Iowa 2023-2024 Regular Session

Iowa House Bill HF554

Introduced
3/2/23  
Refer
5/4/23  
Introduced
3/2/23  

Caption

A bill for an act prohibiting the state or a political subdivision of the state from expending revenue received from taxpayers for payment to persons responsible for ransomware attacks, and including effective date provisions.(Formerly HSB 153.)

Impact

This bill establishes a framework requiring immediate reporting of ransomware attacks to the office of the chief information officer. It stipulates that while taxpayer funds cannot be expended to directly pay off ransomware demands, under emergency circumstances defined by the department of homeland security and emergency management, exceptions may allow for such payments with appropriate notification. This introduces a nuanced approach to crisis management, emphasizing accountability while providing mechanisms to respond effectively in critical situations.

Summary

House File 554 aims to address the growing threat of ransomware attacks by prohibiting the state and its political subdivisions from using taxpayer revenues to make payments to individuals or entities involved in such attacks. The bill seeks to enhance financial accountability and encourage preventive measures against ransomware threats. By enacting this legislation, the state intends to deter payment demands from malicious actors, thus limiting the potential financial losses to public funds and ensuring responsible management of taxpayer money in the face of cybersecurity risks.

Contention

Notable points of contention surrounding HF554 include the tension between maintaining strict prohibitions against ransom payments and the need for flexibility in emergency scenarios. Critics may argue that the inability to use taxpayer dollars for ransom payments, even in life-threatening situations involving critical infrastructure, could leave entities vulnerable and without sufficient recourse. The legislative intent highlights the necessity for well-tested cybersecurity strategies, prompting discussions about what constitutes an effective and flexible policy that balances security, fiscal responsibility, and emergency responsiveness.

Companion Bills

IA HSB153

Related A bill for an act prohibiting the state or a political subdivision of the state from expending revenue received from taxpayers for payment to persons responsible for ransomware attacks, and including effective date provisions.(See HF 554.)

Previously Filed As

IA HSB153

A bill for an act prohibiting the state or a political subdivision of the state from expending revenue received from taxpayers for payment to persons responsible for ransomware attacks, and including effective date provisions.(See HF 554.)

IA HF2710

A bill for an act relating to the duties and responsibilities of the department of revenue including sports wagering, the lottery, cigarette and tobacco taxes, alcoholic beverages, and including effective date provisions.(Formerly HSB 723.)

IA HF143

A bill for an act relating to ransomware and providing penalties. (Formerly HSB 13.) Effective date: 07/01/2023.

IA HF346

A bill for an act relating to consumer data protection, providing civil penalties, and including effective date provisions.(Formerly HSB 12.)

IA HF451

A bill for an act prohibiting the state or a political subdivision of the state from entering into contracts with, or providing tax incentives or specified benefits to, certain companies that censor online content, and including effective date and applicability provisions.

IA HF715

A bill for an act relating to state and local finance and the administration of the tax and related laws by the department of revenue, and including effective date, applicability, and retroactive applicability provisions.(Formerly HSB 187.)

IA HF856

A bill for an act prohibiting public entities from engaging in certain activities relating to diversity, equity, and inclusion, creating a private cause of action, and including effective date provisions. (Formerly HSB 155.) Effective date: 05/27/2025, 07/01/2025.

IA SF2427

A bill for an act relating to the duties and responsibilities of the department of revenue including sports wagering, the lottery, cigarette and tobacco taxes, alcoholic beverages, and including effective date provisions. (Formerly SSB 3179.)

IA HF688

A bill for an act concerning the state rulemaking process, related matters pertaining to agency functions, and including effective date provisions. (Formerly HSB 81.) Effective date: 07/01/2023, 01/01/2024.

IA HF794

A bill for an act relating to state income tax withholdings on winnings from sports wagering, and including effective date provisions.(Formerly HSB 91.)

Similar Bills

IL SB1740

RANSOMWARE ATTACK ACT

IA HSB153

A bill for an act prohibiting the state or a political subdivision of the state from expending revenue received from taxpayers for payment to persons responsible for ransomware attacks, and including effective date provisions.(See HF 554.)

CA SB500

Extortion.

AZ HB2145

Governmental entities; ransomware payment; prohibition

WV SB520

Increasing financial penalties for ransomware attacks

FL H7055

Cybersecurity

WV HB4498

Increasing the financial penalties in regard to ransomware attacks

GA HB886

State government; prohibit state agencies and local government entities from responding to ransomware activity