Privacy Law Library

Insurance Data Security Law

NH Insurance Data Security Law

Data security · Breach notification · Financial

New Hampshire's adoption of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee vendors, keep an incident response plan, investigate cybersecurity events and report qualifying events to the Insurance Commissioner within 3 business days. Consumer notice follows the general breach law, RSA 359-C:20.

Where
New Hampshire
Citation
N.H. Rev. Stat. Ann. ch. 420-P
Status
In force
In force since
2020-01-01
Enforced by
New Hampshire Insurance Commissioner
People can sue
No
Penalties
Penalties under RSA 400-A:15, III: for knowing violations, license suspension or revocation or administrative fines up to $2,500 per violation.
Applies to
  • Insurers, producers and other persons licensed or required to be licensed by the NH Insurance Department
  • Information security program duties do not apply to licensees with fewer than 20 employees, continuing care retirement communities, life settlement providers, and GLBA-compliant banks and credit unions; vendors under RSA 402-K are fully exempt

Security duties

  • Develop, implement and maintain a comprehensive written information security program based on a risk assessment and commensurate with the licensee's size, complexity and data sensitivity, including a data retention and destruction schedule.RSA 420-P:4, I-II · Only if: Licensees with 20 or more employees
  • Maintain a written incident response plan covering roles, communications, remediation, documentation and post-event review.RSA 420-P:4, VIII
  • Require third-party service providers to implement appropriate administrative, technical and physical safeguards for systems and nonpublic information they access or hold.RSA 420-P:4, VI(b)

Breach duties

  • Promptly investigate any actual or possible cybersecurity event and keep records of all events for at least 5 years.RSA 420-P:5
  • Notify affected consumers as required by RSA 359-C:20 and send the Commissioner a copy of the consumer notice.RSA 420-P:6, III
  • Notify the Insurance Commissioner within 3 business days of determining a qualifying cybersecurity event occurred (NH domicile or home state with likely material harm, or 250+ NH consumers involved), with specified details and ongoing updates.RSA 420-P:6, I-II

Other duties

  • NH-domiciled insurers must certify compliance to the Commissioner annually by March 1 and keep supporting records for 5 years.RSA 420-P:4, IX

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Research reference, not legal advice.