An Act To Enact the Maine Insurance Data Security Act
Sec. 1. 24-A MRSA c. 24-B is enacted to read:
CHAPTER 24-B
MAINE INSURANCE DATA SECURITY ACT
§ 2261. Short title
This chapter may be known and cited as "the Maine Insurance Data Security Act."
§ 2262. Construction
This chapter establishes standards for data security and standards for the investigation of and notification to the superintendent regarding a cybersecurity event applicable to licensees. This chapter may not be construed to create or imply a private cause of action for violation of its provisions or to curtail a private cause of action that would otherwise exist in the absence of this chapter.
§ 2263. Definitions
As used in this chapter, unless the context otherwise indicates, the following terms have the following meanings.
"Cybersecurity event" does not include the unauthorized acquisition of encrypted nonpublic information if the encryption process or key is not also acquired, released or used without authorization.
"Cybersecurity event" does not include an event with regard to which the licensee has determined that the nonpublic information accessed by an unauthorized person has not been used or released and has been returned or destroyed.
(1) Social security number;
(2) Driver's license number or nondriver identification card number;
(3) Account number or credit or debit card number;
(4) Any security code, access code or password that would permit access to a consumer's financial account; or
(5) Biometric records; or
(1) The past, present or future physical, mental or behavioral health or condition of a consumer or a member of the consumer's family;
(2) The provision of health care to a consumer; or
(3) Payment for the provision of health care to a consumer.
For the purposes of this definition, a licensee has a reasonable basis to believe that information is lawfully made available to the general public if the licensee has taken steps to determine that the information is of a type that is available to the general public; and whether a consumer can direct that the information not be made available to the general public and, if so, that the consumer has not done so.
§ 2264. Information security program
(1) Employee training and management;
(2) Information systems, including network and software design, as well as information classification, governance, processing, storage, transmission and disposal; and
(3) Detecting, preventing and responding to attacks, intrusions or other system failures; and
(1) Place access controls on information systems, including controls to authenticate and permit access only to authorized individuals to protect against the unauthorized acquisition of nonpublic information;
(2) Identify and manage the data, personnel, devices, systems and facilities that enable the licensee to achieve its business purposes in accordance with their relative importance to business objectives and the licensee's risk management strategy;
(3) Restrict to only authorized individuals access at physical locations containing nonpublic information;
(4) Protect, by encryption or other appropriate means, all nonpublic information while it is being transmitted over an external network and all nonpublic information stored on a laptop computer or other portable computing or storage device or media;
(5) Adopt secure development practices for applications developed and used by the licensee and procedures for evaluating, assessing or testing the security of externally developed applications used by the licensee;
(6) Modify the information system in accordance with the licensee's information security program;
(7) Use effective controls, which may include multifactor authentication procedures, for individuals accessing nonpublic information;
(8) Regularly test and monitor systems and procedures to detect actual and attempted attacks on or intrusions into information systems;
(9) Include audit trails within the information security program designed to detect and respond to cybersecurity events and designed to reconstruct material financial transactions sufficient to support normal operations and obligations of the licensee;
(10) Implement measures to protect against destruction, loss or damage of nonpublic information due to environmental hazards, such as fire and water damage, or other catastrophes or technological failures; and
(11) Develop, implement and maintain procedures for the secure disposal of nonpublic information in any format;
(1) The overall status of the licensee's information security program and the licensee's compliance with this chapter; and
(2) Material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, 3rd-party service provider arrangements, results of testing, cybersecurity events or cybersecurity violations and the executive management's responses to cybersecurity events or cybersecurity violations, and recommendations for changes to the information security program.
If a licensee's executive management delegates any of its responsibilities under this section, the licensee's executive management shall oversee each delegate's efforts with respect to the development, implementation and maintenance of the licensee's information security program and shall require each delegate to submit a report to the board pursuant to paragraph B.
§ 2265. Investigation of cybersecurity event
§ 2266. Notification of cybersecurity event
(1) A cybersecurity event affecting the licensee of which notice is required to be provided to any government body, self-regulatory organization or other supervisory body pursuant to any state or federal law; or
(2) A cybersecurity event that has a reasonable likelihood of materially harming:
(a) Any consumer residing in this State; or
(b) Any material part of the normal operation of the licensee.
The licensee has a continuing obligation to update and supplement initial and subsequent notifications to the superintendent concerning the cybersecurity event.
Nothing in this subsection or in this chapter may be construed to prevent or abrogate an agreement between a licensee and another licensee, a 3rd-party service provider or any other party to fulfill any of the investigation requirements imposed under section 2265 or notice requirements imposed under this subsection.
(1) The assuming insurer shall notify its affected ceding insurers and the superintendent of its state of domicile within 72 hours of making the determination that a cybersecurity event has occurred; and
(2) The ceding insurers that have a direct contractual relationship with affected consumers shall fulfill the consumer notification requirements imposed under the laws of this State and any other notification requirements relating to a cybersecurity event imposed under this section.
(1) The assuming insurer shall notify its affected ceding insurers and the superintendent of its state of domicile within 72 hours of receiving notice from its 3rd-party service provider that a cybersecurity event has occurred; and
(2) The ceding insurers that have a direct contractual relationship with affected consumers shall fulfill the consumer notification requirements imposed under the laws of this State and any other notification requirements relating to a cybersecurity event imposed under this section.
§ 2267. Power of superintendent
§ 2268. Confidentiality
§ 2269. Application; exceptions
If a licensee ceases to qualify for an exception under this section, the licensee has 180 days to comply with this chapter.
§ 2270. Penalties
The superintendent may take any enforcement action permitted under section 12-A against any person that violates any provision of this chapter.
§ 2271. Rules
The superintendent may adopt rules necessary to carry out the provisions of this chapter. Rules adopted pursuant to this section are routine technical rules as defined by Title 5, chapter 375, subchapter 2-A.
§ 2272. Effective date; implementation
This chapter takes effect January 1, 2021. A licensee must comply with section 2264 no later than January 1, 2021, except that a licensee must comply with section 2264, subsection 6 no later than January 1, 2023.
summary
This bill enacts the Maine Insurance Data Security Act. The bill establishes standards for information security programs based on ongoing risk assessment for protecting consumers' personal information. The bill establishes requirements for the investigation of and notification to the Superintendent of Insurance regarding cybersecurity events.