Privacy Law Library

Insurance Data Security Act

OK IDSA

Data security · Breach notification · Financial · Health

Oklahoma's version of the NAIC Insurance Data Security Model Law. Insurance licensees must maintain a risk-based written information security program with an incident response plan and vendor oversight, investigate cybersecurity events, and notify the Insurance Commissioner within three business days of determining a qualifying event, while notifying consumers under the Security Breach Notification Act. It is the exclusive state data security law for licensees.

Where
Oklahoma
Citation
36 O.S. §§ 670-679 (Laws 2024, c. 346, SB 543)
Status
In force
In force since
2024-07-01
Last amended
2025-11-01
Enforced by
Oklahoma Insurance Commissioner
People can sue
No
Penalties
Penalties under the Insurance Code (including 36 O.S. § 908) and license-related sanctions; the act expressly creates no civil liability.
Applies to
  • Persons licensed, authorized, or registered (or required to be) under the Oklahoma Insurance Code, including insurers and producers
  • Exempt: licensees with under $5 million gross annual revenue; out-of-state purchasing and risk retention groups and assuming insurers domiciled elsewhere; HIPAA- or GLBA-compliant licensees are deemed compliant with the security program requirement if they certify

Security duties

  • Develop, implement, and maintain a comprehensive written information security program based on a risk assessment, with access controls, encryption of nonpublic information in transit over external networks and on portable devices, MFA or other effective controls, monitoring, audit trails, secure disposal, and annual staff training.36 O.S. § 673(A)-(D) · From 2025-07-01
  • Maintain a written incident response plan covering roles, communications, remediation, documentation, and post-event review.36 O.S. § 673(H)
  • Exercise due diligence in selecting third-party service providers and require them to implement appropriate safeguards.36 O.S. § 673(F) · From 2026-07-01

Breach duties

  • Promptly investigate any actual or possible cybersecurity event.36 O.S. § 674
  • Notify affected consumers under the Security Breach Notification Act (24 O.S. § 161 et seq.) and give the Commissioner a copy of the consumer notice.36 O.S. § 675(C)
  • Notify the Insurance Commissioner within three business days of determining a cybersecurity event where Oklahoma is the domicile or home state and the event is reasonably likely to cause material harm, or where 250 or more Oklahoma consumers are involved and notice is required elsewhere or material harm is likely; update the notice as facts change.36 O.S. § 675(A)-(B)

Registration

  • Domestic insurers must certify compliance to the Insurance Commissioner annually by April 15 and keep supporting records for five years.36 O.S. § 673(I)

Other duties

  • If the licensee has a board, the board must require management to maintain the program and report on it in writing at least annually.36 O.S. § 673(E)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: effective_on dates for § 673 reflect the § 679 phase-in (one year for § 673, two years for § 673(F)) from July 1, 2024.

Research reference, not legal advice.