Oklahoma 2023 Regular Session

Oklahoma House Bill HB2790

Introduced
2/6/23  
Refer
2/7/23  
Report Pass
3/2/23  
Engrossed
3/23/23  
Refer
3/30/23  
Report Pass
4/13/23  
Enrolled
4/20/23  

Caption

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.

Impact

The bill aims to fortify the data protection capabilities of hospitals across Oklahoma, ensuring they have a robust cybersecurity structure in place to mitigate risks associated with unauthorized access to sensitive data. By promoting compliance with industry-recognized standards, the act seeks to improve overall data integrity and security for patient information. If hospitals establish and adhere to a viable cybersecurity program, they could potentially shield themselves from legal repercussions if a data breach occurs, thus encouraging proactive measures for information security.

Summary

House Bill 2790, titled the Oklahoma Hospital Cybersecurity Protection Act of 2023, establishes a framework to enhance cybersecurity measures within hospitals. The bill lays out clear definitions for key terms, such as 'covered entity' referring to hospitals and provides a roadmap for these entities to implement a written cybersecurity program. This program must include administrative, technical, and physical safeguards that conform to recognized cybersecurity frameworks. The legislation underscores the necessity for hospitals to protect personal and restricted information from breaches, defining what constitutes a data breach and outlining the conditions under which hospitals may seek an affirmative defense in tort claims resulting from such breaches.

Sentiment

General sentiment around HB 2790 is largely positive, particularly among healthcare professionals who recognize the crucial need for enhanced protection of sensitive patient data. Supporters view the legislation as a necessary step to bolster hospital cybersecurity and uphold patient confidence. However, there may be concerns regarding the feasibility of compliance, particularly for smaller, less-resourced healthcare institutions, which could struggle to meet the rigorous requirements outlined in the legislation. Discussions among legislators reflect a commitment to safeguarding patient information while also ensuring that the obligations placed on healthcare entities are attainable.

Contention

While HB 2790 is positioned as a protective measure, stakeholders may debate the balance between state-mandated regulations and the operational independence of hospitals. Some critics may argue that the requirements for cybersecurity compliance could strain resources, particularly in rural areas where hospitals operate on tight budgets. Moreover, there could be discussions around the adequacy of the affirmative defense clause, as the burden of proof falls on the hospitals to demonstrate compliance with the defined cybersecurity frameworks. Thus, while the intent is protective, the implications of these requirements could lead to further debates around accountability and resource allocation in Oklahoma's healthcare sector.

Companion Bills

No companion bills found.

Previously Filed As

OK HB2790

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.

OK HF553

A bill for an act relating to affirmative defenses for entities using cybersecurity programs. (Formerly HSB 154.) Effective date: 07/01/2023.

OK SF495

A bill for an act relating to affirmative defenses for entities using cybersecurity programs.(Formerly SSB 1095.)

OK SSB1095

A bill for an act relating to affirmative defenses for entities using cybersecurity programs and electronic transactions recorded by blockchain technology.(See SF 495.)

OK HB4081

CYBERSECURITY COMPLIANCE ACT

OK SB973

Civil Actions - Affirmative Defenses - Business Data Breaches

OK HSB154

A bill for an act relating to the use of certain technology, including the legal effect of the use of distributed ledger technology or smart contracts and affirmative defenses associated with the use of cybersecurity programs.(See HF 553.)

OK HB1799

Cybersecurity; Cybersecurity Act of 2025; effective date.

OK HB1801

Cybersecurity; Cybersecurity Act of 2025; effective date.

OK HB1802

Cybersecurity; Cybersecurity Act of 2025; effective date.

Similar Bills

OK HB1983

Schools; media literacy and cybersecurity to be taught in sixth, seventh, or eighth grades; State Department of Education to adopt curriculum standards; effective date.

OK SB543

Insurance; creating the Insurance Data Security Act. Effective date. Emergency.

OK SB543

Insurance; creating the Insurance Data Security Act. Effective date.

OK HB2790

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.