HRS §431:3B-305
Reinsurers must tell insurers about data breaches
This section says that when a reinsurer (an assuming insurer) has a data breach involving customer information, it must tell the ceding insurers and its home state's insurance commissioner within three business days. If a third-party service provider has the breach, the reinsurer must tell them within three business days of learning about it. The ceding insurers, who have direct contact with customers, must handle notifying those customers as required by other laws.
The statute, as written — Notice regarding cybersecurity events of reinsures to insurers
(a) In the case of a cybersecurity event involving nonpublic information that is used by the licensee that is acting as an assuming insurer or in the possession, custody, or control of a licensee that is acting as an assuming insurer and that does not have a direct contractual relationship with the affected consumers, the assuming insurer shall notify its affected ceding insurers and the commissioner of its state of domicile within three business days of making the determination that a cybersecurity event has occurred. (b) In the case of a cybersecurity event involving nonpublic information that is in the possession, custody, or control of a third-party service provider of a licensee that is an assuming insurer, the assuming insurer shall notify its affected ceding insurers and the commissioner of its state of domicile within three business days of receiving notice from its third-party service provider that a cybersecurity event has occurred. (c) The ceding insurers that have a direct contractual relationship with affected consumers shall fulfill the consumer notification requirements imposed under chapter 487N and any other notification requirements relating to a cybersecurity event imposed under this part.
LawTrove is not legal advice. The summary above is a computer-generated restatement — the authoritative text is the official version linked above.