Oklahoma 2024 Regular Session

Oklahoma House Bill HB2790

Introduced
2/6/23  
Refer
2/7/23  
Report Pass
3/2/23  
Engrossed
3/23/23  
Refer
3/30/23  
Report Pass
4/13/23  
Enrolled
4/20/23  

Caption

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.

Impact

With the enactment of HB 2790, hospitals will be encouraged to develop and implement robust cybersecurity programs conforming to industry-recognized frameworks. These frameworks include security measures specified under the Health Insurance Portability and Accountability Act (HIPAA). The law also provides an affirmative defense for covered entities that fulfill certain criteria when facing legal actions regarding data breaches. This innovative approach aims to empower hospitals to take proactive measures in safeguarding sensitive information, potentially reducing the number of data breach incidents.

Summary

House Bill 2790, also known as the Oklahoma Hospital Cybersecurity Protection Act of 2023, aims to establish a regulatory framework for cybersecurity measures specifically tailored for hospitals in Oklahoma. The bill defines key terms such as 'covered entity,' which includes any hospital subject to federal regulations, and sets forth requirements that hospitals must meet to maintain strong cybersecurity protocols. The intention behind this legislation is to enhance the protection of personal information and restricted data against data breaches, thus mitigating risks associated with unauthorized access and identity theft.

Sentiment

The reception of HB 2790 appears generally positive among stakeholders, particularly those in the healthcare sector who view the legislation as a necessary step forward in addressing the growing threats posed by cyber-attacks. Advocates argue that providing clear guidelines for cybersecurity will not only protect patients' personal information but also enhance trust in healthcare providers. However, there may be a level of concern over the implementation costs and the adequacy of resources available to all hospitals, especially smaller facilities.

Contention

As the bill progresses, a notable point of contention stems from discussions about the balance between regulatory requirements and the operational burdens that may fall on smaller hospitals. Critics argue that stringent cybersecurity protocols could impose financial strains on facilities that may already be operating on tight budgets. The effectiveness of the affirmative defense provision is also under scrutiny, as some stakeholders question whether it provides sufficient protection for hospitals facing lawsuits for data breaches, particularly if their cybersecurity measures are found wanting.

Companion Bills

OK HB2790

Carry Over Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.

Previously Filed As

OK HB2790

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.

OK SB320

Cybersecurity; requiring Office of Management and Enterprise Services to track and assess cybersecurity incidents from political subdivisions. Effective date.

OK HB1030

Data privacy; Oklahoma Computer Data Privacy Act; consumer protection; civil penalties; effective date.

OK HB2853

Health care; creating the Oklahoma Rebate Pass-Through and PBM Meaningful Transparency Act of 2023; definitions; requirements; effective date.

OK SB543

Insurance; creating the Insurance Data Security Act. Effective date.

OK SB170

Oklahoma Accountancy Act; expanding definition. Effective date.

OK SB635

Oklahoma Industrial Hemp Program; requiring registration of hemp-derived cannabinoid product. Effective date.

OK HB2555

Scholarships; creating the Oklahoma Critical Industries Scholarship Program; effective date; emergency.

OK HB1792

Classification of felony offenses; creating the Oklahoma Crime Reclassification Act of 2023; effective date.

OK SB293

Hospitals; defining rural emergency hospital. Effective date.

Similar Bills

OK HB1983

Schools; media literacy and cybersecurity to be taught in sixth, seventh, or eighth grades; State Department of Education to adopt curriculum standards; effective date.

OK SB543

Insurance; creating the Insurance Data Security Act. Effective date. Emergency.

OK SB543

Insurance; creating the Insurance Data Security Act. Effective date.

OK HB2790

Cybersecurity; The Oklahoma Hospital Cybersecurity Protection Act of 2023; definitions; affirmative defense; industry framework; effective date.