
NAIC Updates
Commissioner Transitions: As of January 2025, several states have new commissioners, with more on the way:
- Mick Campbell is temporarily serving in Missouri until Governor-elect Kehoe’s appointee, Angie Nelson, takes office in March.
- Vermont regulator Sandy Bigglestone is serving as an interim commissioner during a search that is expected to take several months.
- In October 2024, Holly Lambert and Michael Caljouw were appointed as commissioners in Indiana and Massachusetts, respectively.
- James Brown was sworn in as the elected Montana commissioner on January 6, while Patty Kuderer was sworn into the Washington seat on January 15.
Life Insurance and Annuities (A) Committee
Chair: Judith L. French—Director, Ohio Department of Insurance
Co-Vice Chair: Doug Ommen—Commissioner, Iowa Insurance Division
Co-Vice Chair: Carter Lawrence—Commissioner, Tennessee Department of Commerce and Insurance
Health Insurance and Managed Care (B) Committee
Chair: Glen Mulready—Commissioner, Oklahoma Insurance Department
Co-Vice Chair: Ann Gillespie—Acting Director, Illinois Department of Insurance
Co-Vice Chair: Grace Arnold—Commissioner, Minnesota Department of Commerce
Property and Casualty Insurance (C) Committee
Chair: Michael Conway—Commissioner, Colorado Department of Regulatory Agencies, Division of Insurance
Co-Vice Chair: Michael Yaworsky—Commissioner, Florida Office of Insurance Regulation
Co-Vice Chair: Larry D. Deiter—Director, South Dakota Division of Insurance
Market Regulation and Consumer Affairs (D) Committee
Chair: Dean L. Cameron—Director, Idaho Department of Insurance
Co-Vice Chair: Trinidad Navarro—Commissioner, Delaware Department of Insurance
Co-Vice Chair: Scott Kipper—Commissioner, Nevada Division of Insurance
Financial Condition (E) Committee
Chair: Nathan Houdek—Commissioner, Wisconsin Office of the Commissioner of Insurance
Co-Vice Chair: Justin Zimmerman—Commissioner, New Jersey Department of Banking and Insurance
Co-Vice Chair: Michael Wise—Director, South Carolina Department of Insurance
Financial Regulation Standards and Accreditation (F) Committee
Chair: Lori K. Wing-Heier—Director, Alaska Department of Commerce, Community, and Economic Development, Division of Insurance
Co-Vice Chair: Sharon P. Clark—Commissioner, Kentucky Department of Insurance
Co-Vice Chair: Andrew R. Stolfi—Director/Insurance Commissioner, Oregon Department of Consumer and Business Services
International Insurance Relations (G) Committee
Chair: Eric Dunning—Director, Nebraska Department of Insurance
Co-Vice Chair: Timothy J. Temple—Commissioner, Louisiana Department of Insurance
Co-Vice Chair: Justin Zimmerman—Commissioner, New Jersey Department of Banking and Insurance
Innovation, Cybersecurity, and Technology (H) Committee
Chair: Barbara D. Richardson—Director, Arizona Department of Insurance and Financial Institutions
Co-Vice Chair: Karima M. Woods—Commissioner, District of Columbia Department of Insurance, Securities and Banking
Co-Vice Chair: Michael Yaworsky—Commissioner, Florida Office of Insurance Regulation
Multi-State Coalition Calls on DOGE to Abolish FIO: Over the holidays, insurance commissioners from Alabama, Arkansas, Kansas, Louisiana, New Hampshire, North Carolina, Oklahoma, Tennessee, and West Virginia sent a letter to Elon Musk and Vivek Ramaswamy (leaders of the soon-to-be Department of Government Efficiency (DOGE)) recommending the abolishment of the Federal Insurance Office (FIO). The letter characterizes FIO as fluctuating between ineffective and dishonest and asserts that FIO’s role is already fulfilled by state insurance regulators. The letter acknowledges that congressional approval is required to eliminate the office and urges DOGE to collaborate with Congressman (and former Montana commissioner) Troy Downing (R – MT), who has said he wants to introduce such legislation.
PPWG Article IV Exposure: On January 9, 2025, the Privacy Protections Working Group (PPWG) exposed via email Article IV of the Chair’s Draft Revisions to Model #672 for comment through January 23. Article IV consists of the following sections:
- Section 11 – Information to be Included in Privacy Notices
- Section 12 – Form of Opt Out Notice to Consumers and Opt Out Methods
- Section 13 – Revised Privacy Notices
- Section 14 – Privacy Notices to Group Policyholders
- Section 15 – Delivery
Capital Markets Bureau Issues Special Report on ABS/Structured Securities: On January 7, the NAIC’s Capital Markets Bureau issued a special report on insurers’ exposure to asset-backed securities (ABS) and other structured securities. The report notes that the pace of insurers’ increasing exposure to such assets actually slowed to 9% in 2023; the exposure had increased by double digits from 2018–2022.
The report analyzes insurers’ historical exposure to structured securities and outlines the current allocation of these investments in insurers’ investment profiles. Roughly 43% of insurers’ exposure to ABS and other structured securities comes in the form of CLOs, CBOs, and CDOs. Consumer ABS (e.g., auto loans, credit card receivables, and student loans) represent another 9% of the total ABS and structured securities exposure. Life companies account for nearly 80% of the industry’s exposure to structured securities, with P&C companies around 18%. Notably, about 97% of insurers’ investments in this asset class are high-quality, investment-grade investments, with 80% carrying an NAIC 1 designation.
Staff Contact - Sean McKennaMilliman Releases Report on Annuity Surrenders
On January 10, 2025, Milliman released the results of its 2024 Fixed Indexed Annuity Industry Experience Studies (although the report itself has not been released publicly). The two studies cover surrender behavior and partial withdrawals, including income utilization for guaranteed lifetime withdrawal benefit (GLWB) riders. Research shows average surrender rates have been steadily increasing since 2022, with rates at the end of 2023 nearly double the average between 2019 and 2021. Key findings from the studies include:
- Recent data shows that contracts with credited rates much lower than market rates can have surrender rates over three times as high as those with credited rates relatively close to the market rate.
- Surrender rates increased for contracts in their surrender charge period compared to pre-2022 levels, especially for contracts with a living benefit. Observations since 2022 suggest surrender rates are more than 1.5 times higher for contracts without living benefits—and more than 2 times higher for contracts with living benefits—compared to pre-2022 levels.
- As GLWBs become more valuable (in-the-money), average surrender rates tend to decrease, particularly at the end of the surrender charge period, where deep in-the-money surrender rates are about 11% and out-of-the-money surrender rates are about 22%.
- Once GLWB income has commenced, surrender rate patterns are significantly muted and below 5% on average for all durations.
BMA Issues Consultation Paper on Asset/Liability Disclosures
On December 23, 2024, the Bermuda Monetary Authority (BMA) released a consultation paper containing a proposal to publicly disclose the assets and liabilities of Bermuda long-term commercial insurers—an initiative stemming from the BMA’s efforts to enhance its disclosure regime and increase transparency for policyholders and other stakeholders. The consultation paper includes a proposed template that would be used for the public disclosure of both assets and liabilities. (The template would require a significant amount of information on each asset, including its nominal amount, book value, market value, fixed coupon, gross market yield, etc.) The template also includes six asset liability management disclosures.
The paper notes that the public disclosure of investments builds on the BMA’s work implementing the Prudent Person Principle (on which there is also a consultation paper out for comment until February 5) and references insurers’ increased allocation to illiquid, “hard-to-value” assets that are non-publicly traded and can be more complex than liquid traded assets.
The BMA suggests that because a long-term insurer’s investment strategy is developed with consideration of its liability profile, liabilities also should be publicly disclosed, allowing market participants to form a comprehensive view of the appropriateness of the assets backing the company’s liabilities. Notably, the paper recognizes that this proposal “responds to the broader global trend and structural shifts in the life and annuity sector,” a reference that seemingly acknowledges that this work is being pursued in part due to pressures from international standard-setters. Comments are due by February 28, and the BMA intends for the new requirements to become effective on December 31, 2025.
Staff Contact - Sean McKennaOregon Issues AI Guidance
Oregon Attorney General Rosenblum released guidance on the applicability of the Oregon Consumer Privacy Act to the use of AI, and particularly generative AI. The guidance clarifies that:
- Developers using personal data to train AI systems must disclose this through an accessible and clear privacy notice.
- Data suppliers and developers must obtain affirmative consent for new uses of previously collected data (such as AI training that was not previously disclosed).
- Consumers must be given the opportunity to opt-out of the use of AI models for decisions with legal or significant impact.
- Using consumer data in generative AI likely requires a Data Protection Assessment.
Privacy Updates
On January 1, 2025, comprehensive consumer privacy laws took effect in Delaware, Iowa, Nebraska, and New Hampshire. A brief summary of the applicability of the laws is below:
- Delaware: The Delaware Personal Data Privacy Act applies to a person who conducts business in the state or produces products or services targeted to residents of the state, and who during the preceding calendar year (1) controlled or processed the personal data of not less than 35,000 consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) controlled or processed the personal data of not less than 10,000 consumers and derived more than 20% of their gross revenue from the sale of personal data. Financial institutions, affiliates thereof, and data subject to Title V of the Gramm-Leach-Bliley Act (GLBA), as well as protected health information under HIPAA, are exempt.
- Iowa:Iowa’s comprehensive privacy law applies to a person conducting business in the state or producing products or services that are targeted to consumer residents of the state and who during a calendar year either (1) controls or processes the personal data of at least 100,000 consumers; or (2) controls or processes the personal data of at least 25,000 consumers and derives over 50% of gross revenue from the sale of personal data. Financial institutions, affiliates thereof, and data subject to Title V of the GLBA, as well as protected health information under HIPAA, are exempt.
- Nebraska: The Nebraska Data Privacy Act applies to a person who (1) conducts business in the state or produces a product or service consumed by residents of the state; (2) processes or engages in the sale of personal data; and (3) is not a small business as determined under the federal Small Business Act, except to the extent that section 87-1118 applies. Financial institutions, affiliates thereof, and data subject to Title V of the GLBA, as well as protected health information under HIPAA, are exempt.
- New Hampshire:New Hampshire’s data privacy law applies to a person who conducts business in the state or produces products or services targeted to residents of the state and who during a one-year period (1) controlled or processed the personal data of not less than 35,000 unique consumers, excluding personal data controlled or processed solely for the purpose of completing a payment transaction; or (2) controlled or processed the personal data of not less than 10,000 unique consumers and derived more than 25% of their gross revenue from the sale of personal data. Financial institutions, affiliates thereof, and data subject to Title V of the GLBA, as well as protected health information under HIPAA, are exempt.
In addition, the New Jersey Division of Consumer Affairs’ Cyber Fraud Unit released an FAQ on the New Jersey Data Privacy Law. The law went into effect on January 15, 2025.
Staff Contact - Sean McKennaFederal Updates
The Justice Department issued a final rule carrying out Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The rule prohibits and restricts the transfer of sensitive data to countries of concern, including China, Cuba, Iran, North Korea, Russia, and Venezuela. The rule goes into effect on April 8, 2025. In response to the final rule, the Cybersecurity & Infrastructure Security Agency released a set of security requirements for restricted transactions to provide the organizational- and covered system–level security requirements and data-level security requirements for U.S. persons engaging in restricted transactions under the new rule.
The Department of Health and Human Services issued a notice of proposed rulemaking for comments on its proposal to modify the Security Standards for the Protection of Electronic Protected Health Information under HIPAA (the HIPAA Security Rule). The proposed modifications revise existing standards to better protect the confidentiality, integrity, and availability of electronic protected health information (ePHI) by increasing cybersecurity of ePHI. The proposal includes modifications of the HIPAA Security Rule to address changes in the environment in which health care is provided; a significant increase in breaches and cyberattacks; common deficiencies in HIPAA Security Rule compliance; cybersecurity best practices, methodologies, procedures, and processes; and court decisions affecting enforcement of the HIPAA Security Rule. The proposed rule is open for comment through March 7, 2025.
Staff Contact - Sean McKenna