Search

Search bills, members, committees and pages...

B 26-0427

District of Columbia CouncilEngrossed

Summary

B 26-0427, the Cybersecurity and Accountability Act of 2025, was introduced in the Council on Oct 8, 2025 by Sen. Phil Mendelson (D). It last saw action on Jul 14, 2026: First Reading, CC.


Record

Text

B 26-0427 has 1 roll call.

b260427/engrossed.txt
ENGROSSED ORIGINAL
A BILL
26-427
IN THE COUNIL OF THE DISTRICT OF COLUMBIA
________________________
To require that insurance licensees establish standards for data security, investigating
cybersecurity events, and notifying the Commissioner of the Department of Insurance,
Securities and Banking of cybersecurity events; and to amend the Freedom of
Information Act of 1976 to make a conforming change.
BE IT ENACTED BY THE COUNCIL OF THE DISTRICT OF COLUMBIA, That this
act may be cited as the “Cybersecurity and Accountability Amendment Act of 2026”.
TITLE I. CYBERSECURITY AND ACCOUNTABILITY REQUIREMENTS.
Sec. 101. Short title.
This title may be known as the “Cybersecurity and Accountability Act of 2026”.
Sec. 102. Definitions.
For the purposes of this title, the term:
(1) “Authorized individual” means an individual known to, and screened by, the
licensee, and to whom the licensee has determined access to the nonpublic information held
by the licensee and its information systems is necessary and appropriate.
(2) “Commissioner” means the Commissioner of the Department of Insurance,
Securities, and Banking.
1
ENGROSSED ORIGINAL
(3) “Consumer” means a person, including an applicant, policyholder, insured,
beneficiary, claimant, or certificate holder who is a resident of the District and whose nonpublic
information is in a licensee’s possession, custody, or control.
(4) “Cybersecurity event” means an event resulting in unauthorized access to, or
disruption or misuse of, an information system or nonpublic information stored on the
information system but does not include:
(A) The unauthorized acquisition of encrypted nonpublic information if
the encryption, process, or key is not also acquired, released, or used without authorization; or
(B) An event where the licensee has determined that the nonpublic
information accessed by an unauthorized person has not been used or released and has been
returned or destroyed.
(5) “Department” means the Department of Insurance, Securities, and Banking.
(6) “Encrypted” means the transformation of data into a form which results in a
low probability of assigning meaning to the data without the use of a protective process or key.
(7) “Information security program” means the administrative, technical, and
physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use,
transmit, dispose of, or otherwise handle nonpublic information.
(8) “Information system” means a discrete set of electronic information resources
organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition
of electronic information, as well as any specialized system, such as an industrial or process
2
ENGROSSED ORIGINAL
controls system, telephone switching and private branch exchange system, or environmental
control system.
(9) “Licensee” means any person licensed, authorized to operate, or registered, or
required to be licensed, authorized, or registered by the Department, as an insurance producer or
insurer, as those terms are defined under section 2(6) and (7) of the Producer Licensing Act of
2002, effective March 27, 2003 (D.C. Law 14-264; D.C. Official Code § 31-1131.02(6) and (7));
except, that the term “licensee” shall not include a purchasing or a risk retention group chartered
and licensed in a jurisdiction other than the District or a person acting as an assuming insurer that
is domiciled in another state or jurisdiction.
(10) “Multi-factor authentication” means authentication through verification of at
least 2 of the following types of authentication factors:
(A) Knowledge factors, such as a password;
(B) Possession factors, such as a token or text message on a mobile phone;
or
(C) Inherence factors, such as a biometric characteristic.
(11) “Nonpublic information” means information that is not publicly available
information and is:
(A) Business-related information of a licensee, the tampering with, or
unauthorized disclosure, access, or use of which, would cause a material adverse impact to the
business, operations, or security of the licensee;
3
ENGROSSED ORIGINAL
(B) Any information concerning a consumer that, because of name,
number, personal mark, or other identifier, can be used to identify the consumer, in combination
with at least one of the following data elements:
(i) Social Security number;
(ii) Driver’s license number or non-driver identification card
number;
(iii) Bank account number or credit or debit card number;
(iv) Any security code, access code, or password that would permit
access to a consumer’s financial account; or
(v) Biometric records; or
(C) Any information or data, except age or gender, in any form or medium
created by, or derived from, a health care provider or a consumer and that relates to the:
(i) Past, present, or future physical, mental, or behavioral health or
condition of a consumer or a member of the consumer’s family;
(ii) Provision of health care to a consumer; or
(iii) Payment for the provision of health care to a consumer.
(12)(A) “Publicly available information” means any information that a licensee
has a reasonable basis to believe is lawfully made available to the general public from:
(i) Federal, state, or local government records;
(ii) Widely distributed media; or
4
ENGROSSED ORIGINAL
(iii) Disclosures to the general public that are required to be made
by federal, state, or local law.
(B) For purposes of this paragraph, a licensee has a reasonable basis to
believe that information is lawfully made available to the general public if the licensee has taken
steps to determine:
(i) That the information is of the type that is available to the
general public; and
(ii) Whether a consumer can direct that the information not be
made available to the general public and, if so, that the consumer has chosen not to do so.
(13) “Risk assessment” means the assessment that a licensee is required to
conduct under section 103(b).
(14) “Third-Party service provider” means a person that is not a licensee and that
contracts with a licensee to maintain, process, or store nonpublic information, or otherwise is
permitted access to nonpublic information through its provision of services to the licensee.
Sec. 103. Information security program.
(a) Each licensee shall develop, implement, and maintain a comprehensive written
information security program based on the licensee’s risk assessment, which shall include
administrative, technical, and physical safeguards for the protection of nonpublic information
and the licensee’s information system. The information security program shall:
5
ENGROSSED ORIGINAL
(1) Be designed to protect the security and confidentiality of nonpublic
information and the security of the information system;
(2) Be designed to protect against any threats or hazards to the security or
integrity of nonpublic information and the information system;
(3) Be designed to protect against unauthorized access to, or use of, nonpublic
information, and minimize the likelihood of harm to any consumer; and
(4) Define and periodically reevaluate a schedule for the retention of nonpublic
information and a mechanism for its destruction when no longer needed.
(b) The licensee shall conduct a risk assessment as part of its obligations to establish an
information security system, which shall:
(1) Designate one or more employees, an affiliate, or an outside vendor
designated to act on behalf of the licensee who is responsible for the licensee’s information
security program;
(2) Identify reasonably foreseeable internal or external threats that could result in
unauthorized access, transmission, disclosure, misuse, alteration, or destruction of nonpublic
information, including the security of information systems and nonpublic information that are
accessible to, or held by, third-party service providers;
(3) Assess the likelihood and potential damage of these threats, taking into
consideration the sensitivity of the nonpublic information;
6
ENGROSSED ORIGINAL
(4) Assess the sufficiency of policies, procedures, information systems, and other
safeguards in place to manage these threats, including consideration of threats in each relevant
area of the licensee’s operations, including:
(A) Employee training and management;
(B) Information systems, including network and software design,
information classification, governance, processing, storage, transmission, and disposal; and
(C) Detecting, preventing, and responding to attacks, intrusions, or other
systems failures; and
(5) Implement information safeguards to manage the threats identified under
paragraph (2) of this subsection in an operative continuous assessment, and, on an annual basis,
assess the effectiveness of the safeguards’ key controls, systems, and procedures.
(c) Based on its risk assessment, the licensee’s information security system shall:
(1) Be designed to mitigate the identified risks, commensurate with the size and
complexity of the licensee’s activities, including its use of third-party service providers and the
sensitivity of the nonpublic information and certain public information, including personally
identifiable information, used by the licensee or in the licensee’s possession, custody, or control;
(2) Assess which of the following security measures are appropriate and
implement such security measures:
(A) Place access controls on information systems, including controls to
authenticate and permit access only by authorized individuals;
7
ENGROSSED ORIGINAL
(B) Identify and manage the data, personnel, devices, systems, and
facilities that enable the licensee to achieve business purposes in accordance with their relative
importance to business objectives and the licensee’s risk assessment;
(C) Restrict access at physical locations containing nonpublic information
only to authorized individuals;
(D) Protect by encryption or other appropriate means all nonpublic
information while being transmitted over an external network and all nonpublic information
stored on a laptop computer or other portable computing or storage device or media;
(E) Adopt secure development practices for in-house developed
applications utilized by the licensee and procedures for evaluating, assessing, or testing the
security of externally developed applications utilized by the licensee;
(F) Modify the information system in accordance with the licensee’s
information security program;
(G) Utilize effective controls, which may include multi-factor
authentication procedures, for any individual accessing nonpublic information;
(H) Regularly test and monitor systems and procedures to detect actual
and attempted attacks on, or intrusion into, information systems;
(I) Include audit trails within the information security program designed to
detect and respond to cybersecurity events and to reconstruct material financial transactions
sufficient to support normal operations and obligations of the licensee;
8
ENGROSSED ORIGINAL
(J) Implement measures to protect against destruction, loss, or damage of
nonpublic information due to environmental hazards, such as fire and water damage or other
catastrophes or technological failures; and
(K) Develop, implement, and maintain procedures for the secure disposal
of nonpublic information in any format;
(3) Include cybersecurity risks in the licensee’s enterprise risk management
process;
(4) Stay informed on emerging threats or vulnerabilities and utilize reasonable
security measures when sharing information relative to the character of the sharing and the type
of information shared; and
(5) Provide personnel with cybersecurity awareness training that is updated as
necessary to reflect risks identified by the licensee in the risk assessment.
(d) Notwithstanding subsection (c)(2) of this section, the Commissioner may issue
additional security measures through rulemaking.
(e)(1) Beginning on February 15 of the year after the effective date of this title, and
annually thereafter, each licensee shall submit a written statement to the Commissioner
confirming that the insurer is in compliance with the requirements of this section.
(2) Each licensee shall maintain for examination by the Department all records,
schedules, and data supporting its annual written statement for a period of 5 years. To the extent
the licensee has identified areas, systems, or processes that require material improvement,
9
ENGROSSED ORIGINAL
updating, or redesign, it shall document the identification and the remedial efforts planned and
underway to address those areas, systems, or processes, which shall be available for inspection
by the Commissioner.
Sec. 104. Investigation and notification of a cybersecurity event.
(a) If the licensee learns that a cybersecurity event has or may have occurred in its
information system or a system maintained by a third-party service provider, the licensee, an
outside vendor or service provider designated to act on behalf of the licensee, or the third-party
service provider shall conduct a prompt investigation, which shall at a minimum and to the
extent possible:
(1) Determine whether a cybersecurity event has occurred;
(2) Assess the nature and scope of the cybersecurity event;
(3) Identify any nonpublic information that may have been involved in the
cybersecurity event; and
(4) Perform or oversee reasonable measures to restore the security of the
information system compromised in the cybersecurity event to prevent further unauthorized
acquisition, release, or use of nonpublic information in the licensee’s possession, custody, or
control.
(b) The licensee shall maintain records concerning each cybersecurity event for a period
of at least 5 years from the date of cybersecurity event and shall produce those records to the
Commissioner upon request.
10
ENGROSSED ORIGINAL
(c) A licensee shall notify the Commissioner of a cybersecurity event no later than 3
business days after a determination that a cybersecurity event has occurred, if:
(1) The District is the licensee’s jurisdiction of domicile in the case of an insurer
or the District is the licensee’s home jurisdiction in the case of an insurance producer, as those
terms are defined in section 2(7) and (6) of the Producer Licensing Act of 2002, effective March
27, 2003 (D.C. Law 14-264; D.C. Official Code § 31-1131.02(7) and (6)), respectively; or
(2) The licensee reasonably believes that the nonpublic information involves 250
or more consumers residing in the District and the cybersecurity event:
(A) Requires notice to a government body, self-regulatory agency, or any
other supervisory body pursuant to any state or federal law; or
(B) Has a reasonable likelihood of materially harming:
(i) A consumer residing in the District; or
(ii) Any material part of the normal operations of the licensee.
(d) Notwithstanding subsection (c) of this section, if the cybersecurity event occurs in a
system maintained by a third-party service provider, the licensee shall notify the Commissioner
no later than 3 days after the third-party service provider notifies the licensee of the
cybersecurity event or the licensee has actual knowledge of the cybersecurity event, whichever is
sooner;
(e)(1)(A) In the case of a cybersecurity event involving nonpublic information that is
used by or is in the possession, custody, or control of a licensee that is acting as an assuming
11
ENGROSSED ORIGINAL
insurer and that does not have a direct contractual relationship with the affected consumers, the
assuming insurer shall notify its affected ceding insurers and the insurance regulatory agency of
its jurisdiction of domicile within 3 business days of determining that a cybersecurity event has
occurred; and
(B) The ceding insurers that have a direct contractual relationship with
affected consumers shall fulfill the consumer notification requirements imposed under D.C.
Official Code § 28-3852, and any other notification requirements relating to a cybersecurity
event imposed under this section.
(2)(A) In the case of a cybersecurity event involving nonpublic information that is
in the possession, custody, or control of a third-party service provider of a licensee that is an
assuming insurer, the assuming insurer shall notify its affected ceding insurers and the insurance
regulatory agency of its jurisdiction of domicile within 3 business days of receiving notice from
its third-party service provider that a cybersecurity event has occurred;
(B) The ceding insurers that have a direct contractual relationship with
affected consumers shall fulfill the consumer notification requirements imposed under D.C.
Official Code § 28-3852, and any other notification requirements relating to a cybersecurity
event imposed under this section.
(f) In the case of a cybersecurity event involving nonpublic information that is in the
possession, custody, or control of a licensee that is an insurer or its third-party service provider
for which a consumer accesses the insurer’s services through an independent insurance producer,
12
ENGROSSED ORIGINAL
the insurer shall notify the producers of record of all affected consumers as soon as practicable as
directed by the Commissioner. The licensee is excused from the obligation to provide notice to
individual consumers where the licensee does not have the current producer of record
information for those consumers.
Sec. 105. Powers of the Commissioner and penalties.
(a) The Commissioner shall have the power to examine and investigate the affairs of any
licensee to determine whether the licensee has or is engaged in conduct in violation of this title,
in accordance with the Law on Examinations Act of 1993, effective October 21, 1993 (D.C. Law
10-49; D.C. Official Code § 31-1401 et seq.).
(b) An insurer found, without just cause as defined by the Commissioner by rule, to be in
violation of this title, after notice and hearing conducted according to the rules for contested
cases set forth in Chapter 38 of Title 26A of the District of Columbia Municipal Regulations,
shall pay a penalty in an amount not to exceed $1,000 per day; except, that the maximum penalty
assessed shall be no more than $25,000.
(c) The Commissioner may, through rulemaking, establish other penalties for violations
of this title.
Sec. 106. Confidentiality.
(a)(1) Documents, materials, or other information in the control or possession of the
Department that are furnished by a licensee, or agent acting on behalf of a licensee, pursuant to
13
ENGROSSED ORIGINAL
sections 103 and 104, or that are obtained by the Commissioner in an investigation or
examination pursuant to section 105, are confidential and privileged and shall not be subject to:
(A) Disclosure under the Freedom of Information Act of 1976, effective
March 25, 1977 (D.C. Law 1-96; D.C. Official Code § 2-531 et seq.);
(B) Subpoena; or
(C) Discovery or be admissible in evidence in a private civil action;
except, that the Commissioner may use the documents, materials, or other information in the
furtherance of an action brought as part of the Commissioner’s duties.
(2) Neither the Commissioner nor any person who receives documents, materials,
or other information while acting under the authority of the Commissioner shall be permitted to
testify in any private civil action concerning any confidential documents, materials, or
information received pursuant to subsection (a) of this section.
(b) The Commissioner may:
(1) Share documents, materials, or other information, including the confidential
and privileged documents, materials, or information subject to subsection (a) of this section with
other state, federal, and international regulatory agencies, with the National Association of
Insurance Commissioners (“NAIC”), its affiliates or subsidiaries, and with state, federal, and
international law enforcement authorities; provided, that the recipient agrees in writing to
maintain the confidentiality and privileged status of the document, material, or other information;
(2) Receive documents, materials, or information, including otherwise
14
ENGROSSED ORIGINAL
confidential and privileged documents, materials, or information, from the NAIC, its affiliates or
subsidiaries, and from regulatory and law enforcement officials of other foreign or domestic
jurisdictions, and shall maintain as confidential or privileged any document, material, or
information received with notice or the understanding that it is confidential or privileged under
the laws of the jurisdiction that is the source of the document, material, or information;
(3) Share documents, materials, or other information subject to subsection (a) of
this section, with a third-party consultant or vendor; provided, that the consultant agrees in
writing to maintain the confidentiality and the privileged status of the document, material, or
other information; and
(4) Enter into an agreement governing sharing and use of information consistent
with this subsection.
(c) No waiver of any applicable privilege or claim of confidentiality in the documents,
materials, or information shall occur as a result of disclosure to the Commissioner under this
section or as a result of sharing as authorized in subsection (c) of this section.
(e) Nothing in this title shall be construed to prohibit the Commissioner from sharing
final orders of adjudicated actions otherwise open to public inspection pursuant to the Freedom
of Information Act of 1976, effective March 25, 1977 (D.C. Law 1-96; D.C. Official Code § 2-
531 et seq.), to a database or other clearinghouse service maintained by the NAIC, its affiliates,
or subsidiaries.
Sec. 107. Exemptions.
15
ENGROSSED ORIGINAL
(a) The following licensees shall be exempt from the requirements of section 103:
(1) A licensee with fewer than 10 employees, including any independent
contractors;
(2) A licensee subject to the Health Insurance Portability and Accountability Act
of 1996, approved August 21, 1996 (110 Stat. 1936; 42 U.S.C. § 1320d et seq.) (“HIPAA”), that
has established and maintains an information security program pursuant to HIPAA and the rules,
regulations, procedures, or guidelines established thereunder; provided, that the licensee submits
a written statement to the Commissioner certifying its compliance with HIPAA;
(3) A licensee having less than $5 million in annual written premiums in each of
the last 3 calendar years from its District of Columbia business operations;
(4) A licensee having less than $10 million in year-end admitted assets, calculated
in accordance with the NAIC’s statutory accounting principles, including admitted assets of all
affiliates; and
(5) An employee, agent, representative, or designee of a licensee, who is also a
licensee, to the extent that the employee, agent, representative, or designee is covered by the
information security program of the other licensee.
(b) A licensee claiming an exemption under subsection (a) of this section shall file a
request for an exemption in accordance with the rules prescribed by the Commissioner.
(c) In the event that a licensee ceases to qualify for an exception, the licensee shall have
180 days to comply with the requirements of this title.
16
ENGROSSED ORIGINAL
Sec. 108. Rulemaking.
The Commissioner, pursuant to Title I of the District of Columbia Administrative
Procedure Act, approved October 21, 1968 (82 Stat. 1204; D.C. Official Code § 2-501 et seq.),
shall promulgate rules necessary to implement the provisions of this title, including establishing:
(1) Standards and practices that shall be incorporated in a licensee’s information
security program, including risk assessments, the role of the licensee’s board of directors,
oversight of third-party service providers, and the requirement for written incident response
plans; and
(2) Guidance addressing the form and contents of the information that shall be
included in any initial, updated, or supplemental notification to the Commissioner concerning a
cybersecurity event; provided, that a licensee shall provide the Commissioner with a copy of the
notification of security breach sent to consumers as required by D.C. Official Code § 28-3852.
Sec. 109. No private right of action.
Nothing in this title shall be construed to create or imply a private cause of action or
curtail an existing private cause of action under another law.
TITLE II. CONFORMING AMENDMENT; FISCAL IMPACT; EFFECTIVE
DATE.
Sec. 201. Section 204(a) of the Freedom of Information Act of 1976, effective March 31,
1977 (D.C. Law 1-96; D.C. Official Code § 2-534(a)), is amended as follows:
17
ENGROSSED ORIGINAL
(a) Paragraph (23) is amended by striking the phrase “; and” and inserting a semicolon in
its place.
(b) Paragraph (24) is amended by striking the period and inserting the phrase “; and” in
its place.
(c) A new paragraph (25) is added to read as follows:
“(25) Information exempt from disclosure under the Cybersecurity and
Accountability Act of 2026, as approved by the Committee on Health on July 8, 2026
(Committee print of Bill 26-427).”.
Sec. 202. Fiscal Impact Statement.
The Council adopts the fiscal impact statement in the committee report as the fiscal
impact statement required by section 4a of the General Legislative Procedures Act of 1975,
approved October 16, 2006 (120 Stat. 2038; D.C. Official Code § 1-301.47a).
Sec. 203. Effective Date.
This act shall take effect following approval by the Mayor (or in the event of veto by the
Mayor, action by the Council to override the veto) and a 30-day period of congressional review
as provided in section 602(c)(1) of the District of Columbia Home Rule Act, approved December
24, 1973 (87 Stat. 813; D.C. Code § 1-206.02(c)(1)).
18

As introduced, Bill 26-427 would establish standards for data security and standards for investigating and notifying the Commissioner of the Department of Insurance, Securities and Banking of cybersecurity events affecting insurance licensees.

Sponsors

Sen. Phil Mendelson (D) sponsors B 26-0427 alone.

Committees

B 26-0427 went before 2 committees: Business and Economic Development and Health.

Business and Economic Development
Business and Economic Development
Referred to · Oct 21, 2025 · 11 Bills
Health
Health
Referred to · Feb 27, 2026 · 11 Bills

History

B 26-0427 has taken 12 actions since Oct 8, 2025, the latest on Jul 14, 2026.

ChamberAction
Jul 14, 2026
Council
First Reading, CC
Jul 8, 2026
Council
Committee Mark-up of B26-0427
Jun 15, 2026
Council
Public Hearing Held
Jun 5, 2026
Council
Notice of Public Hearing Published in the DC Register
Jun 2, 2026
Council
Notice of Public Hearing Published in the DC Register

Votes

B 26-0427 went to 1 roll call in the Council, the latest on Jul 14, 2026 at 120.

ChamberQuestion
Yea
Nay
Jul 14, 2026
Council
First Reading, CC
12
0

Source: lims.dccouncil.gov · legiscan.com