Insurance Data Security Act
Iowa · Insurance Data Security · §§ 507F.1 to 507F.9 · 16 sections
Overview
The Insurance Data Security Act governs how entities licensed by the state insurance commissioner safeguard the information they hold and how they must respond when that information or their systems are compromised. It requires licensees to maintain an information security program, to address security in their arrangements with third-party service providers, and to investigate cybersecurity events, including those originating with a service provider. It further establishes notification duties — to the commissioner, to affected consumers, and between insurers, reinsurers, and producers of record — together with confidentiality protections for information supplied to the commissioner and the commissioner's authority to adopt rules, enforce the act, and impose penalties.
Editorial summary generated from the text of this act. It is not part of the statute — read the sections below for the operative language.
Sections covered
- Iowa Code § 507F.1Title
- Iowa Code § 507F.10Cybersecurity event reinsurers
- Iowa Code § 507F.11Cybersecurity event — producers of record
- Iowa Code § 507F.12Confidentiality
- Iowa Code § 507F.13Applicability
- Iowa Code § 507F.14Penalties
- Iowa Code § 507F.15Rules and enforcement
- Iowa Code § 507F.16Severability
- Iowa Code § 507F.2Purpose and scope
- Iowa Code § 507F.3Definitions
- Iowa Code § 507F.4Information security program
- Iowa Code § 507F.5Third-party service provider arrangements
- Iowa Code § 507F.6Cybersecurity event — investigation
- Iowa Code § 507F.7Cybersecurity event — notification and report to the commissioner
- Iowa Code § 507F.8Cybersecurity event — notification to consumers
- Iowa Code § 507F.9Cybersecurity event — third-party service providers
Enacted in other states
Download
Copy
Embed on your site
Hover to preview · click to copy the code