Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Senate committee hears bill to tighten cybersecurity reporting for insurers
Summary
The North Dakota Insurance Department urged the Industry and Business Committee to amend state insurance data‑security law to require broader reporting of cyber incidents affecting consumer data, shorten the reporting window and remove exemptions that limit the department—s ability to examine certain licensees.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Senate Industry and Business Committee on Tuesday heard testimony on Senate Bill 2088, a department‑sponsored bill to amend the state—s insurance data security law to require broader reporting of cybersecurity events and give regulators more authority to examine incidents that may affect consumers.
The North Dakota Insurance Department told the committee the bill would remove a current exclusion that allowed licensees to avoid reporting incidents when nonpublic information was accessed but, the licensee says, returned or deleted; shorten the statutory reporting window; eliminate a materiality threshold some companies used to avoid reporting; and remove exemptions for certain small licensees and some HIPAA‑covered entities that previously could not be examined by the department after an incident.
The department—s division director of company licensing and examinations, Matt Fisher, said the state—s law was originally based on the National Association of Insurance Commissioners— (NAIC) 2016 model and that deviations made when the statute was first enacted have produced unintended consequences. Fisher said his office stopped receiving incident reports after a high‑profile breach last year in which the victim paid a ransom, was told data had been deleted, and then the stolen data appeared for sale on the dark web. "We are aware of breaches that have happened since October that are affecting the insurance industry, and we—re not getting anything," Fisher said, arguing the change is needed so the department can perform consumer protection work.
Under the bill, the department would align the reporting period with the model law by changing "3 business days" to 72 hours, and it would let the department—s leadership and the RAND board set the attachment point and coinsurance within statutory floors and ceilings (see related item on the RAND board in a separate article). Fisher said the department offers an amendment designed with a large domestic health insurer to narrow the definition of reportable events so routine internal IT touches (for example, a general ledger) need not be reported while events that could compromise consumer data must be reported.
Industry witnesses told the committee they remain concerned about two provisions: the removal of the materiality threshold and shortening the reporting window from three business days to a flat 72 hours. Dennis Pathroff, a lobbyist for the American Property Casualty Insurance Association (APCIA) and the American Council of Life Insurers (ACLI), said smaller insurers and agents may not have staff available on weekends and holidays to prepare the required notice within 72 hours and asked the committee to retain "3 business days." Pathroff also said the department and industry have been negotiating and that the amendment offered by the department moved the bill in the right direction.
Committee members asked about enforcement and penalties. Fisher said the insurance commissioner has enforcement tools under other statutes, including fines. He described a maximum fine provision in statute that can reach up to $10,000 per violation, but said legal staff would negotiate details if enforcement became necessary. The department also said it would not publish sensitive operational details from an examination that could assist bad actors; public summaries would describe what happened and how consumers were protected, while detailed IT findings would remain in confidential management letters.
Several senators pressed for clarity on the bill—s scope and asked whether the department and industry could reach consensus on the definition and timing language. Fisher said the department had reached agreement with its largest domestic health insurer on the offered amendment but not with the entire industry and wanted the committee—s input.
No committee vote occurred; the bill received a public hearing and the committee recessed to continue its agenda.
The committee received written amendments and negotiations were ongoing between the department and industry representatives following the hearing; committee members signaled interest in preserving a reporting standard that would be workable for small insurers while ensuring consumer incidents are reported to the regulator.
The hearing record contains several technical clarifications and proposed text changes that committee staff and stakeholders asked to refine in subsequent drafts.
The hearing closed with the committee taking no final action on SB 2088.
