Privacy Law Library

Maryland Insurance Data Security law (Insurance Article Title 33)

MD Insurance Data Security

Data security · Breach notification · Financial

Enacted by 2022 Md. Laws ch. 231 (SB 207), Maryland's version of the NAIC Insurance Data Security Model Law requires insurance carriers to run a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days of determining a qualifying event, along with consumer notice under the Personal Information Protection Act.

Where
Maryland
Citation
Md. Code, Ins. §§ 33-101 to 33-109
Status
In force
In force since
2022-10-01
Enforced by
Maryland Insurance Commissioner
People can sue
No
Penalties
Penalty of $100 to $125,000 per violation, in addition to other sanctions (33-108). The title creates no private cause of action (33-102(b)).
Applies to
  • Carriers: authorized insurers, nonprofit health service plans, HMOs, dental organizations, managed general agents, and third-party administrators; excludes out-of-state purchasing and risk retention groups (33-101(c))
  • HIPAA-compliant carriers are deemed compliant with the program and investigation duties but must still notify the Commissioner (33-106(a))

Security duties

  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical, and physical safeguards, a data retention and destruction schedule, and at least annual assessment of key controls.Ins. 33-103(a)-(c)
  • Require third-party service providers to implement appropriate measures to protect information systems and nonpublic information they access or hold.Ins. 33-103(h)

Breach duties

  • Promptly investigate any actual or possible cybersecurity event, restore security, and keep records of all cybersecurity events for at least 5 years.Ins. 33-104
  • Notify the Commissioner within 3 business days of determining a cybersecurity event occurred if Maryland is the domicile state and harm is reasonably likely, or if 250+ Maryland consumers are involved and notice is required elsewhere or material harm is reasonably likely.Ins. 33-105(a)-(b)
  • Notify consumers as required by Com. Law 14-3504 and give the Commissioner a copy of the consumer notice.Ins. 33-105(e)

Other duties

  • Certify compliance to the Commissioner by April 15 each year and keep supporting records for 5 years (qualifying out-of-state carriers exempt).Ins. 33-103(j)-(k)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Any delayed implementation dates inside ch. 231 for particular requirements were not checked.

Research reference, not legal advice.