Insurance Information and Privacy Protection Act and Insurance Data Security Act
VA insurance privacy
Financial · Data security · Breach notification · Health
Virginia's insurance privacy law limits pretext interviews, requires notices of information practices, gives consumers access and correction rights and reasons for adverse underwriting decisions, and restricts disclosure of medical and privileged information without written authorization. The 2020 Insurance Data Security Act adds a written information security program, cybersecurity-event investigation, notice to the Commissioner within three business days, and consumer breach notice.
- Where
- Virginia
- Citation
- Va. Code §§ 38.2-600 to 38.2-620 (Art. 1) and 38.2-621 to 38.2-629 (Art. 2, Insurance Data Security Act)
- Status
- In force
- In force since
- 1981-07-01
- Last amended
- 2022-07-01
- Enforced by
- State Corporation Commission, Bureau of Insurance (38.2-614, 38.2-627)
- People can sue
- Limited
- Penalties
- Individuals may seek equitable relief for access, correction, and adverse-decision violations and actual damages for unlawful disclosure, with fees, within two years (38.2-617); the Data Security Act creates no private action (38.2-622); Commission enforcement otherwise.
- Applies to
- Insurance institutions, agents, and insurance-support organizations collecting information in connection with insurance transactions involving Virginia residents (38.2-601)
- Licensees of the Bureau of Insurance for the Insurance Data Security Act (38.2-621), with HIPAA and GLBA-affiliate compliance safe harbors (38.2-629)
What a privacy notice must say
- Provide a notice of insurance information practices to applicants and policyholders.Va. Code § 38.2-604
- Give specific reasons and information sources for adverse underwriting decisions.Va. Code § 38.2-610
Rights it gives people
- Give individuals access to, and a process to correct, amend, or delete, recorded personal information.Va. Code § 38.2-608; 38.2-609
Practices it requires
- Do not disclose medical-record or privileged information without written authorization except as listed.Va. Code § 38.2-613
- Do not use pretext interviews to obtain information in connection with an insurance transaction (narrow claim-investigation exception).Va. Code § 38.2-603
Security duties
- Develop, implement, and maintain a risk-based comprehensive written information security program, including retention and destruction schedules.Va. Code § 38.2-623 · From 2020-07-01
Breach duties
- Notify the Commissioner as promptly as possible and within three business days of determining a cybersecurity event occurred, for domestic insurers or when 250+ Virginia consumers are involved.Va. Code § 38.2-625(A) · From 2020-07-01
- Notify consumers without unreasonable delay when nonpublic information was acquired and identity theft or fraud is reasonably likely.Va. Code § 38.2-626 · From 2020-07-01
Sources
- Official text
- Va. Code Title 38.2, Chapter 6, Insurance Information and Privacy Protection (law.lis.virginia.gov)
- 2020 HB 1334 (Acts 2020, c. 264, Insurance Data Security Act, effective 2020-07-01) bill history (Virginia LIS)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Original 1981 effective date inferred from Virginia's default July 1 date (1981, c. 389). last_amended 2022-07-01 is based on the latest chapter in the history notes (2022, c. 509 in § 38.2-608) and the default July 1 date; not checked against the bill. Staggered compliance dates for the information security program, if any, were not checked.
Research reference, not legal advice.