Insurance Data Security Act
Iowa Insurance Data Security Act
Data security · Breach notification · Financial
Iowa's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Insurance Commissioner within three business days. Consumer notice follows the general breach law in chapter 715C.
- Where
- Iowa
- Citation
- Iowa Code ch. 507F (507F.1 to 507F.16)
- Status
- In force
- In force since
- 2022-01-01
- Enforced by
- Iowa Commissioner of Insurance (Iowa Insurance Division)
- People can sue
- No
- Penalties
- Violations are subject to penalties under Iowa Code 505.7A and chapter 507B (unfair insurance trade practices) (507F.14). The chapter creates no private cause of action (507F.2(2)).
- Applies to
- Licensees of the Iowa Insurance Division (insurers, producers, and other persons licensed or required to be licensed under Iowa insurance law) (507F.3)
- Information security program duties do not apply to licensees with fewer than 20 workforce members, under $5 million in gross annual revenue, or under $10 million in year-end total assets (507F.4)
- Exempt: licensees subject to and compliant with HIPAA (with annual certification), and licensees owned or controlled by a federally insured depository institution compliant with GLBA (507F.13)
Security duties
- Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with safeguards assessed at least annually (compliance required by January 1, 2023).Iowa Code 507F.4 · Only if: Licensee is not a small licensee under 507F.4 · From 2023-01-01
- Exercise due diligence in selecting third-party service providers and require them to protect information systems and nonpublic information (by January 1, 2024).Iowa Code 507F.5 · From 2024-01-01
Breach duties
- Promptly investigate any suspected cybersecurity event and keep records of it.Iowa Code 507F.6
- Notify the Commissioner within three business days of confirming a cybersecurity event when Iowa is the home state and specified harm or legal-notice triggers apply, or when nonpublic information of 250 or more Iowa consumers is involved and a trigger applies.Iowa Code 507F.7(1)-(2)
- Notify consumers under the general breach law (715C.2) and send the Commissioner copies of consumer notices when a Commissioner notice was required.Iowa Code 507F.8
Other duties
- Domiciled insurers must certify compliance with the information security program requirements to the Commissioner by April 15 each year and keep supporting records for five years.Iowa Code 507F.4(8) · Only if: Insurer domiciled in Iowa
Sources
- Official text
- Iowa Code ch. 507F (Iowa Code 2026, Iowa Legislature)
- 2021 Iowa Acts ch. 79 (HF 719), effective January 1, 2022
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The subsection number of the annual certification duty (507F.4(8)) was read from the PDF text layout and should be spot-checked.
Research reference, not legal advice.