addition to the powers which the Director has under the Illinois Insurance Code, including Sectio…
Confidentiality. (a) Any documents, materials, or other information in the control or possession of the Department that are furnished by a licensee or an employee or agent thereof acting on behalf of licensee pursuant to subsection (i) of Section 10, subsection (b) of Section 20, or that are obtained by the Director in…
Exceptions. (a) The following exceptions shall apply to this Act: (1) A licensee with fewer than 50 employees, including any independent contractors, is exempt from Section 10. (2) A licensee that is subject to, governed by, and compliant with the privacy, security, and breach notification rules issued by the United St…
Penalties. In the case of a violation of this Act, a licensee may be penalized in accordance with the provisions of the Illinois Insurance Code, including Section 403A of the Illinois Insurance Code.(Source: P.A. 103-142, eff. 1-1-24.)
Rules. The Department may, in accordance with the Illinois Administrative Procedure Act and Section 401 of the Illinois Insurance Code, adopt such rules as shall be necessary to carry out the provisions of this Act.(Source: P.A. 103-142, eff. 1-1-24.)
Severability. If any provision of this Act or its application to any person or circumstance is held invalid, the invalidity of that provision or application does not affect other provisions or applications of this Act that can be given effect without the invalid provision or application.(Source: P.A. 103-142, eff. 1-1-…
(Amendatory provisions; text omitted). (Source: P.A. 103-142, eff. 1-1-24; text omitted.)
Effective date. This Act takes effect January 1, 2024.(Source: P.A. 103-142, eff. 1-1-24.)