Privacy Law Library

Insurance Data Security Law

CT Insurance Data Security Law

Data security · Breach notification · Financial

Connecticut's version of the NAIC Insurance Data Security Model Law. Insurers, producers and other licensees must run a risk-based written information security program, oversee vendors, keep an incident response plan, certify compliance annually (domestic insurers), and report cybersecurity events to the Insurance Commissioner within three business days.

Where
Connecticut
Citation
Conn. Gen. Stat. 38a-38 (P.A. 19-117, s. 230, as amended)
Status
In force
In force since
2020-10-01
Enforced by
Connecticut Insurance Commissioner
People can sue
No
Penalties
After a hearing, the Insurance Commissioner may suspend or revoke licenses and impose a civil penalty of up to $50,000 per violation (38a-38(f)).
Applies to
  • Insurance licensees: any person licensed, authorized or registered (or required to be) under Connecticut insurance law, including fraternal benefit societies (38a-38(b)(7))
  • Since 2022-10-01 licensees with fewer than 10 employees (including contractors with data access) are exempt from the program requirements; HIPAA-compliant and NYDFS Part 500-compliant licensees may certify compliance instead (38a-38(c)(10))

Security duties

  • Develop, implement and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical and physical safeguards and a data retention and destruction schedule (by October 1, 2021).Conn. Gen. Stat. 38a-38(c)(1)-(4)
  • Consider and implement appropriate measures such as access controls, encryption of data in transit and on portable devices, multifactor authentication, secure disposal and cybersecurity awareness training.Conn. Gen. Stat. 38a-38(c)(4)(B)-(E)
  • Oversee third-party service providers and, by October 1, 2022, require them to implement appropriate security measures.Conn. Gen. Stat. 38a-38(c)(6)
  • Maintain a written incident response plan for cybersecurity events.Conn. Gen. Stat. 38a-38(c)(8)

Breach duties

  • Notify the Insurance Commissioner within three business days of determining a qualifying cybersecurity event occurred (for example, involving 250 or more Connecticut consumers and reportable elsewhere or likely to cause material harm), and comply with 36a-701b consumer notice, copying the Commissioner.Conn. Gen. Stat. 38a-38(e)(1)-(3)

Registration

  • Domestic insurers, health care centers and fraternal benefit societies must certify compliance to the Insurance Commissioner by April 15 each year.Conn. Gen. Stat. 38a-38(c)(9)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Amendment dates for P.A. 21-157 changes to 38a-38 not confirmed.

Research reference, not legal advice.