Regulation — South Carolina

SC Code §38-99 — Insurance Data Security Act

Adopted 2018. South Carolina was the first state to adopt the NAIC Insurance Data Security Model Law (Model 668). Every SC-authorized insurer must maintain a written information-security program. AI systems that touch PII sit squarely inside the required risk-management scope.

What the statute actually says

"Commensurate with the size and complexity of the Licensee, the nature and scope of the Licensee's activities, including its use of Third-Party Service Providers, and the sensitivity of the Nonpublic Information used by the Licensee or in the Licensee's possession, custody or control, each Licensee shall develop, implement, and maintain a comprehensive written Information Security Program …" SC Code Ann. §38-99-20(A) -- Information Security Program requirement (SC Insurance Data Security Act)
"The Licensee shall … identify reasonably foreseeable internal and external threats that could result in unauthorized access to or transmission, disclosure, misuse, alteration, or destruction of Nonpublic Information … assess the likelihood and potential damage … assess the sufficiency of policies, procedures, information systems and other safeguards …" SC Code Ann. §38-99-20(C) -- Risk assessment requirement

What this means in plain English

Every SC-authorized carrier owes three ongoing duties:

  1. Written information-security program covering all systems that touch nonpublic information (NPI) — including AI systems.
  2. Risk assessment of foreseeable threats, including internal ones. Silent-drift on an AI model that touches PII is a foreseeable internal threat.
  3. Safeguard sufficiency review — are the current controls adequate to the risk?

The statute pre-dates the modern AI wave, but its "risk assessment / safeguards / third-party service providers" scaffold already covers AI vendors and AI-model risk. Regulators do not need new authority to ask the questions.

What triggers the exposure in the sample

The claims-severity AI ingests every BI claim's structured + unstructured record — loss narrative, adjuster notes, medical mentions, police-report text, sometimes ISO ClaimSearch data. That is NPI under §38-99-10. A model that silently starts producing group-differential outputs is a control-effectiveness gap the carrier's Information Security Program is obligated to identify and address. If the SC DOI opens a data-security exam and asks how AI-driven decisions on NPI are risk-assessed, "we didn't monitor for silent drift" is a directly citable gap.

What the $499 Snapshot shows against this rule

How does this help me?

South Carolina data-security exams have historically focused on cyber controls. AI-driven decisions on NPI are the next natural exam frontier. The benefit page walks through what the Snapshot record does when the SC DOI's data-security exam adds an AI section.

Read: SC §38-99 -- what it saves at the next data-security exam →

$499 Snapshot. 3 business days.

Independent-verifier determination + NPI risk-assessment record for the AI surface + 3 fix-first items + signed declaration.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.