Privacy Law Library

Insurance Data Security Act

Iowa Insurance Data Security Act

Data security · Breach notification · Financial

Iowa's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Insurance Commissioner within three business days. Consumer notice follows the general breach law in chapter 715C.

Where
Iowa
Citation
Iowa Code ch. 507F (507F.1 to 507F.16)
Status
In force
In force since
2022-01-01
Enforced by
Iowa Commissioner of Insurance (Iowa Insurance Division)
People can sue
No
Penalties
Violations are subject to penalties under Iowa Code 505.7A and chapter 507B (unfair insurance trade practices) (507F.14). The chapter creates no private cause of action (507F.2(2)).
Applies to
  • Licensees of the Iowa Insurance Division (insurers, producers, and other persons licensed or required to be licensed under Iowa insurance law) (507F.3)
  • Information security program duties do not apply to licensees with fewer than 20 workforce members, under $5 million in gross annual revenue, or under $10 million in year-end total assets (507F.4)
  • Exempt: licensees subject to and compliant with HIPAA (with annual certification), and licensees owned or controlled by a federally insured depository institution compliant with GLBA (507F.13)

Security duties

  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with safeguards assessed at least annually (compliance required by January 1, 2023).Iowa Code 507F.4 · Only if: Licensee is not a small licensee under 507F.4 · From 2023-01-01
  • Exercise due diligence in selecting third-party service providers and require them to protect information systems and nonpublic information (by January 1, 2024).Iowa Code 507F.5 · From 2024-01-01

Breach duties

  • Promptly investigate any suspected cybersecurity event and keep records of it.Iowa Code 507F.6
  • Notify the Commissioner within three business days of confirming a cybersecurity event when Iowa is the home state and specified harm or legal-notice triggers apply, or when nonpublic information of 250 or more Iowa consumers is involved and a trigger applies.Iowa Code 507F.7(1)-(2)
  • Notify consumers under the general breach law (715C.2) and send the Commissioner copies of consumer notices when a Commissioner notice was required.Iowa Code 507F.8

Other duties

  • Domiciled insurers must certify compliance with the information security program requirements to the Commissioner by April 15 each year and keep supporting records for five years.Iowa Code 507F.4(8) · Only if: Insurer domiciled in Iowa

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: The subsection number of the annual certification duty (507F.4(8)) was read from the PDF text layout and should be spot-checked.

Research reference, not legal advice.