Maine Insurance Data Security Act

MaineAgency guidance

Ask Donna

How this section applies to your facts.

Maine Bureau of Insurance Bulletins › Maine Insurance Data Security Act

This text was captured on Aug 14, 2026. It is a snapshot, not a live feed, so check the official code before relying on it.

Text

STATE OF MAINE

DEPARTMENT OF PROFESSIONAL

AND FINANCIAL REGULATION

BUREAU OF INSURANCE

34 STATE HOUSE STATION

AUGUSTA, MAINE

04333-0034

Janet T. Mills

Governor

Eric A. Cioppa

Superintendent

PRINTED ON RECYCLED PAPER

O F F IC E S L O C A T ED A T 76 N O R T H ER N A V EN U E, G A R D IN ER, M A I N E 04345

www.maine.gov/insurance

Phone: (207) 624-8475 TTY: Please call Maine Relay 711 Consumer Assistance: 1-800-300-5000 Fax (207) 624-8599

Bulletin 462

Maine Insurance Data Security Act

The Maine Insurance Data Security Act is effective January 1, 2022.1 The Act establishes

standards applicable to licensees of the Bureau of Insurance for data security, investigation of

cybersecurity events, and notification to the Bureau of these events.2 The purpose of this

Bulletin is to guide licensees on how to comply with the Act.

Scope. The Act applies to all entities and persons who are licensed, authorized to operate, or

registered, or required to be licensed, authorized, or registered pursuant to the Maine Insurance

Code. The Act does not apply to purchasing groups or risk retention groups chartered and

licensed in other states or to licensees acting in their capacity as assuming insurers and not

domiciled in Maine.3

Information Security Program. Licensees must develop, implement, and maintain a

comprehensive written information security program that is commensurate with the licensee’s

size and complexity, the nature and scope of its activities, and the sensitivity of the nonpublic

information that the licensee uses or is in the licensee’s custody, possession, or control.4 The

licensee must base its information security program on the licensee’s risk assessment. This

means that any licensee that must develop an information security program must also conduct an

assessment of the risks that it faces. The information security program’s safeguards must also

address the licensee’s use of third-party service providers

he licensee’s custody, possession, or control.4 The

licensee must base its information security program on the licensee’s risk assessment. This

means that any licensee that must develop an information security program must also conduct an

assessment of the risks that it faces. The information security program’s safeguards must also

address the licensee’s use of third-party service providers. This is especially important because

third-party service providers often have access to sensitive information and because the access

can be a route for unwanted intrusions on that information. The information security program

must cover data and information in electronic and other formats. Licensees must comply with

Section 2264 by January 1, 2022.5

1 P.L. 2021, c. 24, An Act To Enact the Maine Insurance Data Security Act (L.D. 51).

2 24-A M.R.S. § 2262.

3 24-A M.R.S. § 2263(8).

4 24-A M.R.S. § 2264(1).

5 24-A M.R.S. § 2272.

Licensees with fewer than ten employees are exempt from the requirements of Section 2264.6

This headcount includes independent contractors, but only if they work for the licensee in the

business of insurance. For example, someone whose only work for a licensee is providing

landscaping or snowplowing services is not considered an independent contractor under the Act.

Third-Party Service Providers. Licensees subject to Section 2265 must exercise due diligence in

selecting third-party service providers.7 By January 1, 2023, a licensee must require its third-

party service providers to implement appropriate administrative, technical, and physical

measures to protect and secure the information systems and nonpublic information that the third-

party service providers either have access to or hold.

Annual Certifications. The Act requires annual certifications concerning compliance with these

requirements:

•

Maine Domestic Insurers. Under § 2264(9), each Maine domestic insurer must certify its

compliance with the Act’s information security program requirements

secure the information systems and nonpublic information that the third-

party service providers either have access to or hold.

Annual Certifications. The Act requires annual certifications concerning compliance with these

requirements:

•

Maine Domestic Insurers. Under § 2264(9), each Maine domestic insurer must certify its

compliance with the Act’s information security program requirements. The insurer must

maintain all records, schedules, and data supporting each certification for the

Superintendent’s examination for five years from the date the certification is submitted.

An insurance holding company system may submit one statement certifying compliance

on behalf of all domestic insurers in the holding company system. If an insurer has

identified areas, systems, or processes that require material improvement, updating or

redesign, the insurer, either directly or through an affiliate, must document the problems

it has identified and the remedial efforts that are planned and underway, and must make

that documentation available for inspection by the Bureau. Information furnished to the

Bureau under Section 2264(9) is confidential under Section 2268(1).

•

HIPAA- and HITECH-Compliant Licensees. A licensee subject to HIPAA8 and

HITECH9 that maintains a program for information security and breach notification that

treats all nonpublic information related to Maine consumers in the same manner as

protected health information is deemed to meet the requirements of Section 2266.10 This

does not apply to the notification requirement under Subsection 2266(1).

•

Producer Business Entity Licensees. An insurance producer business entity that is owned

by a depository institution and maintains an information security program in compliance

with the standards for safeguarding consumer information of 15 U.S.C

th information is deemed to meet the requirements of Section 2266.10 This

does not apply to the notification requirement under Subsection 2266(1).

•

Producer Business Entity Licensees. An insurance producer business entity that is owned

by a depository institution and maintains an information security program in compliance

with the standards for safeguarding consumer information of 15 U.S.C. §§ 6801 and 6805

is also deemed to have complied with Section 2264 under certain circumstances.11 The

licensee must, on request, produce evidence satisfactory to the Superintendent

independently validating that the parent depository institution has adopted an information

security program that satisfies the federal standards for safeguarding consumer

information.

6 24-A M.R.S. § 2269(1).

7 24-A M.R.S. § 2264(6).

8 Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 and related privacy, security, and

breach notification regulations pursuant to 45 C.F.R. Parts 160 and 164.

9 Health Information Technology for Economic and Clinical Health Act, Public Law 111-5.

10 24-A M.R.S. § 2269(2)(A).

11 24-A M.R.S. § 2269(2)(B).

A licensee must submit its certification by April 15th each year and may use the omnibus

certification form that will be posted on the Bureau’s website or submit its own certification

using the language in the posted form. If a licensee no longer qualifies for the HIPAA or bank

subsidiary safe harbor, it must notify the Superintendent within three months after that change in

status.

Cybersecurity Event Investigations. When a licensee learns that a cybersecurity event has or

might have occurred, the licensee must conduct a prompt investigation in accordance with the

Act. 12 The licensee may designate an outside vendor or service provider to act on its behalf

r bank

subsidiary safe harbor, it must notify the Superintendent within three months after that change in

status.

Cybersecurity Event Investigations. When a licensee learns that a cybersecurity event has or

might have occurred, the licensee must conduct a prompt investigation in accordance with the

Act. 12 The licensee may designate an outside vendor or service provider to act on its behalf.

The investigation must cover at least the following, as applicable:

• determining whether a cybersecurity event occurred;

• assessing the nature and scope of the cybersecurity event;

• identifying any nonpublic information involved in the cybersecurity event; and

• taking steps to restore the security of the information in order to prevent further

unauthorized acquisition, release, or use of nonpublic information in the licensee’s

possession, custody, or control.

If a licensee learns that a cybersecurity event has or may have occurred in a system maintained

by a third-party service provider, the licensee must either use its best efforts to conduct an

investigation using the steps described above or confirm that the third-party service provider has

completed those steps.13

Each licensee must maintain records concerning each cybersecurity event for at least five years

from the date of the event, and must produce such records to the Superintendent upon demand.14

Notification of a Cybersecurity Event. Notification is an important part of the Act. It covers

notification to the Superintendent and, in conjunction with Maine’s Notice of Risk to Personal

Data Act,15 to consumers.

Notification to the Superintendent. As promptly as possible but in no event later than

three business days after determining that a cybersecurity event has occurred, a licensee

must notify the Superintendent that of the event, if:

• The licensee is an insurer domiciled in Maine.

• The licensee is a producer whose home state is Maine

e’s Notice of Risk to Personal

Data Act,15 to consumers.

Notification to the Superintendent. As promptly as possible but in no event later than

three business days after determining that a cybersecurity event has occurred, a licensee

must notify the Superintendent that of the event, if:

• The licensee is an insurer domiciled in Maine.

• The licensee is a producer whose home state is Maine.

• The licensee reasonably believes that the cybersecurity event involves nonpublic

information of 250 or more Maine residents and either:

a. state or federal laws require that a notice concerning the cybersecurity event

be provided to a government body, self-regulatory agency, or another

supervisory body; or

12 24-A M.R.S. § 2265(1).

13 24-A M.R.S. § 2265(2).

14 24-A M.R.S. § 2265(3).

15 10 M.R.S. Ch. 210-B.

b. the event has a reasonable likelihood of materially harming any Maine

resident or a material part of the licensee’s normal operations.16

Licensees notifying the Superintendent of cybersecurity events must use the form and

process to be announced on the Bureau’s website.17 A licensee that has reported a

cybersecurity event has an ongoing obligation to update its initial and any further

notifications.

Notification to Consumers. The Act requires each licensee to comply with the applicable

provisions of Maine’s Notice of Risk to Personal Data Act.18 The licensee must also

provide the Superintendent with templates of any consumer notifications required under

that law.

Notification Involving Third-party Service Providers. When a cybersecurity event

involving an information system maintained by a third-party service provider affects

licensees, the licensees must treat such event as requiring notice to the Superintendent, if

the licensees have actual knowledge of the event.19 However, a licensee may allow the

third-party service provider to provide the required notice to the Superintendent.

Notification to Ceding Insurers

rsecurity event

involving an information system maintained by a third-party service provider affects

licensees, the licensees must treat such event as requiring notice to the Superintendent, if

the licensees have actual knowledge of the event.19 However, a licensee may allow the

third-party service provider to provide the required notice to the Superintendent.

Notification to Ceding Insurers. If a cybersecurity event involves a reinsurer that does

not have a direct contractual relationship with the Maine residents affected by the event,

the reinsurer is not responsible for providing notice to the affected consumers. Instead,

the reinsurer must notify its domiciliary regulator and the affected ceding insurers within

three business days after determining that a cybersecurity event has occurred, or after

receiving notice from a third-party service provider that a cybersecurity event has

occurred.20 Ceding insurers that have a direct contractual relationship with affected

Maine residents must comply with the consumer notification requirements of the Act and

the Notice of Risk to Personal Data Act.

Notice by Insurers to Producers of Record. If the cybersecurity event involves nonpublic

information that is in the possession, custody, or control of an insurer or its third-party

service provider, the insurer must notify each affected consumer’s producer of record, if

the consumer accessed services through an independent insurance producer and the

insurer has current producer-of-record information for the consumer. This notice must be

given no later than the notice to the affected consumer, unless otherwise directed by the

Superintendent.21

The Act specifically allows licensees to agree with other licensees, third-party services providers,

or other persons to meet the investigation requirements of Section 2265 or the notice

requirements of Section 2266.22 For example, an insurer producer business entity may comply

16 24-A M.R.S. § 2266(1).

17 24-A M.R.S. § 2266(2).

18 24-A M.R.S

s otherwise directed by the

Superintendent.21

The Act specifically allows licensees to agree with other licensees, third-party services providers,

or other persons to meet the investigation requirements of Section 2265 or the notice

requirements of Section 2266.22 For example, an insurer producer business entity may comply

16 24-A M.R.S. § 2266(1).

17 24-A M.R.S. § 2266(2).

18 24-A M.R.S. § 2266(3).

19 24-A M.R.S. § 2266(4).

20 24-A M.R.S. § 2266(5).

21 24-A M.R.S. § 2266(6).

22 24-A M.R.S. § 2266(4).

with these requirements on behalf of the producers that it employs, and a law firm may do so for

its client.

Confidentiality. The Act recognizes the need for some balance between consumers’ need to have

some information about cybersecurity events involving licensees that they do business with and

licensees’ need to protect the confidentiality of the processes that they use to secure their

information systems. The Act therefore treats as confidential the information security program

information that the Superintendent obtains from licensees under Section 2264(9), as described

above; some of the cybersecurity event information that licensees must report to the

Superintendent under Section 2266(2); and information obtained in an investigation or

examination under Section 2267.23

It is worth explaining what is confidential and not confidential in the notification required under

Section 2266(2). The information covered by Subsections 2266(1)(B), (C), (D), (E), (H), (J),

and (K) is confidential. This includes the mechanism of the cybersecurity event, how the

licensee discovered the event, whether and how the licensee recovered the information at issue,

the identity of the attacker, the period of compromise, the results of any forensic review of the

event, and the licensee’s steps to remediate the vulnerability. The information covered by

Subsections 2266(2)(A), (F), (G), (I), (L), and (M) is public

he mechanism of the cybersecurity event, how the

licensee discovered the event, whether and how the licensee recovered the information at issue,

the identity of the attacker, the period of compromise, the results of any forensic review of the

event, and the licensee’s steps to remediate the vulnerability. The information covered by

Subsections 2266(2)(A), (F), (G), (I), (L), and (M) is public. This includes the fact that a

cybersecurity event has happened, the reporting licensee’s identity, whether reports have been

filed with law enforcement officials, the types of affected information, the number of affected

people, the affected licensee’s privacy policy and investigation and notification steps, and the

licensee’s contact person are public information.

When the information described in Section 2268(2) is in the Superintendent’s possession or

control, it is not only confidential but also not subject to subpoena or discovery nor admissible in

evidence in any private civil action. This status does not prevent the Superintendent from using

this information in any regulatory or legal action made as part of the Superintendent’s duties, nor

from sharing this information under Section 216(5).

Last, Bureau staff will add a page to our website with information about the Act, including the

certification form and notification form mentioned at pages 2 and 3. Anyone interested in

receiving further announcements about the Act is encouraged to sign up at the “Get Notified” box

on the Bureau’s home page, www.maine.gov/pfr/insurance.

October 4, 2021

Eric A. Cioppa

Superintendent of Insurance

NOTE: This Bulletin is intended solely for informational purposes. It is not intended to set forth legal

rights, duties, or privileges, nor is it intended to provide legal advice. Readers should consult applicable

statutes and rules and contact the Bureau of Insurance if additional information is needed.

23 24-A M.R.S. § 2268(1).

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.

Maine Insurance Data Security Act · ME Insurance Bulletin 462 | Frix