Insurance Data Security Act

OK IDSA
active

Oklahoma's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with an incident response plan and vendor oversight, investigate cybersecurity events, and notify the Insurance Commissioner within three business days of determining a qualifying event, while notifying consumers under the Security Breach Notification Act. It is the exclusive state data security law for licensees.

Jurisdiction

Oklahoma

Jurisdiction Type

state

Country

United States

Effective Date

7/1/2024

Enforcing Authority

Oklahoma Insurance Commissioner

Fines Under This Regulation

0

Total Fine Amount (USD)

--