Ohio Data Breach Notification: The 45-Day Deadline Under ORC 1349.19 and 1347.12
Ohio gives you forty-five days from discovery. Here is which of the two statutes applies to you, what actually starts the clock, how notice has to be given, and what a late one costs per day.
By William Bradshaw | August 31, 2026 | 13 min read
The worst time to read a notification statute for the first time is on the day you need it. By then the clock has already been running for some number of days that nobody wrote down, the people who could reconstruct the timeline are busy restoring systems, and the question of whether this even counts as a breach is being decided by whoever is in the room.
Ohio's answer is short and unusually specific. You have forty-five days from discovery to tell affected residents. The deadline is the same whether you are a manufacturer in Dayton or a township in Geauga County, but the statute you are complying with is not, because Ohio wrote the duty twice: once for businesses and once for public entities.
This article works through both. What triggers the duty, what the definitions actually exclude, how the forty-five days is measured, how notice must be delivered, who else has to be told, who is exempt, and what the Attorney General can seek when a notification is late. It is practical guidance from a managed-services lens, not legal advice; confirm how these sections apply to your specific organization with the statute and your legal counsel.
If you are looking for the other half of Ohio's cybersecurity posture, the part that offers businesses something rather than requiring it, that is ORC 1354 and its cybersecurity safe harbor. The two chapters are independent. A perfect 1354 program does not shorten this deadline by a day.
Two Statutes, One Duty
Most states have one breach notification law. Ohio has two, and they are close enough that people cite the wrong one routinely. The split is by who you are, not by what happened.
| Businesses | Public entities | |
|---|---|---|
| Statute | ORC 1349.19 | ORC 1347.12 |
| Who it binds | Any "person" per ORC 1.59 that owns or licenses computerized data including personal information. A business entity is included only if it conducts business in Ohio. | A "state agency" per ORC 1.60, or an "agency of a political subdivision", meaning an organized body, office or agency established by a political subdivision for the exercise of any function. |
| Deadline | 45 days from discovery, division (B)(2) | 45 days from discovery, division (B)(2) |
| Notice methods and substitute notice | Division (E) | Division (E) |
| Consumer reporting agencies above 1,000 residents | Division (G) | Division (F) |
| Federal exemption | Division (F), express carve-out | Built into the definitions rather than a separate division |
| Enforcement | Division (I), Attorney General via 1349.191 and 1349.192 | Division (G), Attorney General via 1349.191 and 1349.192 |
The practical consequence of the split is smaller than it looks. The duties are substantively identical, so an incident response plan written against one will not lead you astray if you are governed by the other. What matters is that the citation in your plan, your board reporting and your notification letter is the one that actually binds you. A township whose plan cites 1349.19 is describing a statute that does not apply to it, and that is the sort of detail that gets noticed precisely when you least want the scrutiny.
One structural note worth carrying: division numbering diverges after (E). The consumer reporting agency duty is (G) for businesses and (F) for public entities, because 1349.19 spends a division on the federal exemption that 1347.12 handles inside its definitions instead. If you are copying division references between the two, check them.
What Counts as a Breach
Both statutes define a breach of the security of the system the same way: unauthorized access to and acquisition of computerized data that compromises the security or confidentiality of personal information, and that causes, is reasonably believed to have caused, or is reasonably believed will cause a material risk of identity theft or other fraud to the resident.
Read slowly, that sentence contains four separate gates, and an incident has to clear all of them before the forty-five day clock has anything to run against.
- Computerized data. The statute reaches electronic records. A filing cabinet emptied overnight is a serious problem and may trigger duties elsewhere, but it is not this statute's subject.
- Access and acquisition. Both, not either. An attacker who reached a system without taking anything from it is arguably outside the definition. This is where most of the genuine legal argument in a real incident lives, and it is exactly why forensic logging that can distinguish the two is worth paying for before you need it.
- Personal information as defined. A narrow term of art, covered in the next section. Most exposed data is not personal information under this definition.
- Material risk of identity theft or other fraud. The judgment call. It is not a rhetorical flourish attached to the end of the definition; it is a condition, and a documented, reasoned conclusion that no material risk exists is a legitimate outcome of an investigation.
There is also an express exception for good faith acquisition of personal information by your own employee or agent for your purposes, provided the information is not used for an unlawful purpose or subject to further unauthorized disclosure. An employee who pulls a report they should not have had access to has not created a notifiable breach by doing so. An employee who pulls that report and emails it to a personal account has moved outside the exception.
The practical takeaway is that "we had an incident" and "we have a notification duty" are different findings, and the distance between them is investigation. That investigation is also the thing the deadline is measured against, which is the subject of the next section but one.
Personal Information Is Narrower Than You Think
This is the definition that decides most incidents, and it is considerably narrower than the everyday meaning of the phrase. Personal information means an individual's name, meaning a first name or first initial plus a last name, in combination with at least one of the following data elements, where both the name and the element are not encrypted, redacted, or otherwise altered so as to be unreadable:
- Social security number.
- Driver's license number or state identification card number.
- Account number, or credit or debit card number, in combination with and linked to any required security code, access code, or password that would permit access to the individual's financial account.
Three consequences follow, and each one surprises somebody during an incident.
A name alone is not personal information. Neither is an email address, a phone number, a home address, a date of birth, or a mother's maiden name. A leaked customer list with names, addresses and order histories, and nothing from the list above, does not meet the definition. It may still be a reputational catastrophe and may still trigger contractual notice obligations. It does not trigger this statute.
A card number on its own is not enough either. The third element requires the account or card number plus the code or password that would permit access. Card numbers without the accompanying security credential fall outside the definition, which is a meaningful carve-out for organizations that tokenize or truncate at rest.
Encryption and redaction take you out of the definition. If the elements were genuinely unreadable, the definition is not met. Redacted is defined as truncated so that no more than the last four digits are accessible. Two cautions: encryption whose key the attacker also took is not unreadable in any useful sense, and data encrypted at rest but exposed through a live authenticated application session was readable at the moment it mattered.
Finally, both statutes exclude information lawfully made available to the general public from federal, state or local government records, and information in widely distributed media. Publicly filed data does not become notifiable because a copy of it also sat in your system.
The Forty-Five Day Clock, and What It Runs From
The operative language is identical in both statutes. Disclosure must be made in the most expedient time possible but not later than forty-five days following its discovery or notification of the breach in the security of the system, subject to the legitimate needs of law enforcement and to any measures necessary to determine the scope of the breach and restore the reasonable integrity of the system.
Four things in that sentence are worth separating out, because they get conflated in planning documents.
Discovery starts the clock, not the intrusion. An attacker resident in your network for eight months does not consume the forty-five days. The day you discover it, or the day someone else notifies you of it, is day zero.
Being told counts as discovering. The phrase is "discovery or notification". A vendor, a payment processor, a customer, or law enforcement telling you starts the same clock as your own detection. This is why a vendor contract that lets a processor sit on a finding for three weeks is a serious operational exposure and not a legal nicety.
Forty-five days is the ceiling, not the target. The primary instruction is "in the most expedient time possible". Forty-five days is the outer bound on that, not a budget you are entitled to spend. An organization that could reasonably have notified on day twelve and chose day forty-four has not obviously complied with the first clause.
Scoping and restoration are accommodated, not open-ended. The statute allows for the measures necessary to determine the scope and restore integrity. That is not a general extension. It contemplates that you cannot notify people accurately before you know who is affected.
One practical implication runs through all four: the date of discovery is a fact that somebody will eventually ask you to prove, and the answer is much easier when it was recorded contemporaneously in a ticket, an alert, or an incident log than when it is reconstructed months later from memory and email timestamps. Writing down the moment you learned of something is close to zero-cost at the time and disproportionately valuable afterwards.
If your incident response plan does not currently name a person responsible for stamping the discovery date, that is the cheapest improvement available to it. Our walkthrough of an Ohio incident response plan covers where that fits alongside the rest of the sequence.
The Law Enforcement Delay Is Narrower Than It Sounds
Division (D) of both statutes permits delay where a law enforcement agency determines that disclosure or notification will impede a criminal investigation or jeopardize homeland or national security. When that happens, notification is made after the agency determines that it will no longer compromise the investigation or the security concern.
Two features of that provision routinely get missed. The determination is the agency's, not yours. Reporting an incident to the FBI or to a local department does not by itself pause anything; someone at that agency has to determine that disclosure would impede the investigation. And the pause lasts only as long as that determination holds, so this is a delay with a condition attached rather than an indefinite extension.
If you are relying on this division, get the determination in writing, note who made it and when, and diarise a recurring check on whether it still applies. A delay you cannot evidence is indistinguishable, after the fact, from a delay you did not have.
How Notice Has to Be Given
Division (E) of both statutes sets out the permitted methods. Three are ordinary, and two are substitute methods available only when you can demonstrate that you qualify for them.
| Method | Conditions |
|---|---|
| Written notice | Always available. The default, and the one that is easiest to evidence later. |
| Electronic notice | Available where the primary method of communication with the individual is electronic. |
| Telephone notice | Available as a method of disclosure in its own right. |
| Substitute notice, large breach | Where you demonstrate insufficient contact information, or that the cost of notice would exceed $250,000, or that the affected class exceeds 500,000 persons. |
| Substitute notice, small entity | Where you demonstrate ten employees or fewer and that the cost of notice will exceed $10,000. |
Substitute notice is not a lighter option. It is a different and in some ways heavier one, because it is public. The large-breach version requires all three of: electronic mail notice where you have an address, conspicuous posting of the notice on your website if you maintain one, and notification to major media outlets whose cumulative audience equals or exceeds seventy-five per cent of Ohio's population.
The small-entity version is more specific still, and it is the one most likely to catch a very small organization by surprise. It requires a paid advertisement in a local newspaper of general circulation, of a size covering at least one-quarter of a page, published at least once a week for three consecutive weeks, plus conspicuous posting on the entity's website if it has one, plus notification to major media outlets in its geographic area.
Read the small-entity thresholds together and the arithmetic is unforgiving: an organization with ten or fewer employees has to show that directly notifying the affected individuals would cost more than ten thousand dollars before it may substitute a quarter-page advertisement running for three weeks. For most small organizations, direct notice will be both cheaper and considerably less public. Substitute notice is an escape hatch for when contact information genuinely does not exist, not a shortcut.
Who Else Has to Be Told
Two secondary duties sit alongside the duty to residents, and both are easy to overlook in the middle of an incident because neither involves the affected individuals.
Consumer reporting agencies, above one thousand residents. If the breach requires notification to more than one thousand Ohio residents, you must also notify all nationwide consumer reporting agencies, without unreasonable delay, of the timing, distribution and content of the notices. This is ORC 1349.19 division (G) for businesses and ORC 1347.12 division (F) for public entities. Note what it is: a notification about the notices, so the agencies know what is arriving and when. It does not substitute for anything, and it does not require you to send them the affected individuals' data.
The custodian duty, division (C). If you maintain or store computerized data that you do not own or license, and you discover a breach of it, you must notify the owner or licensee of the data in an expeditious manner. This is the provision that binds hosting providers, managed service providers, payroll processors and anyone else holding somebody else's records.
Division (C) is worth reading from both ends of the relationship. If you hold data for clients, it is a statutory duty running from you to them. If your data sits with vendors, it is a duty running to you, and "expeditious" is doing a lot of unspecified work in that sentence. Your contracts are the place to convert it into a number, because your own forty-five day clock starts the moment they tell you and not a day later.
Who Is Exempt, and How Far the Exemption Reaches
ORC 1349.19 division (F) carves out two categories. The first is a person already required by federal law or regulation to notify customers of an information security breach, who maintains procedures for that purpose under the applicable federal regime and notifies in accordance with it. In practice that is the Gramm-Leach-Bliley path for financial institutions. The second is a person who is a covered entity as defined in 45 C.F.R. 160.103, which is the HIPAA definition.
ORC 1347.12 reaches the same result by a different route. Rather than a standalone exemption division, it writes the exclusion into the definitions themselves: a covered entity under 45 C.F.R. 160.103 is not a "state agency" and not an "agency of a political subdivision" for the purposes of that section. A county hospital and a county auditor are treated differently by the same statute for this reason.
The exemption follows the data, not the letterhead. Being a covered entity does not make an organization exempt for everything it holds. Protected health information is covered by HIPAA's own notification regime. Employee payroll files, donor records, vendor banking details and the human resources system are generally not protected health information, and a breach confined to those records does not become exempt because the organization is a covered entity for other purposes. The same logic applies to a financial institution's non-GLBA data.
If you are relying on an exemption, the useful exercise is to write down which systems it actually covers and which it does not, before an incident forces the question. Organizations that discover mid-incident that their exemption is narrower than assumed lose days they cannot get back.
What a Late Notification Costs
Enforcement of both statutes runs through ORC 1349.191 and 1349.192. The Attorney General has exclusive authority to bring a civil action in a court of common pleas, seeking a temporary restraining order, a preliminary or permanent injunction, and civil penalties. There is no private right of action attached to these sections, so the exposure here is regulatory rather than a new avenue for plaintiffs.
The civil penalties are structured per day of non-compliance and escalate in three tiers:
| Period of non-compliance | Maximum civil penalty |
|---|---|
| Each day during the first 60 days | Up to $1,000 per day |
| Each day from day 61 through day 90 | Up to $5,000 per day |
| Each day beyond day 90 | Up to $10,000 per day |
A defendant may also be ordered to reimburse the Attorney General's costs of investigating and bringing the action, and penalties are paid into the consumer protection enforcement fund. The court weighs the circumstances in setting an amount within these ranges, including whether the responsible officials acted in bad faith, so these are ceilings rather than schedules.
The shape of the tiers is the point. The cost of lateness is not a fixed fine you can price into a decision; it compounds, and it compounds faster the longer the delay runs. An organization that is going to be late is materially better off being late by a week than by a quarter, which is an argument for notifying on the information you have rather than waiting for an investigation to reach a level of certainty the statute never asked for.
What to Settle Before You Need Any of This
Everything above is decided under time pressure unless it was decided in advance. Six items are worth settling while nothing is happening, and none of them requires a budget cycle.
1. Name the statute that binds you, in writing
One line in the incident response plan. ORC 1349.19 if you are a business, ORC 1347.12 if you are a state agency or an agency of a political subdivision. If you are a covered entity under 45 C.F.R. 160.103, write down which of your systems that actually covers.
2. Assign the discovery timestamp to a person
Someone owns recording the date and time you learned of an incident, and where that record lives. It is the single most consequential fact in any later review and the easiest one to lose.
3. Know where the three data elements live
Social security numbers, driver's license and state ID numbers, and account or card numbers with their access credentials. If you cannot say which systems hold them, you cannot scope a breach quickly, and scoping is what the forty-five days is mostly spent on. A recurring scan and inventory is the usual route to that answer.
4. Put a number on your vendors' "expeditious"
Division (C) obliges a custodian to tell you expeditiously. Your contracts should convert that into a specific number of hours, because their delay consumes your deadline.
5. Make sure your logs can separate access from acquisition
The definition turns on both being present. Telemetry that shows a session but not what left the building forces you to assume the worst, and assuming the worst means notifying people you might not have had to notify.
6. Draft the notification letter now
A template written calmly, reviewed by counsel once, and left in the plan is worth more than a perfect letter drafted on day forty. Leave the facts blank and settle the structure.
None of this reduces the chance of a breach. What it does is convert the forty-five days from a scramble into a sequence, and reduce the number of decisions being made for the first time by people who have not slept.
Frequently Asked Questions
How long do you have to report a data breach in Ohio?
Forty-five days from discovery or notification, under ORC 1349.19 division (B)(2) for businesses and ORC 1347.12 division (B)(2) for public entities. The statute's primary instruction is to disclose in the most expedient time possible, with forty-five days as the outer limit, subject to the legitimate needs of law enforcement and the measures needed to determine scope and restore system integrity.
Does Ohio require notifying the Attorney General of a breach?
Neither section requires a routine filing with the Attorney General the way some states do. The Attorney General's role in these sections is enforcement: investigating and bringing a civil action under ORC 1349.191 and 1349.192 where there is an alleged failure to comply. The mandatory secondary notification is to the nationwide consumer reporting agencies, and only above one thousand affected Ohio residents.
Do we have to notify if we cannot tell whether data was taken?
The duty attaches to unauthorized access and acquisition causing a material risk of identity theft or other fraud. If your evidence cannot rule acquisition out, you are making a risk judgment rather than reading a clear answer off the statute, and that judgment should be documented with the reasoning and the evidence it rested on. The practical answer for most organizations is that thin telemetry pushes you toward notifying, which is one of the strongest operational arguments for better logging.
Does a ransomware attack always trigger Ohio notification?
Not automatically. Encryption of your systems by an attacker is not by itself acquisition of personal information. Modern ransomware operations usually exfiltrate before encrypting, and where they did, the definition is met. The question to answer is whether personal information as defined was both accessed and acquired, and whether that creates a material risk of identity theft or other fraud, not whether the incident was disruptive.
Does ORC 1354's safe harbor help with a notification failure?
No. ORC 1354 provides an affirmative defense to tort claims alleging that inadequate security controls caused a breach. It says nothing about notification timing and expressly does not relieve anyone of the duties in these sections. A business can hold an impeccable recognized cybersecurity program and still face an Attorney General action for notifying late.
What about residents of other states?
These sections govern notification to Ohio residents. Nearly every other state has its own breach notification statute with its own definitions, deadlines and regulator filing requirements, and several are shorter than forty-five days. If your affected population crosses state lines, Ohio's deadline is one input into the schedule rather than the schedule itself.
Could You Prove the Date You Found Out?
Bullium helps Ohio businesses and public entities get the parts of this decided before an incident forces them: where the regulated data elements actually live, whether your logging can separate access from acquisition, what your vendor contracts commit to, and what your incident response plan says on the day it gets used. We will review what you have and tell you plainly where the gaps are. No commitment to engage further.
Related Reading
ORC 1354 Cybersecurity Safe Harbor
The other half of the pair: what Ohio offers a business in exchange for a written cybersecurity program, and why it does not touch these deadlines.
ORC 9.64 Cybersecurity Compliance
The readiness obligation on Ohio political subdivisions, whose program requirements are what a 1347.12 notification will be judged against.
Incident Response Plan for Ohio Public Entities
Where the discovery timestamp, the scoping work and the notification decision fit in the wider sequence.
The First Hours After a Breach
What a small business should do in the hours before any of these deadlines become the main question.
Cyber Insurance Requirements for 2026
Notification costs are the line item most policies actually pay out on, and the controls underwriters ask about are the ones that shorten an investigation.
Backup and Disaster Recovery for Ohio Entities
Restoring the reasonable integrity of the system is one of the two things the statute lets you take time for. Being able to do it quickly shortens the clock.
Related Services
Security Consulting
Incident response planning, data mapping, and the notification decision tree written down before you need it.
Network Assessment
Finding where the regulated data elements actually live, which is what scoping a breach depends on.
Managed IT Services
Monitoring and log retention that can tell access apart from acquisition when the answer matters.
Business Continuity
Restoring the reasonable integrity of a system, tested in advance rather than during the forty-five days.