Insurance Data Security

IN Insurance Data Security
active

Indiana's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a written, risk-based information security program, oversee vendors, and keep an incident response plan. They must investigate cybersecurity events and notify the Insurance Commissioner within three business days of certain events. Consumer notice follows the general breach law, IC 24-4.9.

Jurisdiction

Indiana

Jurisdiction Type

state

Country

United States

Effective Date

7/1/2021

Enforcing Authority

Indiana Insurance Commissioner / Department of Insurance

Fines Under This Regulation

0

Total Fine Amount (USD)

--