Subdivision 1. Terms. As used in sections 60A.985 to 60A.9857, the following terms have the meanings given.
Subd. 2. Authorized individual. "Authorized individual" means an individual known to and screened by the licensee and determined to be necessary and appropriate to have access to the nonpublic information held by the licensee and its information systems.
Subd. 3. Consumer. "Consumer" means an individual, including but not limited to an applicant, policyholder, insured, beneficiary, claimant, and certificate holder who is a resident of this state and whose nonpublic information is in a licensee's possession, custody, or control.
Subd. 4. Cybersecurity event. "Cybersecurity event" means an event resulting in unauthorized access to, or disruption or misuse of, an information system or nonpublic information stored on an information system.
Cybersecurity event does not include the unauthorized acquisition of encrypted nonpublic information if the encryption, process, or key is not also acquired, released, or used without authorization.
Cybersecurity event does not include an event with regard to which the licensee has determined that the nonpublic information accessed by an unauthorized person has not been used or released and has been returned or destroyed.
Subd. 5. Encrypted. "Encrypted" means the transformation of data into a form which results in a low probability of assigning meaning without the use of a protective process or key.
Subd. 6. Information security program. "Information security program" means the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle nonpublic information.
Subd. 7. Information system. "Information system" means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of nonpublic electronic information, as well as any specialized system such as industrial or process controls systems, telephone switching and private branch exchange systems, and environmental control systems.
Subd. 8. Licensee. "Licensee" means any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered by the Department of Commerce or the Department of Health under chapters 59A to 62M, 62Q to 62V, and 64B to 79A.
Subd. 9. Multifactor authentication. "Multifactor authentication" means authentication through verification of at least two of the following types of authentication factors:
(1) knowledge factors, such as a password;
(2) possession factors, such as a token or text message on a mobile phone; or
(3) inherence factors, such as a biometric characteristic.
Subd. 10. Nonpublic information. "Nonpublic information" means electronic information that is not publicly available information and is:
(1) any information concerning a consumer which because of name, number, personal mark, or other identifier can be used to identify the consumer, in combination with any one or more of the following data elements:
(i) Social Security number;
(ii) driver's license number or nondriver identification card number;
(iii) financial account number, credit card number, or debit card number;
(iv) any security code, access code, or password that would permit access to a consumer's financial account; or
(v) biometric records; or
(2) any information or data, except age or gender, in any form or medium created by or derived from a health care provider or a consumer that can be used to identify a particular consumer and that relates to:
(i) the past, present, or future physical, mental, or behavioral health or condition of any consumer or a member of the consumer's family;
(ii) the provision of health care to any consumer; or
(iii) payment for the provision of health care to any consumer.
Subd. 11. Person. "Person" means any individual or any nongovernmental entity, including but not limited to any nongovernmental partnership, corporation, branch, agency, or association.
Subd. 12. Publicly available information. "Publicly available information" means any information that a licensee has a reasonable basis to believe is lawfully made available to the general public from: federal, state, or local government records; widely distributed media; or disclosures to the general public that are required to be made by federal, state, or local law.
For the purposes of this definition, a licensee has a reasonable basis to believe that information is lawfully made available to the general public if the licensee has taken steps to determine:
(1) that the information is of the type that is available to the general public; and
(2) whether a consumer can direct that the information not be made available to the general public and, if so, that such consumer has not done so.
Subd. 13. Risk assessment. "Risk assessment" means the risk assessment that each licensee is required to conduct under section 60A.9851, subdivision 3.
Subd. 14. State. "State" means the state of Minnesota.
Subd. 15. Third-party service provider. "Third-party service provider" means a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, or store nonpublic information, or is otherwise permitted access to nonpublic information through its provision of services to the licensee.
1Sp2021 c 4 art 3 s 5; 2022 c 55 art 1 s 14
Structure Minnesota Statutes
Chapters 59A - 79A — Insurance
Chapter 60A — General Insurance Powers
Section 60A.03 — Commissioner Of Commerce.
Section 60A.031 — Examinations.
Section 60A.032 — Commissioner's Orders, Report.
Section 60A.033 — Scheduling Conference And Order.
Section 60A.035 — Government Controlled Or Owned Company Prohibited From Transacting Business.
Section 60A.052 — Certificates Of Authority; Enforcement Actions.
Section 60A.06 — Kinds Of Insurance Permitted.
Section 60A.07 — Authorization And Requirements.
Section 60A.078 — Short Title.
Section 60A.0782 — Definitions.
Section 60A.0783 — Insurable Interest Required.
Section 60A.0784 — Prohibited Practices.
Section 60A.0785 — Prohibition; Entry Into Settlement Contracts.
Section 60A.0786 — Presumption Of Stoli Practices.
Section 60A.0787 — Processing Change Of Ownership Or Beneficiary Requests.
Section 60A.0788 — Fraudulent Acts.
Section 60A.08 — Contracts Of Insurance.
Section 60A.081 — Aircraft Insurance.
Section 60A.0811 — Breach Of Insurance Policy; Recovery Of Interest.
Section 60A.082 — Group Insurance; Benefits Continued If Insurer Changed.
Section 60A.084 — Notification On Group Policies.
Section 60A.085 — Cancellation Of Group Coverage; Notification To Covered Persons.
Section 60A.086 — Retroactive Termination Of Coverage Under Group Policies Prohibited.
Section 60A.09 — Limits Of Risk; Reinsurance.
Section 60A.091 — Definition; Qualified United States Financial Institution.
Section 60A.092 — Reinsurance Credit Allowed A Domestic Ceding Insurer.
Section 60A.0921 — Credit For Reinsurance; Certified Reinsurers.
Section 60A.095 — Reinsurance Agreements Affected.
Section 60A.096 — Qualifying Letter Of Credit.
Section 60A.097 — Qualifying Trust Agreements.
Section 60A.10 — Deposits For Protection Of Policyholders.
Section 60A.11 — Investments Permitted For Domestic Companies.
Section 60A.112 — Investment Policy Required.
Section 60A.12 — Assets And Liabilities.
Section 60A.121 — Valuations; Definitions.
Section 60A.122 — Required Written Procedures For Valuations.
Section 60A.123 — Valuation Procedure.
Section 60A.124 — Independent Audit.
Section 60A.125 — Appraisal By Independent Appraiser.
Section 60A.126 — Reports To Board; Valuations.
Section 60A.127 — Independent Appraisals Of Certain Properties.
Section 60A.1285 — Other Impairments.
Section 60A.1291 — Annual Audit.
Section 60A.1295 — Actuarial Opinion Of Reserves And Supporting Documentation.
Section 60A.1296 — Confidentiality.
Section 60A.13 — Annual Statement, Inquiries, Renewal Licenses.
Section 60A.131 — Other Business And Insurance Interests, Disclosure.
Section 60A.135 — Report; Certain Transactions.
Section 60A.136 — Acquisitions And Dispositions Of Assets.
Section 60A.137 — Nonrenewals, Cancellations, Or Revisions Of Ceded Reinsurance Agreements.
Section 60A.139 — Electronic Notices And Documents.
Section 60A.1391 — Corporate Governance Annual Disclosure.
Section 60A.16 — Mergers And Consolidations.
Section 60A.161 — Insurer Domestication And Conversion.
Section 60A.172 — Insurance Agency Contracts; Cancellation.
Section 60A.173 — Effective Date.
Section 60A.174 — Severability.
Section 60A.175 — Agent Commissions.
Section 60A.1755 — Agent Errors And Omissions Insurance; Choice Of Source.
Section 60A.176 — Definitions.
Section 60A.177 — Involuntary Termination Of An Agent By The Insurer.
Section 60A.178 — Life Or Health Insurance Sales Quotas.
Section 60A.179 — Life Or Health Insurance Sales Quotas For Exclusive Agents.
Section 60A.19 — Foreign Companies.
Section 60A.196 — Definitions.
Section 60A.197 — Rates And Forms.
Section 60A.198 — Transaction Of Nonadmitted Insurance.
Section 60A.199 — Examinations.
Section 60A.201 — Placement Of Insurance By Broker.
Section 60A.202 — Evidence Of Placement Of Insurance By Broker.
Section 60A.203 — Retention Of Records.
Section 60A.204 — Fees And Commissions.
Section 60A.205 — Compensation.
Section 60A.206 — Qualification As Eligible Surplus Lines Insurer.
Section 60A.207 — Policies To Include Notice.
Section 60A.208 — Broker Association.
Section 60A.2085 — Surplus Lines Association Of Minnesota.
Section 60A.2086 — Licensee's Duty To Submit Documents; Penalty.
Section 60A.209 — Insurance Procured From Ineligible Insurers.
Section 60A.2095 — Construction.
Section 60A.21 — Unauthorized Insurers Process Act.
Section 60A.23 — Miscellaneous.
Section 60A.236 — Stop Loss Regulation; Small Employer Coverage.
Section 60A.24 — Exemptions From Insurance Laws Of This State.
Section 60A.25 — Insolvent Companies.
Section 60A.26 — Suspension Of Insurers; Notifications And Reports.
Section 60A.27 — Discipline Of Insurer By Another State; Notice To Commissioner.
Section 60A.28 — Documents Filed With Commissioner, Verification.
Section 60A.29 — Nonprofit Risk Indemnification Trust Act.
Section 60A.315 — Expedited Form And Rate Filing.
Section 60A.32 — Rate Filing For Crop Hail Insurance.
Section 60A.351 — Renewal Of Insurance Policy With Altered Rates.
Section 60A.352 — Workers' Compensation Insurance.
Section 60A.36 — Midterm Cancellation.
Section 60A.38 — Interpretation And Penalties.
Section 60A.39 — Certificates Of Insurance.
Section 60A.41 — Subrogation Against Insureds Prohibited.
Section 60A.42 — Disability Income Coverage; Prohibited Provision.
Section 60A.52 — Company Action Level Event.
Section 60A.53 — Regulatory Action Level Event.
Section 60A.54 — Authorized Control Level Event.
Section 60A.55 — Mandatory Control Level Event.
Section 60A.57 — Access To And Use Of Rbc Information.
Section 60A.58 — Supplemental Provisions.
Section 60A.59 — Foreign Health Organizations.
Section 60A.61 — Risk-based Capital Reports.
Section 60A.62 — Company Action Level Event.
Section 60A.63 — Regulatory Action Level Event.
Section 60A.64 — Authorized Control Level Event.
Section 60A.65 — Mandatory Control Level Event.
Section 60A.67 — Confidentiality.
Section 60A.68 — Supplemental Provisions; Rules; Exemption.
Section 60A.69 — Foreign Insurers.
Section 60A.705 — Definitions.
Section 60A.715 — Required Contract Provisions; Reinsurance Intermediary-brokers.
Section 60A.72 — Books And Records; Reinsurance Intermediary-brokers.
Section 60A.725 — Duties Of Insurers Utilizing The Services Of A Reinsurance Intermediary-broker.
Section 60A.73 — Required Contract Provisions; Reinsurance Intermediary-managers.
Section 60A.735 — Prohibited Acts.
Section 60A.74 — Duties Of Reinsurer Utilizing The Services Of A Reinsurance Intermediary-manager.
Section 60A.745 — Examination Authority; Reinsurance Intermediary - Broker.
Section 60A.76 — Purpose And Scope.
Section 60A.761 — Glossary Of Technical Terms Used.
Section 60A.762 — Categories Of Reserves.
Section 60A.763 — Claim Reserves.
Section 60A.764 — Premium Reserves.
Section 60A.765 — Contract Reserves Required.
Section 60A.766 — Minimum Standards For Contract Reserves.
Section 60A.767 — Reinsurance.
Section 60A.768 — Specific Standards For Morbidity, Interest, And Mortality.
Section 60A.803 — Life And Health Reinsurance Agreements.
Section 60A.91 — Filing Requirements.
Section 60A.93 — Confidentiality.
Section 60A.94 — Revocation Of Certificate Of Authority.
Section 60A.951 — Definitions.
Section 60A.952 — Disclosure Of Information.
Section 60A.953 — Enforcement; Refusal To Cooperate With An Investigation.
Section 60A.954 — Insurance Antifraud Plan.
Section 60A.955 — Claim Forms To Contain Fraud Warning.
Section 60A.956 — Other Law Enforcement Authority.
Section 60A.957 — Definitions.
Section 60A.9572 — License And Bond Requirements.
Section 60A.9573 — License Revocation And Denial.
Section 60A.9574 — Approval Of Viatical Settlement Contracts And Disclosure Statements.
Section 60A.9575 — Reporting Requirements And Privacy.
Section 60A.9577 — Disclosure To Viator.
Section 60A.9579 — General Rules.
Section 60A.9581 — Prohibited Practices And Conflicts Of Interest.
Section 60A.9583 — Fraud Prevention And Control.
Section 60A.9585 — Unfair Trade Practice.
Section 60A.975 — Definitions.
Section 60A.976 — Annuity Issuers Financial Requirements.
Section 60A.985 — Definitions.
Section 60A.9851 — Information Security Program.
Section 60A.9852 — Investigation Of A Cybersecurity Event.
Section 60A.9853 — Notification Of A Cybersecurity Event.
Section 60A.9854 — Power Of Commissioner.
Section 60A.9855 — Confidentiality.
Section 60A.9856 — Exceptions.
Section 60A.9858 — Exclusivity.
Section 60A.99 — Interstate Insurance Product Regulation Compact.
Section 60A.991 — Interstate Insurance Product Regulation Compact Opt Out Administration.