{"data":{"id":"us-ky/krs-304.3-760","jurisdiction":"us-ky","citation":"KRS 304.3-760","heading":"Notification to commissioner of cybersecurity event -- Procedures.","body":"(1) Each licensee shall notify the commissioner of a cybersecurity event involving\nnonpublic information that is in the possession of the licensee as promptly as\npossible, but in no event later than three (3) business days from a determination that\na cybersecurity event has occurred, if:\n(a) In the case of an insurer, this state is the licensee's state of domicile and the\ncybersecurity event has a reasonable likelihood of har ming any material part\nof normal operations of the licensee;\n(b) In the case of an insurance producer, this state is the licensee's home state, as\nthose terms are defined in KRS 304.9-020; or\n(c) The licensee reasonably believes that:\n1. The nonpublic information involved in the cybersecurity event is related\nto two hundred fifty (250) or more consumers residing in this state; and\n2. The cybersecurity event is either of the following:\na. A cybersecurity event requiring the licensee to provide notice to\nany governmental body, self -regulatory agency, or any other\nsupervisory body pursuant to any state or federal law; or\nb. A cybersecurity event that has a reasonable likelihood of\nmaterially harming any:\ni. Consumer residing in this state; or\nii. Material part of the normal operations of the licensee.\n(2) (a) In its notification to the commissioner under subsection (1) of this section, the\nlicensee shall provide, in an electronic form prescribed by the commis sioner,\nthe following information:\n1. The date of the cybersecurity event;\n2. A description of how the information was exposed, lost, stolen, or\nbreached, including the specific roles and responsibilities of third -party\nservice providers, if any;\n3. How the cybersecurity event was discovered;\n4. Whether any lost, stolen, or breached information has been recovered,\nand if so, how the information was recovered;\n5. The identity of the source of the cybersecurity event;\n6. Whether the licensee has filed a polic e report or has notified any\nregulatory, government, or law enforcement agencies, and if so, when\nthe notification was provided;\n7. A description of the specific types of information acquired without\nauthorization, including but not limited to types of med ical information,\nfinancial information, or information allowing identification of the\nconsumer;\n8. The period during which the information system was compromised by\nthe cybersecurity event;\n9. The licensee's best estimate of the number of total consumers in this\nstate affected by the cybersecurity event, which shall be updated with\neach subsequent report to the commissioner pursuant to this section;\n10. The results of any internal review:\na. Identifying a lapse in automated controls or internal procedures; or\nb. Confirming that all automated controls or internal procedures were\nfollowed;\n11. A description of the efforts being undertaken to remediate the situation\nthat permitted the cybersecurity event to occur;\n12. A copy of the licensee's privacy policy an d a statement outlining the\nsteps the licensee will take to investigate and notify consumers affected\nby the cybersecurity event;\n13. A copy of the notice sent to consumers under KRS 365.732, if\napplicable; and\n14. The name of a contact person who is famil iar with the cybersecurity\nevent and authorized to act for the licensee.\n(b) The licensee shall have a continuing obligation under subsection (1) of this\nsection to update and supplement initial and subsequent notifications to the\ncommissioner concerning the cybersecurity event.\n(3) Each licensee shall comply with KRS 365.732, as applicable.\n(4) In the case of a cybersecurity event in a system maintained by a third -party service\nprovider of which the licensee has become aware:\n(a) Except as provided under subsection (5) of this section, the licensee shall treat\nthe cybersecurity event as it would under subsection (1) of this section; and\n(b) The computation of the licensee's deadlines under this subsection shall begin\non the earlier of the day after:\n1. The third -party service provider notifies the licensee of the\ncybersecurity event; or\n2. The licensee otherwise has actual knowledge of the cybersecurity event.\n(5) Nothing in KRS 304.3 -750 to 304.3 -768 shall prevent or abrogate an agreement\nbetween a licensee and another licensee, a third-party service provider, or any other\nparty to fulfill the obligations of or obligations similar to:\n(a) Investigation requirements under KRS 304.3-758; or\n(b) Notice requirements under this section.\n(6) (a) In the case of  a cybersecurity event involving nonpublic information that is\nused by a licensee acting as an assuming insurer, or that is in the possession,\ncustody, or control of a licensee that is acting as an assuming insurer, and the\nassuming insurer does not have a  direct contractual relationship with the\naffected consumers, the assuming insurer shall notify its affected ceding\ninsurers and the commissioner of its state of domicile within three (3)\nbusiness days of making the determination that a cybersecurity event  has\noccurred.\n(b) In the case of a cybersecurity event involving nonpublic information that is in\nthe possession, custody, or control of a third -party service provider of a\nlicensee that is an assuming insurer, the assuming insurer shall notify its\naffected ceding insurers and the commissioner of its state of domicile within\nthree (3) business days of receiving notice from its third -party service\nprovider that a cybersecurity event has occurred.\n(c) A ceding insurer under paragraph (a) or (b) of this subse ction that has a direct\ncontractual relationship with affected consumers shall fulfill:\n1. The consumer notification requirements imposed under KRS 365.732;\nand\n2. Any other notification requirements relating to a cybersecurity event\nunder this section.\n(d) Except as provided in paragraph (a) or (b) of this subsection, a licensee acting\nas an assuming insurer shall not be subject to any notice obligations relating\nto a cybersecurity event or other data breach under this section.\n(7) (a) Except as provided i n paragraph (b) of this subsection, in the case of a\ncybersecurity event involving nonpublic information that is in the possession,\ncustody, or control of a licensee that is an insurer, or its third -party service\nprovider, and for which a consumer accessed  the insurer's services through an\nindependent insurance producer, the insurer shall notify the producers of\nrecord at the same time as all affected consumers when a licensee is required\nto notify consumers under KRS 365.732.\n(b) An insurer shall not be re quired to comply with paragraph (a) of this\nsubsection when the insurer does not have the current producer of record\ninformation for any individual consumer.","path":[],"source_url":"https://apps.legislature.ky.gov/law/statutes/statute.aspx?id=53296","current_through":"Includes enactments through the 2026 Regular Session","vintage":"09/05/2026","retrieved_at":"2026-09-05T20:57:38Z","sha256":"bb915ee52c8975c3db54d42051a3d14fd9f4e0dcf46b5c5fbe739645d61bd6b6","source_id":"us-ky","stale":false,"prev":"us-ky/krs-304.3-758","next":"us-ky/krs-304.3-762"},"notice":"GroundRules: Original legal text. Not legal advice."}
