{"data":{"id":"us-ok/okla.-stat.-tit.-18-18-2071","jurisdiction":"us-ok","citation":"Okla. Stat. tit. 18, § 18-2071","heading":"Industry-recognized cybersecurity framework","body":"A covered entity's cybersecurity program, as described in\n\nSection 3 of this act, reasonably conforms to an industry-recognized\n\ncybersecurity framework for purposes of that section if this section\n\nis satisfied:\n\n1. The covered entity is subject to the requirements of the\n\nlaws or regulations listed below, and the cybersecurity program\n\nreasonably conforms to the entirety of the current version of both\n\nof the following, subject to paragraph 2 of this section:\n\na. the security requirements of the Health Insurance\n\nPortability and Accountability Act of 1996, as set\n\nforth in 45 CFR Part 164 Subpart C, and\n\nb. the Health Information Technology for Economic and\n\nClinical Health Act, as set forth in 45 CFR Part 162;\n\nand\n\n2. When a framework listed in paragraph 1 of this section is\n\namended, a covered entity whose cybersecurity program reasonably\n\nconforms to that framework shall reasonably conform to the amended\n\nframework not later than one (1) year after the effective date of\n\nthe amended framework.","path":["OK Code","Title 18"],"source_url":"https://www.oklegislature.gov/OK_Statutes/CompleteTitles/os18.pdf","current_through":"2026-08-14","vintage":"open-us-law v2026.08, retrieved 2026-09-14","retrieved_at":"2026-09-14T18:32:36Z","sha256":"6c7574e82179295b1297422fab5a2ba167808eb7a9388662383049fd634c7724","source_id":"us-ok","stale":false,"prev":"us-ok/okla.-stat.-tit.-18-18-2070","next":"us-ok/okla.-stat.-tit.-18-18-2072"},"notice":"GroundRules: Original legal text. Not legal advice."}
