DATE: XX X, XXXX
TO: Insurers, Nonprofit Health Service Plans, Health Maintenance Organizations, Dental Organizations, Managed General Agents and Third Party Administrators
RE: Insurance Data Security – Notification of Cybersecurity Event
The purpose of this Bulletin is to provide additional guidance on the cybersecurity event reporting requirements as originally conveyed in Bulletin 22-13 and mandated by Insurance Article § 33-1051, which requires carriers to notify the Commissioner of a cybersecurity event within three business days when there is a reasonable likelihood a consumer's non-public information was compromised.
Reporting Requirement
As a reminder, “Carrier" is defined in § 33-101 to mean an authorized insurer; a nonprofit health service plan; a health maintenance organization; a dental organization; a managed general agent; or a third-party administrator. “Cybersecurity event" is defined in § 33-101(e) to mean “an event resulting in unauthorized access to, or disruption or misuse of, an information system or nonpublic information stored on an information system."
Section 33-105 provides the reporting requirements for both domestic and non- domestic carriers, under sub-section (a) as follows:
(a) A carrier shall notify the Commissioner as promptly as possible but in no event later than 3 business days from a determination that a cybersecurity event has occurred when either of the following criteria has been met:
(1)(i) the State is the carrier's state of domicile; and (ii) the cybersecurity event has a reasonable likelihood of harming a consumer residing in the State or any material part of the normal operations of the carrier; or
(2) the carrier reasonably believes that the nonpublic information involved is of 250 or more consumers residing in the State and either of the following circumstances is present:
(i) a cybersecurity event impacting the carrier has occurred for which notice must be provided to a government body, self-regulatory agency, or any other supervisory body under state or federal law; or
(ii) a cybersecurity event has occurred that has a reasonable likelihood of materially harming:
1. a consumer residing in the State; or
2. a material part of the normal operation of the carrier.
(emphasis added)
It is our experience that many events are not reported timely. A carrier domiciled in Maryland is required to report within the required 3-day window from the date of a determination that a cybersecurity event occurred. The Administration considers a “reasonable likelihood of harm" to be an event that more likely than not will result in harm to a consumer with respect to the disclosure of non-public information. Carriers should not wait to report an event until they know beyond a reasonable doubt that nonpublic Information has been compromised. A domestic carrier that has had any material part of normal operations harmed or disrupted is also required to report the cybersecurity event to the MIA. Please note there is no minimum threshold number of potentially impacted consumers if the carrier is a domestic carrier. If there is a reasonable likelihood that any Maryland consumer sustained harm by the event, submit the information to the Administration within the 3 business day window. Furthermore, Third Party administrators handling work for carriers are subject to the cyber security law and the reporting requirement as noted above. A third party administrator should report the incident as required by the statute when applicable. Carriers with customers impacted by an event targeting an administrator should also report the incident.
Pursuant to § 33-105, if a carrier is not a domestic carrier, that carrier is also required to notify the Commissioner within 3 business days from a determination that a cybersecurity event has occurred when a carrier reasonably believes that the nonpublic information of 250 or more residents of Maryland is involved and either one of two requirements is present:
(i) the incident must be reported to a government body, self–regulatory agency, or any other supervisory body under state or federal law; or
(ii) a consumer or the carrier's normal operations are materially harmed by the event.
Carriers are required to report within 3 business days2 from the date that the carrier reasonably believes that the conditions requiring a report are met. A carrier may not delay reporting until it has certainty as to the number of Maryland residents, the degree to which nonpublic information is involved, or that there is material harm; the statute requires reasonable belief or reasonable likelihood.
The intent of timely notification is to help the Administration immediately step in, if needed, to assist in mitigation efforts when warranted. There is no penalty for reporting an incident with a likelihood of impact that ultimately does not involve non-public information after the investigation into the incident is completed. The Administration does and will continue to enforce compliance with the reporting requirement. The Cybersecurity event reporting form is located on the MIA site.
Please direct questions concerning this Bulletin to Mary Kwei, Associate Commissioner for Market Regulation and Professional Licensing at (410) 468-2113 or [email protected]
MARIE GRANT
Commissioner
Signature on Original
Mary M. Kwei
Associate Commissioner
Market Regulation & Professional Licensing
1 All statutory references herein are to the Insurance Article, Maryland Annotated Code, unless otherwise specified.
2“Business days" is interpreted to mean any calendar day other than a Saturday, Sunday or State holiday consistent with guidance provided in MD Bulletin 2024-18.