Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Data Security topic
No spam. Unsubscribe anytime.
Committee hears bill to require insurers to adopt cybersecurity programs; Department of Commerce and Insurance supports measure
Summary
House Bill 4 36, the Insurance Data Security Act, would require insurance licensees to maintain risk-based information security programs and report cybersecurity events to the Department of Commerce and Insurance; the department and industry groups testified in support.
Get email alerts on the Data Security topic
No spam. Unsubscribe anytime.
Representative Bill Hardwick introduced House Bill 4 36, the Insurance Data Security Act, saying that “in this day and age, there are more and more cyberattacks” and that insurance licensees hold large amounts of personal data. He told the committee the bill “requires that those licensees implement a cybersecurity defensive program that's consistent with the complexity, the size and scope of their business operation and the risk,” and that cybersecurity events would be reported to the Department of Commerce and Insurance.
Hardwick and subsequent witnesses framed the measure as aligning Missouri with a national model. Hampton Williams of the Missouri Insurance Coalition told the committee the bill largely follows model language produced by the National Association of Insurance Commissioners and that 26 states have adopted similar rules since 2017. Williams summarized the bill's main elements: annual risk assessments, written information security programs, incident response plans, notification of the insurance commissioner and consumer notification when breaches occur, and due diligence for third-party vendors.
Larry Case of the Missouri Association of Insurance Agents registered support without additional comment. Tyler Hobbs, legislative director for the Missouri Department of Commerce and Insurance, said the department supports the bill and expects to work with the sponsor on technical tweaks.
Committee members asked questions about storage and retention, quantum computing and whether the statute should prescribe specific technical protocols. Representative Murphy asked whether the bill should address how data is stored in light of advances such as quantum computing; Hardwick responded that the bill intentionally avoids prescribing specific technical standards because cybersecurity technology changes quickly. He said the bill instead requires a risk-based program and reporting, preserving flexibility for businesses to adopt appropriate measures. Hardwick also noted an existing statutory protection he authored in 2021 that keeps cybersecurity vulnerabilities out of sunshine/open-records disclosure.
No witnesses in opposition were recorded in the hearing segment of the transcript, and the Department of Commerce and Insurance and multiple industry groups registered support. The committee concluded the hearing and moved to the next item.
