Oklahoma Code § 18-2071

Title 18. Corporations: Industry-recognized cybersecurity framework
Open in Lexace · Ask the AI about this section
A covered entity's cybersecurity program, as described in
Section 3 of this act, reasonably conforms to an industry-recognized
cybersecurity framework for purposes of that section if this section
is satisfied:
1.  The covered entity is subject to the requirements of the
laws or regulations listed below, and the cybersecurity program

reasonably conforms to the entirety of the current version of both
of the following, subject to paragraph 2 of this section:
a. the security requirements of the Health Insurance
Portability and Accountability Act of 1996, as set
forth in 45 CFR Part 164 Subpart C, and
b. the Health Information Technology for Economic and
Clinical Health Act, as set forth in 45 CFR Part 162;
and
2.  When a framework listed in paragraph 1 of this section is
amended, a covered entity whose cybersecurity program reasonably
conforms to that framework shall reasonably conform to the amended
framework not later than one (1) year after the effective date of
the amended framework.

‹ Prev All Oklahoma sections Next ›


Lexace provides legal information, not legal advice, and no attorney–client relationship is created. Statute text is provided for general information and may not reflect the most recent amendments; verify against the official state code.