Insurance Data Security Law
Illinois · Insurance · §§ 215-215-1 to 215-215-999 · 14 sections
Overview
The Insurance Data Security Law governs how insurers, agents, and other entities licensed by a state's insurance regulator protect nonpublic information they hold and respond when that protection fails. It requires licensees to develop and maintain a written information security program, to investigate cybersecurity events affecting their systems or data, and to notify the state insurance regulator when such an event occurs. The act also grants the regulator investigative and rulemaking authority, keeps information gathered under it confidential, exempts certain licensees from some or all of its requirements, and provides penalties for noncompliance.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- 215 ILCS 215/1Short title
- 215 ILCS 215/10Information security program
- 215 ILCS 215/105(Amendatory provisions; text omitted)
- 215 ILCS 215/15Investigation of a cybersecurity event
- 215 ILCS 215/2Purpose and intent
- 215 ILCS 215/20Notification of a cybersecurity event
- 215 ILCS 215/25Power of Director
- 215 ILCS 215/30Confidentiality
- 215 ILCS 215/35Exceptions
- 215 ILCS 215/40Penalties
- 215 ILCS 215/45Rules
- 215 ILCS 215/5Definitions
- 215 ILCS 215/50Severability
- 215 ILCS 215/999Effective date
Enacted in other states
Alabama, Connecticut, Louisiana, Mississippi, New Hampshire, Vermont
Download
Copy
Embed on your site
Hover to preview · click to copy the code