The Maryland Insurance Administration issued Bulletin 24-6, regarding information security program certification. The first certification is required on or before April 15.
The bulletin states, “Carriers that are required to file an information security program certification with the insurance commissioner must do so on or before April 15 of each year. The first certification is required on or before April 15, 2024.”
It noted that Bulletin 23-18 provided information regarding the requirements to have in place, a comprehensive written information security program based on the carrier’s risk assessment and a written incident response plan designed to promptly respond to, and recover from, a cybersecurity event.
“The purpose of this bulletin is to provide the method for carriers to file the required Information security program certification online,” the bulletin states. “The information security program certification can now be submitted via electronic form at: https://marylandinsurance.jotform.com/240356360389965.”
It noted that this is the primary method of submitting the filing. Questions regarding the form should be sent to Raymond Guzman, chief of market analysis, market regulation and professional licensing at [email protected].
“Questions or comments on the requirement to file may be sent to Mary Kwei, associate commissioner, Market Regulation and Professional Licensing, Maryland Insurance Administration, 200 Saint Paul Place, Suite 2700, Baltimore, MD 21202, or call 410-468-2113, or email to [email protected],” it stated.