• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
ReSource Pro Compliance | Insurance Licensing Services

ReSource Pro Compliance | Insurance Licensing Services

Insurance Licensing, Compliance, Surplus Lines and More...

  • Home
  • Services
    • Insurance Licensing
      • Initial Licensing
      • Affiliations & Appointments
      • License Renewals
      • Change Tracking & Notifications
      • License Cancellations
    • Corporate Compliance
      • Business Registrations
      • Registered Agent Services
      • Name Approvals and DBA Registrations
      • Annual / Biennial Returns
      • Franchise / Foreign Corporation Tax Filings
    • Surplus Lines Tax Filings
      • Surplus Lines Calculator and Tax Tool
      • Surplus Lines Industry Connection
      • Policy Filings
      • Premium Tax and Zero Reports
    • Compliance Reviews
      • Mergers and Acquisitions Support
  • Resources
    • State Regulators
    • Bulletins
    • Press Releases
    • Compliance Terminology
  • Contact Us
  • (833) 895-0541
Home » Bulletins » North Dakota Insurance Department Issues Updated Guidance on Data Security and Cyber Event Notification Requirements for Licensees

North Dakota Insurance Department Issues Updated Guidance on Data Security and Cyber Event Notification Requirements for Licensees

ND| North Dakota Insurance Bulletin 2025-1 establishes updated requirements for insurance licensees regarding data security and cybersecurity event reporting, effective August 1, 2025, under NDCC 26.1-02.2 and SB 2088. Licensees—including insurers, producers, TPAs, MGAs, and other entities—must implement a written Information Security Program, promptly investigate potential cybersecurity events, and notify the Insurance Commissioner within three business days if certain thresholds are met. HIPAA-covered entities are generally exempt from some requirements but must still comply with breach notification to the Commissioner.

Key Points

  • All licensees must implement, monitor, and update an Information Security Program, including risk assessment and third-party diligence; smaller entities (under $5M revenue or $10M assets) may tailor programs to their scale.
  • Cybersecurity events must be investigated immediately, documented for at least five years, and reported to the Commissioner within three business days if North Dakota residents or 250+ consumers are impacted.
  • HIPAA-covered licensees may be exempt from certain provisions but remain subject to event notification requirements; guidance is available from the Insurance Department.

Click here to see ND Bulletin 2025-1

Primary Sidebar

Ready to Start Your Journey To Compliance

Contact Us

Footer

Services

  • Insurance Licensing
    • Initial Licensing
    • Affiliations & Appointments
    • License Renewals
    • Change Tracking & Notifications
    • License Cancellations
  • Corporate Compliance
    • Business Registrations
    • Registered Agent Services
    • Name Approvals and DBA Registrations
    • Annual / Biennial Returns
    • Franchise / Foreign Corporation Tax Filings
  • Surplus Lines Tax Filings
    • Surplus Lines Calculator and Tax Tool
    • Surplus Lines Industry Connection
    • Policy Filings
    • Premium Tax and Zero Reports
  • Compliance Reviews
    • Mergers and Acquisitions Support

Resources

  • Bulletins
  • Press Releases
  • Regulators
  • Compliance Terminology

Contact Information

111 North Railroad Street
Groesbeck, TX76642
833-895-0541
254-729-8002
compliance@resourcepro.com
Call Us

Copyright © 2025 ReSource Pro, LLC. All rights reserved