May 24, 2012

Q&A: Connecticut’s New Data Breach Mandate from Connecticut Department of Insurance

Risk Management Monitor

Many states are enacting data breach notification laws, but Connecticut is the first state to have its insurance department get involved, enacting what is known as Bulletin IC-25. Wanting to know more about this recent development, I contacted Ed Goodman, chief privacy officer at Identity Theft 911. Below is our exchange:

What is Bulletin IC-25?

EG: On August 18, 2010, the Connecticut Insurance Department issued Bulletin IC-25. Bulletin IC-25 covers the handling of information security incidents that pose a potential risk to an individual’s personal health and/or financial information.

Is Connecticut the first state to issue such requirements for insurance companies doing business in the state?

EG: While CT already has data breach notification laws, this is the first time any state Insurance Department set out specific stringent breach requirements for insurance companies doing business in its state.

Why is this rule important?

EG: Insurance companies doing business in Connecticut must know how the rule affects them and what they are required to do if they suffer a data breach. Companies with BOP (business owner policies) need to know how the new law affects their business customers, so they can address concerns and meet their customers’ needs. While other states (California and Massachusetts) have been on the cutting edge of data breach regulations, Connecticut is the first to establish the insurance department in an active role in data breaches specifically in the insurance industry. Understanding breach regulations is crucial to every insurance company to:
*       Avoid sanctions or fines
*       Preserve goodwill with people who trust them with their personal data
*       Listening, then advising, educating and advocating protecting and restoring their identities

Do you see other states enacting the same sort of rule in the near future?

EG: Other state insurance departments will follow Connecticut. So all U.S. insurance companies should be prepared and knowledgeable, as well. The State of Connecticut Insurance Department’s Bulletin IC-25 is the beginning of a trend towards high scrutiny security incidents by regulators, especially in the insurance industry. Expect to see more departments following suit in the coming years.

data breach

The above article is reprinted from the Risk Management Monitor - the official blog of Risk Management magazine.

Reprinted with permission from the Risk Management Monitor. Copyright 2010 Risk and Insurance Management Society, Inc. All rights reserved.

About the Author

Editor

Emily Holbrook is the editor of Risk Management magazine and the Risk Management Monitor blog.

212-655-5915

Boost: AJAX core statistics

Legal Disclaimer

You are responsible for reading, understanding and agreeing to the National Law Review's (NLR’s) and the National Law Forum LLC's  Terms of Use and Privacy Policy before using the National Law Review website. The National Law Review is a free to use, no-log in database of legal and business articles. The content and links on www.NatLawReview.com are intended for general information purposes only. Any legal analysis, legislative updates or other content and links should not be construed as legal or professional advice or a substitute for such advice. No attorney-client or confidential relationship is formed by the transmission of information between you and the National Law Review website or any of the law firms, attorneys or other professionals or organizations who include content on the National Law Review website. If you require legal or professional advice, kindly contact an attorney or other suitable professional advisor.  

Some states have laws and ethical rules regarding solicitation and advertisement practices by attorneys and/or other professionals. NLR does not accept advertising from attorneys or law firms. The National Law Review is not a law firm nor is www.NatLawReview.com  intended to be an advertisement or a referral service for attorneys and/or other professionals. The NLR does not wish, nor does it intend, to solicit the business of anyone or to refer anyone to an attorney or other professional.  NLR does not answer legal questions nor will we refer you to an attorney or other professional if you request such information from us. 

Under certain state laws the following statements may be required on this website and we have included them in order to be in full compliance with these rules. The choice of a lawyer or other professional is an important decision and should not be based solely upon advertisements. Attorney Advertising Notice: Prior results do not guarantee a similar outcome. Statement in compliance with Texas Rules of Professional Conduct. Unless otherwise noted, attorneys are not certified by the Texas Board of Legal Specialization, nor can NLR attest to the accuracy of any notation of Legal Specialization or other Professional Credentials.