☰ Revisor of Missouri

Title XXIV BUSINESS AND FINANCIAL INSTITUTIONS

Chapter 375

< > Effective - 01 Jan 2026, see footnote    bottom

  375.1402.  Definitions. — As used in sections 375.1400 to 375.1427, the following terms mean:

  (1)  "Authorized person", an individual known to and authorized by the licensee and determined to be necessary and appropriate to have access to the nonpublic information held by the licensee and its information systems;

  (2)  "Consumer", an individual, including, but not limited to, applicants, policyholders, insureds, beneficiaries, claimants, and certificate holders, who is a resident of this state and whose nonpublic information is in a licensee's possession, custody, or control;

  (3)  "Cybersecurity event", an event resulting in unauthorized access to, malicious disruption of, or misuse of an information system or nonpublic information in the possession, custody, or control of a licensee or an authorized person; however:

  (a)  The term "cybersecurity event" does not include the unauthorized acquisition of encrypted, nonpublic information if the encryption, process, or key is not also acquired, released, or used without authorization; and

  (b)  The term "cybersecurity event" does not include an event with regard to which the licensee has determined that the nonpublic information accessed by an unauthorized person has not been used or released and has been returned or destroyed;

  (4)  "Department", the department of commerce and insurance;

  (5)  "Director", the director of the department of commerce and insurance;

  (6)  "Encrypted", the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key;

  (7)  "HIPAA", the federal Health Insurance Portability and Accountability Act (42 U.S.C. Section 1320d et seq.);

  (8)  "Information security program", the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle nonpublic information;

  (9)  "Information system", a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of electronic nonpublic information, as well as any specialized system such as industrial and process controls systems, telephone switching and private branch exchange systems, and environmental control systems;

  (10)  "Licensee", any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered under the insurance laws of this state, but shall not include a purchasing group or a risk retention group chartered and licensed in a state other than this state or a licensee that is acting as an assuming insurer that is domiciled in another state or jurisdiction;

  (11)  "Multifactor authentication", authentication through verification of at least two of the following types of authentication factors:

  (a)  Knowledge factors, such as a password;

  (b)  Possession factors, such as a token or text message on a mobile phone; or

  (c)  Inherence factors, such as a biometric characteristic;

  (12)  "Nonpublic information", information that is not publicly available information and is:

  (a)  Business-related information of a licensee, the tampering with which, or unauthorized disclosure, access, or use of which, would cause a material adverse impact to the business, operations, or security of the licensee;

  (b)  Any information concerning a consumer that, because of name, number, personal mark, or other identifier, can be used to identify such consumer, in combination with any one or more of the following data elements:

  a.  Social Security number;

  b.  Driver's license number or nondriver identification card number;

  c.  Financial account number or credit or debit card number;

  d.  Any security code, access code, or password that would permit access to a consumer's financial account;

  e.  Biometric records; or

  f.  Military identification number;

  (c)  Any information or data, except age or gender, in any form or medium created by or derived from a health care provider or a consumer and that relates to:

  a.  The past, present, or future physical, mental, or behavioral health or condition of any consumer or a member of the consumer's family;

  b.  The provision of health care to any consumer; or

  c.  Payment for the provision of health care to any consumer;

  (13)  "Person", any individual or any nongovernmental entity including, but not limited to, any nongovernmental partnership, corporation, branch, agency, or association;

  (14)  "Publicly available information", any information that a licensee has a reasonable basis to believe is lawfully made available to the general public from federal, state, or local government records; widely distributed media; or disclosures to the general public that are required to be made by federal, state, or local law.  For the purposes of this definition, a licensee has a reasonable basis to believe that information is lawfully made available to the general public if the licensee has taken steps to determine:

  (a)  That the information is of the type that is available to the general public; and

  (b)  Whether a consumer can direct that the information not be made available to the general public and, if so, that such consumer has not done so;

  (15)  "Risk assessment", the risk assessment that each licensee is required to conduct under subsection 3 of section 375.1405;

  (16)  "State", the state of Missouri;

  (17)  "Third-party service provider", a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, store, or otherwise is permitted access to nonpublic information through its provision of services to the licensee.

­­--------

(L. 2025 H.B. 974, et al.)

Effective 1-01-26; see § 375.1427


---- end of effective  01 Jan 2026 ----

use this link to bookmark section  375.1402


Click here for the Reorganization Act of 1974 - or - Concurrent Resolutions Having Force & Effect of Law
In accordance with Section 3.090, the language of statutory sections enacted during a legislative session are updated and available on this website on the effective date of such enacted statutory section. Revisor Home    

Other Information
 Recent Sections Editorials May Be Cited As Tables & Forms Multiple Enact
Repeal & Transfer Definitions End Report

Site changes Pictures Contact

Other Links
Legislative Research Oversight MOLIS
Library MO WebMasters
Senate
Missouri Senate
State of Missouri
MO.gov
House
Missouri House