Missouri Cybersecurity Event Notification Form

This electronic form shall be used by licensees to provide information to the Director of the Missouri Department of Commerce and Insurance (“Director” of the “DCI”) concerning the occurrence of cybersecurity events involving nonpublic information for which notification to the Director is required under section 375.1410, RSMo.

Licensees are strongly encouraged to review the definitions found in section 375.1402, RSMo and the exclusions found in section 375.1417, RSMo prior to reporting a cybersecurity event.

As described in section 375.1410.2, RSMo, licensees shall provide as much of the following information as practicable, except that licensees shall not release nonpublic information (as defined in section 375.1402, RSMo) of the consumer unless given written authority by the consumer or otherwise required by law. Licensees may respond using attachments by indicating as such in the fields below and attaching the responsive document(s) to this form.

Licensees shall have a continuing obligation to update initial and subsequent notifications to the Director regarding material changes to previously provided information relating to the cybersecurity event.

Questions regarding this electronic form should be sent to cyberbreach@insurance.mo.gov. DO NOT send nonpublic information to this email address, as all cybersecurity event notifications and updates should be submitted using this electronic form.

Licensees providing information on this electronic form do not need to log in when submitting a notification.


1. Is this an initial or subsequent notification to the Director?
7. Is this notification being made by a Company or a Licensee?
9. Estimated Cybersecurity Event Occurrence Period
to
16. Is a notice to impacted Missouri consumers required by law, including section 407.1500, RSMo?
“Specific types of information” means particular data elements including, for example, types of medical information, types of financial information, or types of information allowing identification of the consumer.


Licensees must attach the following with appropriate labeling in the file names as part of this notification:

1) A copy of the licensee’s privacy policy,
2) A statement outlining the steps the licensee will take to investigate and notify consumers affected by the cybersecurity event,
3) A copy of any report/notification referenced in question 15, above,
4) A copy of any internal review report referenced in question 20, above,
5) A copy of the notice sent to consumers under section 407.1500, RSMo, as applicable, and
6) Any other attachments referenced in this notification.

Max file size: 20 MB. Allowed file extension(s): jpg, jpeg, png, pdf, doc, docx.