SB0725112th GA (Historical)Introduced

Amends TCA Title 56, Chapter 2.

ON APRIL 8, 2021, THE HOUSE ADOPTED AMENDMENT #1 AND PASSED HOUSE BILL 766, AS AMENDED. AMENDMENT #1 rewrites this bill and enacts the "Insurance Data Security Law." The stated purpose of this amendment is to establish the exclusive standards for data security, licensees' investigations of cybersecurity events, and licensees' notification of cybersecurity events to the commissioner and affected consumers. A "licensee" for purposes of this amendment and summary is a person: licensed, authorized to operate, or registered pursuant to laws governing insurance in this state; or required to be licensed, authorized to operate, or registered pursuant to such; and does not include a purchasing group or risk retention group chartered and licensed in another state or a person acting as an assuming insurer and domiciled in another state or jurisdiction. This amendment requires the following, by July 1, 2022: (1) Commensurate with the size and complexity of the licensee and the nature and scope of its activities, each licensee to develop, implement, and maintain a comprehensive, written information security program based on the licensee's risk assessment (required by this amendment) that contains administrative, technical, and physical safeguards for the protection of the nonpublic information and the licensee's information system; (2) That a licensee's information security program be designed to: (A) Protect the security and confidentiality of nonpublic information and the security of the information system; (B) Protect against threats or hazards to the security or integrity of nonpublic information and the information system; (C) Protect against unauthorized access to or use of nonpublic information and minimize the likelihood of harm to a consumer as a result of unauthorized access or use; and (D) Define and periodically reevaluate a schedule for retaining nonpublic information and a mechanism for the destruction of nonpublic information when the information is no longer needed; (3) A licensee to conduct a risk assessment, the requirements for which are specified in detail in this amendment; (4) Based on a licensee's risk assessment, the licensee to: (A) Design an information security program to mitigate the identified risks, commensurate with the size and complexity of the licensee and the nature and scope of its activities; (B) Determine which of certain security measures (set out in detail in this amendment) are appropriate for the licensee and implement those security measures. Such measures include: placing access controls on information systems; restricting physical access to nonpublic information to authorized individuals; and utilizing effective controls that may include multi-factor authentication procedures for authorized individuals accessing nonpublic information; (C) Include cybersecurity risks in the licensee's enterprise risk management process; (D) Remain informed regarding emerging threats or vulnerabilities to the licensee and utilize reasonable security measures when sharing information, relative to the nature of the sharing and the type of information being shared; or (E) Provide personnel with cybersecurity awareness training that is updated as necessary to reflect risks identified by the licensee in the risk assessment; (5) If the licensee has a board of directors, then the board or an appropriate committee of the board to, at a minimum: (A) Require the licensee's executive management or delegates to develop, implement, and maintain the licensee's information security program; (B) Require the licensee's executive management or delegates to report in writing, at least annually: the status of the licensee's information security program and compliance with this amendment; and material matters related to the licensee's information security program, including risk assessment, risk management and control decisions, third-party service provider arrangements, results of testing, cybersecurity events or violations and the licensee's responses thereto, and recommendations for changes to the information security program; and (C) If the licensee's executive management delegates any of the executive management's responsibilities under this provision, then the executive management must oversee the development, implementation, and maintenance of the licensee's information security program prepared by the delegates and must either prepare the report or receive a copy of the report prepared by the delegates pursuant to (5)(B); (6) A licensee to exercise due diligence in selecting a third-party service provider and, by July 1, 2023, require that each third-party service provider implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information accessible to, or held by, the third-party service provider; (7) The licensee to monitor, evaluate, and adjust, as appropriate, its information security program, consistent with relevant changes in technology, the sensitivity of its nonpublic information, internal or external threats to its information, and its changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to information systems; (8) As part of a licensee's information security program, a licensee to establish a written incident response plan designed to promptly respond to, and recover from, a cybersecurity event that compromises the confidentiality, integrity, or availability of the licensee's nonpublic information or information systems or the continuing functionality of the licensee's operations. This amendment sets out in detail what must be addressed in the incident response; and (9) Each insurer domiciled in this state to submit to the commissioner by April 15 of each year written certification that the insurer is in compliance with this amendment. Each insurer must maintain for examination by the department all records, schedules, and data supporting the certification for a period of five years from the date of the corresponding certification. If an insurer identifies areas, systems, or processes requiring material improvement, updating, or redesign, then the insurer must document planned and ongoing remedial efforts to address those areas, systems, or processes, and the documentation must be made available for inspection by the commissioner upon request. This amendment also sets out in detail other requirements and processes governing the following: (1) Investigation of a cybersecurity event. This amendment requires that a prompt investigation be conducted if a licensee learns that a cybersecurity event has or may have occurred, then the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation. This amendment sets out minimum requirements for such an investigation; (2) Notification of a cybersecurity event. This amendment sets out in detail the requirements for notification, which include requiring a licensee to notify the commissioner as soon as practicable, and in no event more than three business days, following a determination that a cybersecurity event has occurred if: (A) The licensee is domiciled in this state, in the case of an insurer, or this state is the licensee's home state, in the case of an insurance producer; and the cybersecurity event has a reasonable likelihood of materially harming a consumer residing in this state or a material part of the licensee's normal operations; or (B) The licensee reasonably believes that the nonpublic information of 250 or more consumers residing in this state is involved in the cybersecurity event and that the cybersecurity event is: a cybersecurity event of which notice must be provided to a government body, self-regulatory agency, or other supervisory body pursuant to state or federal law; or a cybersecurity event with a reasonable likelihood of materially harming a consumer residing in this state or a material part of the licensee's normal operations; (3) Notice to consumers. Under this amendment, following a determination that a cybersecurity event has occurred, a licensee must notify consumers affected, or reasonably believed to have been affected, by the cybersecurity event. The disclosure must be made no later than 45 days after the determination of the cybersecurity event, unless a longer period of time is required due to the legitimate needs of law enforcement. This amendment sets out in detail other requirements regarding such notice, which includes alternative notice processes if the licensee demonstrates that the cost of providing notice would exceed $250,000, the affected class of subject persons to be notified exceeds 500,000 persons, or the licensee does not have sufficient contact information; (4) Authority of commissioner. This amendment authorizes the commissioner of commerce and insurance to examine and investigate a licensee to determine whether the licensee has been or is engaged in conduct in violation of this amendment. If the commissioner has reason to believe that a licensee has been or is engaged in conduct in this state that violates this amendment, then the commissioner may take necessary or appropriate action to enforce this amendment in accordance with present law provisions governing violations of the insurance laws by licensees; (5) Confidentiality. This amendment specifies that documents, materials, or information in the department's control or possession that are furnished by a licensee, or an employee or agent acting on behalf of the licensee, or that are obtained by the commissioner in connection with an investigation or examination are confidential and not open for inspection by members of the public and are not subject to subpoena or discovery in a private civil action, except that the commissioner may use the documents, materials, or information in the furtherance of regulatory or legal action by the commissioner. This amendment further specifies that the commissioner, or a person who received documents, materials, or information while acting under the authority of the commissioner, will not be permitted or required to testify in a private civil action concerning documents, materials, or information made confidential under this provisions. This amendment sets out certain limited exceptions under which certain documents may be shared; (6) Exceptions. This amendment specifies that it does not apply to a licensee who employs less than 25 individuals, regardless of whether the individuals are employees or independent contractors; a licensee with less than $5 million in gross annual revenue; or a licensee with less than $10 million in year-end total assets. This amendment also specifies that certain licensees will be deemed to be in compliance with certain provisions of this amendment, if the licensee subject to and complies with specified federal laws; and (7) Penalties. This amendment authorizes the commissioner to seek penalties under present for a violation of this amendment. Those present law provisions provide for, among other things, monetary penalties of up to $1,000 per violation, and of up to $25,000 per violation if the violation was intentional. ON APRIL 15, 2021, THE SENATE SUBSTITUTED HOUSE BILL 766 FOR SENATE BILL 725, ADOPTED AMENDMENT #1, AND PASSED HOUSE BILL 766, AS AMENDED. AMENDMENT #1 adds, in regard to the actions a licensee must take following a determination that a cybersecurity event has occurred, that the requirement to take such action applies if the licensee determines that the cybersecurity event has a reasonable likelihood of materially harming a consumer. This amendment also limits to whom the notice must be provided to "consumers residing in this state whose nonpublic information has been acquired or reasonably believed to have been acquired." Also, in regard to the confidentiality of certain documents and documents not being subject to subpoena or discovery (see above in summary for House Amendment #1 in item (5)), this amendment adds that the referenced documents are also not admissible in evidence in a private civil action.

What moved, what's on next week's agenda, new filings — every Monday, from the public record, free.

No account. Unsubscribe in one click.

Overview

ON APRIL 8, 2021, THE HOUSE ADOPTED AMENDMENT #1 AND PASSED HOUSE BILL 766, AS AMENDED. AMENDMENT #1 rewrites this bill and enacts the "Insurance Data Security Law." The stated purpose of this amendment is to establish the exclusive standards for data security, licensees' investigations of cybersecurity events, and licensees' notification of cybersecurity events to the commissioner and affected consumers. A "licensee" for purposes of this amendment and summary is a person: licensed, authorized to operate, or registered pursuant to laws governing insurance in this state; or required to be licensed, authorized to operate, or registered pursuant to such; and does not include a purchasing group or risk retention group chartered and licensed in another state or a person acting as an assuming insurer and domiciled in another state or jurisdiction. This amendment requires the following, by July 1, 2022: (1) Commensurate with the size and complexity of the licensee and the nature and scope of its activities, each licensee to develop, implement, and maintain a comprehensive, written information security program based on the licensee's risk assessment (required by this amendment) that contains administrative, technical, and physical safeguards for the protection of the nonpublic information and the licensee's information system; (2) That a licensee's information security program be designed to: (A) Protect the security and confidentiality of nonpublic information and the security of the information system; (B) Protect against threats or hazards to the security or integrity of nonpublic information and the information system; (C) Protect against unauthorized access to or use of nonpublic information and minimize the likelihood of harm to a consumer as a result of unauthorized access or use; and (D) Define and periodically reevaluate a schedule for retaining nonpublic information and a mechanism for the destruction of nonpublic information when the information is no longer needed; (3) A licensee to conduct a risk assessment, the requirements for which are specified in detail in this amendment; (4) Based on a licensee's risk assessment, the licensee to: (A) Design an information security program to mitigate the identified risks, commensurate with the size and complexity of the licensee and the nature and scope of its activities; (B) Determine which of certain security measures (set out in detail in this amendment) are appropriate for the licensee and implement those security measures. Such measures include: placing access controls on information systems; restricting physical access to nonpublic information to authorized individuals; and utilizing effective controls that may include multi-factor authentication procedures for authorized individuals accessing nonpublic information; (C) Include cybersecurity risks in the licensee's enterprise risk management process; (D) Remain informed regarding emerging threats or vulnerabilities to the licensee and utilize reasonable security measures when sharing information, relative to the nature of the sharing and the type of information being shared; or (E) Provide personnel with cybersecurity awareness training that is updated as necessary to reflect risks identified by the licensee in the risk assessment; (5) If the licensee has a board of directors, then the board or an appropriate committee of the board to, at a minimum: (A) Require the licensee's executive management or delegates to develop, implement, and maintain the licensee's information security program; (B) Require the licensee's executive management or delegates to report in writing, at least annually: the status of the licensee's information security program and compliance with this amendment; and material matters related to the licensee's information security program, including risk assessment, risk management and control decisions, third-party service provider arrangements, results of testing, cybersecurity events or violations and the licensee's responses thereto, and recommendations for changes to the information security program; and (C) If the licensee's executive management delegates any of the executive management's responsibilities under this provision, then the executive management must oversee the development, implementation, and maintenance of the licensee's information security program prepared by the delegates and must either prepare the report or receive a copy of the report prepared by the delegates pursuant to (5)(B); (6) A licensee to exercise due diligence in selecting a third-party service provider and, by July 1, 2023, require that each third-party service provider implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information accessible to, or held by, the third-party service provider; (7) The licensee to monitor, evaluate, and adjust, as appropriate, its information security program, consistent with relevant changes in technology, the sensitivity of its nonpublic information, internal or external threats to its information, and its changing business arrangements, such as mergers and acquisitions, alliances and joint ventures, outsourcing arrangements, and changes to information systems; (8) As part of a licensee's information security program, a licensee to establish a written incident response plan designed to promptly respond to, and recover from, a cybersecurity event that compromises the confidentiality, integrity, or availability of the licensee's nonpublic information or information systems or the continuing functionality of the licensee's operations. This amendment sets out in detail what must be addressed in the incident response; and (9) Each insurer domiciled in this state to submit to the commissioner by April 15 of each year written certification that the insurer is in compliance with this amendment. Each insurer must maintain for examination by the department all records, schedules, and data supporting the certification for a period of five years from the date of the corresponding certification. If an insurer identifies areas, systems, or processes requiring material improvement, updating, or redesign, then the insurer must document planned and ongoing remedial efforts to address those areas, systems, or processes, and the documentation must be made available for inspection by the commissioner upon request. This amendment also sets out in detail other requirements and processes governing the following: (1) Investigation of a cybersecurity event. This amendment requires that a prompt investigation be conducted if a licensee learns that a cybersecurity event has or may have occurred, then the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation. This amendment sets out minimum requirements for such an investigation; (2) Notification of a cybersecurity event. This amendment sets out in detail the requirements for notification, which include requiring a licensee to notify the commissioner as soon as practicable, and in no event more than three business days, following a determination that a cybersecurity event has occurred if: (A) The licensee is domiciled in this state, in the case of an insurer, or this state is the licensee's home state, in the case of an insurance producer; and the cybersecurity event has a reasonable likelihood of materially harming a consumer residing in this state or a material part of the licensee's normal operations; or (B) The licensee reasonably believes that the nonpublic information of 250 or more consumers residing in this state is involved in the cybersecurity event and that the cybersecurity event is: a cybersecurity event of which notice must be provided to a government body, self-regulatory agency, or other supervisory body pursuant to state or federal law; or a cybersecurity event with a reasonable likelihood of materially harming a consumer residing in this state or a material part of the licensee's normal operations; (3) Notice to consumers. Under this amendment, following a determination that a cybersecurity event has occurred, a licensee must notify consumers affected, or reasonably believed to have been affected, by the cybersecurity event. The disclosure must be made no later than 45 days after the determination of the cybersecurity event, unless a longer period of time is required due to the legitimate needs of law enforcement. This amendment sets out in detail other requirements regarding such notice, which includes alternative notice processes if the licensee demonstrates that the cost of providing notice would exceed $250,000, the affected class of subject persons to be notified exceeds 500,000 persons, or the licensee does not have sufficient contact information; (4) Authority of commissioner. This amendment authorizes the commissioner of commerce and insurance to examine and investigate a licensee to determine whether the licensee has been or is engaged in conduct in violation of this amendment. If the commissioner has reason to believe that a licensee has been or is engaged in conduct in this state that violates this amendment, then the commissioner may take necessary or appropriate action to enforce this amendment in accordance with present law provisions governing violations of the insurance laws by licensees; (5) Confidentiality. This amendment specifies that documents, materials, or information in the department's control or possession that are furnished by a licensee, or an employee or agent acting on behalf of the licensee, or that are obtained by the commissioner in connection with an investigation or examination are confidential and not open for inspection by members of the public and are not subject to subpoena or discovery in a private civil action, except that the commissioner may use the documents, materials, or information in the furtherance of regulatory or legal action by the commissioner. This amendment further specifies that the commissioner, or a person who received documents, materials, or information while acting under the authority of the commissioner, will not be permitted or required to testify in a private civil action concerning documents, materials, or information made confidential under this provisions. This amendment sets out certain limited exceptions under which certain documents may be shared; (6) Exceptions. This amendment specifies that it does not apply to a licensee who employs less than 25 individuals, regardless of whether the individuals are employees or independent contractors; a licensee with less than $5 million in gross annual revenue; or a licensee with less than $10 million in year-end total assets. This amendment also specifies that certain licensees will be deemed to be in compliance with certain provisions of this amendment, if the licensee subject to and complies with specified federal laws; and (7) Penalties. This amendment authorizes the commissioner to seek penalties under present for a violation of this amendment. Those present law provisions provide for, among other things, monetary penalties of up to $1,000 per violation, and of up to $25,000 per violation if the violation was intentional. ON APRIL 15, 2021, THE SENATE SUBSTITUTED HOUSE BILL 766 FOR SENATE BILL 725, ADOPTED AMENDMENT #1, AND PASSED HOUSE BILL 766, AS AMENDED. AMENDMENT #1 adds, in regard to the actions a licensee must take following a determination that a cybersecurity event has occurred, that the requirement to take such action applies if the licensee determines that the cybersecurity event has a reasonable likelihood of materially harming a consumer. This amendment also limits to whom the notice must be provided to "consumers residing in this state whose nonpublic information has been acquired or reasonably believed to have been acquired." Also, in regard to the confidentiality of certain documents and documents not being subject to subpoena or discovery (see above in summary for House Amendment #1 in item (5)), this amendment adds that the referenced documents are also not admissible in evidence in a private civil action.

Track Tennessee Legislation Like a Pro

Join hundreds of professionals using LegisGo to stay ahead of legislative changes.

Instant Alerts

Get notified when bills you track move through the legislature

AI Summaries

Understand complex legislation in seconds with AI-powered analysis

Full Access

All 132 legislators, committee schedules, and voting records

Sponsor

Unknown

Details
Session

112th General Assembly

Introduced

February 9, 2021

Subjects
241548231010

Want to track this bill? Get instant alerts and AI-powered insights.