Under Ohio Revised Code §1349.19, any person or business that owns, licenses, or maintains computerized personal information about Ohio residents must notify affected individuals when that data is accessed and acquired in a way that causes, or reasonably will cause, a material risk of identity theft or fraud. The notice must go out in the most expedient time possible and no later than 45 days after discovery, unless a law enforcement agency requests a delay. That 45-day clock is the headline number every Ohio employer needs to know.
Three things determine whether you have a legal obligation to act:
- What data was involved: Ohio law defines “personal information” as a person’s name combined with a Social Security number, driver’s license or state ID number, or an account, credit card, or debit card number paired with a security code or password. If your records contain these combinations, you are in scope.
- Who must notify: Owners, licensees, and custodians of computerized data, including third-party vendors holding data on behalf of another business, all carry notification duties under ORC §1349.19.
- What exceptions apply: Encrypted data that is unreadable to the unauthorized party, entities regulated by federal financial notification rules, and HIPAA-covered entities may fall outside or alongside Ohio’s requirements.
Ohio also offers a meaningful incentive for proactive businesses: ORC §1354, the Data Protection Act, grants an affirmative defense to certain tort claims when a business maintains a written cybersecurity program that conforms to a recognized industry framework. The Ohio Attorney General’s guidance on personal information and breach response supplements the statute with practical recommendations every Ohio business should read before an incident occurs.
Key Takeaways
Ohio’s Security Breach Notification Act (ORC §1349.19) requires notice to affected Ohio residents within 45 days of discovery when computerized personal information is accessed and acquired in a way that creates a material risk of identity theft or fraud.
| Point | Details |
|---|---|
| 45-day notice deadline | Notify affected Ohio residents no later than 45 days after discovery, unless law enforcement authorizes a delay. |
| Personal information definition | Name plus SSN, driver’s license number, or financial account number with access credentials triggers Ohio notice obligations. |
| Credit bureau notification | When more than 1,000 Ohio residents are affected in one occurrence, notify all nationwide consumer reporting agencies without unreasonable delay. |
| ORC §1354 safe harbor | Maintain a written cybersecurity program conforming to NIST CSF or CIS Controls to support an affirmative defense to tort claims. |
| Mavericks Office Solutions | Provides 24/7 monitoring, incident response support, and cybersecurity program development to help Ohio businesses meet ORC obligations. |
Table of Contents
- What does Ohio’s data breach law actually require?
- What counts as a security breach under Ohio’s notification rules?
- How and when must you send breach notifications in Ohio?
- Who is exempt, and how does Ohio law interact with federal rules?
- How does Ohio’s Data Protection Act create a safe harbor for your business?
- Step-by-step incident response for Ohio businesses
- What enforcement and civil risk does Ohio law create?
- What should an Ohio breach notice actually say?
- Why breach preparedness is a business priority, not just a legal one
- How Mavericks Office Solutions helps Ohio businesses meet their ORC obligations
- Sources
What does Ohio’s data breach law actually require?
Ohio Revised Code §1349.19, commonly called the Security Breach Notification Act, is the core statute governing Ohio data breach notification. Its language is precise, and understanding it at the definition level saves businesses from both over-notifying and under-notifying.
A “breach of the security of the system” means unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information and that causes, or reasonably is believed will cause, a material risk of identity theft or other fraud to any resident of Ohio.
That definition does real work. “Access” alone is not enough. The statute requires acquisition, meaning the attacker must have actually obtained the data, not merely viewed a login screen. And the material risk standard means a documented risk assessment, not a reflexive assumption, drives the notice decision.
Who must disclose under ORC §1349.19:
- Owners of computerized data containing personal information about Ohio residents
- Licensees of such data
- Custodians holding data on behalf of another entity (third-party processors and vendors are explicitly included)
What “personal information” means under Ohio law:
- First name or first initial plus last name, combined with any of the following:
- Social Security number
- Driver’s license number or state identification card number
- Account number, credit card number, or debit card number, when combined with a security code, access code, or password that permits access to the account
The Ohio Attorney General advises businesses to map their data inventories against this definition before an incident occurs. Knowing exactly where SSNs, financial account numbers, and access credentials live in your systems is the first practical step toward compliance readiness.
For purposes of the statute, “resident” means any individual whose personal information is in the breached dataset and who is a resident of Ohio. If your customer or employee database includes Ohio residents alongside out-of-state individuals, Ohio law applies to the Ohio-resident subset.
What counts as a security breach under Ohio’s notification rules?
The “material risk” threshold is where most Ohio businesses get tripped up. Not every unauthorized access event triggers a notice obligation. The statute asks a forward-looking question: given what was accessed and acquired, does a realistic risk of identity theft or fraud exist?
Data combinations that trigger Ohio notice requirements:
- Names + Social Security numbers (the most common trigger)
- Names + driver’s license or state ID numbers
- Names + financial account or card numbers combined with access credentials
Data that typically does NOT trigger notice on its own:
- Email addresses without accompanying sensitive identifiers
- Phone numbers alone
- Publicly available information
- Encrypted data where the encryption key was not also compromised
Two concrete examples illustrate the difference. A stolen laptop containing an unencrypted spreadsheet with employee names and SSNs almost certainly triggers notice. A misconfigured web server that briefly exposed a list of customer email addresses, with no financial or government ID data, likely does not meet the material risk threshold, though a documented risk assessment should confirm that conclusion.
The access-versus-acquisition distinction matters practically. If forensic evidence shows an attacker entered a network but logs confirm the sensitive data partition was never reached, acquisition may not have occurred. That forensic analysis needs to happen quickly and be documented thoroughly.

Pro Tip: Document your risk assessment in writing the moment you begin triage. Record what data was in scope, what the attacker could realistically do with it, and the reasoning behind your notice decision. That documentation is your first line of defense if the Ohio Attorney General later asks why you did or did not notify.
How and when must you send breach notifications in Ohio?
Timing and method are both statutory requirements, not suggestions. Once you determine that a breach meets the material risk threshold, the 45-day clock is running.
The 45-day deadline and the law enforcement exception
ORC §1349.19 requires notice “in the most expedient time possible but not later than 45 days after the discovery of the breach.” The law enforcement exception allows delay when a law enforcement agency determines that disclosure would impede a criminal investigation or jeopardize national security. Once law enforcement confirms the investigation will not be compromised, disclosure must follow promptly. Document every communication with law enforcement and every decision to delay.
Acceptable notice methods
Per the Ohio Attorney General’s breach-response guide, businesses may notify affected individuals by:
- Written notice mailed to the individual’s last known address
- Electronic notice when the individual has consented to electronic communication
- Telephone notice when direct contact is feasible
Substitute notice conditions
Substitute notice is available under narrow conditions: when the cost of direct notification would be prohibitive, when contact information for affected individuals is insufficient, or when the number of affected individuals is extremely large. Substitute notice requires a combination of email notification (where addresses are available), a conspicuous posting on the business’s website, and notification to major statewide media outlets. The statutory conditions for substitute notice are strict, and businesses should document why direct notice was not feasible before relying on this option.
Credit reporting agency notification
When a single breach affects more than 1,000 Ohio residents, ORC §1349.19 requires notification to all nationwide consumer reporting agencies without unreasonable delay. This notification must cover the timing, distribution, and content of the notices sent to individuals.
| Milestone | Deadline / Trigger |
|---|---|
| Discovery of potential breach | immediately: begin containment and investigation immediately |
| Risk assessment complete | As soon as forensically possible; document findings |
| Law enforcement contact (if applicable) | Before or concurrent with investigation; document delay authorization |
| Individual notice deadline | No later than 45 days after discovery |
| Consumer reporting agency notice | Without unreasonable delay when >1,000 Ohio residents affected |
| Recordkeeping checkpoint | Preserve all documentation indefinitely for potential AG review |
Who is exempt, and how does Ohio law interact with federal rules?
Ohio’s breach notification law does not operate in a vacuum. Several categories of businesses are exempt from ORC §1349.19, and others face layered obligations under federal sector rules.
Statutory exemptions under ORC §1349.19:
- Financial institutions subject to federal breach notification requirements (such as those under the Gramm-Leach-Bliley Act) are exempt from Ohio’s state notice requirements for the same breach
- Entities subject to HIPAA’s breach notification rule are similarly exempt from ORC §1349.19 to the extent HIPAA governs the same breach
- Data that is encrypted and rendered unreadable to the unauthorized party does not trigger Ohio notice obligations
Federal overlay rules Ohio businesses in regulated sectors must evaluate:
- HIPAA (healthcare): The HHS Office for Civil Rights enforces separate breach notification rules for covered entities and business associates. HIPAA’s 60-day notification window and its definition of a breach differ from Ohio’s statute. Healthcare businesses must satisfy HIPAA’s requirements and confirm whether Ohio’s law applies to any non-HIPAA-covered data they also hold.
- GLBA (financial services): Banks, credit unions, and other financial institutions subject to the Gramm-Leach-Bliley Act follow federal financial regulator guidance on breach notification. Ohio’s exemption for these entities reflects that federal framework.
- FERPA (education): Educational institutions holding student records face federal obligations under FERPA that may run alongside or supersede Ohio’s requirements for certain data categories.
Agencies a multi-regulated Ohio business may need to coordinate with:
- Ohio Attorney General (ORC §1349.19 enforcement)
- HHS Office for Civil Rights (HIPAA)
- Federal financial regulators (CFPB, OCC, FDIC, or state banking regulators, depending on charter)
When obligations overlap, the practical guidance from the Ohio Attorney General is clear: consult legal counsel before finalizing your notice strategy. Federal exemptions do not always eliminate Ohio duties entirely, and the scope of each exemption depends on which data was breached and which regulatory framework covers it.
How does Ohio’s Data Protection Act create a safe harbor for your business?
ORC §1354, the Ohio Data Protection Act, is one of the most practically useful tools available to Ohio businesses. It does not eliminate your notice obligations under ORC §1349.19, but it can provide an affirmative defense to certain tort claims arising from a breach.
The statute’s logic is straightforward: if you built and maintained a reasonable cybersecurity program before the breach, you are in a materially better legal position than a business that did nothing. Courts evaluating tort claims must consider whether the defendant had a qualifying program in place.
What a qualifying cybersecurity program must include
To claim the ORC §1354 affirmative defense, your written cybersecurity program must contain administrative, technical, and physical safeguards, and it must reasonably conform to an industry-recognized framework. The statute explicitly contemplates that program scope scales with the size and nature of the organization.

Recognized frameworks the statute contemplates include the NIST Cybersecurity Framework (CSF) and the CIS Controls, among others. A written cybersecurity plan aligned to one of these frameworks is the foundation of the defense.
ORC §1354 safe harbor self-assessment checklist:
- Do you have a written cybersecurity policy that is formally adopted and dated?
- Does the policy address administrative safeguards (access controls, employee training, vendor management)?
- Does it address technical safeguards (encryption, multi-factor authentication, endpoint protection, patch management)?
- Does it address physical safeguards (facility access controls, device security)?
- Does the program reference a recognized framework (NIST CSF, CIS Controls, ISO 27001, or a sector-specific equivalent)?
- Do you conduct periodic risk assessments and document the results?
- Do you have a documented incident response plan?
- Do you review and update the program at least annually or after significant changes?
- Do you manage third-party vendor security through written agreements and periodic reviews?
- Is all of the above documented and retrievable?
If you answered “no” to any of those questions, your program likely would not support the affirmative defense today.
Pro Tip: The affirmative defense lives or dies on documentation. A penetration test you ran but never wrote up, a risk assessment that existed only in someone’s head, or a policy that was drafted but never formally adopted all weaken your position. Treat documentation as a legal asset, not an administrative chore.
Step-by-step incident response for Ohio businesses
When a potential breach surfaces, the first hour matters more than most businesses realize. Here is an ordered response sequence built around ORC §1349.19’s requirements and Ohio Attorney General guidance.
- Contain the incident. Isolate affected systems immediately to prevent further unauthorized access or data exfiltration. Preserve logs and evidence before taking any action that could overwrite them.
- Assemble your incident response team. Assign clear roles: IT handles containment and forensics; Legal interprets statutory obligations and manages external communications; HR coordinates employee notification if workforce data is involved; PR prepares external messaging.
- Notify internal stakeholders. Brief executive leadership and your legal counsel within hours of discovery, not days. Early counsel involvement shapes every subsequent decision.
- Engage legal counsel. Counsel should be involved before any external communication, including law enforcement contact. Attorney-client privilege can protect your internal investigation communications.
- Conduct forensic investigation. Determine what data was accessed, what was acquired, and by whom. Document the methodology, the investigators, and the findings.
- Complete a documented risk assessment. Evaluate whether the acquired data meets Ohio’s “personal information” definition and whether the material risk of identity theft or fraud standard is satisfied. Record the outcome in writing.
- Decide on notice. Based on the risk assessment and legal counsel’s guidance, determine whether ORC §1349.19 requires notification. Document the decision and the reasoning.
- Contact law enforcement if appropriate. If criminal activity is suspected, notify law enforcement and document whether they request a notification delay. Record any delay authorization in writing.
- Draft and send notifications. Prepare individual notices that meet the AG’s clarity and content standards. If more than 1,000 Ohio residents are affected, prepare consumer reporting agency notifications simultaneously.
- Implement remediation. Patch vulnerabilities, reset credentials, strengthen controls, and address the root cause of the breach.
- Monitor and follow up. Watch for signs of misuse of the compromised data. Offer credit monitoring or other protective services to affected individuals where appropriate.
- Document everything. Preserve the complete incident record, including the decision log described below.
Decision log fields to capture:
- Discovery timestamp and discovery method
- Data elements confirmed as involved
- Names and roles of investigators
- Risk assessment outcome and reasoning
- Notice decision, date, and signoff
- Law enforcement contact details and any delay authorization
- Remediation steps taken and completion dates
Pro Tip: Draft your breach notice template now, before an incident occurs. Pre-approve the language with legal counsel, and establish the internal sign-off chain. When the 45-day clock is running, a pre-approved template can save 12 to 24 hours of drafting time while preserving the legal review your notice requires.
What enforcement and civil risk does Ohio law create?
Ohio’s breach notification statute gives the Attorney General authority to investigate failures to comply with ORC §1349.19 and to pursue civil actions against non-compliant businesses. That enforcement authority is real, and the reputational cost of an AG investigation often exceeds the direct legal penalty.
Key enforcement and liability points:
- The Ohio Attorney General can investigate any business that fails to provide timely, adequate notice to affected residents.
- Civil actions can follow AG investigations, and private tort claims from affected individuals are a separate exposure channel.
- Federal regulators, including HHS OCR for healthcare entities and financial regulators for GLBA-covered businesses, may pursue parallel enforcement actions when their sector rules are also implicated.
- A documented ORC §1354 cybersecurity program provides an affirmative defense to certain tort claims but does not eliminate the notice duty under ORC §1349.19. The two statutes serve different purposes: §1349.19 governs what you must do after a breach; §1354 governs how a pre-breach program affects your tort exposure.
Best practices to minimize enforcement risk:
- Document every decision in the incident response process, including the reasoning behind a decision not to notify.
- Preserve system logs, forensic reports, and communications with law enforcement.
- Engage legal counsel early and maintain attorney-client privilege over the investigation.
- Send notices on time. Late notice is the most common trigger for AG scrutiny.
- Confirm consumer reporting agency notifications when the 1,000-resident threshold is crossed.
The practical reality for Ohio businesses is that enforcement risk compounds when documentation is thin. An AG investigation that finds a well-documented incident response, a timely notice, and a written cybersecurity program looks very different from one that finds no records, a late notice, and no security policies.
What should an Ohio breach notice actually say?
The statute does not prescribe exact notice language, but the Ohio Attorney General is clear that notices must be meaningful, clear, and easy to understand. A notice that buries the key facts in legal boilerplate fails that standard.
Required and recommended elements for an Ohio breach notice:
- A plain-language description of what happened and when
- The specific categories of personal information involved (e.g., “names and Social Security numbers”)
- Steps the business has taken to investigate and contain the breach
- Steps the business is taking to prevent recurrence
- Specific advice to recipients on protecting themselves: placing a credit freeze, enrolling in credit monitoring, reviewing account statements
- A dedicated contact (phone number, email, or mailing address) for questions
- The date the breach was discovered and the date notice is being sent
The Ohio Attorney General advises: notices should be written so that a recipient who has no legal or technical background can immediately understand what happened, what data was involved, and what they should do next. Clarity is not optional. A notice that requires a second reading to understand the scope of the breach is not a compliant notice.
Template sentence stems for legal teams to adapt:
- “On [date], we discovered that unauthorized access to our systems may have exposed your [data type].”
- “The information involved may include your name and [SSN / driver’s license number / account number and access code].”
- “We have taken the following steps to secure our systems and prevent further unauthorized access: [list steps].”
- “To protect yourself, we recommend placing a free credit freeze with each of the three major credit bureaus.”
Before sending any notice, run a legal review checkpoint covering three items: confirm the scope of affected individuals is accurate, verify whether law enforcement has cleared the disclosure, and confirm whether consumer reporting agency notifications are required given the number of Ohio residents affected.
When contact information is incomplete for some individuals, substitute notice (email, website posting, and media notification) may be used for that subset, but document why direct notice was not feasible for each affected group.
Why breach preparedness is a business priority, not just a legal one
Most Ohio businesses treat data breach compliance as a legal checkbox. That framing is too narrow, and it tends to produce the worst possible outcome: a reactive scramble after an incident, with no documentation, no pre-approved notice template, and no cybersecurity program to support an affirmative defense.
The businesses that fare best after a breach are the ones that treated the 45-day clock as a planning constraint, not a surprise. They built their incident response plan before the breach, documented their cybersecurity program against a recognized framework, and had legal counsel on speed dial. When the incident happened, they moved fast because the decisions had already been made in advance.
Ohio’s Data Protection Act safe harbor under ORC §1354 is genuinely useful, but only if the program it protects was real and documented before the breach. A cybersecurity policy written the week after an incident does not qualify. The affirmative defense rewards preparation, not reaction.
For Ohio employers, the business case for proactive cybersecurity is not abstract. A breach that triggers AG investigation, private tort claims, and federal regulatory scrutiny simultaneously can cost far more in legal fees, remediation, and reputational damage than a well-maintained managed security program costs annually. The math is not complicated.
How Mavericks Office Solutions helps Ohio businesses meet their ORC obligations
Meeting Ohio’s data breach notification requirements takes more than reading the statute. It takes 24/7 monitoring to detect incidents quickly, forensic capability to assess what was actually acquired, pre-built response workflows to hit the 45-day deadline, and a documented cybersecurity program that can support an ORC §1354 affirmative defense.

Mavericks Office Solutions serves as an outsourced IT and cybersecurity department for Ohio small and medium businesses, with an average help desk response time under 12 minutes and continuous monitoring that shortens the gap between breach and discovery. Specific services directly relevant to ORC compliance include incident response support, written cybersecurity program development aligned to NIST CSF and CIS Controls, continuous endpoint monitoring, backup and recovery, and vendor security coordination. For businesses that need compliance guidance without a full-time IT leader, fractional IT leadership services provide executive-level technology strategy on a part-time basis.
Combine vendor support with qualified legal counsel for all final notice decisions. Mavericks Office Solutions handles the technical and operational side; your attorney handles the statutory interpretation. To discuss your current readiness and where gaps exist, connect with the team through managed IT services and get a clear picture of where your business stands before an incident forces the question.
Sources
The statutes and official guidance below are the primary sources for Ohio data breach compliance. Bookmark them and share them with your legal counsel.
- Section 1349.19 – Ohio Revised Code
- Personal Information for Consumers – Ohio Attorney General
- Breach Notification Rule (HHS OCR)
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Recommended
- Why Every Ohio Small Business Needs a Cybersecurity Plan in 2026 – Mavericks Office Solutions
- Microsoft 365 Backup: What Ohio SMBs Need to Know – Mavericks Office Solutions
- SaaS Security Controls for Ohio SMBs: 2026 Guide – Mavericks Office Solutions
- HIPAA Compliance IT for Michigan: Your 90-Day Action Plan – Mavericks Office Solutions