Insurer Information Security Program and Cybersecurity Event Notification
RI Insurance Data Security LawEnacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.
Jurisdiction
Rhode Island
Jurisdiction Type
state
Country
United States
Effective Date
1/1/2025
Enforcing Authority
Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)
Fines Under This Regulation
0
Total Fine Amount (USD)
--