Indiana's private-sector security-topic presence is a single standalone duty sitting inside its breach-notification statute: Ind.
Code sec. 24-4.9-3-3.5, added to the Disclosure of Security Breach Act by P.L.137-2009 and amended by P.L.76-2017, requires a 'data base owner' (a person that owns or licenses computerized data including personal information of an Indiana resident) to implement and maintain reasonable procedures to protect and safeguard that personal information from unlawful use or disclosure, and to dispose of records containing it only by shredding, incinerating, mutilating, erasing, or otherwise rendering it illegible.
A data base owner already following its own compliance plan under a named federal privacy or security regime (the USA PATRIOT Act, Executive Order 13224, the Driver's Privacy Protection Act, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or Health Insurance Portability and Accountability Act (HIPAA)) is exempt from this duty, except that a current or former health care provider that claimed the HIPAA-based exemption remains bound for personal information, including health records, if its own compliance plan does not require, or is not implemented to provide, that protection once the provider stops being a HIPAA covered entity.
Indiana's codified history notes for this section carry only a public-law-and-year citation with no day-precise commencement date, so no effective date is recorded here, the same source-quality gap this jurisdiction's privacy-topic row records for the surrounding breach-notification sections. The duty sits structurally the same way New York's SHIELD Act splits across two topics: the Disclosure of Security Breach Act's title and its notification sections (Ind.
Code secs. 24-4.9-3-1 through 24-4.9-3-4, 24-4.9-4-1, 24-4.9-4-2) are already this jurisdiction's privacy-topic row, a breach-notification duty about personal data, while section 3-3.5's safeguards and disposal duty is a standalone security-programme provision inside that same article, so it is filed here instead. The Indiana Consumer Data Protection Act's own security clause, Ind.
Code sec. 24-15-4-1(3), requiring a controller to establish, implement, and maintain reasonable administrative, technical, and physical data security practices appropriate to the volume and nature of the personal data at issue, is likewise not repeated here: it is one subsection of INCDPA's own controller-duties chapter, the same shape as the General Data Protection Regulation's Article 32 and the Texas Data Privacy and Security Act's section 541.101(a)(2), and it is already researched as part of this jurisdiction's privacy-topic INCDPA row.
No enacted Indiana statute was located that sets security requirements a connected device or software product must meet before or after it reaches the market, comparable to California's, Oregon's, or Connecticut's connected-device statutes or the Cyber Resilience Act; a targeted search for an Indiana connected-device or IoT security law returned no citable statutory text on the Indiana General Assembly's or Justia's own Indiana Code pages, only unsourced secondary summaries that are not relied on for this finding, so it is treated as a researched absence rather than a gap in coverage.
Indiana has no general private-sector duty to report an exploited vulnerability or a security incident to an authority or to users: the state's only cyber-incident-reporting statute, enacted in 2021 and administered through the Indiana Office of Technology's IN-ISAC, binds only a political subdivision of Indiana state government to a 48-hour reporting duty, outside this profile's private-sector scope, and 2025's Senate Enrolled Act 472, effective July 1, 2025, likewise requires only a public entity's own technology-resources and cybersecurity policies, so neither is recorded as an instrument here.
Indiana's Insurance Data Security Law, Ind.
Code sec. 27-2-27 (P.L.130-2020, applicable after June 30, 2021), requires a 'licensee,' any person licensed, authorized to operate, or registered, or required to be, under Indiana's insurance title, to develop, implement, and maintain a comprehensive written information security program and to notify the insurance commissioner of a cybersecurity event, with an exemption for a licensee under 50 employees, under $5,000,000 in gross annual revenue, or under $10,000,000 in year-end total assets, no private right of action, and an affirmative tort defense for a compliant licensee; because it binds only an insurance-title licensee, a bound-party class no activity in the LexLint vocabulary expresses, it is recorded here rather than flagged on a guess or filed as an instrument.
Section 3.5 is enforced solely by the Indiana Attorney General as a deceptive act, with a civil penalty of up to $5,000 per deceptive act (a related series of acts or omissions counts as one), and it creates no private right of action, distinct from the $150,000-per-act penalty that governs a failure of the article's own breach-notification duty.