Insurance Data Security Law
Tenn. Insurance Data Security Law
Data security · Breach notification · Financial
Tennessee's version of the NAIC Insurance Data Security Model Law. Insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, notify the Commissioner within three business days of qualifying events, and notify affected Tennessee consumers within 45 days when an event is reasonably likely to cause them material harm.
- Where
- Tennessee
- Citation
- Tenn. Code Ann. §§ 56-2-1001 to 56-2-1011 (2021 Tenn. Pub. Acts ch. 345, HB 766)
- Status
- In force
- In force since
- 2021-07-01
- Enforced by
- Tennessee Commissioner of Commerce and Insurance
- People can sue
- No
- Penalties
- The commissioner may seek penalties under § 56-2-305 for violations.
- Applies to
- Insurers, producers, and other persons licensed or required to be licensed under Tennessee insurance law ("licensees")
- Exempt: licensees with fewer than 25 employees and contractors, less than $5 million gross annual revenue, or less than $10 million year-end assets; HIPAA-compliant licensees that certify compliance are deemed compliant with the program and consumer-notice sections
Security duties
- By July 1, 2022, implement a comprehensive written information security program based on a risk assessment, with safeguards whose key controls are assessed at least annually and an incident response plan.Tenn. Code Ann. § 56-2-1004 · From 2022-07-01
- By July 1, 2023, require third-party service providers to implement appropriate administrative, technical, and physical safeguards for nonpublic information.Tenn. Code Ann. § 56-2-1004 · From 2023-07-01
Breach duties
- Investigate any cybersecurity event promptly, including events at third-party service providers.Tenn. Code Ann. § 56-2-1005
- Notify the Commissioner within three business days after determining a qualifying cybersecurity event occurred (Tennessee-domiciled or home-state licensees with material harm likely, or events involving 250 or more Tennessee consumers), with listed details and ongoing updates.Tenn. Code Ann. § 56-2-1006(a)-(b)
- Notify affected Tennessee consumers no later than 45 days after determining an event reasonably likely to materially harm them, by written, electronic, or substitute notice.Tenn. Code Ann. § 56-2-1006(c)
Other duties
- Domestic insurers must certify compliance to the Commissioner by April 15 each year and keep supporting records for five years.Tenn. Code Ann. § 56-2-1004 · Only if: Insurers domiciled in Tennessee
Sources
- Official text
- 2021 Tenn. Pub. Acts ch. 345 (HB 766), Tennessee Secretary of State
- Tenn. Code Ann. title 56, ch. 2, part 10 (2025 code text, Justia)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Penalty amounts under § 56-2-305 were not reviewed. | Citations to § 56-2-1004 are to the section as a whole; subdivision numbers were not confirmed from the codified text.
Research reference, not legal advice.