Two States Enact Insurance Data Security Laws


In April 2022, two states enacted insurance data security legislation based on the National Association of Insurance Commissioners (“NAIC”) Insurance Data Security Model Law (MDL-668). Kentucky Governor Andy Beshear signed HB 474 into law on April 8, 2022, and Maryland Governor Larry Hogan signed SB 207 into law on April 21, 2022. The new laws establish data security obligations for insurance carriers and generally require carriers to take the following actions, subject to certain exemptions:

Maryland’s law takes effect on October 1, 2022, with certain grace periods for compliance as follows:

Kentucky’s law goes into effect on January 1, 2023. Similar to Maryland, the Kentucky law grants a one-year grace period with respect to the requirement to establish a written information security program and a two-year grace period for compliance with relevant service provider oversight requirements.


Copyright © 2025, Hunton Andrews Kurth LLP. All Rights Reserved.
National Law Review, Volume XII, Number 124