§ 38.2-621 Definitions.
§ 38.2-622 Private cause of action; neither created nor curtailed.
§ 38.2-623 Information security program.
§ 38.2-624 Investigation of a cybersecurity event.
§ 38.2-625 Notice to Commissioner.
§ 38.2-626 Notice to consumers.
§ 38.2-627 Powers and duties of the Commission; exclusive state standards.
§ 38.2-628 Confidentiality.
§ 38.2-629 Exceptions.

Ask an insurance law question, get an answer ASAP!
Click here to chat with a lawyer about your rights.

Terms Used In Virginia Code > Title 38.2 > Chapter 6 > Article 2 - Insurance Data Security Act.

  • Authorized person: means a person known to and authorized by the licensee and determined to be necessary and appropriate to have access to the nonpublic information held by the licensee and its information systems. See Virginia Code 38.2-621
  • Commission: means the State Corporation Commission. See Virginia Code 38.2-100
  • Company: means any association, aggregate of individuals, business, corporation, individual, joint-stock company, Lloyds type of organization, organization, partnership, receiver, reciprocal or interinsurance exchange, trustee or society. See Virginia Code 38.2-100
  • Consumer: means an individual, including applicants, policyholders, insureds, beneficiaries, claimants, and certificate holders, who is a resident of the Commonwealth and whose nonpublic information is in the possession, custody, or control of a licensee or an authorized person. See Virginia Code 38.2-621
  • Corporation: A legal entity owned by the holders of shares of stock that have been issued, and that can own, receive, and transfer property, and carry on business in its own name.
  • Cybersecurity event: means an event resulting in unauthorized access to, disruption of, or misuse of an information system or nonpublic information in the possession, custody, or control of a licensee or an authorized person. See Virginia Code 38.2-621
  • Discovery: Lawyers' examination, before trial, of facts and documents in possession of the opponents to help the lawyers prepare for trial.
  • Encrypted: means the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key. See Virginia Code 38.2-621
  • Evidence: Information presented in testimony or in documents that is used to persuade the fact finder (judge or jury) to decide the case for one side or the other.
  • Fair Debt Collection Practices Act: The Fair Debt Collection Practices Act is a set of United States statutes added as Title VIII of the Consumer Credit Protection Act. Its purpose is to ensure ethical practices in the collection of consumer debts and to provide consumers with an avenue for disputing and obtaining validation of debt information in order to ensure the information's accuracy. It is often used in conjunction with the Fair Credit Reporting Act. Source: OCC
  • Fraud: Intentional deception resulting in injury to another.
  • HIPAA: means the federal Health Insurance Portability and Accountability Act (Virginia Code 38.2-621
  • in writing: include any representation of words, letters, symbols, numbers, or figures, whether (i) printed or inscribed on a tangible medium or (ii) stored in an electronic or other medium and retrievable in a perceivable form and whether an electronic signature authorized by Virginia Code 1-257
  • Information security program: means the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle nonpublic information. See Virginia Code 38.2-621
  • Information system: means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic information, as well as any specialized system such as industrial or process control systems, telephone switching and private branch exchange systems, and environmental control systems. See Virginia Code 38.2-621
  • Insurer: means an insurance company. See Virginia Code 38.2-100
  • Jurisdiction: (1) The legal authority of a court to hear and decide a case. Concurrent jurisdiction exists when two courts have simultaneous responsibility for the same case. (2) The geographic area over which the court has authority to decide cases.
  • Licensee: means any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered pursuant to the insurance laws of the Commonwealth. See Virginia Code 38.2-621
  • Nonpublic information: means information that is not publicly available information and is:

    1. See Virginia Code 38.2-621

  • Obligation: An order placed, contract awarded, service received, or similar transaction during a given period that will require payments during the same or a future period.
  • Partnership: A voluntary contract between two or more persons to pool some or all of their assets into a business, with the agreement that there will be a proportional sharing of profits and losses.
  • Person: means any individual or any nongovernmental entity, including any nongovernmental partnership, corporation, branch, agency, or association. See Virginia Code 38.2-621
  • Process: includes subpoenas, the summons and complaint in a civil action, and process in statutory actions. See Virginia Code 1-237
  • Publicly available information: means any information that a licensee has a reasonable basis to believe is lawfully made available to the general public from federal, state, or local government records; widely distributed media; or disclosures to the general public that are required to be made by federal, state, or local law. See Virginia Code 38.2-621
  • State: means any commonwealth, state, territory, district or insular possession of the United States. See Virginia Code 38.2-100
  • state agency: means the same as that term is defined in § Virginia Code 1-206
  • Subpoena: A command to a witness to appear and give testimony.
  • Testify: Answer questions in court.
  • Third-party service provider: means (i) a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, or store nonpublic information, or otherwise is permitted access to nonpublic information through its provision of services to the licensee or (ii) an insurance-support organization. See Virginia Code 38.2-621