Insurance Data Security Law

Tenn. Insurance Data Security Law
active

Tennessee's version of the NAIC Insurance Data Security Model Law. Insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, notify the Commissioner within three business days of qualifying events, and notify affected Tennessee consumers within 45 days when an event is reasonably likely to cause them material harm.

Jurisdiction

Tennessee

Jurisdiction Type

state

Country

United States

Effective Date

7/1/2021

Enforcing Authority

Tennessee Commissioner of Commerce and Insurance

Fines Under This Regulation

0

Total Fine Amount (USD)

--