Cybersecurity and Accountability Act of 2025 mandates information security programs for insurers in the District of Columbia.
The Cybersecurity and Accountability Act of 2025 requires insurers in the District of Columbia to develop, implement, and maintain a comprehensive written information security program. This program must include administrative, technical, and physical safeguards to protect nonpublic information and information systems. Insurers must also conduct risk assessments, implement security measures, and notify the Commissioner of cybersecurity events. Exemptions apply to certain small insurers and those complying with the Health Insurance Portability and Accountability Act.
Included in complete analysis
- Overview
- Core Provisions
- Implementation
- Impact
- Legal Framework
- Critical Issues
See what it does, who it affects, and the critical issues in plain language. Free, 30 seconds.