Insurance Data Security Law
NH Insurance Data Security Law
Data security · Breach notification · Financial
New Hampshire's adoption of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee vendors, keep an incident response plan, investigate cybersecurity events and report qualifying events to the Insurance Commissioner within 3 business days. Consumer notice follows the general breach law, RSA 359-C:20.
- Where
- New Hampshire
- Citation
- N.H. Rev. Stat. Ann. ch. 420-P
- Status
- In force
- In force since
- 2020-01-01
- Enforced by
- New Hampshire Insurance Commissioner
- People can sue
- No
- Penalties
- Penalties under RSA 400-A:15, III: for knowing violations, license suspension or revocation or administrative fines up to $2,500 per violation.
- Applies to
- Insurers, producers and other persons licensed or required to be licensed by the NH Insurance Department
- Information security program duties do not apply to licensees with fewer than 20 employees, continuing care retirement communities, life settlement providers, and GLBA-compliant banks and credit unions; vendors under RSA 402-K are fully exempt
Security duties
- Develop, implement and maintain a comprehensive written information security program based on a risk assessment and commensurate with the licensee's size, complexity and data sensitivity, including a data retention and destruction schedule.RSA 420-P:4, I-II · Only if: Licensees with 20 or more employees
- Maintain a written incident response plan covering roles, communications, remediation, documentation and post-event review.RSA 420-P:4, VIII
- Require third-party service providers to implement appropriate administrative, technical and physical safeguards for systems and nonpublic information they access or hold.RSA 420-P:4, VI(b)
Breach duties
- Promptly investigate any actual or possible cybersecurity event and keep records of all events for at least 5 years.RSA 420-P:5
- Notify affected consumers as required by RSA 359-C:20 and send the Commissioner a copy of the consumer notice.RSA 420-P:6, III
- Notify the Insurance Commissioner within 3 business days of determining a qualifying cybersecurity event occurred (NH domicile or home state with likely material harm, or 250+ NH consumers involved), with specified details and ongoing updates.RSA 420-P:6, I-II
Other duties
- NH-domiciled insurers must certify compliance to the Commissioner annually by March 1 and keep supporting records for 5 years.RSA 420-P:4, IX
Sources
- Official text
- RSA ch. 420-P, Insurance Data Security Law (NH General Court)
- RSA 400-A:15, Powers of Commissioner (penalties)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Research reference, not legal advice.