Oklahoma Hospital Cybersecurity Protection Act of 2023
OK Hospital Cybersecurity Act
Data security · Health · Breach notification
A voluntary cybersecurity safe harbor for Oklahoma hospitals. A hospital that keeps a documented written cybersecurity program reasonably conforming to the HIPAA Security Rule and HITECH requirements, reviewed annually, gets an affirmative defense to tort suits over data breaches of personal or other identifying information.
- Where
- Oklahoma
- Citation
- 18 O.S. §§ 2068-2072 (Laws 2023, c. 84, HB 2790)
- Status
- In force
- In force since
- 2023-11-01
- Enforced by
- None (safe-harbor statute applied by courts)
- People can sue
- No
- Penalties
- No penalties; the act is voluntary and grants an affirmative defense to tort claims alleging that failure to implement reasonable security controls caused a data breach.
- Applies to
- Hospitals (as defined in 63 O.S. § 1-701), for-profit or nonprofit, owned or managed in whole or part by hospitals subject to HIPAA
Security duties
- To claim the defense, create, maintain, comply with, and document a written cybersecurity program with administrative, technical, and physical safeguards for personal and restricted information, scaled to the hospital's size, activities, data sensitivity, and resources.18 O.S. § 2070(A)(1)-(3) · Only if: Voluntary; required only to qualify for the affirmative defense
- The program must reasonably conform to the current HIPAA Security Rule (45 CFR Part 164 Subpart C) and HITECH requirements, updating within one year after those frameworks change.18 O.S. § 2071 · Only if: Voluntary
- Review, evaluate, and update the program at least annually and document the review.18 O.S. § 2070(A)(4) · Only if: Voluntary
Sources
- Official text
- Enrolled HB 2790 (2023), Oklahoma Hospital Cybersecurity Protection Act of 2023 (Oklahoma Legislature)
- 24 O.S. § 164 (cross-reference deeming compliance with the Security Breach Notification Act) (OSCN)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Codification at 18 O.S. §§ 2068-2072 is taken from the enrolled bill's 'to be codified' directions; the codified sections were not opened (OSCN bot verification). Session law chapter (2023 c. 84) is from the OSCN 2023 session law index title 'Cybersecurity'.
Research reference, not legal advice.