ARTICLE
14 August 2023

Iowa Joins Growing List To Offer Potential Safe Harbor For Companies With Security Programs

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
Iowa recently became the fifth state to offer businesses a safe harbor if they have a written cybersecurity program.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Iowa recently became the fifth state to offer businesses a safe harbor if they have a written cybersecurity program. Others are Connecticut (October 1, 2021), Ohio (effective November 2, 2018), Oregon (effective January 1, 2020), and Utah (effective March 5, 2021). Like these, as of July 1, 2023, businesses that have a written cybersecurity program and suffer a breach may have an affirmative defense in Iowa against tort claims for inadequate security measures.

To take advantage of the safe harbor, the company must have a written cybersecurity program that contains certain elements. The program must, inter alia:

  • Evaluate and mitigate anticipated risks on a continual basis
  • Be of an appropriate scope and scale, measured by it costing "no less than [the company's] most recently calculated maximum probable loss value"
  • Assess -at least annually- the potential maximum probable loss from a breach
  • In the event of a breach, provide that the company will tell impacted parties what steps they can take "to reduce any damages"

These elements mirror those expected under other state safe harbor laws, but are more detailed than we have seen in the past. Program that reasonably conform to an industry recognized cybersecurity framework will be deemed to have a qualifying program.1 These industry programs include the NIST Cybersecurity Framework, FedRAMP and ISO/IEC 2700. Businesses regulated by -and adhering to- several well-known laws will also be viewed as having a sufficient program. These include both HIPAA And GLBA.

Putting it into Practice: Iowa's safe harbor law picks up from similar provisions last passed by a state in 2021 (Connecticut). As the cost of breach-related lawsuits continues to rise, these provisions can offer some comfort to companies. We will be watching to see if other states begin incorporating similar provisions in their breach notice laws.

Footnote

1 554G.3(1).

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

ARTICLE
14 August 2023

Iowa Joins Growing List To Offer Potential Safe Harbor For Companies With Security Programs

United States Technology

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More