§ 507F.1 Title
§ 507F.2 Purpose and scope
§ 507F.3 Definitions
§ 507F.4 Information security program
§ 507F.5 Third-party service provider arrangements
§ 507F.6 Cybersecurity event — investigation
§ 507F.7 Cybersecurity event — notification and report to the commissioner
§ 507F.8 Cybersecurity event — notification to consumers
§ 507F.9 Cybersecurity event — third-party service providers
§ 507F.10 Cybersecurity event reinsurers
§ 507F.11 Cybersecurity event — producers of record
§ 507F.12 Confidentiality
§ 507F.13 Applicability
§ 507F.14 Penalties
§ 507F.15 Rules and enforcement
§ 507F.16 Severability

Terms Used In Iowa Code > Chapter 507F - Insurance Data Security

  • Account: means the same as defined in section 554. See Iowa Code 554E.1
  • Assets: (1) The property comprising the estate of a deceased person, or (2) the property in a trust account.
  • Beneficiary: A person who is entitled to receive the benefits or proceeds of a will, trust, insurance policy, retirement plan, annuity, or other contract. Source: OCC
  • Board: means the engineering and land surveying examining board provided by this chapter. See Iowa Code 542B.2
  • Commissioner: means the commissioner of insurance. See Iowa Code 507F.3
  • Consumer: means an individual, including but not limited to an applicant, policyholder, insured, beneficiary, claimant, or certificate holder, who is a resident of this state and whose nonpublic information is in a licensee's possession, custody, or control. See Iowa Code 507F.3
  • Corporation: A legal entity owned by the holders of shares of stock that have been issued, and that can own, receive, and transfer property, and carry on business in its own name.
  • Cybersecurity event: means an event resulting in unauthorized access to, or the disruption or misuse of, an information system or of nonpublic information stored on an information system. See Iowa Code 507F.3
  • Discovery: Lawyers' examination, before trial, of facts and documents in possession of the opponents to help the lawyers prepare for trial.
  • Electronic: means the same as defined in section 554D. See Iowa Code 554E.1
  • Encrypted: means the transformation of data into a form that results in a low probability of assigning meaning to the data without the use of a protective process or key. See Iowa Code 507F.3
  • Evidence: Information presented in testimony or in documents that is used to persuade the fact finder (judge or jury) to decide the case for one side or the other.
  • following: when used by way of reference to a chapter or other part of a statute mean the next preceding or next following chapter or other part. See Iowa Code 4.1
  • HIPAA: means the Health Insurance Portability and Accountability Act of 1996, Pub. See Iowa Code 507F.3
  • Home state: means the same as defined in section 522B. See Iowa Code 507F.3
  • Information security program: means the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle nonpublic information. See Iowa Code 507F.3
  • Information system: means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic nonpublic information, and any specialized system such as an industrial or process controls system, a telephone switching and private branch exchange system, or an environmental control system. See Iowa Code 507F.3
  • Insurer: means the same as defined in section 521A. See Iowa Code 507F.3
  • Jurisdiction: (1) The legal authority of a court to hear and decide a case. Concurrent jurisdiction exists when two courts have simultaneous responsibility for the same case. (2) The geographic area over which the court has authority to decide cases.
  • Licensee: means a person licensed, authorized to operate, or registered, or a person required to be licensed, authorized to operate, or registered pursuant to the insurance laws of this state. See Iowa Code 507F.3
  • Multi-factor authentication: means authentication through verification of at least two of the following types of authentication factors:
  • Nonpublic information: means electronic information that is not publicly available information and that is any of the following:
  • Obligation: An order placed, contract awarded, service received, or similar transaction during a given period that will require payments during the same or a future period.
  • Oversight: Committee review of the activities of a Federal agency or program.
  • Partnership: A voluntary contract between two or more persons to pool some or all of their assets into a business, with the agreement that there will be a proportional sharing of profits and losses.
  • Person: means an individual or a nongovernmental entity, including but not limited to a nongovernmental partnership, corporation, branch, agency, or association. See Iowa Code 507F.3
  • Publicly available information: means information that a licensee has a reasonable basis to believe is lawfully made available to the general public from federal, state, or local government records, by widely distributed media, or by disclosure to the general public as required by federal, state, or local law. See Iowa Code 507F.3
  • Record: means the same as defined in section 554D. See Iowa Code 554E.1
  • Risk assessment: means the assessment that a licensee is required to conduct pursuant to section 507F. See Iowa Code 507F.3
  • Rule: includes "regulation". See Iowa Code 4.1
  • state: when applied to the different parts of the United States, includes the District of Columbia and the territories, and the words "United States" may include the said district and territories. See Iowa Code 4.1
  • Subpoena: A command to a witness to appear and give testimony.
  • Testify: Answer questions in court.
  • Third-party service provider: means a person that is not a licensee that contracts with a licensee to maintain, process, store, or is otherwise permitted access to nonpublic information through the person's provision of services to the licensee. See Iowa Code 507F.3