{"data":{"id":"us-ok/okla.-stat.-tit.-36-36-675","jurisdiction":"us-ok","citation":"Okla. Stat. tit. 36, § 36-675","heading":"Notification of cybersecurity event — Required","body":"information.\n\nA. Every licensee shall notify the Insurance Commissioner\n\nwithout unreasonable delay, but not later than three business days,\n\nfrom a determination that a cybersecurity event involving nonpublic\n\ninformation that is in the possession of a licensee has occurred\n\nwhen either of the following criteria has been met:\n\n1. This state is the state of domicile of the licensee, in the\n\ncase of an insurer, or this state is the home state of the licensee,\n\nin the case of a producer, as those terms are defined in the\n\nOklahoma Producer Licensing Act, Sections 1435.1 through 1435.41 of\n\nTitle 36 of the Oklahoma Statutes, and the cybersecurity event has a\n\nreasonable likelihood of materially harming any material part of the\n\nnormal operations of the licensee or any consumer residing in this\n\nstate; or\n\n2. The licensee reasonably believes that the nonpublic\n\ninformation involved is of two hundred fifty (250) or more consumers\n\nresiding in this state and is either of the following:\n\na. a cybersecurity event impacting the licensee of which\n\nnotice is required to be provided to any government\n\nbody, self-regulatory agency, or any other supervisory\n\nbody pursuant to any state or federal law, or\n\nb. a cybersecurity event that has a reasonable likelihood\n\nof materially harming:\n\n(1) any consumer residing in this state, or\n\n(2) any material part of the normal operation or\n\noperations of the licensee.\n\nB. The licensee making the notification required in subsection\n\nA of this section shall provide as much of the following information\n\nas possible, electronically in the manner and form prescribed by the\n\nCommissioner, along with any applicable fees. The licensee shall\n\nhave a continuing obligation to update and supplement initial and\n\nsubsequent notifications to the Commissioner regarding material\n\nchanges to previously provided information relating to the\n\ncybersecurity event. The licensee shall provide:\n\n1. Date of the cybersecurity event;\n\n2. Description of how the information was exposed, lost,\n\nstolen, or breached including, but not limited to, the specific\n\nroles and responsibilities of third-party service providers, if any;\n\n3. How the cybersecurity event was discovered;\n\n4. Whether any lost, stolen, or breached information has been\n\nrecovered and, if so, how this was done;\n\n5. The identity of the source of the cybersecurity event;\n\n6. Whether the licensee has filed a police report or has\n\nnotified any regulatory, government, or law enforcement agencies\n\nand, if so, when such notification was provided;\n\n7. Description of the specific types of information acquired\n\nwithout authorization. The term “specific types of information”\n\nmeans particular data elements including, but not limited to, types\n\nof medical information, financial information, or information\n\nallowing identification of the consumer;\n\n8. The period during which the information system was\n\ncompromised by the cybersecurity event;\n\n9. The number of total consumers in this state affected by the\n\ncybersecurity event. The licensee shall provide the best estimate\n\nin the initial report to the Commissioner and update this estimate\n\nwith each subsequent report to the Commissioner pursuant to this\n\nsection;\n\n10. The results of any internal review identifying a lapse in\n\neither automated controls or internal procedures, or confirming that\n\nall automated controls or internal procedures were followed;\n\n11. Description of efforts being undertaken to remediate the\n\nsituation which permitted the cybersecurity event to occur;\n\n12. A copy of the privacy policy of the licensee and a\n\nstatement outlining the steps the licensee will take to investigate\n\nand notify consumers affected by the cybersecurity event; and\n\n13. Name of a contact person who is both familiar with the\n\ncybersecurity event and authorized to act for the licensee.\nng undertaken to remediate the\n\nsituation which permitted the cybersecurity event to occur;\n\n12. A copy of the privacy policy of the licensee and a\n\nstatement outlining the steps the licensee will take to investigate\n\nand notify consumers affected by the cybersecurity event; and\n\n13. Name of a contact person who is both familiar with the\n\ncybersecurity event and authorized to act for the licensee.\n\nC. A licensee shall comply with the procedures of the Security\n\nBreach Notification Act, Section 161 et seq. of Title 24 of the\n\nOklahoma Statutes, to notify affected consumers and provide a copy\n\nof the notice sent to consumers under that statute to the\n\nCommissioner, when a licensee is required to notify the Commissioner\n\nunder subsection A of this section.\n\nD. 1. In the case of a cybersecurity event in a system\n\nmaintained by a third-party service provider, of which the licensee\n\nhas become aware, the licensee shall treat the event as it would\n\nunder subsection A of this section unless the third-party service\n\nprovider provides the notice required under subsection A of this\n\nsection to the Commissioner and the licensee.\n\n2. The computation of deadlines of the licensee shall begin on\n\nthe day after the third-party service provider notifies the licensee\n\nof the cybersecurity event or the licensee otherwise has actual\n\nknowledge of the cybersecurity event, whichever is sooner.\n\n3. Nothing in this act shall prevent or abrogate an agreement\n\nbetween a licensee and another licensee, a third-party service\n\nprovider, or any other party to fulfill any of the investigation\n\nrequirements or notice requirements imposed under this act.\n\nE. 1. In the case of a cybersecurity event involving nonpublic\n\ninformation that is used by the licensee that is acting as an\n\nassuming insurer, or in the possession, custody, or control of a\n\nlicensee, that is acting as an assuming insurer and that does not\n\nhave a direct contractual relationship with the affected consumers,\n\nthe assuming insurer shall notify its affected ceding insurers and\n\nthe Commissioner of its state of domicile within three (3) business\n\ndays of making the determination that a cybersecurity event has\n\noccurred. The ceding insurers that have a direct contractual\n\nrelationship with affected consumers shall fulfill the consumer\n\nnotification requirements imposed under the Security Breach\n\nNotification Act, Section 161 et seq. of Title 24 of the Oklahoma\n\nStatutes, and any other notification requirements relating to a\n\ncybersecurity event imposed under this section.\n\n2. In the case of a cybersecurity event involving nonpublic\n\ninformation that is in the possession, custody, or control of a\n\nthird-party service provider of a licensee that is an assuming\n\ninsurer, the assuming insurer shall notify its affected ceding\n\ninsurers and the Commissioner of its state of domicile within three\nimposed under this section.\n\n2. In the case of a cybersecurity event involving nonpublic\n\ninformation that is in the possession, custody, or control of a\n\nthird-party service provider of a licensee that is an assuming\n\ninsurer, the assuming insurer shall notify its affected ceding\n\ninsurers and the Commissioner of its state of domicile within three\n\n(3) business days of receiving notice from its third-party service\n\nprovider that a cybersecurity event has occurred. The ceding\n\ninsurers that have a direct contractual relationship with affected\n\nconsumers shall fulfill the consumer notification requirements\n\nimposed under Security Breach Notification Act, Section 161 et seq.\n\nof Title 24 of the Oklahoma Statutes, and any other notification\n\nrequirements relating to a cybersecurity event imposed under this\n\nsection.\n\nF. In the case of a cybersecurity event involving nonpublic\n\ninformation that is in the possession, custody, or control of a\n\nlicensee that is an insurer or its third-party service provider for\n\nwhich a consumer accessed the services of the insurer through an\n\nindependent insurance producer, and for which consumer notice is\n\nrequired by this act or the Security Breach Notification Act,\n\nSection 161 et seq. of Title 24 of the Oklahoma Statutes, the\n\ninsurer shall notify the producers of record of all affected\n\nconsumers of the cybersecurity event no later than the time at which\n\nnotice is provided to the affected consumers. The insurer is\n\nexcused from this obligation for any producers who are not\n\nauthorized by law or contract to sell, solicit, or negotiate on\n\nbehalf of the insurer, and in those instances in which the insurer\n\ndoes not have the current producer of record information for an\n\nindividual consumer. Any licensee acting as an assuming insurer\n\nshall have no other notice obligations relating to a cybersecurity\n\nevent or other data breach under this section or any other law of\n\nthis state.","path":["OK Code","Title 36"],"source_url":"https://www.oklegislature.gov/OK_Statutes/CompleteTitles/os36.pdf","current_through":"2026-08-14","vintage":"open-us-law v2026.08, retrieved 2026-09-14","retrieved_at":"2026-09-14T18:32:36Z","sha256":"f7c074d29f3f72f6fdfd0def37cfef08df63fe50e380eefb57f3c47053e78ce2","source_id":"us-ok","stale":false,"prev":"us-ok/okla.-stat.-tit.-36-36-674","next":"us-ok/okla.-stat.-tit.-36-36-6750"},"notice":"GroundRules: Original legal text. Not legal advice."}
