HB 324 — An Act relating to insurance data security; amending Rule 26, Alaska Rules of Civil Procedure, and Rules 402 and 501, Alaska Rules of Evidence; and providing for an effective date.
Last action — (H) Minutes (HJUD)
-
✓Introduced
-
2In Committee
-
3Passed House
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill died with 33rd Legislature (2023-2024). It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.
Bill Text
What changed in the latest version
493 added · 526 removedPlain-language change summary
The recent amendment to Bill HB 324 changes the section number and specific requirements for insurance data security. Previously, the bill required risk assessments to be tailored to the size and complexity of the licensee, while the new version emphasizes evaluating the security and confidentiality of nonpublic information more broadly. This shift is important because it expands the focus on data security, ensuring that all licensees are thoroughly vetting potential risks to sensitive information, regardless of their size or scope. This could lead to stronger protections for consumers and better preparedness against cybersecurity threats.
33-LS1348\S33-LS1348\A CS FOR HOUSE BILL NO.
324(L&C)324 IN THE LEGISLATURE OF THE STATE OF ALASKA THIRTY-THIRD LEGISLATURE - SECOND SESSION BY THEREPRESENTATIVE HOUSESTAPP LABORIntroduced: AND COMMERCE COMMITTEE Referred:
Judiciary2/14/24 Sponsor(s):Referred:
REPRESENTATIVELabor STAPPand ACommerce. BILL FOR AN ACT ENTITLED "An Act relating to insurance data security;
Judiciary A BILL FOR AN ACT ENTITLED "An Act relating to insurance data security;
AS 21.2321.96 is amended by adding new sections to read:
Article 2.
Insurance Data Security.
21.23.240.21.96.250.
Purpose and construction.
(a) AS 21.23.240 - 21.23.399 establish the exclusive state standard for data security for licensees and govern the investigation and notification of a cybersecurity event.
(b) AS 21.23.240 - 21.23.399 may not be construed to (1) create or imply a privateause of action for violation of AS 21.23.240 - 21.23.399;
or (2) prevent a private cause of action that would otherwise exist in the absence of AS 21.23.240 - 21.23.399.
HB0324b -1- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S Sec.
21.23.250.
(a) A licensee shall conduct a risk assessment commensurate with the size and complexity of the licensee and in consideration of the nature and scope of the licensee's activities to evaluate the security and confidentiality of nonpublic informationinformation. used by or in the possession or control of the licensee.
(2) assess the likelihood and potential damage of the threats identified HB0324a -1- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A in (1) of this subsection, taking into consideration the sensitivity of nonpublic information;
(b) A licensee shall use the licensee's risk assessment to design the licensee's information security program required under AS 21.23.260(a).21.96.260(a).
21.23.260.21.96.260.
(a) A licensee shall develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment conducted under AS 21.23.250(a).21.96.250(a).
(b) A licensee's information security program must CSHB 324(L&C) -2- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (1) contain administrative, technical, and physical safeguards to protect the security and confidentiality of nonpublic information and the security of the licensee's information system;
HB 324 -2- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (c) In developing, implementing, and maintaining a licensee's information security program, the licensee shall (1) based on the licensee's risk assessment conducted under AS 21.23.250(a),21.96.250(a), implement the following security measures if the licensee determines that the security measure is appropriate:
HB0324b -3- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (E) adopt secure development practices for applications used by the licensee that are developed in-house;
the licensee shall adopt procedures for evaluating, assessing, or testing the security of externally developed applications used by the licensee;
(H) include audit trails inside the information security program that are designed to detect and respond to cybersecurity events and to HB0324a -3- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A reconstruct material financial transactions sufficient to support normal operations and obligations of the licensee;
CSHB 324(L&C) -4- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (7) exercise due diligence in selecting a third-party service provider;
(8) where appropriate, require a third-party service provider to implement appropriate administrative, technical, and physical measures to protect and secure the information systems and nonpublic information that are accessible to, or held by, the third-party service provider;
for purposes of this paragraph, encrypted nonpublic information is not considered accessible to, or held by, the third-party service provider if the associated protective process or key necessary to assign meaning to the nonpublic information is not within the possession of the third-party service provider;
and HB 324 -4- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (10) establish a written incident response plan designed to promptly respond to, and recover from, a cybersecurity event that compromises the confidentiality, integrity, or availability of nonpublic information in the licensee's possession, the licensee's information systems, or the continuing functionality of an aspect of the licensee's business or operations;
(F) the documentation and reporting of cybersecurity events HB0324b -5- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S and related incident response activities;
(A) the overall status of the information security program and the licensee's compliance with AS 21.23.24021.96.250 - 21.23.399;21.96.399;
and (B) material matters related to the information security program, including risk assessment, risk management and control decisions, HB0324a -5- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A third-party service provider arrangements, results of testing, cybersecurity events or violations, management's responses to the cybersecurity events or violations, and recommendations for changes in the information security program.
(f) Each licensee who is an insurer domiciled in this state shall (1) submit to the director a written statement by February 15 of each year certifying that the insurer is in compliance with the requirements under AS 21.23.25021.96.250 and this section;
and CSHB 324(L&C) -6- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (3) provide documentation of any areas, information systems, or processes that the insurer has identified as requiring material improvement, updating, or redesign, and provide documentation of the remedial efforts planned and underway to address the areas, information systems, or processes;
or HB 324 -6- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (C) an inherence factor, including a biometric characteristic.
21.23.270.21.96.270.
and (3) perform or oversee reasonable measures to restore the security of the information systems compromised in the cybersecurity event to prevent further unauthorized acquisition, release, or use of nonpublic information in the licensee's possessionpossession, custody, or control.
(b) If a licensee becomes aware that a cybersecurity event has or may have HB0324b -7- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S occurred in an information system maintained by a third-party service provider, the licensee shall, to the extent possible, complete the actions described in (a) of this section or confirm and document that the third-party service provider has completed those actions.
21.23.280.21.96.280.
(a) UnlessA a federal law enforcement official instructs the licensee not to distribute information regarding a cybersecurity event, a licensee shall notify the director as soon as possible and not later than three72 businesshours days after thea licensee determines that a cybersecurity event has occurred, if (1) the licensee is an insurer and domiciled in this state;
Show all 99 changed lines (59 more)
or (3) the licensee reasonably believes that the cybersecurity event involves the nonpublic information of 250 or more consumers residing in this state and HB0324a -7- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A the cybersecurity event (A) affects the licensee, and a state or federal law requires the licensee to provide notice of the cybersecurity event to a government agency;
(b) ToThe notification to the greatestdirector under (a) of this section must include, to the extent possible and in a form and format prescribed by the director, the notification to the director under (a) of this section must include the following information:
CSHB 324(L&C) -8- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (3) an explanation of how the cybersecurity event was discovered;
(10) the results of an internal review identifying a lapse ineither the HB 324 -8- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A licensee's automated controls or internal procedures or confirming that the licensee followed all automated controls or internal procedures;
(d) In addition to the requirements of this section, a licensee shall comply with HB0324b -9- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S all applicable provisions of AS 45.48 (Alaska Personal Information Protection Act).
(e) UnlessIf a third-party service provider of a licensee notifies the director, if the licensee becomes aware of a cybersecurity event that affects an information system maintained by thea third-party service provider,provider of the licensee, the licensee shall comply with the requirements of this section, except that the time prescribed in (a) of this section tobegins the greatestday extentafter possible.the third-party service provider notifies the licensee of the cybersecurity event or the day after the date the licensee has actual knowledge of the cybersecurity event, whichever is earlier.
For(f) purposesA oflicensee thisacting subsection,as thean timeassuming prescribedinsurer inthat (a)determines ofthat thisa sectioncybersecurity beginsevent thehas dayoccurred shall, not later than 72 hours after the third-partydetermination, servicenotify providerthe notifieslicensee's affected ceding insurers and the licenseeinsurance supervisory official of the licensee's state of domicile if (1) the cybersecurity event orinvolves thenonpublic dayinformation afterand the datenonpublic information is information used by or in the licenseepossession, hascustody, actualor knowledgecontrol of the cybersecuritylicensee event,acting whicheveras isan earlier.assuming insurer;
(f)and AHB0324a licensee-9- actingHB as324 anNew assumingText insurerUnderlined that[DELETED determinesTEXT thatBRACKETED] a33-LS1348\A cybersecurity(2) eventthe haslicensee occurreddoes shall, not laterhave thana threedirect businesscontractual daysrelationship afterwith thea determination,consumer notify the licensee's affected cedingby insurers and the insurance supervisory official of the licensee's state of domicile if (1) the cybersecurity eventevent. involves nonpublic information and the nonpublic information is information used by or in the possession or control of the licensee acting as an assuming insurer;
and(g) (2)A licensee acting as an assuming insurer that receives notification from the licenseelicensee's doesthird-party notservice haveprovider that a directcybersecurity contractualevent relationshiphas withoccurred ashall, consumernot later than 72 hours after receiving notification, notify the licensee's affected byceding insurers and the insurance supervisory official of the licensee's state of domicile if the cybersecurity event.event involves nonpublic information and the nonpublic information is in the possession, custody, or control of the third-party service provider.
(g)(h) A licenseeceding acting as an assuming insurer thatnotified receivesunder notification(f) fromor the(g) licensee'sof third-partythis servicesection provider that a cybersecurity event has occurreda shall,direct notcontractual laterrelationship thanwith threean businessaffected daysconsumer aftershall receivingcomply notification,with notifythis thesection licensee's affected ceding insurers and theall insuranceapplicable supervisoryprovisions official of theAS licensee's45.48 state(Alaska ofPersonal domicileInformation ifProtection theAct). cybersecurity event involves nonpublic information and the nonpublic information is in the possession or control of the third-party service provider.
(h)(i) ExceptA aslicensee providedthat inis (f)an insurer and (g)that ofbecomes thisaware section,that a licenseecybersecurity actingevent involving nonpublic information has occurred shall, as ansoon assumingas insurerpossible doesand notin havea otherform noticeand obligationsformat relatingprescribed toby the director, notify each independent insurance producer of record of a consumer affected by the cybersecurity event underif this(1) section.the nonpublic information is in the possession, custody, or control of the licensee or the licensee's third-party service provider;
(i) A licensee that is an insurer and that becomes aware that a cybersecurity event involving nonpublic information has occurred shall, ason as possible and in a CSHB 324(L&C) -10- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S form and format prescribed by the director, notify each independent insurance producer of record of a consumer affected by the cybersecurity event if (1) the nonpublic information is in the possession or control of the licensee or the licensee's third-party service provider;
(j) An insurer shall notify an insurance producer of a cybersecurity event involving nonpublic information, not later than the date the notice is provided to the affected consumers, if (1) the nonpublic information is in the possession or control of a licensee that is an insurer or the licensee's third-party service provider;
(2) the consumer accessed the insurer's services through an insurance producer;
and (3) the insurer is required to notify affected consumers under AS 21.23.240 - 21.23.399 or AS 45.48.
(k) An insurer is exempt from notifying an insurance producer under (j) of this section if (1) the producer is not authorized by law or contract to sell, solicit, or negotiate on behalf of the insurer;
or (2) the insurer does not have the current producer information for an affected consumer.
21.23.290.21.96.290.
(a) Any document, material, or information in the possession or control of the division that is provided by a licensee or an employee or agent acting on behalf of a licensee under AS 21.23.260(f)21.96.260(f) or 21.23.280(b)(2)21.96.280(b)(2) - (5), (8), (10), or (11) or that is obtained by the director in an investigation or examination under AS 21.23.31021.96.310 (1) is confidential and privileged;
HB0324b -11- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (3) may not be obtained by subpoena or discovery;
HB 324 -10- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (b) The director may use a document, material, or information described in (a) of this section in a regulatory or legal proceeding brought in the performance of the duties of the director under this title.
(d) In the performance of duties under AS 21.23.24021.96.250 - 21.23.399,21.96.399, the director (1) may (1) disclose a document, material, or information, including a document, material, or information that is confidential and privileged or subject to (a) of this section, to state, federal, and international regulatory or law enforcement agencies, or to the National Association of Insurance Commissioners and its affiliates or subsidiaries, if the recipient agrees in writing to maintain the confidentiality and privileged status of the document, material, or information;
(2) may receive a document, material, or information, including a document, material, or information that is confidential and privileged, from the National Association of Insurance Commissioners and its affiliates or subsidiaries, and from state, federal, and international regulatory or law enforcement agencies;
(3) may disclose a document, material, or information that is subject to (a) of this section with a third-party service provider if the third-party service provider agrees in writing to maintain the confidentiality and privileged status of the document, material, or information;
and (4) may enter into agreements consistent with this section governing the sharing and use of a document, material, or information that is confidential or privileged or subject to (a) of this section.
CSHB 324(L&C) -12- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (e) A person does not waive a claim of privilege or confidentiality that the HB0324a -11- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A person possesses by providing a document, material, or information to the director under AS 21.23.24021.96.250 - 21.23.39921.96.399 or by the disclosure, receipt, or sharing of a document, material, or information under (d) of this section.
21.23.300.21.96.300.
(a) AS 21.23.25021.96.250 and 21.23.26021.96.260 do not apply to (1) a licensee, including an independent contractor, with fewer than 1510 employees;
(b) AS 21.23.24021.96.250 - 21.23.39921.96.399 do not apply to a licensee subject to the Health Insurance Portability and Accountability Act of 1996 (P.L.
(c) If a licensee no longer qualifies for an exception to the applicability of AS 21.23.24021.96.250 - 21.23.39921.96.399 under this section, the licensee shall comply with AS 21.23.24021.96.250 - 21.23.39921.96.399 within 180 days after the licensee no longer qualifies for the exception.
21.23.310.21.96.310.
(a) In addition to the director's power to examine or investigate under AS 21.06.120, the director may examine and investigate the affairs of a licensee to determine whether the licensee is or has been in violation of AS 21.23.24021.96.250 - 21.23.399.21.96.399.
The director may take necessary or HB0324b -13- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S appropriate action to enforce AS 21.23.24021.96.250 - 21.23.399.21.96.399.
HB 324 -12- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (b) In addition to any other penalty provided by law, a person who violates AS 21.23.24021.96.250 - 21.23.39921.96.399 is subject to the penalties provided under AS 21.27.440.
(c) AS 21.96.250 - 21.96.399 do not create or imply a private cause of action for a violation of AS 21.96.250 - 21.96.399.
21.23.399.21.96.399.
In AS 21.23.24021.96.250 - 21.23.399,21.96.399, (1) "consumer" means an individual who is a resident of thethis state and whose nonpublic information is in a licensee's possessionpossession, custody, or control;
(5) "information system" means (A) a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic information;
(6)HB0324a "licensee"-13- CSHBHB 324(L&C)324 -14- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S33-LS1348\A (6) "licensee" (A) means a person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered, under the insurance laws of this title;state;
(iii) aan financial account, credit card, or debit card number;
or (C) information or data, except age or gender, in any form or medium created by or derived from a health care provider or a consumer that can be used to identify a particular consumer and relates to (i) the past, present, or future physical, mental, or behavioral health or condition of a consumer or a member of the consumer's family;
HB 324 -14- HB0324a New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A (8) "person" means an individual or a nongovernmental entity;
HB0324b -15- CSHB 324(L&C) New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S (9) "publicly available information" means information that a licensee has determined is made available to the general public from (A) a federal, state, or local government record;
(a) AS 21.23.290(a)(3),21.96.290(a)(3), enacted by sec.
1 of this Act, has the effect of changing Rule 26, Alaska Rules of Civil Procedure, by prohibiting discovery of evidence in the possession or control of the division of insurance that is provided by a licensee or an employee or agent acting on behalf of a licensee under AS 21.23.260(f)21.96.260(f) or 21.23.280(b)(2)21.96.280(b)(2) - (5), (8), (10), or (11) or that is obtained by the director in an investigation or examination under AS 21.23.310.21.96.310.
(b) AS 21.23.290(a)(4)21.96.290(a)(4) and (c), enacted by sec.
and (2) precluding admissibility of evidence in a private action of documents, materials, or other information in the possession or control of the division of insurance that is provided by a licensee or an employee or agent acting on behalf of a licensee under AS 21.23.260(f)21.96.260(f) or 21.23.280(b)(2)21.96.280(b)(2) - (5), (8), (10), or (11) or that is obtained by the director in an investigation or examination under AS 21.23.310.21.96.310.
The uncodified law of the State of Alaska is amended by adding a new section to HB0324a -15- HB 324 New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\A read:
CSHB 324(L&C) -16- HB0324b New Text Underlined [DELETED TEXT BRACKETED] 33-LS1348\S TRANSITION:
AS 21.23.290(a)(3)21.96.290(a)(3) andand(4) (4) and (c), enacted by sec.
If AS 21.23.290(a)(3)21.96.250 and (4)21.96.260(a), and(b), (c)(c)(1) take- effect,(6), they(9), takeand effect(10), Januaryand 1,(d) 2025.- (g), enacted by sec.
* Sec.
7.
AS 21.23.250 and 21.23.260(a), (b), (c)(1) - (6), (9), and (10), and (d) - (g), enacted by sec.
8.7.
AS 21.23.260(c)(7)21.96.260(c)(7) and (8), enacted by sec.
9.8.
5 - 87 of this Act, this Act takes effect January 1, 2025.
HB0324bHB -17-324 CSHB-16- 324(L&C)HB0324a New Text Underlined [DELETED TEXT BRACKETED]
Show all 99 changed rows (59 more)
Action History
-
(H) Minutes (HJUD)
-
(H) <Bill Hearing Canceled> -- Delayed to 2 PM --
-
(H) JUDICIARY at 01:00 PM GRUENBERG 120
-
(H) REFERRED TO JUDICIARY
-
(H) FN1: ZERO(CED)
-
(H) NR: RUFFRIDGE, WRIGHT, FIELDS, CARRICK, SADDLER
-
(H) DP: PRAX, SUMNER
-
(H) L&C RPT CS(L&C) 2DP 5NR
-
(H) Minutes (HL&C)
-
(H) Moved CSHB 324(L&C) Out of Committee
-
(H) LABOR & COMMERCE at 03:15 PM BARNES 124
-
(H) Minutes (HL&C)
-
(H) Heard & Held
-
(H) LABOR & COMMERCE at 03:15 PM BARNES 124
-
(H) L&C, JUD
-
(H) READ THE FIRST TIME - REFERRALS
Sponsors
- Will Stapp · Primary
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 0 co-sponsors · 64 not signed on
Sponsors (1)
Co-sponsors (0)
None.
Not signed on (64)
64 members have not signed on to this bill.
Show all 64 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Subjects
Frequently asked questions
- Who sponsors HB 324?
- HB 324 is sponsored by Will Stapp (R).
- What is the current status of HB 324?
- This bill died with 33rd Legislature (2023-2024). It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
- Where can I track HB 324?
- Track HB 324 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 324
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 324
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →