North Dakota 2025-2026 Regular Session

North Dakota Senate Bill SB2088

Introduced
1/7/25  
Refer
1/7/25  
Report Pass
1/29/25  
Engrossed
2/3/25  
Refer
2/18/25  
Report Pass
3/17/25  
Enrolled
3/24/25  

Caption

AN ACT to amend and reenact subsection 4 of section 26.1-02.2-01, sections 26.1-02.2-05 and 26.1-02.2-07, and subsection 1 of section 26.1-02.2-08 of the North Dakota Century Code, relating to data security requirements for insurance producers; and to repeal section 26.1-02.2-11 of the North Dakota Century Code, relating to implementation dates for certain data security requirements for insurance producers.

Summary

SB 2088 updates North Dakota’s insurance data security law for insurance producers, insurers, and certain third-party service providers. The bill revises the definition of a “cybersecurity event,” clarifies when encrypted data incidents are excluded, and tightens the timing and content of required notices to the Insurance Commissioner when nonpublic information is involved. It generally requires prompt notice within three business days after a qualifying event is determined, and it expands the list of information that must be reported, including the nature of the breach, affected consumers, remediation efforts, and whether law enforcement or other regulators were notified. The bill also addresses cybersecurity events involving third-party service providers, assuming insurers, and insurers that use independent insurance producers. In those cases, it allocates notice responsibilities among the parties and requires insurers to notify producers of record when consumer notice is required. The bill preserves the requirement to comply with North Dakota’s consumer breach-notification law, chapter 51-30, and it repeals a prior implementation-date section that is no longer needed. It also updates confidentiality provisions governing information shared with the commissioner and other regulators, and it maintains certain exemptions for smaller licensees and entities already subject to HIPAA-compliant privacy and security rules.

Impact

SB 2088 amends chapter 26.1-02.2 of the North Dakota Century Code, which governs insurance data security requirements. Its practical effect is to refine reporting obligations, clarify who must notify whom after a cybersecurity event, and strengthen the commissioner’s oversight by requiring more detailed incident reporting and updated follow-up notices. It also preserves confidentiality protections for materials submitted during investigations and allows sharing with other regulators, law enforcement, and consultants under confidentiality agreements. Affected parties include insurers, insurance producers, assuming insurers, ceding insurers, third-party service providers, and consumers whose nonpublic information may be compromised.

Sentiment

The bill appears to have been received favorably and passed with overwhelming support. It cleared the Senate 43-1 and the House 93-0, indicating broad bipartisan agreement that the changes were needed. The absence of committee transcript material suggests there was little recorded public controversy or, at minimum, no significant opposition captured in the available record.

Contention

The main policy issues in the bill are not about whether cybersecurity reporting should exist, but about how quickly and by whom notice must be given, especially when third-party service providers or assuming insurers are involved. Another point of potential concern is the balance between transparency and confidentiality: the bill expands reporting to the commissioner while preserving strong confidentiality protections for submitted materials. The limited exemptions for smaller licensees and for entities already covered by HIPAA-related federal rules may also be relevant, but the recorded votes suggest these provisions were not especially contentious.

Companion Bills

No companion bills found.

Previously Filed As

ND SB2088

AN ACT to amend and reenact subsection 4 of section 26.1-02.2-01, sections 26.1-02.2-05 and 26.1-02.2-07, and subsection 1 of section 26.1-02.2-08 of the North Dakota Century Code, relating to data security requirements for insurance producers; and to repeal section 26.1-02.2-11 of the North Dakota Century Code, relating to implementation dates for certain data security requirements for insurance producers.

ND HB1165

Election notices and municipal voter registration.

ND HB1165

AN ACT to amend and reenact section 4.1-20-16, subsection 1 of section 4.1-20-18, section 16.1-01-00.1, subsection 1 of section 16.1-01-09, section 16.1-01-15.1, subsection 3 of section 16.1-05-01, section 16.1-06-02, subdivision g of subsection 1 of section 16.1-06-04, section 16.1-07-07, subsection 4 of section 16.1-07-08, section 16.1-07-09, subsection 3 of section 16.1-07-21, section 16.1-07-24, subsection 2 of section 16.1-07-26, sections 16.1-11-27 and 16.1-11.1-04, subsection 1 of section 16.1-11.1-07, subsection 3 of section 16.1-12-02.2, and subsection 2 of section 16.1-13-05 of the North Dakota Century Code, relating to absentee ballots, election practices and administration; and to repeal sections 16.1-07-30 and 40-21-10 of the North Dakota Century Code, relating to election notices and municipal voter registration.

ND SB2214

The insurance commissioner assuming the duties of the securities commissioner; to provide for a transfer; to provide an effective date; and to declare an emergency.

ND SB2214

AN ACT to amend and reenact subsection 4 of section 6-01-07.1, subsections 4 and 5 of section 10-04-02, sections 10-04-03 and 10-04-16, paragraph 2 of subdivision a of subsection 1 of section 10-04-16.1, section 26.1-06-12, subsection 3 of section 43-10.1-01, subsection 2 of section 43-23.1-05, subsection 4 of section 51-19-02, subsection 3 of section 51-23-02, subsection 1 of section 51-23-15, subsection 1 of section 54-12-08, subsection 1 of section 54-59-22.1, subsection 4 of section 57-38.5-01, and subsection 5 of section 57-38.6-01 of the North Dakota Century Code, relating to the insurance commissioner assuming the duties of the securities commissioner; to provide for a transfer; to provide an effective date; and to declare an emergency.

ND HB1127

The department of financial institutions, financial institutions, response to department requests, renewal of licenses, orders to cease and desist, issuance of licenses, revocation of licenses, and exemptions from licenses.

ND HB1127

AN ACT to create and enact chapter 13-01.2 of the North Dakota Century Code, relating to the financial institution data security program; and to amend and reenact sections 6-01-04.1 and 6-01-04.2, subsection 7 of section 6-03-02, sections 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, and 13-09.1-14, subsection 3 of section 13-09.1-17, sections 13-09.1-38 and 13-10-05, subsection 1 of section 13-11-10, section 13-12-19, subsections 6, 21, and 22 of section 13-13-01, and sections 13-13-04 and 13-13-18 of the North Dakota Century Code, relating to the department of financial institutions, financial institutions, response to department requests, renewal of licenses, orders to cease and desist, issuance of licenses, revocation of licenses, and exemptions from licenses.

ND HB1123

Fees charged by the insurance commissioner.

ND HB1123

AN ACT to amend and reenact sections 26.1-01-07 and 26.1-26-13.4, subsection 4 of section 26.1-26.8-04, subdivision b of subsection 1 of section 26.1-26.8-05, subdivision a of subsection 1 of section 26.1-26.8-06, subdivision b of subsection 1 of section 26.1-26.8-09, subdivision b of subsection 2 of section 26.1-26.8-09, and subsections 2 and 4 of section 26.1-27-03 of the North Dakota Century Code, relating to fees charged by the insurance commissioner.

ND SB2092

Life settlement producer licenses and reporting requirements.

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.