Insurer Information Security Program and Cybersecurity Event Notification
RI Insurance Data Security Law
Data security · Breach notification · Financial · Health · Biometric
Enacted in 2024 and effective January 1, 2025, this law adapts the NAIC Insurance Data Security Model Law. Insurers must keep a written, risk-based information security program for nonpublic consumer information with encryption, multi-factor authentication, training, vendor oversight and board oversight, and must notify the insurance commissioner within three business days of qualifying cybersecurity events.
- Where
- Rhode Island
- Citation
- R.I. Gen. Laws §§ 27-1-46, 27-1-47 (domestic insurers); 27-2-29, 27-2-30 (foreign insurers)
- Status
- In force
- In force since
- 2025-01-01
- Enforced by
- Rhode Island Department of Business Regulation, Insurance Division (commissioner/director)
- People can sue
- No
- Penalties
- No specific penalty in the sections; enforced through the insurance commissioner's examination (ch. 27-13.1) and general regulatory powers.
- Applies to
- Domestic insurance companies (ch. 27-1)
- Foreign insurance companies licensed in Rhode Island (ch. 27-2)
- Covers nonpublic information: sensitive business information, consumer identifiers combined with SSN, license, account or card numbers, access codes or biometric records, and health information
Security duties
- Develop, implement and maintain a comprehensive written information security program, based on a risk assessment, with administrative, technical and physical safeguards for nonpublic information and information systems, including a retention and destruction schedule.R.I. Gen. Laws §§ 27-1-46(a)-(b), 27-2-29(a)-(b)
- Designate responsible personnel, assess risks at least annually, and implement controls such as encryption of nonpublic information in transit and at rest, multi-factor authentication, and cybersecurity awareness training.R.I. Gen. Laws § 27-1-46(c)-(d)
Breach duties
- Notify the commissioner within three business days after determining a cybersecurity event occurred that must be reported to another regulator or is reasonably likely to materially harm a Rhode Island consumer or the insurer's operations (foreign insurers: when 250 or more Rhode Island consumers are affected), and update the notice as information develops.R.I. Gen. Laws §§ 27-1-47(a)-(b), 27-2-30(a)
- Comply with consumer notice under ch. 11-49.3 and send the commissioner a copy of the consumer notice; keep cybersecurity event records for five years; reinsurers must notify ceding insurers within 72 hours.R.I. Gen. Laws § 27-1-47(c)-(e)
Registration
- Domestic insurers must submit a written statement to the commissioner by April 15 each year certifying compliance and keep supporting records for five years; HIPAA-compliant programs may be relied on for certification.R.I. Gen. Laws § 27-1-46(i)-(j) · Only if: Domestic insurers
Other duties
- Boards of directors (or a committee) must oversee the program and receive at least annual reports; insurers must oversee third-party service providers.R.I. Gen. Laws § 27-1-46(e)
Sources
- Official text
- R.I. Gen. Laws ch. 27-1 index (§§ 27-1-46, 27-1-47)
- R.I. Gen. Laws ch. 27-2 index (§§ 27-2-29, 27-2-30)
- P.L. 2024, ch. 354 (2024-H 7281 Sub A), effective January 1, 2025
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Text was read from the 2024 public law; the codified sections were confirmed by title in the chapter indexes only. | Subsection letters for training, encryption and board oversight in § 27-1-46 are approximate. | Characterization as based on the NAIC model law is an inference from matching structure.
Research reference, not legal advice.