Cybersecurity requirements for insurers.
Summary
Requires an insurer to: (1) develop, maintain, and update an information security program for the purpose of protecting consumers' nonpublic information; (2) conduct a risk assessment of its information systems to aid in the development of an information security program; (3) notify the insurance commissioner if a cybersecurity event affecting the nonpublic information of 250 or more consumers occurs; and (4) develop an incident response plan to respond to cybersecurity events.
Bill status
in committee
1 of 4 stages cleared
Introduction
Jan 2020
Committee Review
Floor Vote
Governor
Introduced Jan 9, 2020
Last action Jan 9, 2020
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
0
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Liz Brown
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about SB 240
Scope: IN
Hi! I can help you understand SB 240. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline