(1) The following data and information from technology systems owned by, under contract with, or maintained by Citizens Property Insurance Corporation are confidential and exempt from s. 119.07(1) and s. 24(a), Art. I of the State Constitution:
(a) Records held by the corporation which identify detection, investigation, or response practices for suspected or confirmed information technology security incidents, including suspected or confirmed breaches, if the disclosure of such records would facilitate unauthorized access to or unauthorized modification, disclosure, or destruction of:
1. Data or information, whether physical or virtual; or
2. Information technology resources, including:
a. Information relating to the security of the corporation’s technologies, processes, and practices designed to protect networks, computers, data processing software, and data from attack, damage, or unauthorized access; or
b. Security information, whether physical or virtual, which relates to the corporation’s existing or proposed information technology systems.
(b) Those portions of risk assessments, evaluations, audits, and other reports of the corporation’s information technology security program for its data, information, and information technology resources which are held by the corporation, if the disclosure of such records would facilitate unauthorized access to or the unauthorized modification, disclosure, or destruction of:
1. Data or information, whether physical or virtual; or
2. Information technology resources, which include:
a. Information relating to the security of the corporation’s technologies, processes, and practices designed to protect networks, computers, data processing software, and data from attack, damage, or unauthorized access; or
b. Security information, whether physical or virtual, which relates to the corporation’s existing or proposed information technology systems.
(2) Those portions of a public meeting as specified in s. 286.011 which would reveal data and information described in subsection (1) are exempt from s. 286.011 and s. 24(b), Art. I of the State Constitution. No exempt portion of an exempt meeting may be off the record. All exempt portions of such a meeting must be recorded and transcribed. The recording and transcript of the meeting must remain confidential and exempt from disclosure under s. 119.07(1) and s. 24(a), Art. I of the State Constitution unless a court of competent jurisdiction, following an in camera review, determines that the meeting was not restricted to the discussion of data and information made confidential and exempt by this section. In the event of such a judicial determination, only that portion of the transcript which reveals nonexempt data and information may be disclosed to a third party.
(3) The records and portions of public meeting recordings and transcripts described in subsection (2) must be available to the Auditor General, the Cybercrime Office of the Department of Law Enforcement, and the Office of Insurance Regulation. Such records and portions of meetings, recordings, and transcripts may be made available to a state or federal agency for security purposes or in furtherance of the agency’s official duties.
(4) The exemptions provided by this section apply to records held by the corporation before, on, or after the effective date of this act.
(5) This section is subject to the Open Government Sunset Review Act in accordance with s. 119.15 and shall stand repealed on October 2, 2023, unless reviewed and saved from repeal through reenactment by the Legislature.
History.—s. 1, ch. 2018-65.
Structure Florida Statutes
Chapter 627 - Insurance Rates and Contracts
Part I - Rates and Rating Organizations (Ss. 627.011-627.381)
627.031 - Purposes of this part; interpretation.
627.0612 - Administrative proceedings in rating determinations.
627.0621 - Transparency in rate regulation.
627.0625 - Commercial property and casualty risk management plans.
627.06281 - Public hurricane loss projection model; reporting of data by insurers.
627.0629 - Residential property insurance; rate filings.
627.06291 - Excess profits of residential property insurer; return.
627.06292 - Reports of hurricane loss data and associated exposure data; public records exemption.
627.06501 - Insurance discounts for certain persons completing driver improvement course.
627.0651 - Making and use of rates for motor vehicle insurance.
627.0652 - Insurance discounts for certain persons completing safety course.
627.0653 - Insurance discounts for specified motor vehicle equipment.
627.06535 - Electric vehicles; restrictions on imposing surcharges.
627.0654 - Insurance discounts for buildings with fire sprinklers.
627.0655 - Policyholder loss or expense-related premium discounts.
627.066 - Excessive profits for motor vehicle insurance prohibited.
627.0665 - Automatic bank withdrawal agreements; notification required.
627.072 - Making and use of rates.
627.091 - Rate filings; workers’ compensation and employer’s liability insurances.
627.0915 - Rate filings; workers’ compensation, drug-free workplace, and safe employers.
627.0916 - Agricultural horse farms.
627.092 - Workers’ Compensation Administrator.
627.093 - Application of s. 286.011 to workers’ compensation and employer’s liability insurances.
627.096 - Workers’ Compensation Rating Bureau.
627.101 - When filing becomes effective; workers’ compensation and employer’s liability insurances.
627.111 - Effective date of filing.
627.1615 - Workers’ compensation applicant discrimination.
627.191 - Adherence to filings; workers’ compensation and employer’s liability insurances.
627.192 - Workers’ compensation insurance; employee leasing arrangements.
627.211 - Deviations; workers’ compensation and employer’s liability insurances.
627.212 - Workplace safety program surcharge.
627.215 - Excessive profits for commercial property and commercial casualty insurance prohibited.
627.221 - Rating organizations; licensing; fee.
627.231 - Subscribers to rating organizations.
627.251 - Bureau rules not to affect dividends.
627.261 - Actuarial and technical services.
627.285 - Independent actuarial peer review of workers’ compensation rating organization.
627.301 - Advisory organizations.
627.311 - Joint underwriters and joint reinsurers; public records and public meetings exemptions.
627.312 - Transitional provisions.
627.3121 - Public records and public meetings exemptions.
627.313 - Workers’ Compensation Joint Underwriting Plan; audit requirements.
627.314 - Concerted action by two or more insurers.
627.331 - Recording and reporting of loss, expense, and claims experience; rating information.
627.351 - Insurance risk apportionment plans.
627.3511 - Depopulation of Citizens Property Insurance Corporation.
627.3512 - Recoupment of residual market deficit assessments.
627.3513 - Standards for sale of bonds by Citizens Property Insurance Corporation.
627.3515 - Market assistance plan; property and casualty risks.
627.3518 - Citizens Property Insurance Corporation policyholder eligibility clearinghouse program.
627.352 - Security of data and information technology in Citizens Property Insurance Corporation.
627.357 - Medical malpractice self-insurance.