Ohio Revised Code Search
Section |
---|
Section 3798.04 | Prohibited disclosures of protected health information.
...A covered entity shall not do either of the following: (A) Use or disclose protected health information without an authorization that is valid under 45 C.F.R. 164.508 and, if applicable, 42 C.F.R. part 2, except when the use or disclosure is required or permitted without such authorization by Subchapter C of Subtitle A of Title 45 of the Code of Federal Regulations and, if applicable, 42 C.F.R. part 2; (B) U... |
Section 3798.07 | Conditions for disclosure to health information exchange.
...at govern the confidentiality, privacy, security, or privileged status of protected health information in the possession or custody of an agency as defined in section 111.15 of the Revised Code; govern the process for obtaining from a patient consent to the provision of health care or consent for participation in medical or other scientific research; govern the process for determining whether an adult has a physical ... |
Section 3798.10 | Standard authorization form.
...he medicaid director shall prescribe by rules adopted in accordance with Chapter 119. of the Revised Code a standard authorization form for the use and disclosure of protected health information by covered entities in this state. The form shall meet all requirements specified in 45 C.F.R. 164.508 and, where applicable, 42 C.F.R. part 2. (B) If a form the medicaid director prescribes under division (A) of this secti... |
Section 3798.12 | Conflicts with other laws.
...ining to the confidentiality, privacy, security, or privileged status of protected health information transacted, maintained in, or accessed through a health information exchange is unenforceable if it conflicts with this chapter: (1) A section of the Revised Code that is not in this chapter; (2) A rule as defined in section 119.01 of the Revised Code; (3) An internal management rule as defined in section 111... |
Section 3798.13 | Adoption of rules regarding classification of minors.
...The medicaid director shall adopt rules for purposes of specifying the criteria a person who is mentally or physically disabled and who is under twenty-one years of age must meet to be considered a minor for purposes of sections 3798.07 and 3798.12 of the Revised Code. |
Section 3799.01 | Compact.
...the Commission 1. To adopt bylaws and rules pursuant to Articles V and VI of the compact, which shall have the force and effect of law and shall be binding in the compacting states to the extent and in the manner provided in the compact; 2. To receive and review in an expeditious manner treatments and therapeutic protocols for the cure of disease submitted to the commission and to award prizes for submissions tha... |
Section 3965.01 | Definitions.
...nt, and certificate holder. (E) "Cybersecurity event" means an event resulting in unauthorized access to, disruption of, or misuse of an information system or nonpublic information stored on an information system that has a reasonable likelihood of materially harming any consumer residing in this state or any material part of the normal operations of the licensee. "Cybersecurity event" does not include the unauthor... |
Section 3965.02 | Information security program.
...ain a comprehensive written information security program based on the licensee's risk assessment. The program shall be commensurate with the size and complexity of the licensee, the nature and scope of the licensee's activities including its use of third-party service providers, and the sensitivity of the nonpublic information used by the licensee or in the licensee's possession, custody, or control. (B) The inform... |
Section 3965.03 | Investigation of events.
...(A) If a licensee learns that a cybersecurity event has or may have occurred, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall conduct a prompt investigation. (B) During the investigation, the licensee or an outside vendor or service provider designated to act on behalf of the licensee shall, at a minimum, do as much of the following as possible: (1) Determin... |
Section 3965.04 | Notification to superintendent.
...sible after a determination that a cybersecurity event involving nonpublic information in the possession of the licensee has occurred, but in no event later than three business days after that determination, when either of the following criteria has been met: (1) Both of the following apply: (a) This state is the licensee's state of domicile, in the case of an insurer, or this state is the licensee's home state, ... |
Section 3965.05 | Powers of superintendent.
...(A) The superintendent of insurance shall have power to examine and investigate into the affairs of any licensee to determine whether the licensee has been or is engaged in any conduct in violation of this chapter. This power is in addition to the powers that the superintendent has under Title XXXIX and Chapters 1739. and 1751. of the Revised Code. (B) Whenever the superintendent has reason to believe that a licens... |
Section 3965.06 | Confidentiality.
...(A)(1) Any documents, materials, or other information in the control or possession of the department of insurance that are furnished pursuant to divisions (H)(1) and (I) of section 3965.02 and divisions (B)(1)(b), (c), (d), (e), (h), (j), and (k) of section 3965.04 of the Revised Code, or that are obtained by, created by, or disclosed to the superintendent of insurance in an investigation or examination pursuant to s... |
Section 3965.07 | Exemptions.
...yee, agent, representative, independent contractor, or designee of a licensee, who is also a licensee, is exempt from section 3965.02 of the Revised Code and need not develop its own information security program to the extent that the employee, agent, representative, independent contractor, or designee is covered by the information security program of the other licensee. (D) If a licensee ceases to qualify for an e... |
Section 3965.08 | Affirmative defense.
...ure to implement reasonable information security controls resulted in a data breach concerning nonpublic information. (B) The affirmative defenses permitted under this section shall not limit any other affirmative defenses available to a licensee. |
Section 3965.09 | Applicability and scope of chapter.
... applicable to licensees regarding cybersecurity events, the security of nonpublic information, data security, investigation of cybersecurity events, and notification to the superintendent of cybersecurity events. |
Section 3965.10 | Adoption of rules.
...ter 119. of the Revised Code, may adopt rules as necessary to carry out the provisions of this chapter. |
Section 3965.11 | Administration.
...administering this chapter and adopting rules pursuant to this chapter. |
Section 4101.083 | Duties of board of building standards.
...the protection of the public health and safety and shall include rules establishing the safe working pressure to be carried by any such systems; a program for the certification of the welding and brazing procedures proposed to be used on any such system by the owner or operator of any welding or brazing business and for quinquennial performance testing of welders and brazers who work on any such system; and measures ... |
Section 4101.11 | Duty of employer to protect employees and frequenters.
...quenters thereof, shall furnish and use safety devices and safeguards, shall adopt and use methods and processes, follow and obey orders, and prescribe hours of labor reasonably adequate to render such employment and places of employment safe, and shall do every other thing reasonably necessary to protect the life, health, safety, and welfare of such employees and frequenters. |
Section 4101.12 | Duty of employer to furnish safe place of employment.
...shall fail to furnish, provide, and use safety devices and safeguards, or fail to obey and follow orders or to adopt and use methods and processes reasonably adequate to render such employment and place of employment safe. No employer shall fail to do every other thing reasonably necessary to protect the life, health, safety, and welfare of such employees or frequenters. No such employer or other person shall constru... |
Section 4101.13 | Duties of employees.
...lace, damage, destroy, or carry off any safety device or safeguard furnished or provided for use in any employment or place of employment, or interfere in any way with the use thereof by any other person. No employee shall interfere with the use of any method or process adopted for the protection of any employee in such employment or place of employment, or frequenter of such place of employment, or fail to follow an... |
Section 4101.14 | Substantial compliance.
...A substantial compliance with the applicable sections of sections 4101.01 to 4101.16, inclusive, and 4121.01 to 4121.29, inclusive, of the Revised Code, is sufficient to give effect to orders, and such orders shall not be declared inoperative, illegal, or void for any omission of a technical nature in respect thereto. |
Section 4101.15 | Prohibited acts.
...No employer, employee, or other person shall violate this chapter or Chapter 4121. of the Revised Code, do any act prohibited by such chapters, fail to perform any duty lawfully enjoined, within the time prescribed by the bureau of workers' compensation, for which violation no penalty has been specifically provided, or fail to obey any lawful order given or made by the bureau, or any judgment or decree made by ... |
Section 4101.16 | Every day a separate violation.
...Every day during which any person, or corporation, or any officer, agent, or employee thereof fails to observe and comply with any order of the bureau of workers' compensation, or to perform any duty enjoined by this chapter and Chapter 4121. of the Revised Code, constitutes a separate violation of the order or chapters. |
Section 4101.99 | Penalty.
...(A) Whoever violates section 4101.15 of the Revised Code shall be fined not less than fifty nor more than one thousand dollars for a first offense; for each subsequent offense such person shall be fined not less than one hundred nor more than five thousand dollars. |