This past summer, Ohio adopted legislation (SB220) that primarily provides for a legal safe harbor from certain data-breach related tort claims to covered entities that implement a specified cybersecurity program that “reasonably conforms” to a recognized cybersecurity framework for the protection of personal information and “restricted information” or comply with certain industry-specific federal privacy laws. … Continue Reading