NuHarbor Security
  • Solutions
    Solutions
    Custom cybersecurity solutions that meet you where you are.
    • Overview
    • Our Approach
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • By Business Need
      • Identify Gaps in My Cybersecurity Plan
      • Detect and Respond to Threats in My Environment
      • Fulfill Compliance Assessments and Requirements
      • Verify Security With Expert-Led Testing
      • Manage Complex Cybersecurity Technologies
      • Security Monitoring With Splunk
    • By Industry
      • State & Local Government
      • Higher Education
      • Federal
      • Finance
      • Healthcare
      • Insurance
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Services
    Services
    Outcomes you want from a team of experts you can trust.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Security Testing
      • Penetration Testing
      • Application Penetration Testing
      • Vulnerability Scanning
      • Wireless Penetration Testing
      • Internal Penetration Testing
      • External Penetration Testing
    • Assessment & Compliance
      • CMMC Compliance
      • NIST 800-53
      • HIPAA Security Standards
      • ISO 27001
      • MARS-E Security Standards
      • New York Cybersecurity (23 NYCRR 500)
      • Payment Card Industry (PCI)
    • Advisory & Planning
      • Security Strategy
      • Incident Response Planning
      • Security Program Reviews
      • Security Risk Assessments
      • Virtual CISO
      • Policy Review
    • Managed Services
      • Curated Threat Intelligence
      • Managed Detection and Response (MDR)
      • Sentinel Managed Extended Detection and Response (MXDR)
      • SOC as a Service
      • Splunk Managed Services
      • Tenable Managed Services
      • Vendor Security Assessments
      • Vulnerability Management
      • Zscaler Support Services
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Partners
  • Resources
    Resources
    Explore reports, webinars, case studies, and more.
    • Browse Resources
    • Consultation Icon Consult with an expert
    • Blog icon Blog
    • Podcast icon Podcast
    • Annual SLED CPR icon Annual SLED CPR
    • Downloadable Assets icon Downloadable Assets
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Company
    Company
    We do cybersecurity differently – the right way.
    • Overview
    • Data Icon Resources
    • Consultation Icon Consult with an expert
    • Leadership
    • News
    • Careers
    • Contact
    Report 2023-2024 SLED Cybersecurity Priorities Report
    2023-2024 SLED Cybersecurity Priorities Report
    Read Report
  • Consult with an expert
  • Client support
  • Careers
  • Contact
1.800.917.5719
NuHarbor Security Blog
    • Compliance
    • Cybersecurity Technology
    • Security Operations
    • Industry Insights
    • Security Testing
    • Advisory and Planning
    • Application Security
    • Managed Detection and Response
    • Threat Intelligence
    • NuHarbor
    • Managed Services
    • Cyber Talent
June 3, 2019

4 Things To Know About The Ohio Data Protection Act

Justin Fimlaid Justin Fimlaid

The Ohio Data Protection Act was passed in August of 2018 and went into effect as of November 2018. What's unique about this data protection law is that it's unlike recently passed privacy legislation recently seen in California and Colorado.

1. It's not a punitive law

What's also unique about this Ohio Data Protection Act is that it does not rely on punitive measures as a means to enforcement. The Ohio Data Protection Act offers businesses the ability to self select secure behaviors in a form of voluntary actions in order to receive what's considered a safe harbor.  Before we talk about safe harbor, let's chat about who is in scope. The Ohio Data Protection Act applies broadly to any businesses that accesses, maintains, communicates, or processes personal information or restricted information. Restricted information is generally considered any information that is unencrypted about an individual that can be used to distinguish or trace an individual's identity--think of restricted information as a secondary form information that on its own would seem anonymous but if you gather enough of it you could trace this back to a named individual.

2. Qualifying for safe harbor requires you align with a framework.

What's also unique about this law is the ability for businesses to qualify what's considered safe harbor. Safe harbor requires that a business create maintain and comply with a written security program that reasonably conforms to one of the industry's several recognized cybersecurity frameworks. Some of those include:

  • NIST Cybersecurity Framework
  • NIST 800-53
  • NIST 800-171
  • ISO 27001
  • HIPAA
  • PCI-DSS
  • Plus Others.

Most importantly to leverage safe harbor provisions the cybersecurity program must:

  • be designed to protect the security and confidentiality of personal information,
  • protect against any anticipated threats or hazards to the security or integrity of personal information,
  • protect against unauthorized access to an acquisition of the information that is likely to result in the material risk of identity theft or other fraud.

3. Offers limitation of breach liability

Now the purpose of the Ohio Data Protection Act is to provide covered entities with an affirmative defense in data breach claims based on tort law. By invoking the affirmative defense covered entities may refute liability in certain lawsuits that claim a business's failure to implement reasonable information security measures resulted in a data breach.

The Safe Harbor has several limitations. For business to leverage the affirmative defense in a lawsuit the claim must be brought under Ohio law or in Ohio Courts, it must allege that failure to implement a reasonable information security controls resulted in a data breach, and it must arise under tort law.

As you think about designing your security program and you should think about choosing which security framework is relevant to you. Your cyber security program under Ohio's Data Protection Law must be designed in such a way where you can invoke safe harbor.

4. Offers ability to flex your program to match business needs

Now a key point in the law is that it requires reasonable compliance with one of the frameworks that I listed earlier. The Ohio Data Protection Act also allows covered entities to tailor and scale and scope their cybersecurity program according to their own business needs. In selecting the appropriate security program businesses or entities should also consider the size and complexity of their business.   Considerations should also be given to actual sensitivity of information, the cost and availability of tools and resources in order to operated the aforementioned frameworks.

Some other states that have done this in the past include Massachusetts and New York and have required businesses that handle personal information to maintain a written information security program or WISP. However what's unique about Ohio's Data Protection Act is that it's voluntary in its approach and it is different from the other programs that tend drive behaviors with fines versus incentives.

Included Topics

  • Compliance
Justin Fimlaid
Justin Fimlaid

Justin (he/him) is the founder and CEO of NuHarbor Security, where he continues to advance modern integrated cybersecurity services. He has over 20 years of cybersecurity experience, much of it earned while leading security efforts for multinational corporations, most recently serving as global CISO at Keurig Green Mountain Coffee. Justin serves multiple local organizations in the public interest, including his board membership at Champlain College.

Related Posts

3 min read
Commencement of Phase Two HIPAA Audits: Are you compliant? Read More
Compliance 4 min read
Which Security Controls Framework Is Right for You? Read More
Security Operations 2 min read
Information security for your local city, town, or village Read More

Subscribe via Email

Subscribe to our blog to get insights sent directly to your inbox.

Subscribe Here!

Latest Pwned episodes

Episode 200 - Reflections of Pwned...Until Next Time
April 03, 2024
Episode 200 - Reflections of Pwned...Until Next Time
Listen Now
Episode 199 - When a BlackCat Crosses Your Path...
March 21, 2024
Episode 199 - When a BlackCat Crosses Your Path...
Listen Now
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
March 08, 2024
Episode 198 - Heard it Through the Grapevine - Beyond the Beltway, 2024
Listen Now
NuHarbor Security logo
NuHarbor Security

553 Roosevelt Highway
Colchester, VT 05446

1.800.917.5719

  • Solutions
  • Services
  • Partners
  • Resources
  • Company
  • Contact
  • Privacy Policy
Connect
  • Twitter
  • Linkedin
  • YouTube
©2025 NuHarbor Security. All rights reserved.