Full text
Official document · full textBulletinMO DCI Bulletin 26-01
26-01 - Insurance Data Security Act, January 5, 2026
Version history
v1fetched Jul 19, 2026·effective Jan 5, 2026fea73d6387ea
¶1
DEPARTMENT OF COMMERCE AND INSURANCE
P.O. Box 690, Jefferson City, Mo. 65102-0690
¶2
INSURANCE BULLETIN 26-01
Insurance Data Security Act
¶3
Issued: January 5, 2026
¶4
The following Bulletin is issued by the Missouri Department ofCommerce and
Insurance ("Department'? to inform and educate the reader on the specified issue. It
does not have the force and effect of law, is not an evaluation of any specific facts or
circumstances, shall not be considered a statement of general applicability and is not
binding on the Department. See§ 374.015, RSMo.
¶5
To: All persons and entities regulated
¶6
From: Angela L. Nelson, Director
¶7
Re: Implementation of the Insurance Data
¶8
The Missouri General Assembly enacted the Insurance Data Security Act, sections
375.1400 to 375.1427 RSMo Supp. 2025, during the 2025 First Regular Session. The Act
took effect on January 1, 2026, although licensees have until later dates to implement
certain sections of the Act. See§ 375.1427 RSMo Supp. 2025.
¶9
The Director issues this bulletin to provide guidance concerning the Act.
¶10
Reporting Cybersecurity Event- Electronic Form
¶11
Section 375.1410.1 RSMo Supp. 2025 requires a licensee to notify the Director that a
cybersecurity event has occurred when specific requirements are met.
For this purpose, the Department has prepared an electronic notification form. The
electronic form can be accessed at the following website address:
https://apps.dci.mo.gov/fonns/CybersecurityEventNotification. Questions about the
electronic form, which should not include any nonpublic information, may be sent by
email to cyberbreach@insurance.mo.gov.
¶12
All cybersecurity event notifications should be submitted using this electronic form.
¶13
Section 375.1410.2 RSMo Supp. 2025 requires licensees to update and supplement initial
and subsequent notifications to the Director regarding material changes to previously
provided information, which should also be submitted using the electronic form.
¶14
Licensees are strongly encouraged to review the definitions found in section 375.1402
RSMo Supp. 2025 and the exclusions found in section 375.1417 RSMo Supp. 2025 before
reporting a cybersecurity event.
¶15
Cybersecurity Events Involving Third-Party Service Providers
¶16
Cybersecurity events involving a licensee's third-party service providers also require
notification to the Director. A "third-party service provider" is "a person, not otherwise
defined as a licensee, that contracts with a licensee to maintain, process, store, or otherwise
is permitted access to nonpublic information through its provision of services to the
licensee." § 375.1410. l RSMo Supp. 2025.
¶17
If a cybersecurity event occurs in a system maintained by a licensee's third-party service
provider, and if the licensee becomes aware of the event, "the licensee shall treat such event
as it would under subsection l of section 375.1410." § 375.1410.4(1) RSMo Supp. 2025.
This means that the licensee shall notify the Director of the cybersecurity event in
accordance with section 375.1410.l RSMo Supp. 2025. Computation of the licensee's
deadlines is provided in section 375.1410.4(2) RSMo Supp. 2025.
¶18
Regulated entities that are not "licensees"
¶19
Section 375.1402.1(10) RSMo Supp. 2025 defines "licensee" as
¶20
any person licensed, authorized to operate, or registered, or required to be
licensed, authorized, or registered under the insurance laws of this state, but
shall not include a purchasing group or a risk retention group chartered and
licensed in a state other than this state or a licensee that is acting as an
assuming insurer that is domiciled in another state or jurisdiction.
¶21
2
Notwithstanding the breadth of this definition, the Department sets forth the following
nonexhaustive list of entities that are not "licensees" (in addition to the purchasing groups,
risk retention groups, and assuming insurers already expressly excluded):
¶22
o health services corporations (HSCs), health maintenance organizations (HMOs), or
prepaid dental plan corporations authorized or licensed under chapter 354 RSMo;
¶23
o captive insurance companies or special purpose life insurance captives (SPLRCs)
licensed under chapter 379;
¶24
o Missouri mutual insurance companies operating under chapter 380;
¶25
o associations licensed under chapter 383; and
¶26
o providers registered under chapter 385 that are complying with the provisions of
sections 385.200 to 385.220.
¶27
The Department does not consider the definition of "licensee" in section 375.1402.1(10)
RSMo Supp. 2025 to include the entities identified in the bullets above because the Jaws
governing these entities provide that general insurance laws do not apply unless certain
requirements are satisfied. See, e.g., §§ 354.505. l (insurance laws not applicable to HM Os
unless made specifically applicable by statute); 379. 1330 (no insurance laws applicable to
captive insurance companies except as contained or referenced in sections 3 79.1300 to
379.1350); 383.035.4 (other than provided in section 383.035, no insurance law applies to
associations licensed under chapter 383, unless such law expressly states it applies).
¶28
Section 375.1402.1(10) RSMo Supp. 2025's definition of"licensee" is a general insurance
law. The definition does not satisfy the requirements necessary to make it applicable to
HSCs, HM Os, prepaid dental corporations, or the other entities identified above. Therefore,
the term "licensee" in 375.1402.1(10) RSMo Supp. 2025 does not include those entities.
¶29
Scope of "those terms" in Section 375.1410.1(1)
¶30
As indicated above, section 375.1410.1 RS Mo Supp. 2025 requires a licensee to notify the
Director that a cybersecurity event has occurred when certain requirements are met. These
requirements include, but are not limited to, the following: "This state is the licensee' s state
of domicile, in the case of an insurer, or this state is the licensee's home state, in the case
of a producer, as those terms are defined in section 375.012." § 375.1410.1(1) RSMo Supp.
2025 (emphasis added).
¶31
3
The phrase "those tenns" in section 375.1410.1(1) RSMo Supp. 2025 refers to "home
state" and "producer," such that "home state" and "producer" are as defined in section
375.012.
¶32
However, "those terms" in section 375.1410.1(1) RSMo Supp. 2025 does not refer to
"insurer" in section 375.1410.1 (1) RSMo Supp. 2025. This approach avoids conflicts,
inconsistencies, and interpretation problems that would otherwise arise, and it aligns with
how other states have implemented NAIC Model Law 668, on which the Insurance Data
Security Act is based. See, e.g. , Alaska Stat. Ann. § 2 l.23 .280 (for notification of
cybersecurity event, defining only "insurance producer" and "home state" with reference
to state producer statute); Conn. Gen. Stat. Ann. § 38a-38(e)(A) (same); Ky. Rev. Stat.
Ann.§ 304.3-760(1) (same).
¶33
If you have questions regarding this bulletin, please contact the Department at
cyberbreach@insurance.mo.gov.
¶34
###
¶35
4