that the nonpublic information accessed by an
unauthorized person has not been used or released and has
been returned or destroyed.
"Department." The Insurance Department of the Commonwealth.
"Encrypted." The transformation of data into a form that has
a low probability of assignment of meaning without the use of a
protective process or key.
"Information security program." The administrative,
technical and physical safeguards that a licensee uses to
access, collect, distribute, process, protect, store, use,
transmit, dispose of or otherwise handle nonpublic information.
"Information system." Any of the following:
(1) A discrete set of information resources that is
stored in an electronic system and is organized for the
collection, processing, maintenance, use, sharing,
dissemination or disposition of electronic nonpublic
information.
(2) Any specialized system such as an industrial or
process control system, telephone switching and private
branch exchange system or an environmental control system.
"Insurer." A n insurance company, association, exchange,
interinsurance exchange, health maintenance organization,
preferred provider organization, professional health services
plan corporation subject to Chapter 63 (relating to professional
health services plan corporations), a hospital plan corporation
subject to Chapter 61 (relating to hospital plan corporations),
fraternal benefit society, beneficial association, Lloyd's
insurer or health plan corporation.
"Licensee." As follows:
(1) A person that is or is required to be licensed,
20220HB2499PN3448 - 3 -
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30