As used in sections 60A.985 to 60A.9857, the following terms have the meanings given.
"Authorized individual" means an individual known to and screened by the licensee and determined to be necessary and appropriate to have access to the nonpublic information held by the licensee and its information systems.
"Consumer" means an individual, including but not limited to an applicant, policyholder, insured, beneficiary, claimant, and certificate holder who is a resident of this state and whose nonpublic information is in a licensee's possession, custody, or control.
"Cybersecurity event" means an event resulting in unauthorized access to, or disruption or misuse of, an information system or nonpublic information stored on an information system.
Cybersecurity event does not include the unauthorized acquisition of encrypted nonpublic information if the encryption, process, or key is not also acquired, released, or used without authorization.
Cybersecurity event does not include an event with regard to which the licensee has determined that the nonpublic information accessed by an unauthorized person has not been used or released and has been returned or destroyed.
"Encrypted" means the transformation of data into a form which results in a low probability of assigning meaning without the use of a protective process or key.
"Information security program" means the administrative, technical, and physical safeguards that a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of, or otherwise handle nonpublic information.
"Information system" means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of nonpublic electronic information, as well as any specialized system such as industrial or process controls systems, telephone switching and private branch exchange systems, and environmental control systems.
"Licensee" means any person licensed, authorized to operate, or registered, or required to be licensed, authorized, or registered by the Department of Commerce or the Department of Health under chapters 59A to 62M, 62Q to 62V, and 64B to 79A.
"Multifactor authentication" means authentication through verification of at least two of the following types of authentication factors:
"Nonpublic information" means electronic information that is not publicly available information and is:
"Person" means any individual or any nongovernmental entity, including but not limited to any nongovernmental partnership, corporation, branch, agency, or association.
"Publicly available information" means any information that a licensee has a reasonable basis to believe is lawfully made available to the general public from: federal, state, or local government records; widely distributed media; or disclosures to the general public that are required to be made by federal, state, or local law.
For the purposes of this definition, a licensee has a reasonable basis to believe that information is lawfully made available to the general public if the licensee has taken steps to determine:
"Risk assessment" means the risk assessment that each licensee is required to conduct under section 60A.9851, subdivision 3.
"State" means the state of Minnesota.
"Third-party service provider" means a person, not otherwise defined as a licensee, that contracts with a licensee to maintain, process, or store nonpublic information, or is otherwise permitted access to nonpublic information through its provision of services to the licensee.
Minn. Stat. § 60A.985