Code of Virginia
Chapter 6 - Insurance Information and Privacy Protection
§ 38.2-627. Powers and duties of the Commission; exclusive state standards

A. The Commissioner may examine and investigate the affairs of any licensee to determine whether a licensee has been or is engaged in any conduct in violation of this article. This power is in addition to the powers that the Commissioner has under Article 4 of Chapter 13 (38.2-1300 et seq.) and Chapter 18 (38.2-1800 et seq.). Any such investigation or examination shall be conducted pursuant to Chapters 13 and 18.
B. Whenever the Commissioner has reason to believe that a licensee has been or is engaged in conduct in the Commonwealth that violates this article, the Commissioner may take action that is necessary or appropriate to enforce the provisions of this article.
C. The Commission may examine and investigate the affairs of any insurance-support organization that acts on behalf of an insurance institution or agent as defined in § 38.2-602 and that either (i) transacts business in the Commonwealth or (ii) transacts business outside the Commonwealth and has an effect on a person residing in the Commonwealth, in order to determine whether the insurance-support organization has been or is engaged in any conduct in violation of this article.
D. The Commission shall adopt rules and regulations implementing the provisions of this article.
E. This article and any rules adopted pursuant to this article establish the exclusive state standards applicable to licensees for data security, the security of nonpublic information, the investigation of cybersecurity events, and notification of cybersecurity events for those individuals and entities subject to this article.
2020, c. 264.

Structure Code of Virginia

Code of Virginia

Title 38.2 - Insurance

Chapter 6 - Insurance Information and Privacy Protection

§ 38.2-600. Purposes

§ 38.2-601. Application of article

§ 38.2-602. Definitions

§ 38.2-603. Pretext interviews

§ 38.2-604. Notice of information collection and disclosure practices

§ 38.2-604.1. Notice of financial information collection and disclosure practices

§ 38.2-605. Marketing and research surveys

§ 38.2-606. Content of disclosure authorization forms

§ 38.2-607. Investigative consumer reports

§ 38.2-608. Access to recorded personal information

§ 38.2-609. Correction, amendment, or deletion of recorded personal information

§ 38.2-610. Notice of adverse underwriting decision; furnishing reasons for decisions and sources of information

§ 38.2-611. Information concerning previous adverse underwriting decisions

§ 38.2-612. Bases for adverse underwriting decisions

§ 38.2-612.1. Special requirements for providing financial information to nonaffiliated third parties

§ 38.2-612.2. Protection of the Fair Credit Reporting Act

§ 38.2-613. Disclosure limitations and conditions

§ 38.2-613.01. Commission to promulgate regulations on disclosure of certain medical test results to insurance applicants

§ 38.2-613.1. Disclosure of agent's moratorium required

§ 38.2-613.2. Repealed

§ 38.2-614. Powers of Commission

§ 38.2-615. Hearings and procedures

§ 38.2-616. Service of process on insurance-support organizations

§ 38.2-617. Individual remedies

§ 38.2-618. Immunity of persons disclosing information

§ 38.2-619. Obtaining information under false pretenses

§ 38.2-620. Repealed

§ 38.2-621. Definitions

§ 38.2-622. Private cause of action; neither created nor curtailed

§ 38.2-623. Information security program

§ 38.2-624. Investigation of a cybersecurity event

§ 38.2-625. Notice to Commissioner

§ 38.2-626. Notice to consumers

§ 38.2-627. Powers and duties of the Commission; exclusive state standards

§ 38.2-628. Confidentiality

§ 38.2-629. Exceptions