Privacy Law Library

Kentucky Insurance Data Security Law

KY Insurance Data Security

Data security · Breach notification · Financial

Kentucky's version of the NAIC Insurance Data Security Model Law. Covered insurance licensees must run a risk-based written information security program, oversee third-party service providers, investigate cybersecurity events, and report qualifying events to the Commissioner within three business days. Domestic insurers must certify compliance annually.

Where
Kentucky
Citation
KRS 304.3-750 to 304.3-768 (created 2022 Ky. Acts ch. 149, HB 474)
Status
In force
In force since
2023-01-01
Enforced by
Kentucky Department of Insurance (Commissioner)
People can sue
No
Penalties
Penalties follow the general Insurance Code penalty provision, KRS 304.99-020.
Applies to
  • Licensees of the Kentucky Department of Insurance (insurers, producers, and others licensed or authorized under the Insurance Code)
  • Exempt: licensees with fewer than 50 employees, including independent contractors

Security duties

  • Exercise due diligence in selecting third-party service providers and require them to implement appropriate safeguards for accessible nonpublic information.KRS 304.3-756(6)
  • Designate a responsible person, identify threats, assess safeguards at least annually, apply controls such as access limits, encryption, and possibly multi-factor authentication, monitor systems, keep audit trails, and train personnel.KRS 304.3-756(3)-(4)
  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with administrative, technical, and physical safeguards scaled to the licensee's size, activities, and data sensitivity, including data retention and destruction schedules compliant with KRS 365.725.KRS 304.3-756(2)

Breach duties

  • Promptly investigate any cybersecurity event involving nonpublic information.KRS 304.3-758
  • Notify the Commissioner within 3 business days of determining a cybersecurity event occurred when Kentucky is the insurer's domicile or producer's home state, or when 250 or more Kentucky consumers are involved and notice is required elsewhere or material harm is reasonably likely; include prescribed details and a copy of any KRS 365.732 consumer notice, and update as facts develop.KRS 304.3-760(1)-(2)

Other duties

  • Domestic insurers must certify compliance to the Commissioner by February 15 each year and keep supporting records for five years.KRS 304.3-756(9) · Only if: Insurers domiciled in Kentucky
  • Executive management must report at least annually in writing to the board (if any) on program status and material security matters.KRS 304.3-756(5)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Bill number HB 474 (2022) comes from a search-result link to the legislature's bill document; the statute history confirms 2022 Ky. Acts ch. 149. | KRS 304.3-758 (investigation) and 304.3-766 were read from index titles only; the absence of a private right of action was not confirmed in the text (NAIC model language typically says none). | Implementing regulation 806 KAR 3:250 (cybersecurity reporting procedures) was identified by search but not fetched.

Research reference, not legal advice.