{"data":{"id":"us-nd/n.d.-cent.-code-54-59.1-03","jurisdiction":"us-nd","citation":"N.D. Cent. Code § 54-59.1-03","heading":"Ongoing disclosure to the department during a cybersecurity incident","body":"Until a cybersecurity incident is resolved, an entity shall disclose clarifying details regarding a cybersecurity incident to the department, including:\n1.The number of potentially exposed records;\n2.The type of records potentially exposed, including health insurance information, medical information, criminal justice information, regulated information, financial information, and personal information;\n3.Efforts the entity is undertaking to mitigate and remediate the damage of the incident to the entity and other affected entities; and\n4.The expected impact of the incident, including:\na.The disruption of the entity services;\nb.The effect on customers and employees that experienced data or service losses;\nc.The effect on entities receiving wide area network services from the department; and\nd.Other concerns that could potentially disrupt or degrade the confidentiality, integrity, or availability of information systems, data, or services that may affect the state.","path":["Title 54 State Government","Chapter 54-59.1 Cybersecurity Incident Reporting Requirements"],"source_url":"https://ndlegis.gov/cencode/t54c59-1.pdf","current_through":"2026-07-31T11:12:02","vintage":"","retrieved_at":"2026-09-02T21:04:14Z","sha256":"41124f186257f94f6212a510a6abe5ebd022b532898cf3f3a42eb1cd8223c078","source_id":"us-nd","stale":true,"prev":"us-nd/n.d.-cent.-code-54-59.1-02","next":"us-nd/n.d.-cent.-code-54-59.1-04"},"notice":"GroundRules: Original legal text. Not legal advice."}
