Privacy Law Library

Insurer Information Security Program and Cybersecurity Event Notification

RI Insurance Data Security Law

Data security · Breach notification · Financial · Health · Biometric

Enacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.

Where
Rhode Island
Citation
R.I. Gen. Laws §§ 27-1-46, 27-1-47 (domestic insurers); 27-2-29, 27-2-30 (foreign insurers)
Status
In force
In force since
2025-01-01
Enforced by
Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)
People can sue
No
Penalties
No specific penalty in the sections; enforced through the insurance commissioner's examination (ch. 27-13.1) and general regulatory powers.
Applies to
  • Domestic insurance companies (ch. 27-1)
  • Foreign insurance companies licensed in Rhode Island (ch. 27-2)
  • Covers nonpublic information: sensitive business information, consumer identifiers combined with SSN, license, account or card numbers, access codes or biometric records, and health information

Security duties

  • Develop, implement and maintain a comprehensive written information security program, based on a risk assessment, with administrative, technical and physical safeguards for nonpublic information and information systems, including a retention and destruction schedule.R.I. Gen. Laws §§ 27-1-46(a)-(b), 27-2-29(a)-(b)
  • Designate responsible personnel, assess risks at least annually, and implement controls such as encryption of nonpublic information in transit and at rest, multi-factor authentication, and cybersecurity awareness training.R.I. Gen. Laws § 27-1-46(c)-(d)

Breach duties

  • Notify the commissioner within three business days after determining a cybersecurity event occurred that must be reported to another regulator or is reasonably likely to materially harm a Rhode Island consumer or the insurer's operations (foreign insurers: when 250 or more Rhode Island consumers are affected), and update the notice as information develops.R.I. Gen. Laws §§ 27-1-47(a)-(b), 27-2-30(a)
  • Comply with consumer notice under ch. 11-49.3 and send the commissioner a copy of the consumer notice; keep cybersecurity event records for five years; reinsurers must notify ceding insurers within 72 hours.R.I. Gen. Laws § 27-1-47(c)-(e)

Registration

  • Domestic insurers must submit a written statement to the commissioner by April 15 each year certifying compliance and keep supporting records for five years; HIPAA-compliant programs may be relied on for certification.R.I. Gen. Laws § 27-1-46(i)-(j) · Only if: Domestic insurers

Other duties

  • Boards of directors (or a committee) must oversee the program and receive at least annual reports; insurers must oversee third-party service providers.R.I. Gen. Laws § 27-1-46(e)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Text was read from the 2024 public law; the codified sections were confirmed by title in the chapter indexes only. | Subsection letters for training, encryption and board oversight in § 27-1-46 are approximate. | Characterization as based on the NAIC model law is an inference from matching structure.

Research reference, not legal advice.