Insurance Data Security
IN Insurance Data Security
Data security · Breach notification · Financial
Indiana's version of the NAIC Insurance Data Security Model Law requires insurance licensees to run a written, risk-based information security program, oversee vendors, and keep an incident response plan. They must investigate cybersecurity events and notify the Insurance Commissioner within three business days of certain events. Consumer notice follows the general breach law, IC 24-4.9.
- Where
- Indiana
- Citation
- Ind. Code ch. 27-2-27 (IC 27-2-27-1 to 27-2-27-32)
- Status
- In force
- In force since
- 2021-07-01
- Enforced by
- Indiana Insurance Commissioner / Department of Insurance
- People can sue
- No
- Penalties
- After notice and hearing, the commissioner may suspend or revoke the licensee's license or registration (IC 27-2-27-27). No private right of action (IC 27-2-27-29); compliant licensees get an affirmative defense to data-breach tort claims (IC 27-2-27-32).
- Applies to
- Persons licensed, authorized, or registered, or required to be, under Indiana insurance law (insurers, producers, and others) (IC 27-2-27-10)
- Licensees with fewer than 50 employees, under $5 million in revenue, or under $10 million in assets are exempt from the program requirements (sections 16-20) but not from cybersecurity event notice; HIPAA-compliant licensees are deemed compliant except for notice (IC 27-2-27-26)
Security duties
- Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical, and physical safeguards.IC 27-2-27-16, 27-2-27-17 · Only if: Not required for small licensees exempt under IC 27-2-27-26(a)
- Maintain a written incident response plan for cybersecurity events.IC 27-2-27-20
- Based on the risk assessment, use measures such as encryption of nonpublic information in transit and on portable devices and multi-factor authentication for employees who access nonpublic information.IC 27-2-27-18
- The board of directors (if any) must require management to develop and maintain the program and receive reports on it.IC 27-2-27-19
Breach duties
- Promptly investigate suspected cybersecurity events and keep records of all events for five years.IC 27-2-27-21(a)-(b)
- Notify the Insurance Commissioner within three business days after determining that a qualifying cybersecurity event occurred (Indiana-domiciled insurer or home-state producer, or at least 250 Indiana consumers affected).IC 27-2-27-21(c)-(e)
- Notify consumers under IC 24-4.9 and give the commissioner a copy of the consumer notice.IC 27-2-27-21(f)
Sources
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: The effective date comes from IC 27-2-27-1 ('applies after June 30, 2021'); the P.L.130-2020 enrolled act was not opened.
Research reference, not legal advice.