RegCorpus.comSubscribe
Missouri library
BulletinMO DCI Bulletin 26-01

26-01 - Insurance Data Security Act, January 5, 2026

Missouri · Department of Commerce and Insurance · effective January 5, 2026
First seen July 19, 2026 · last checked July 19, 2026
Version history
v1fetched Jul 19, 2026·effective Jan 5, 2026fea73d6387ea
Full text
Official document · full text
1
DEPARTMENT OF COMMERCE AND INSURANCE P.O. Box 690, Jefferson City, Mo. 65102-0690
2
INSURANCE BULLETIN 26-01 Insurance Data Security Act
3
Issued: January 5, 2026
4
The following Bulletin is issued by the Missouri Department ofCommerce and Insurance ("Department'? to inform and educate the reader on the specified issue. It does not have the force and effect of law, is not an evaluation of any specific facts or circumstances, shall not be considered a statement of general applicability and is not binding on the Department. See§ 374.015, RSMo.
5
To: All persons and entities regulated
6
From: Angela L. Nelson, Director
7
Re: Implementation of the Insurance Data
8
The Missouri General Assembly enacted the Insurance Data Security Act, sections 375.1400 to 375.1427 RSMo Supp. 2025, during the 2025 First Regular Session. The Act took effect on January 1, 2026, although licensees have until later dates to implement certain sections of the Act. See§ 375.1427 RSMo Supp. 2025.
9
The Director issues this bulletin to provide guidance concerning the Act.
10
Reporting Cybersecurity Event- Electronic Form
11
Section 375.1410.1 RSMo Supp. 2025 requires a licensee to notify the Director that a cybersecurity event has occurred when specific requirements are met. For this purpose, the Department has prepared an electronic notification form. The electronic form can be accessed at the following website address: https://apps.dci.mo.gov/fonns/CybersecurityEventNotification. Questions about the electronic form, which should not include any nonpublic information, may be sent by email to cyberbreach@insurance.mo.gov.
12
All cybersecurity event notifications should be submitted using this electronic form.
13
Section 375.1410.2 RSMo Supp. 2025 requires licensees to update and supplement initial and subsequent notifications to the Director regarding material changes to previously provided information, which should also be submitted using the electronic form.
14
Licensees are strongly encouraged to review the definitions found in section 375.1402 RSMo Supp. 2025 and the exclusions found in section 375.1417 RSMo Supp. 2025 before reporting a cybersecurity event.
15
Cybersecurity Events Involving Third-Party Service Providers
16
Cybersecurity events involving a licensee's third-party service providers also require notification to the Director. A "third-party service provider" is "a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, store, or otherwise is permitted access to nonpublic information through its provision of services to the licensee." § 375.1410. l RSMo Supp. 2025.
17
If a cybersecurity event occurs in a system maintained by a licensee's third-party service provider, and if the licensee becomes aware of the event, "the licensee shall treat such event as it would under subsection l of section 375.1410." § 375.1410.4(1) RSMo Supp. 2025. This means that the licensee shall notify the Director of the cybersecurity event in accordance with section 375.1410.l RSMo Supp. 2025. Computation of the licensee's deadlines is provided in section 375.1410.4(2) RSMo Supp. 2025.
18
Regulated entities that are not "licensees"
19
Section 375.1402.1(10) RSMo Supp. 2025 defines "licensee" as
20
any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered under the insurance laws of this state, but shall not include a purchasing group or a risk retention group chartered and licensed in a state other than this state or a licensee that is acting as an assuming insurer that is domiciled in another state or jurisdiction.
21
2 Notwithstanding the breadth of this definition, the Department sets forth the following nonexhaustive list of entities that are not "licensees" (in addition to the purchasing groups, risk retention groups, and assuming insurers already expressly excluded):
22
o health services corporations (HSCs), health maintenance organizations (HMOs), or prepaid dental plan corporations authorized or licensed under chapter 354 RSMo;
23
o captive insurance companies or special purpose life insurance captives (SPLRCs) licensed under chapter 379;
24
o Missouri mutual insurance companies operating under chapter 380;
25
o associations licensed under chapter 383; and
26
o providers registered under chapter 385 that are complying with the provisions of sections 385.200 to 385.220.
27
The Department does not consider the definition of "licensee" in section 375.1402.1(10) RSMo Supp. 2025 to include the entities identified in the bullets above because the Jaws governing these entities provide that general insurance laws do not apply unless certain requirements are satisfied. See, e.g., §§ 354.505. l (insurance laws not applicable to HM Os unless made specifically applicable by statute); 379. 1330 (no insurance laws applicable to captive insurance companies except as contained or referenced in sections 3 79.1300 to 379.1350); 383.035.4 (other than provided in section 383.035, no insurance law applies to associations licensed under chapter 383, unless such law expressly states it applies).
28
Section 375.1402.1(10) RSMo Supp. 2025's definition of"licensee" is a general insurance law. The definition does not satisfy the requirements necessary to make it applicable to HSCs, HM Os, prepaid dental corporations, or the other entities identified above. Therefore, the term "licensee" in 375.1402.1(10) RSMo Supp. 2025 does not include those entities.
29
Scope of "those terms" in Section 375.1410.1(1)
30
As indicated above, section 375.1410.1 RS Mo Supp. 2025 requires a licensee to notify the Director that a cybersecurity event has occurred when certain requirements are met. These requirements include, but are not limited to, the following: "This state is the licensee' s state of domicile, in the case of an insurer, or this state is the licensee's home state, in the case of a producer, as those terms are defined in section 375.012." § 375.1410.1(1) RSMo Supp. 2025 (emphasis added).
31
3 The phrase "those tenns" in section 375.1410.1(1) RSMo Supp. 2025 refers to "home state" and "producer," such that "home state" and "producer" are as defined in section 375.012.
32
However, "those terms" in section 375.1410.1(1) RSMo Supp. 2025 does not refer to "insurer" in section 375.1410.1 (1) RSMo Supp. 2025. This approach avoids conflicts, inconsistencies, and interpretation problems that would otherwise arise, and it aligns with how other states have implemented NAIC Model Law 668, on which the Insurance Data Security Act is based. See, e.g. , Alaska Stat. Ann. § 2 l.23 .280 (for notification of cybersecurity event, defining only "insurance producer" and "home state" with reference to state producer statute); Conn. Gen. Stat. Ann. § 38a-38(e)(A) (same); Ky. Rev. Stat. Ann.§ 304.3-760(1) (same).
33
If you have questions regarding this bulletin, please contact the Department at cyberbreach@insurance.mo.gov.
34
###