Cybersecurity, Privacy, & AI

Trending Now
Doxim Data Breach Settlement Underscores Third-Party Data Security Risk • SASC Proposes Reorganization of Pentagon’s IT, Cyber Leadership • Anthropic Suspends Top AI Models After U.S. Export Control Order • Senate Bill Seeks to Restore Funding for Cyber Information-Sharing Program • CISA Directive Orders Agencies to Prioritize Vulnerability Patching in a New Way

New Ohio Law Creates Safe Harbor for Certain Breach-Related Claims

A breach law that just went into effect in Ohio provides covered entities with a legal safe harbor for certain data breach-related claims under Ohio law. It is the first law in the U.S. to offer an incentive to businesses that take steps to ensure that there are policies and procedures in place to protect against data breaches.

To qualify, at the time of the breach the entity must comply with a cybersecurity program that:

  • contains administrative, technical, and physical safeguards for the protection of personal information; and
  • reasonably conforms to one of several “industry-recognized” cybersecurity frameworks.

In addition, the program must be designed to:

  • protect the security and confidentiality of the information;
  • protect against any anticipated threats or hazards to the security or integrity of the information; and
  • protect against unauthorized access to information that is likely to result in a material risk of identity theft or other fraud.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.