HB 1380 Mississippi House · 2025 Regular Session

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

HB 1380 protects Mississippi state/local governments and commercial entities (like businesses handling personal data) from lawsuits related to cybersecurity incidents if they follow specific, nationally recognized security standards. The bill requires these entities to adopt cybersecurity programs aligned with frameworks such as NIST, HIPAA, or ISO 27000, creating a strong legal defense against liability claims. It establishes that compliance with these standards is presumed valid unless a plaintiff proves otherwise with clear evidence. This law directly affects organizations managing sensitive data by reducing legal risks tied to data breaches while mandating adherence to established security practices. The protection applies to covered entities starting January 1, 2026.
Bill status died 4 of 5 stages cleared
Introduction
Feb 2025
Committee Review
Mar 2025
House Passage
Feb 2025
Senate Passage
Mar 2025
Governor
Introduced Feb 17, 2025 Last action Mar 31, 2025
Maddy AI version diff · 1 comparison

What changed between versions

As Introduced Current version · 6 edits
MODERATE
This bill was amended to strengthen cybersecurity protections for state and local government entities by adding a 'rebuttable presumption' against liability when they follow recognized cybersecurity standards. The changes also expanded the list of federal and industry standards that qualify for liability protection and clarified burden of proof requirements in lawsuits. Additionally, the bill was restructured to bring forward an existing state cybersecurity statute with updated requirements for enterprise security programs.
Scope change
The bill's scope was expanded to include a rebuttable presumption against liability for commercial entities that substantially align with specified cybersecurity standards, in addition to the existing immunity for state and local government entities.
REQUIREMENT

Added a rebuttable presumption against liability for commercial entities that substantially comply with recognized cybersecurity standards, shifting some burden of proof to plaintiffs in lawsuits.

Expanded the list of qualifying cybersecurity standards to include additional NIST publications, ISO/IEC 27000 series, and specific federal laws like FISMA and HITECH.

Added requirements for covered entities to update their cybersecurity programs within one year when two or more referenced standards are revised.

DEFINITION

Added clear definitions for 'cyberattack' and 'ransomware' with specific dates for reporting requirements.

TIMELINE

Changed the effective date to January 1, 2026, and set a repeal date of December 31, 2025, indicating the act is intended to be temporary.

ENFORCEMENT

Added provisions requiring state agencies to notify the Department of Information Technology Services of cyberattacks or ransomware demands within one business day.

Floor votes · Senate Mar 12, 2025 · House Feb 13, 2025

How they voted

4110
Passed
Total votes 51
Mar 12, 2025
D Democratic16
10 Yea 6 Nay
62% Yea
R Republican35
31 Yea 4 Nay
88% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
18
Key actions
6
Committee
4
Amendments
2
Mar 12, 2025
Upper · Passed
Passed As Amended
upper
Mar 12, 2025
Upper · Passed
Amended
upper
Mar 3, 2025
Upper · Passed
Title Suff Do Pass As Amended
upper
Feb 18, 2025
Committee
Referred To Judiciary, Division A;Technology
upper
Feb 17, 2025
Introduced
Transmitted To Senate
lower
Feb 13, 2025
Lower · Passed
Passed As Amended
lower
Feb 13, 2025
Lower · Passed
Amended
lower
Jan 30, 2025
Lower · Passed
Title Suff Do Pass As Amended
lower
Jan 20, 2025
Committee
Referred To Judiciary A;Technology
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Joey Hood
Joey Hood
RRepublican
MS
35