§18-2071. Industry-recognized cybersecurity framework.
173 words·~1 min read·
/ok/title-18-corporations/18-2071·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
A covered entity's cybersecurity program, as described in Section 3 of this act, reasonably conforms to an industry-recognized cybersecurity framework for purposes of that section if this section is satisfied:
1. The covered entity is subject to the requirements of the laws or regulations listed below, and the cybersecurity program
reasonably conforms to the entirety of the current version of both of the following, subject to paragraph 2 of this section:
a. the security requirements of the Health Insurance
Portability and Accountability Act of 1996, as set
forth in 45 CFR Part 164 Subpart C, and
b. the Health Information Technology for Economic and
Clinical Health Act, as set forth in 45 CFR Part 162;
and
2. When a framework listed in paragraph 1 of this section is amended, a covered entity whose cybersecurity program reasonably conforms to that framework shall reasonably conform to the amended framework not later than one
(1)year after the effective date of the amended framework. Added by Laws 2023, c. 84, § 4, eff. Nov. 1, 2023.