Insurance Data Security Law
CT Insurance Data Security Law
Data security · Breach notification · Financial
Connecticut's version of the NAIC Insurance Data Security Model Law. Insurers, producers and other licensees must run a risk-based written information security program, oversee vendors, keep an incident response plan, certify compliance annually (domestic insurers), and report cybersecurity events to the Insurance Commissioner within three business days.
- Where
- Connecticut
- Citation
- Conn. Gen. Stat. 38a-38 (P.A. 19-117, s. 230, as amended)
- Status
- In force
- In force since
- 2020-10-01
- Enforced by
- Connecticut Insurance Commissioner
- People can sue
- No
- Penalties
- After a hearing, the Insurance Commissioner may suspend or revoke licenses and impose a civil penalty of up to $50,000 per violation (38a-38(f)).
- Applies to
- Insurance licensees: any person licensed, authorized or registered (or required to be) under Connecticut insurance law, including fraternal benefit societies (38a-38(b)(7))
- Since 2022-10-01 licensees with fewer than 10 employees (including contractors with data access) are exempt from the program requirements; HIPAA-compliant and NYDFS Part 500-compliant licensees may certify compliance instead (38a-38(c)(10))
Security duties
- Develop, implement and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical and physical safeguards and a data retention and destruction schedule (by October 1, 2021).Conn. Gen. Stat. 38a-38(c)(1)-(4)
- Consider and implement appropriate measures such as access controls, encryption of data in transit and on portable devices, multifactor authentication, secure disposal and cybersecurity awareness training.Conn. Gen. Stat. 38a-38(c)(4)(B)-(E)
- Oversee third-party service providers and, by October 1, 2022, require them to implement appropriate security measures.Conn. Gen. Stat. 38a-38(c)(6)
- Maintain a written incident response plan for cybersecurity events.Conn. Gen. Stat. 38a-38(c)(8)
Breach duties
- Notify the Insurance Commissioner within three business days of determining a qualifying cybersecurity event occurred (for example, involving 250 or more Connecticut consumers and reportable elsewhere or likely to cause material harm), and comply with 36a-701b consumer notice, copying the Commissioner.Conn. Gen. Stat. 38a-38(e)(1)-(3)
Registration
- Domestic insurers, health care centers and fraternal benefit societies must certify compliance to the Insurance Commissioner by April 15 each year.Conn. Gen. Stat. 38a-38(c)(9)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Amendment dates for P.A. 21-157 changes to 38a-38 not confirmed.
Research reference, not legal advice.