43 chapters · 1,367 sections in this title.
Ohio Rev. Code Ann. § 3965.01 Definitions
6.1K chars
As used in this chapter: (A) "Assuming insurer" has the same meaning as in section 3901.61 of the Revised Code. (B) "Authorized individual" means an individual authorized by the licensee to access nonpublic information held by the licensee and its information systems. (C) "Ceding…
Ohio Rev. Code Ann. § 3965.02 Information security program
10.5K chars
(A) Each licensee shall develop, implement, and maintain a comprehensive written information security program based on the licensee's risk assessment. The program shall be commensurate with the size and complexity of the licensee, the nature and scope of the licensee's activities…
Ohio Rev. Code Ann. § 3965.03 Investigation of events
1.5K chars
(A) If a licensee learns that a cybersecurity event has or may have occurred, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation. (B) During the investigation, the licensee or an outside vendor or…
Ohio Rev. Code Ann. § 3965.04 Notification to superintendent
7.5K chars
(A) Each licensee shall notify the superintendent of insurance as promptly as possible after a determination that a cybersecurity event involving nonpublic information in the possession of the licensee has occurred, but in no event later than three business days after that determ…