Kentucky Statutes 393A.820 – Security of information
Current as of: 2024 | Check for updates
|
Other versions
(1) If a holder is required to include confidential information in a report to the administrator, the information shall be provided by a secure means.
(2) If confidential information in a record is provided to and maintained by the administrator or administrator’s agent as required by this chapter, the administrator or agent shall:
(a) Implement administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of the information as required by KRS
365.720 to 365.730 and federal privacy and data security law, whether or not the administrator or the administrator’s agent is subject to the law;
(b) Protect against reasonably anticipated threats or hazards to the security, confidentiality, or integrity of the information; and
(c) Protect against unauthorized access to or use of the information which could result in substantial harm or inconvenience to a holder or the holder’s customers, including insureds, annuitants, and policy or contract owners and their beneficiaries.
(3) The administrator:
(a) After notice and comment, shall adopt and implement a security plan that identifies and assesses reasonably foreseeable internal and external risks to confidential information in the administrator’s possession and seeks to mitigate the risks; and
(b) Shall ensure that an administrator’s agent adopts and implements a similar plan with respect to confidential information in the agent’s possession.
(4) The administrator and the administrator’s agent shall educate and train their employees regarding the plan adopted under subsection (3) of this section.
(5) The administrator and the administrator’s agent shall in a secure manner return or destroy all confidential information no longer reasonably needed under this chapter.
Effective: July 14, 2018
History: Created 2018 Ky. Acts ch. 163, sec. 82, effective July 14, 2018.
(2) If confidential information in a record is provided to and maintained by the administrator or administrator’s agent as required by this chapter, the administrator or agent shall:
Terms Used In Kentucky Statutes 393A.820
- Administrator: means the Kentucky State Treasurer. See Kentucky Statutes 393A.010
- Confidential information: means records, reports, and information that are confidential under KRS §. See Kentucky Statutes 393A.010
- Contract: A legal written agreement that becomes binding when signed.
- Federal: refers to the United States. See Kentucky Statutes 446.010
- Holder: means a person obligated to hold for the account of, or to deliver or pay to, the owner, property subject to this chapter. See Kentucky Statutes 393A.010
- Record: means information that is inscribed on a tangible medium or that is stored in an electronic or other medium and is retrievable in perceivable form. See Kentucky Statutes 393A.010
- Security: means :
(a) A security as defined in KRS §. See Kentucky Statutes 393A.010
(a) Implement administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of the information as required by KRS
365.720 to 365.730 and federal privacy and data security law, whether or not the administrator or the administrator’s agent is subject to the law;
(b) Protect against reasonably anticipated threats or hazards to the security, confidentiality, or integrity of the information; and
(c) Protect against unauthorized access to or use of the information which could result in substantial harm or inconvenience to a holder or the holder’s customers, including insureds, annuitants, and policy or contract owners and their beneficiaries.
(3) The administrator:
(a) After notice and comment, shall adopt and implement a security plan that identifies and assesses reasonably foreseeable internal and external risks to confidential information in the administrator’s possession and seeks to mitigate the risks; and
(b) Shall ensure that an administrator’s agent adopts and implements a similar plan with respect to confidential information in the agent’s possession.
(4) The administrator and the administrator’s agent shall educate and train their employees regarding the plan adopted under subsection (3) of this section.
(5) The administrator and the administrator’s agent shall in a secure manner return or destroy all confidential information no longer reasonably needed under this chapter.
Effective: July 14, 2018
History: Created 2018 Ky. Acts ch. 163, sec. 82, effective July 14, 2018.