Loading chat...

MI HB6268

Bill

Status

Introduced

12/10/2024

Primary Sponsor

Donavan McKinney

Click for details

Origin

House of Representatives

102nd Legislature

AI Summary

  • Removes requirement for licensees to determine whether a cybersecurity event has caused substantial loss or injury before notifying affected residents, making notification mandatory upon discovery of unauthorized access to personal information.

  • Modifies definition of "cybersecurity event" to focus on unauthorized access or disruption rather than "acquisition" of information, and simplifies exception for encrypted data breaches to cases where data has not been used, released, and has been returned or destroyed.

  • Adds new enforcement authority allowing the director to examine and investigate licensees for violations of data security requirements under section 222, with ability to take necessary action to enforce the chapter.

  • Establishes that licensees violating the data security chapter are subject to civil fines under section 150 of the Insurance Code.

  • Makes technical amendments to section 563 regarding confidentiality of licensee documents and materials submitted to the director for regulatory purposes.

Legislative Description

Insurance: other; data security enforcement; modify. Amends secs. 553, 561 & 563 of 1956 PA 218 (MCL 500.553 et seq.) & adds secs. 564 & 564a.

Insurance: other

Last Action

Bill Electronically Reproduced 12/11/2024

12/11/2024

Committee Referrals

Insurance And Financial Services12/10/2024

Full Bill Text

No bill text available