Insurance Data Security Law
Connecticut · 38A · §§ 38a-38 to 38a-38 · 1 section
Overview
The Insurance Data Security Law governs how insurers, agents, and other entities licensed by a state's insurance regulator protect nonpublic information they hold and respond when that protection fails. It requires licensees to develop and maintain a written information security program, to investigate cybersecurity events affecting their systems or data, and to notify the state insurance regulator when such an event occurs. The act also grants the regulator investigative and rulemaking authority, keeps information gathered under it confidential, exempts certain licensees from some or all of its requirements, and provides penalties for noncompliance.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- Conn. Gen. Stat. § 38a-38Insurance Data Security Law. Regulations
Enacted in other states
Alabama, Illinois, Louisiana, Mississippi, New Hampshire, Vermont
All Connecticut named statutes →
Download
Copy
Embed on your site
Hover to preview · click to copy the code