Privacy Law Library

Privacy of Consumer Financial and Health Information and Standards for Safeguarding Customer Information (insurance regulations)

RI Insurance Privacy Regulations

Financial · Health · Data security · Breach notification

Rhode Island's insurance-sector implementation of Gramm-Leach-Bliley privacy and safeguards rules, adopted under R.I. Gen. Laws §§ 27-58-4 and 27-58-10. Licensees must give initial and annual privacy notices and an opt-out before sharing consumers' nonpublic financial information with nonaffiliated third parties, must obtain written authorization before disclosing nonpublic health information outside listed insurance functions, and must maintain written information security programs.

Where
Rhode Island
Citation
230-RICR-20-60-7 (formerly Insurance Regulation 99); 230-RICR-20-60-8
Status
In force
Enforced by
Rhode Island Department of Business Regulation, Insurance Division
People can sue
No
Penalties
The insurance regulators may investigate and impose fines and other sanctions as authorized by law (230-RICR-20-60-7 § 7.25).
Applies to
  • All insurance licensees of the Rhode Island Department of Business Regulation: licensed insurers, producers and other persons licensed, authorized or registered under the insurance laws

What a privacy notice must say

  • Provide clear and conspicuous initial privacy notices to consumers and annual notices to customers describing information practices, and revised notices when practices change.230-RICR-20-60-7 §§ 7.5-7.7, 7.9

Rights it gives people

  • Give consumers a reasonable opportunity and method to opt out before disclosing nonpublic personal financial information to nonaffiliated third parties, subject to service-provider, joint-marketing, processing and other exceptions.230-RICR-20-60-7 §§ 7.8, 7.12, 7.15-7.17

Practices it requires

  • Do not share account numbers or access codes with nonaffiliated third parties for marketing.230-RICR-20-60-7 § 7.14
  • Do not disclose nonpublic personal health information without the individual's authorization, except for listed insurance functions such as claims administration; HIPAA-compliant licensees are exempt from the health provisions.230-RICR-20-60-7 §§ 7.18-7.19, 7.2

Security duties

  • Implement a comprehensive written information security program with administrative, technical and physical safeguards for customer information, including risk assessment, service-provider oversight and program adjustment.230-RICR-20-60-8 §§ 8.4-8.10

Breach duties

  • A licensee required to send breach notices under R.I. Gen. Laws § 11-49.3-4 must also send notice of the breach to the Department of Business Regulation.230-RICR-20-60-8 § 8.11

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Effective and last-amended dates of both regulation parts were not captured from the Secretary of State pages.

Research reference, not legal advice.