Loading chat...

MN HF3842

Bill

Status

Introduced

2/26/2020

Primary Sponsor

Steve Elkins

Click for details

Origin

House of Representatives

91st Legislature 2019-2020

AI Summary

  • Establishes a comprehensive Insurance Data Security Law requiring all Minnesota-regulated insurance licensees to develop, implement, and maintain written information security programs with administrative, technical, and physical safeguards for protecting nonpublic information.

  • Requires licensees to conduct risk assessments, designate security officers, implement specified security measures including encryption and multifactor authentication, and annually certify compliance to the commissioner by February 15.

  • Mandates licensees notify the commissioner of commerce or health within three business days of determining a cybersecurity event has occurred if it affects 250+ Minnesota consumers or could materially harm consumers or normal operations.

  • Requires prompt investigation of cybersecurity events, maintenance of incident response plans, and compliance with existing consumer notification requirements under Minnesota Statutes section 325E.61.

  • Exempts licensees with fewer than 25 employees, those compliant with HIPAA or federal banking safeguards, and certain affiliated entities; violations subject to penalties under section 60A.052; effective August 1, 2020 with one-year implementation period.

Legislative Description

Insurance Data Security Law established.

Last Action

Committee report, to adopt as amended and re-refer to Judiciary Finance and Civil Law Division

4/14/2020

Committee Referrals

Judiciary Finance and Civil Law4/14/2020
Commerce2/26/2020

Full Bill Text

No bill text available