Okla. Stat. tit. 18, § 18-2071: Industry-recognized cybersecurity framework
Where this section sits in the code
- OK Code
- Title 18
A covered entity's cybersecurity program, as described in
Section 3 of this act, reasonably conforms to an industry-recognized
cybersecurity framework for purposes of that section if this section
is satisfied:
1. The covered entity is subject to the requirements of the
laws or regulations listed below, and the cybersecurity program
reasonably conforms to the entirety of the current version of both
of the following, subject to paragraph 2 of this section:
a. the security requirements of the Health Insurance
Portability and Accountability Act of 1996, as set
forth in 45 CFR Part 164 Subpart C, and
b. the Health Information Technology for Economic and
Clinical Health Act, as set forth in 45 CFR Part 162;
and
2. When a framework listed in paragraph 1 of this section is
amended, a covered entity whose cybersecurity program reasonably
conforms to that framework shall reasonably conform to the amended
framework not later than one (1) year after the effective date of
the amended framework.
Collected 2026-09-14T18:32:36Z. Source file · JSON