Learn About The Law
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Current as of January 01, 2025 | Updated by Findlaw Staff
(a) Licensee criteria.--A licensee meeting any of the following criteria shall be exempt from sections 4512 (relating to risk assessment), 4513 (relating to information security program), 4514 (relating to corporate oversight), 4515 (relating to oversight of third-party service provider arrangements) and 4516 (relating to certification):
(1) The licensee has fewer than 10 employees.
(2) The licensee has less than $5,000,000 in gross revenue.
(3) The licensee has less than $10,000,000 in year-end total assets.
(b) Federal law.--A licensee that is subject to and governed by the privacy, security and breach notification rules issued by the United States Department of Health and Human Services under 45 CFR Pts. 160 (relating to general administrative requirements) and 164 (relating to security and privacy), established in accordance with the Health Insurance Portability and Accountability Act of 1996 (Public Law 104-191, 110 Stat. 1936) and the Health Information Technology for Economic and Clinical Health Act (Public Law 111-5, 123 Stat. 226-279 and 467-496), and which maintains nonpublic information in the same manner as protected health information shall be deemed to comply with the requirements of this chapter except for the notification requirements of section 4518(a), (b) and (c) (relating to notification of cybersecurity event).
(c) Employees, agents, representatives and designees.--An employee, agent, representative or designee of a licensee, who is also a licensee, shall be exempt from sections 4512, 4513, 4514, 4515 and 4516 and need not develop its own information security program to the extent that the employee, agent, representative or designee is covered by the information security program of the other licensee.
(d) Compliance.--If a licensee ceases to qualify for an exemption under this section, the licensee shall have 180 days to comply with this chapter.
Cite this article: FindLaw.com - Pennsylvania Statutes Title 40 Pa.C.S.A. Insurance § 4532. Exemptions - last updated January 01, 2025 | https://codes.findlaw.com/pa/title-40-pacsa-insurance/pa-csa-sect-40-4532/
FindLaw Codes may not reflect the most recent version of the law in your jurisdiction. Please verify the status of the code you are researching with the state legislature before relying on it for your legal needs.
A free source of state and federal court opinions, state laws, and the United States Code. For more information about the legal concepts addressed by these cases and statutes, visit FindLaw’s Learn About the Law.
Get help with your legal needs
FindLaw’s Learn About the Law features thousands of informational articles to help you understand your options. And if you’re ready to hire an attorney, find one in your area who can help.
Search our directory by legal issue
Enter information in one or both fields (Required)