Data Breach Notification in Ohio: What You Must Report

Data Breach Notification

Ohio businesses that hold computerized personal information have a legal duty to tell people when that information is exposed. The core requirement sits in Ohio Revised Code Section 1349.19, which states that any person that owns or licenses computerized data that includes personal information must disclose a breach of the security of the system. Sections 1349.191 and 1349.192 sit alongside it. For most small and mid-sized employers in Northeast Ohio, the practical question is not whether the law exists. It is what has to be reported, to whom, and how fast.

The short version: notice to affected Ohio residents must go out in the quickest way possible and no later than 45 days after the breach is discovered. Everything else, including who counts as an affected resident and whether a specific incident meets the legal threshold, depends on the facts. What follows is the framework, the deadlines, and the operational steps that keep a business on the right side of both.

Who Has to Report Under Ohio Law

Ohio’s notification duty attaches to the entity that owns or licenses the data, not just to whoever happened to lose it. That distinction matters when a vendor, cloud provider, or payroll processor is the party that actually experiences the intrusion. The obligation to notify still generally traces back to the business that holds the relationship with the affected person.

The statute applies to individuals and commercial entities that conduct business in the state and that own, license, or maintain covered information. Some types of businesses may be exempt from some or all of these requirements, so the first step in any incident is confirming which rules actually apply to your organization.

  • Any person that owns or licenses computerized data containing personal information
  • Businesses operating in Ohio that own, license, or maintain covered information
  • Employers holding personal information about their own workers
  • Organizations that outsource storage or processing but still own the underlying data

What Counts as a Reportable Breach

Ohio’s definitional trigger centers on unauthorized access to and acquisition of personal information stored in computerized form, combined with a breach of the security of the system. That wording does two things at once. It narrows the scope to electronic records, and it ties the duty to access and acquisition rather than to intent or to the identity of the attacker.

Ohio is also among the states that build a harm threshold into the notification trigger. A harm threshold means not every incident automatically produces a notice obligation. Whether a given event crosses the line is a judgment call that depends on what was exposed, how it was exposed, and what a reasonable assessment says about the risk to the people involved. That judgment is exactly where legal counsel and a competent technical investigation need to work together, because the answer determines whether the 45 day clock produces letters or a documented decision not to notify.

The 45 Day Deadline and Other Core Requirements

Ohio Attorney General guidance is direct on timing: consumers must be notified in the quickest way possible, but not later than 45 days after the breach is discovered. The statute’s language tracks that same standard, requiring notice in the most expedient time possible and no later than 45 days following discovery.

Requirement What Ohio Requires
Notice to affected individuals Most expedient time possible, no later than 45 days after discovery of the breach
Trigger Breach of the security of computerized data containing personal information, with a harm threshold
Government notification No general state agency notification required under the general breach law
Employee data Employers must provide timely notification, not later than 45 days
Delivery methods Mail, email, or substitute notice as appropriate under the law

The clock starts at discovery. Not at the end of the forensic investigation, not at the point where the scope is fully understood, and not when the insurance carrier signs off. Discovery is the trigger, which is why incident response timelines in Ohio are compressed compared to what many business owners expect. A two week forensic engagement can consume nearly a third of the allowable window before a single letter is drafted.

How Notice Reaches Affected People

Ohio recognizes more than one channel for delivering notice. The most appropriate manner of notification to impacted individuals can be determined as mail, email, or substitute notice, as required under the law. In practice that gives organizations flexibility, but it does not give them unlimited discretion. Substitute notice is generally a fallback for situations where direct contact is impractical, not a default choice to save on postage.

Mailed letters remain the most common approach because they are the easiest to document. Email notice can be faster, but it carries deliverability risk, and a notice that lands in a spam folder is hard to defend. Whatever channel you choose, the record of when notice went out and to whom matters as much as the notice itself.

Employer Obligations When Employee Data Is Breached

Employee records are not a separate category that escapes the statute. Under Ohio law, when an employer experiences a data breach involving employees’ personal information, the employer must provide timely notification, within the same 45 day window that applies to customers. Payroll files, benefit enrollments, direct deposit details, and I-9 documentation all carry personal information that can trigger the duty.

This is where many small businesses get caught flat footed. An HR platform compromise or a phishing incident that captures a payroll administrator’s credentials can expose hundreds of employees at once, and the affected population is internal rather than external. Internal notification still requires the same discipline as a customer mailing: a defined population, an approved message, a delivery method, and a record of completion.

Government and Regulator Notification

The general Ohio breach notification statute does not require government notification, which separates Ohio from states that mandate a filing with a state regulator. That does not mean a report is never required. Sector specific obligations, contractual commitments with enterprise customers, and cyber insurance conditions can each create separate reporting duties that run on their own timelines.

Ohio’s Attorney General office publishes guidance on security breaches and the compromise of personal information, and it serves as a resource for consumers and businesses dealing with identity theft fallout. Ohio also lists a data breach hotline at 877.382.2724, written as 877.DTA.BRCH. Statutory language is amended over time, so confirm current requirements against the Ohio Revised Code and the Attorney General’s published guidance before you act on any single source.

A Practical Response Sequence

Deadlines are easier to hit when the work is sequenced rather than improvised. A defensible response in Ohio generally moves through the same stages regardless of company size.

  1. Contain the incident and preserve evidence before systems are rebuilt or wiped.
  2. Engage counsel early so the investigation and the notification decision are handled under privilege where appropriate.
  3. Determine whether personal information was actually accessed or acquired, and which individuals are affected.
  4. Assess the harm threshold and document the reasoning behind the conclusion.
  5. Draft and deliver notice through mail, email, or substitute notice within the 45 day window.
  6. Record the timeline, the notification list, and the delivery confirmation in a file you can produce later.

Step three is usually the bottleneck. Identifying affected individuals requires correlating logs, file access records, and data inventories that many organizations have never assembled in one place. Companies that maintain an accurate data map and retention schedule before an incident routinely cut days off this stage.

Where IT and Compliance Meet

Notification law is a legal obligation, but it is supported by technical facts. Whether personal information was accessed, how long an intruder had access, and which records were touched are all questions answered by logging, endpoint telemetry, and identity data. An organization with poor visibility cannot confidently assess a harm threshold, and an organization with good visibility can resolve the question quickly and get notice out well inside the 45 day limit.

CortComp works with small and mid-sized businesses across Warren, Cortland, and the surrounding Mahoning Valley on managed IT, cybersecurity strategy, and incident response. That includes compliance management for frameworks such as HIPAA, CMMC, GLBA, PCI-DSS, CJIS, and the Ohio Data Protection Act, plus 24/7 monitoring and breach remediation support. The goal is not paperwork for its own sake. It is being able to answer the questions Ohio law asks, with evidence, on a timeline the statute sets.

Frequently Asked Questions

How long do Ohio businesses have to notify people after a data breach?

Ohio law requires notice in the most expedient time possible and in no case later than 45 days after the breach is discovered. The clock starts at discovery, not at the end of the investigation. Businesses that take weeks to scope an incident can burn through that window quickly, so containment and notification planning should run in parallel rather than one after the other.

Does Ohio require businesses to notify a state agency about a breach?

The general Ohio breach notification statute does not require government notification, which separates Ohio from states that mandate a filing with a state regulator. That does not mean a report is never required. Sector rules and contracts can create separate duties, and the Ohio Attorney General’s office is a resource for consumers and businesses dealing with identity theft from a breach.

What does an Ohio breach notice need to say?

Ohio law focuses on timing and delivery. Notice must reach affected residents in the quickest way possible and within 45 days of discovery, and mailed letters, email, and substitute notice are the recognized channels. Because drafting expectations can shift with the facts of an incident and statutes are amended over time, confirm current requirements against Ohio Revised Code Section 1349.19 and advice from counsel.

Do employers have to notify employees whose personal information was breached?

Yes. When an employer experiences a breach involving employees’ personal information, Ohio’s requirements apply to those employees the same way they apply to customers. Notice still has to be timely, within the 45 day window, and delivered through an approved method. Employee records, payroll files, and benefit data all sit inside the same framework, so HR and IT should coordinate early.

Where can Ohio residents get help after a breach?

The Ohio Attorney General’s office publishes guidance on security breaches and the compromise of personal information, and Ohio lists a data breach hotline at 877.382.2724, also written as 877.DTA.BRCH. Affected consumers can use those resources to understand next steps, question a notice they received, and get help resolving problems caused by identity theft.

Recent Post

Complete IT Management
Tired of playing the middleman between your IT vendors? Not sure what IT costs you should be paying or renewing? Confused and unable to get an accurate picture of your IT budget? We understand – most business have been there; It’s time to be done with everything once and for all. We bundle support, subscriptions, incidents, solutions, visits, monitoring, licensing and more into one simple charge. Finally, budget simplicity and support clarity.