On October 17, 2024, Oklahoma issued a bulletin regarding the Insurance Data Security Act. Key provisions include:
1. Exclusive state law for data security and cybersecurity event investigations
2. The obligation for licensees with a board of directors to submit annual information security program reports starting July 1, 2025
3. An annual data security attestation compliance attestation due by April 15 each year.
4. Licensees must notify the Insurance Commissioner of any cybersecurity events involving nonpublic information within three business days under certain conditions.
Please see the following link for more information Bulletin 10/2024