Insurance Data Security Law
Alabama · Insurance · §§ 27-62-1 to 27-62-9 · 11 sections
Overview
The Insurance Data Security Law governs how insurers, agents, and other entities licensed by a state's insurance regulator protect nonpublic information they hold and respond when that protection fails. It requires licensees to develop and maintain a written information security program, to investigate cybersecurity events affecting their systems or data, and to notify the state insurance regulator when such an event occurs. The act also grants the regulator investigative and rulemaking authority, keeps information gathered under it confidential, exempts certain licensees from some or all of its requirements, and provides penalties for noncompliance.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- Ala. Code § 27-62-1Short Title.
- Ala. Code § 27-62-10Penalties.
- Ala. Code § 27-62-11Rules.
- Ala. Code § 27-62-2Purpose and Intent.
- Ala. Code § 27-62-3Definitions.
- Ala. Code § 27-62-4Information Security Program.
- Ala. Code § 27-62-5Investigation of Cybersecurity Event.
- Ala. Code § 27-62-6Notification of Cybersecurity Event.
- Ala. Code § 27-62-7Power of Commissioner.
- Ala. Code § 27-62-8Confidentiality.
- Ala. Code § 27-62-9Exceptions.
Enacted in other states
Connecticut, Illinois, Louisiana, Mississippi, New Hampshire, Vermont
Download
Copy
Embed on your site
Hover to preview · click to copy the code