U.S. South Carolina Insurance Data Security Act

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
The U.S. SouthCarolina Insurance Data Security Act is a state-level cybersecurityregulation that helps insurance companies safeguard nonpublicinformation and mitigate risks associated with data breaches. Theregulation establishes standards for the protection of sensitiveconsumer data maintained by licensed insurers, agencies, and otherlicensees operating in South Carolina.
Enacted by theSouth Carolina Department of Insurance, the Act applies to allentities required to maintain licenses under state insurance laws. Itsets out requirements for developing information security programs,managing third-party service providers, conducting risk assessments,and reporting cybersecurity events. Focus areas include cybersecuritycontrols, data protection, risk management, and incident response.
Organizationssubject to the Act typically implement written information securitypolicies, adopt technical and administrative controls, and prepareincident response plans. The regulation supports compliance oversightprograms and often complements broader frameworks such as the NAICInsurance Data Security Model Law and sector-specific informationsecurity standards.
Why it Matters
The SouthCarolina Insurance Data Security Act establishes a clear framework tohelp insurers protect sensitive information and demonstrateregulatory compliance.
Key benefitsinclude:
• Strengthen data security controls
Implement robustsecurity measures to better safeguard policyholder information fromunauthorized access, loss, or misuse.
• Enhance regulatory compliance
Alignorganizational practices with state-mandated requirements, supportingcompliance efforts and reducing the risk of regulatory penalties.
• Improve incident response readiness
Require timelydetection of and response to security events, minimizing the impactof data breaches or cyber incidents.
• Increase accountability and oversight
Promoteessential roles and documented policies that clarify organizationalresponsibilities for information security and risk management.
• Promote third-party risk management
Mandateevaluation and oversight of vendor security practices, reducingexposure to risks from external service providers.
How it Works
The U.S. SouthCarolina Insurance Data Security Act establishes a regulatoryframework consisting of a set of security requirements, governanceobligations, and incident response provisions for licensed insurersoperating within South Carolina. The Act structures its requirementsaround risk management processes, mandatory security safeguards,periodic risk assessments, and formal incident notificationprocedures. By clearly defining standards for the protection ofnonpublic information within the insurance sector, the Act alignswith recognized security practices and regulatory expectations.
Organizationsoperationalize the requirements of the South Carolina Insurance DataSecurity Act by implementing security controls across theirinformation systems, conducting annual risk assessments to identifyand address vulnerabilities, and adopting formal policies to managecybersecurity risks. Regular compliance assessments and ongoingsecurity monitoring are key activities, as are the establishment ofincident response processes to ensure timely notification toregulators in the event of a qualifying breach. These operationalpractices help organizations maintain compliance while strengtheningtheir overall security posture.
UsingSmartSuite, organizations can operationalize the Act by leveragingcontrol libraries to map statutory requirements, maintaining riskregisters to document threats and mitigation activities, andsupporting policy governance through centralized documentation.SmartSuite enables evidence collection for compliance tracking,organizes remediation workflows to address deficiencies, and providesdashboards for audit readiness and reporting, helping organizationsautomate and streamline ongoing compliance with the South CarolinaInsurance Data Security Act.
Key Elements
• Information Security Program Structure
Establishesrequirements for insurers to develop and maintain a writteninformation security program tailored to company risk.
• Risk Assessment Procedures
Specifiesprocesses for regular evaluation and identification of reasonablyforeseeable internal and external security threats.
• Third-Party Service Provider Oversight
Outlinesexpectations for the due diligence and monitoring of vendors handlingnonpublic information.
• Incident Response Planning
Describesnecessary components of an incident response plan to addresscybersecurity events and mitigate impact.
• Regulatory Reporting Protocols
Defines stepsfor notifying the insurance commissioner of cybersecurity eventsaffecting South Carolina residents.
• Annual Certification and Documentation
Requires boardsof directors or senior management to certify compliance and maintainsupporting documentation for inspection.
• Data Protection Measures
Enumeratesadministrative, technical, and physical safeguards to protectnonpublic information and mitigate data breach risks.
Framework Scope
The U.S. SouthCarolina Insurance Data Security Act is adopted by insurancelicensees, agencies, and companies managing consumer and policyholderinformation. It governs the protection of nonpublic personal data andrelated information systems, typically enforced when meeting statecybersecurity compliance, mitigating data breaches, and supportinginsurance sector assurance programs.
Framework Objectives
The SouthCarolina Insurance Data Security Act sets out comprehensiveobjectives for safeguarding sensitive insurance data and managingcybersecurity risk.
• Protect nonpublic information through effective data protectionand security controls
• Strengthen governance and oversight of information security riskmanagement programs
• Establish a formalized approach to cybersecurity compliancewithin regulated entities
• Enhance operational resilience against emerging cyber threatsand incidents
• Ensure organizations can demonstrate ongoing compliance andaudit readiness
• Promote accountability for safeguarding consumer informationwithin the insurance sector The South Carolina Insurance DataSecurity Act aligns closely with frameworks like the NAIC InsuranceData Security Model Law and NIST Cybersecurity Framework. Insurerstypically implement this act to achieve regulatory compliance,particularly when handling nonpublic information and reportingsecurity incidents to regulators within the state insurance sector.
Common Framework Mappings
Organizationsoften map the South Carolina Insurance Data Security Act to otherrecognized cybersecurity frameworks to streamline compliance, ensurecomprehensive security controls, and satisfy overlapping regulatoryand industry requirements.
Mappedframeworks include:
CIS Controls
COBIT
GLBA
HIPAA
ISO/IEC 27001
ISO/IEC 27002
NISTCybersecurity Framework
NIST SP 800-53
PCI DSS
SOC 2
- ClassicifationCategoryData Protection & PrivacyDomainFinancial Services RegulationFramework FamilyGlobal Privacy Regulations
- Regulatory ContextTypeRegulationLegal InstrumentActSectorFinancial SectorIndustryInsurance
- Region / PublisherRegionNorth AmericaRegion DetailSouth CarolinaPublisherNational Association of Insurance Commissioners (NAIC)
- VersioningVersion2018Effective DateJanuary 1, 2019Issue DateMay 3, 2018
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityModerate
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
South Carolina's Insurance Data Security Act statute text is publicly available on the state's official government website. License included with platform
How SmartSuite Supports SC Insurance Data Security Act
Manage insurance cybersecurity requirements by organizing South Carolina Insurance Data Security Act obligations, tracking security controls, and maintaining evidence supporting risk management, incident response, and regulatory compliance.
Written Information Security Program (WISP)
Structure written information security program (WISP), policies, roles, and oversight aligned to regulatory expectations.
Risk Assessment and Safeguard Implementation
Track risk assessments and implementation of administrative, technical, and physical safeguards.
Nonpublic Information Scope and System Tracking
Track nonpublic information, systems, and processing activities subject to insurance data security requirements.
Insurance Data Access and Security Controls
Manage user access, authentication, encryption, and safeguards protecting sensitive insurance data.
Cybersecurity Event and Regulatory Notification Management
Track cybersecurity events and manage investigation, response, and regulatory notification requirements.
Insurance Cybersecurity Compliance Reporting
Provide dashboards showing security posture, incident readiness, and compliance with insurance cybersecurity regulations.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

The GLBA Safeguards Rule requires financial institutions to implement security programs to protect consumer financial information.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.
Frequently Asked Questions For U.S. South Carolina Insurance Data Security Act
The U.S. South Carolina Insurance Data Security Act establishes minimum standards for data security in the insurance industry within South Carolina. Its purpose is to protect sensitive consumer information handled by insurance licensees and ensure robust cybersecurity practices.
Yes, the Act is mandatory for all insurance licensees authorized or required to operate under South Carolina law. Noncompliance can result in regulatory enforcement actions and penalties from the state Department of Insurance.
The Act applies to all entities licensed, authorized, or registered under the South Carolina insurance code, including insurers, agents, and other licensees. Certain limited exemptions exist for licensees with fewer than ten employees or those covered by HIPAA.
Key requirements include the development of a comprehensive information security program, routine risk assessments, implementation of safeguards to protect nonpublic information, and breach notification protocols. Licensees must also exercise due diligence in selecting and overseeing third-party service providers.
Implementation starts with formal risk assessment and the creation of an information security program tailored to organizational risks and operations. Ongoing employee training, technical safeguards, and written incident response plans are also required components.
While the Act shares similarities with the NY Department of Financial Services Cybersecurity Regulation and the Gramm-Leach-Bliley Act (GLBA), it applies specifically to South Carolina insurance licensees. Organizations may leverage overlapping controls to streamline compliance with multiple frameworks.
Licensees must annually certify compliance to the South Carolina Department of Insurance and maintain relevant documentation and records. They are also required to notify the Commissioner within 72 hours of discovering a cybersecurity event involving nonpublic information.
SmartSuite can help organizations manage South Carolina Insurance Data Security Act compliance by centralizing risk tracking, documenting and monitoring required controls, facilitating evidence collection for audits, and maintaining audit readiness. Its reporting tools support ongoing compliance status and regulatory notifications.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

