IL HB3040 | 2021-2022 | 102nd General Assembly

Status

Spectrum: Partisan Bill (Republican 1-0)
Status: Introduced on February 18 2021 - 25% progression, died in committee
Action: 2021-03-27 - Rule 19(a) / Re-referred to Rules Committee
Pending: House Rules Committee
Text: Latest bill text (Introduced) [HTML]

Summary

Creates the Insurance Data Security Act. Requires any person licensed, authorized to operate, or registered as an insurer in accordance with the insurance laws of this State to conduct a risk assessment of cybersecurity threats, implement appropriate security measures, and no less than annually assess the effectiveness of the safeguards' key controls, systems, and procedures. Requires a licensee to develop, implement, and maintain a written information security program based on the licensee's risk assessment. Requires each licensee to establish a written incident response plan designed to promptly respond to, and recover from, any cybersecurity event that compromises the confidentiality, integrity, or availability of nonpublic information in its possession, the licensee's information systems, or the continuing functionality of any aspect of the licensee's business or operations. Requires licensees domiciled in this State to annually submit a written certification of compliance to the Director of Insurance. Provides that a licensee shall notify the Director as promptly as possible, but not later than 72 hours from a determination that a cybersecurity event has occurred in specified circumstances. Provides standards and procedures for risk management, data security, and notification and investigation of cybersecurity events resulting in unauthorized access to, disruption of, or misuse of nonpublic data. Provides that the Director has the power to examine and investigate to determine whether a licensee has been or is engaged in any conduct in violation of the Act. Grants the Department of Insurance rulemaking authority to implement the Act. Provides that any documents, materials, or other information obtained pursuant to the Act is confidential by law and privileged, is not subject to the Freedom of Information Act, is not subject to subpoena, and is not subject to discovery or admissible in evidence in any private civil action. Makes a conforming change in the Freedom of Information Act. Defines terms. Effective January 1, 2022.

Tracking Information

Register now for our free OneVote public service or GAITS Pro trial account and you can begin tracking this and other legislation, all driven by the real-time data of the LegiScan API. Providing tools allowing you to research pending legislation, stay informed with email alerts, content feeds, and share dynamic reports. Use our new PolitiCorps to join with friends and collegaues to monitor & discuss bills through the process.

Monitor Legislation or view this same bill number from multiple sessions or take advantage of our national legislative search.

Title

INSURANCE DATA SECURITY ACT

Sponsors


History

DateChamberAction
2021-03-27HouseRule 19(a) / Re-referred to Rules Committee
2021-03-16HouseAssigned to Cybersecurity, Data Analytics, & IT Committee
2021-02-19HouseReferred to Rules Committee
2021-02-19HouseFirst Reading
2021-02-18HouseFiled with the Clerk by Rep. Keith R. Wheeler

Code Citations

ChapterArticleSectionCitation TypeStatute Text
51407.5Amended CodeCitation Text

Illinois State Sources


Bill Comments

feedback