Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Security topic

No spam. Unsubscribe anytime.

Committee amends data-security law to require producers and licensees to report cyber incidents; bill sent to floor

2663444 ยท March 17, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The committee approved Senate Bill 2088, amending North Dakota's insurance data-security law to tighten reporting requirements for licensees (including producers) and to align with state breach-notification code; the bill drew industry input and a unanimous-to-near-unanimous committee vote with one recorded no vote.

The House Industry, Business and Labor Committee voted to recommend Senate Bill 2088, which tightens data-security reporting for insurance licensees and clarifies the department's examination and reporting authorities.

"To fulfill the department's mission of serving the needs of the insurance consumers in North Dakota, we believe Senate Bill 20 Senate Bill 2,088 strengthens our role as a consumer protection agency," Matt Fisher, division director of company licensing and examinations for the North Dakota Insurance Department, told the committee. Fisher said the measure would remove several carve-outs that have led to inconsistent reporting and would tie the reporting trigger to North Dakota Century Code 51-30 (the state's general cybersecurity/breach-notification statute).

The bill removes language that allowed licensees to avoid reporting events when nonpublic information was later claimed to have been deleted or returned to an attacker; Fisher cited examples from other breaches where data allegedly returned was later sold. The bill also eliminates a "materiality" threshold that the department said allowed large firms to treat the unauthorized access of a single individual's data as nonreportable. Fisher said the department already has statutory authority to examine licensees and that the bill would preserve the ability to issue general examination reports while avoiding disclosure of granular IT findings.

Industry witnesses described extensive negotiation with the department. "We were able to discuss some of the noise and over reporting that we thought was part of the original bill, got to a good compromise, and, are supportive of the draft as it is today," Megan Ruby of Blue Cross Blue Shield of North Dakota said.

Committee members asked how producers and small licensees would be affected. Fisher said the bill would still exempt small licensees from maintaining a full information-security program but would require a plan commensurate with their size and complexity and a known vendor point of contact. He said that if a producer has no consumer data on its own systems and all data resides only with a carrier, the producer would typically not be subject to reporting.

Representative Schauer moved and Representative Bail seconded a due-pass recommendation. The committee called the roll and recommended the bill. Representative Casper recorded the lone recorded "No" vote during the roll call; the remainder of the committee voted in favor. A committee member volunteered to carry the bill to the floor.

The department reported that it has received fewer cyber incident reports than expected since the original 2021 law โ€” roughly 60 reports over four years, many associated with large national breaches โ€” and that the bill is intended to close loopholes the department says discourage reporting. Fisher said the department has cybersecurity expertise on staff and can call outside contractors for examinations when necessary.

The committee closed the hearing after hearing no opposition and agreed the revisions strike a balance between avoiding trivial "noise" and ensuring consumer-impacting incidents are reported to the department.

Votes at a glance

- Motion: Recommend Senate Bill 2088 (due pass) - Mover: Representative Schauer - Second: Representative Bail - Outcome: approved - Roll call (as recorded in committee): multiple members recorded "Yes"; Representative Casper recorded "No."