Law / United States / Oregon
Security requirements for Internet-connected devices
ORS 646A.813 (added by 2019 c.193 (H.B. 2395-A) sec. 1; amending ORS 646.607)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A product security requirements rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds a manufacturer, a person that makes a connected device and sells or offers to sell it in Oregon; a connected device is a physical object, used primarily for personal, family or household purposes, that connects directly or indirectly to the Internet or is assigned an address for making a short-range wireless connection. It does not by itself reach a developer who ships only software or an app with no connected device of its own, and it imposes no duty on the manufacturer for software, firmware or peripheral devices that another manufacturer makes and a consumer later installs on the device.
- Equip the connected device with reasonable security features appropriate to its nature, function and the information it may collect, store or transmit, satisfied by giving each device a unique preprogrammed authentication credential or by requiring the user to generate new credentials before first use, or by complying with an applicable federal security requirement for connected devices.
- The duty does not apply where a consumer installs unapproved software or devices that disable or modify the device's own security features, to a HIPAA-covered entity or business associate as to an activity HIPAA regulates, or to a device whose functions already comply with Food and Drug Administration medical-device requirements.
- A violation is an unlawful trade practice under ORS 646.607, enforceable by the Attorney General or a district attorney by injunction, carrying a civil penalty of up to $25,000 for a willful violation; Oregon's private right of action for unlawful trade practices reaches only a practice declared unlawful under the separate ORS 646.608, so this duty carries no private remedy of its own.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
The $25,000-per-violation civil penalty is ORS 646.642(3), the Unlawful Trade Practices Act's general civil-penalty provision, not an amount stated in ORS 646A.813 itself, and requires a court finding that the violation was willful; it is recoverable only by the Attorney General or a district attorney petitioning the court in a suit brought under ORS 646.632.
- Rule
- Per violation only
- As of
- 12 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 25,000
Who enforces it
Enforcement body
The Attorney General or a district attorney (Oregon's “prosecuting attorney”) may sue to enjoin a violation under ORS 646.632; the section names no dedicated regulator of its own and creates no private right of action.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A manufacturer, a person that makes a connected device and sells or offers to sell it in Oregon, must equip the device with reasonable security features: a preprogrammed authentication credential unique to each unit, or a requirement that the user generate new credentials before first use, or compliance with an applicable federal security requirement for connected devices.
A connected device is limited, under the section's own definition, to a physical object used primarily for personal, family or household purposes that connects to the Internet or is assigned an address for a short-range wireless connection.
The section expressly imposes no duty on the manufacturer for software, firmware or peripheral devices that another manufacturer makes and a consumer later installs or adds, so it does not by itself reach a developer who ships only software or an app with no connected device of its own. It also exempts a device already regulated as to the relevant activity under HIPAA, or already subject to Food and Drug Administration medical-device requirements.
It imposes no verification duty on an app store or marketplace. A violation is declared an unlawful trade practice under ORS 646.607, enforceable only by the Attorney General or a district attorney by injunction and a civil penalty of up to $25,000 per willful violation. Oregon's general private right of action for unlawful trade practices, ORS 646.638, reaches only a practice declared unlawful under the separate ORS 646.608, so a violation of this section carries no private remedy of its own.
The enacted bill carries no operative-date or emergency clause of its own, so the section took effect under Oregon's constitutional default rule, ninety-one days after the 2019 regular session adjourned; no source located states that calendar day, so no day-precise effective date is recorded here.
When LexLint raises it
distributes_software_product
Read the law
Official statute text, Oregon Revised Statutes, ORS chapter 646A