Okla. Stat. tit. 18, § 18-2071
This is the official text of Okla. Stat. tit. 18, § 18-2071, part of Oklahoma’s Stat. tit. 18, — part of the compiled statutory law of Oklahoma, published by the state as "Stat. tit. 18,." Browse the sections below, each linked to its official government source.
Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.
Industry-recognized cybersecurity framework
Official statutory text
A covered entity's cybersecurity program, as described in
Section 3 of this act, reasonably conforms to an industry-recognized
cybersecurity framework for purposes of that section if this section
is satisfied:
1. The covered entity is subject to the requirements of the
laws or regulations listed below, and the cybersecurity program
Oklahoma Statutes - Title 18. Corporations Page 627
reasonably conforms to the entirety of the current version of both
of the following, subject to paragraph 2 of this section:
a. the security requirements of the Health Insurance
Portability and Accountability Act of 1996, as set
forth in 45 CFR Part 164 Subpart C, and
b. the Health Information Technology for Economic and
Clinical Health Act, as set forth in 45 CFR Part 162;
and
2. When a framework listed in paragraph 1 of this section is
amended, a covered entity whose cybersecurity program reasonably
conforms to that framework shall reasonably conform to the amended
framework not later than one (1) year after the effective date of
the amended framework.
Section 3 of this act, reasonably conforms to an industry-recognized
cybersecurity framework for purposes of that section if this section
is satisfied:
1. The covered entity is subject to the requirements of the
laws or regulations listed below, and the cybersecurity program
Oklahoma Statutes - Title 18. Corporations Page 627
reasonably conforms to the entirety of the current version of both
of the following, subject to paragraph 2 of this section:
a. the security requirements of the Health Insurance
Portability and Accountability Act of 1996, as set
forth in 45 CFR Part 164 Subpart C, and
b. the Health Information Technology for Economic and
Clinical Health Act, as set forth in 45 CFR Part 162;
and
2. When a framework listed in paragraph 1 of this section is
amended, a covered entity whose cybersecurity program reasonably
conforms to that framework shall reasonably conform to the amended
framework not later than one (1) year after the effective date of
the amended framework.
Status: in_force · Read it on the official government site
Need a lawyer in Oklahoma?
Find a Oklahoma lawyer
About this page: Statute text is reproduced from official government publishers via the
Open US Law dataset
(Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine
(Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.