Maryland Insurance Data Security law (Insurance Article Title 33)
MD Insurance Data Security
Data security · Breach notification · Financial
Enacted by 2022 Md. Laws ch. 231 (SB 207), Maryland's version of the NAIC Insurance Data Security Model Law requires insurance carriers to run a risk-based written information security program, oversee vendors, investigate cybersecurity events, and notify the Insurance Commissioner within 3 business days of determining a qualifying event, along with consumer notice under the Personal Information Protection Act.
- Where
- Maryland
- Citation
- Md. Code, Ins. §§ 33-101 to 33-109
- Status
- In force
- In force since
- 2022-10-01
- Enforced by
- Maryland Insurance Commissioner
- People can sue
- No
- Penalties
- Penalty of $100 to $125,000 per violation, in addition to other sanctions (33-108). The title creates no private cause of action (33-102(b)).
- Applies to
- Carriers: authorized insurers, nonprofit health service plans, HMOs, dental organizations, managed general agents, and third-party administrators; excludes out-of-state purchasing and risk retention groups (33-101(c))
- HIPAA-compliant carriers are deemed compliant with the program and investigation duties but must still notify the Commissioner (33-106(a))
Security duties
- Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical, and physical safeguards, a data retention and destruction schedule, and at least annual assessment of key controls.Ins. 33-103(a)-(c)
- Require third-party service providers to implement appropriate measures to protect information systems and nonpublic information they access or hold.Ins. 33-103(h)
Breach duties
- Promptly investigate any actual or possible cybersecurity event, restore security, and keep records of all cybersecurity events for at least 5 years.Ins. 33-104
- Notify the Commissioner within 3 business days of determining a cybersecurity event occurred if Maryland is the domicile state and harm is reasonably likely, or if 250+ Maryland consumers are involved and notice is required elsewhere or material harm is reasonably likely.Ins. 33-105(a)-(b)
- Notify consumers as required by Com. Law 14-3504 and give the Commissioner a copy of the consumer notice.Ins. 33-105(e)
Other duties
- Certify compliance to the Commissioner by April 15 each year and keep supporting records for 5 years (qualifying out-of-state carriers exempt).Ins. 33-103(j)-(k)
Sources
- Official text
- Md. Code, Ins. § 33-101 (definitions)
- Md. Code, Ins. § 33-102 (purpose; no private action)
- Md. Code, Ins. § 33-103 (information security program)
- Md. Code, Ins. § 33-104 (investigation)
- Md. Code, Ins. § 33-105 (notification)
- Md. Code, Ins. § 33-106 (HIPAA deemed compliance)
- Md. Code, Ins. § 33-108 (penalties)
- 2022 Md. Laws ch. 231 (SB 207), effective 2022-10-01
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Any delayed implementation dates inside ch. 231 for particular requirements were not checked.
Research reference, not legal advice.