A Guide for Insurers on Creating and Maintaining a Cybersecurity Plan

Locke Lord LLP
Contact

The intersection of valuable and personally identifiable digitized information and the increasing incidence of cybersecurity breaches makes the creation and maintenance of a cybersecurity plan one of the most pressing concerns for every insurer doing business in the U.S. This article lays out a basic framework for a cybersecurity plan, an insurer, particularly an insurer holding health data, can use when designing and updating its cybersecurity program.

The news has been full of reports of cyberattacks on American businesses and the resulting breaches of companies’—and their customers’—most sensitive data. Insurers, particularly health insurers, are not immune to these attacks; criminal attacks in health care are up 125 percent since 2010, and are now the leading cause of data breaches. However, health insurers are not the only insurers that maintain the kind of medical and personal information that has been the targeted: Carriers writing accidental death and dismemberment, disability and long-term care insurance also have reason to gather and retain sensitive medical information, which could make them targets. Auto insurers and other liability writers may gather detailed personal information about both insureds and claimants who have suffered bodily injury. So it is not terribly surprising that in June 2015, the North Dakota state workers compensation carrier announced that its server suffered a breach that may have led to the disclosure of consumer information. And other insurers also maintain information other than health data that could be a tempting crime target. For example, financial guaranty companies have detailed financial information on their insureds, while surety companies may also obtain detailed financial pictures of individuals as well as businesses.

Originally published in Bloomberg BNA's Privacy & Security Law Report, 14 PVLR 1545, 08/24/2015.

Please see full publication below for more information.

LOADING PDF: If there are any problems, click here to download the file.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Locke Lord LLP | Attorney Advertising

Written by:

Locke Lord LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Locke Lord LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide