Idaho 2025 Regular Session

Idaho House Bill H0117

Introduced
2/4/25  
Refer
2/5/25  

Caption

Adds to existing law to establish the Insurance Data Security Act in the event of cybersecurity attacks.

Summary

House Bill 117 creates a new chapter in Idaho insurance law called the Insurance Data Security Act. It requires insurance licensees to develop, implement, and maintain written information security programs with administrative, technical, and physical safeguards for nonpublic information and information systems. The bill also requires incident response planning, record retention, and prompt investigation of cybersecurity events, including events involving third-party service providers. The bill establishes notice obligations for cybersecurity events. Depending on the circumstances, licensees must notify the Idaho insurance director within 10 business days after determining that a qualifying cybersecurity event occurred, and must notify affected Idaho consumers without unreasonable delay when material harm is likely. The bill also addresses special notice rules for reinsurers, insurers using independent producers, and events handled by third-party service providers. It gives the insurance director authority to examine and investigate compliance, share confidential materials with regulators and law enforcement under safeguards, and enforce the chapter through existing civil penalty provisions.

Impact

The bill adds a new regulatory framework to Title 41 governing insurance data security in Idaho. It imposes compliance duties on insurers, producers, and other insurance licensees regarding cybersecurity governance, breach investigation, and notification, while also creating confidentiality protections for information submitted to the department. The act preempts other state standards for covered licensees on these topics and expressly removes application of Idaho Code sections 28-51-104 through 28-51-107 to licensees. It also includes exemptions for smaller licensees and for entities already covered by HIPAA, GLBA-related safeguards, or comparable insurance data security laws in other jurisdictions.

Sentiment

The bill appears generally favorable and administrative in nature, aimed at strengthening cybersecurity protections in the insurance sector rather than creating a new consumer-rights enforcement scheme. The available context shows it was introduced by the House Business Committee and there are no recorded votes or committee transcript excerpts indicating opposition or debate. Its structure suggests support for aligning Idaho with standard insurance cybersecurity requirements used in other states and regulatory frameworks.

Contention

The main points of potential contention are the compliance burden and scope of preemption. Smaller insurers and producers may view the information security program, investigation, and notice requirements as costly or administratively demanding, which is why the bill includes exemptions and a delayed compliance date. Another possible issue is that the bill bars a private cause of action, meaning enforcement is left to the insurance director and civil penalties rather than lawsuits by consumers. The bill also centralizes state standards and displaces other state breach-notice provisions for licensees, which may be seen as simplifying compliance by some and limiting alternative remedies by others.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.