{"data":{"id":"us-in/ic-4-13.1-2-9","jurisdiction":"us-in","citation":"IC 4-13.1-2-9","heading":"State agency reporting requirements","body":"Sec. 9. (a) This section does not apply to an entity subject to IC 13-18-16.5.\n(b) A state agency (as defined in IC 4-1-10-2) other than a state educational institution, and a political subdivision (as defined in IC 36-1-2-13), other than a department of public utilities established under IC 8-1-11.1, shall:\n(1) report any cybersecurity incident using their best professional judgment to the office without unreasonable delay and not later than two (2) business days after discovery of the cybersecurity incident in a format prescribed by the chief information officer; and\n(2) provide the office with the name and contact information of any individual who will act as the primary reporter of a cybersecurity incident described in subdivision (1) before September 1, 2021, and before September 1 of every year thereafter.\nNothing in this section shall be construed to require reporting that conflicts with federal privacy laws or is prohibited due to an ongoing law enforcement investigation.","path":["TITLE 4. STATE OFFICES AND ADMINISTRATION","ARTICLE 13.1. OFFICE OF TECHNOLOGY","Chapter 2. Office of Technology"],"source_url":"https://iga.in.gov/ic/2026/Title_4.html#4-13.1-2-9","current_through":"2026","vintage":"2026","retrieved_at":"2026-08-30T06:26:00Z","sha256":"ec213ce972a37de6cbf45fa076c1627d855977a0f7f85f6ea87360abb3b19994","source_id":"us-in","stale":false,"prev":"us-in/ic-4-13.1-2-8","next":"us-in/ic-4-13.1-2-10"},"notice":"GroundRules: Original legal text. Not legal advice."}
