Ohio Statutes

§ 3965.03 — Investigation of events

Ohio § 3965.03
JurisdictionOhio
Title 39Insurance
Ch. 3965Cybersecurity Requirements For Insurance Companies

This text of Ohio § 3965.03 (Investigation of events) is published on Counsel Stack Legal Research, covering Ohio primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
Ohio Rev. Code Ann. § 3965.03 (2026).

Text

(A)If a licensee learns that a cybersecurity event has or may have occurred, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation.
(B)During the investigation, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall, at a minimum, do as much of the following as possible:
(1)Determine whether a cybersecurity event has occurred;
(2)Assess the nature and scope of the cybersecurity event;
(3)Identify any nonpublic information that may have been involved in the cybersecurity event;
(4)Perform or oversee reasonable measures to restore the security of the information systems compromised in the cybersecurity event in order to prevent further unauthorized acqu

Free access — add to your briefcase to read the full text and ask questions with AI

Legislative History

Effective: March 20, 2019 | Latest Legislation: Senate Bill 273 - 132nd General Assembly

Nearby Sections

11
View on official source ↗

Cite This Page — Counsel Stack

Bluebook (online)
Ohio § 3965.03, Counsel Stack Legal Research, https://law.counselstack.com/statute/oh/3965.03.