Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Security Insurance topic
No spam. Unsubscribe anytime.
Committee advances Insurance Data Security Act after industry and regulator back the bill
Summary
The House Business Committee voted to send House Bill 117 to the floor after testimony from insurers, trade groups and the Idaho Department of Insurance that the bill would require insurers to report breaches and set baseline security expectations while exempting very small firms.
Get email alerts on the Data Security Insurance topic
No spam. Unsubscribe anytime.
House Bill 117, the Insurance Data Security Act, advanced from the House Business Committee on March 11 after supporters from the insurance industry and the Idaho Department of Insurance said the measure will create statewide reporting and minimum safeguards for nonpublic consumer data.
Representative Jordan Redmond, R‑Kootenai County, told the committee the bill would “establish essential common sense industry standards for reporting data breaches and standards for protection [of] personal information.” He said the measure exempts companies with fewer than 50 employees and was drafted with input from the Department of Insurance and the insurance industry.
The bill’s backers — including United Heritage Life Insurance Company, the Idaho Counties Risk Management Program, the Idaho Association of Health Plans, the American Property Casualty Insurance Association and State Farm — told the committee they supported the measure. Jeff Neumeier, chief administrative officer and general counsel for United Heritage, said the bill is a “workable solution that protects consumer data in insurance related transactions” and urged a due‑pass recommendation. Steve Thomas, representing the Idaho Association of Health Plans, said the bill was based on the National Association of Insurance Commissioners model and takes care to avoid duplicating federal HIPAA regulation.
Wes Trexler, deputy director of the Idaho Department of Insurance, answered committee questions about the bill’s definitions and its requirements for licensees to require third‑party vendors to safeguard data. Trexler described common scenarios in which insurers must share nonpublic information — for example, to process credit‑card payments or to provide claims information to independent adjusters — and said the bill would require both insurers and their service providers to protect that information and report losses to the department.
Committee members asked how insurers must verify third parties’ safeguards and how a licensee could determine that accessed nonpublic information “has not been used or released,” language that creates an exception to the cybersecurity‑event definition. Trexler pointed to investigation requirements in the bill (the committee was shown draft language in a provision cited as provisions for investigation and reporting) that direct a licensee to assess the scope of a potential event, identify affected information, and document findings — a standard the department included in the draft.
Representative Birch moved to send the bill to the House floor with a due pass recommendation. The committee completed a roll‑call vote and the motion carried, 7 to 5.
Supporters told the committee the law would improve transparency after breaches and promote coordination across jurisdictions, while maintaining tailored compliance for small carriers. Several committee members voiced reservations about specific language and reserved the right to vote differently on the House floor.
The committee record includes written and in‑person testimony from insurer trade groups and carriers; the Department of Insurance staff responded to technical questions about investigation standards and vendor contracting.
Representative Redmond closed by asking for a due‑pass recommendation and said the bill aims to protect Idaho consumers without imposing undue burdens on the industry.
The bill now goes to the full House.
