Insurer Information Security Program and Cybersecurity Event Notification

RI Insurance Data Security Law
active

Enacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.

Jurisdiction

Rhode Island

Jurisdiction Type

state

Country

United States

Effective Date

1/1/2025

Enforcing Authority

Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)

Fines Under This Regulation

0

Total Fine Amount (USD)

--