HB 436 Missouri House · 2025 Regular Session

Establishes cybersecurity and informational security standards to safeguard insurance company customer information

HB 436 establishes mandatory cybersecurity standards for insurance companies licensed to operate in Missouri, directly affecting all such insurers handling customer data. The bill requires insurers to develop written security programs based on risk assessments, including specific safeguards for sensitive customer information like Social Security numbers, health records, financial account details, and biometric data. Key provisions mandate multi-factor authentication for access, regular threat assessments, and protocols for responding to cybersecurity incidents. Insurers must also define data retention and secure destruction practices, with no private legal claims allowed for violations. The law sets the exclusive state standard for data security, overriding conflicting local rules but not impacting existing private lawsuits.
Bill status in committee 1 of 4 stages cleared
Introduction
Dec 2024
Committee Review
Floor Vote
Governor
Introduced Dec 6, 2024 Last action May 6, 2025
Maddy AI version diff · 1 comparison

What changed between versions

Introduced House Committee Substitute · 2 edits
MINOR
The bill was amended from its original introduction to a House Committee Substitute version, primarily updating administrative details and refining the definition of a cybersecurity event. The Chief Clerk's name was changed from Dana Rademan Miller to Joseph Engler, and the bill identifier was updated to reflect its committee substitute status. Most notably, the definition of a 'cybersecurity event' was narrowed by adding the word 'malicious' before 'disruption', which limits the scope of the definition to intentional attacks rather than accidental system failures.
Scope change
The scope of the bill was narrowed by requiring that a cybersecurity event involve 'malicious' disruption, excluding accidental or non-malicious system disruptions from the definition.
DEFINITION

The definition of 'cybersecurity event' was modified to specify that the disruption must be 'malicious', narrowing the definition to exclude accidental or non-malicious system disruptions.

TECHNICAL

Administrative details were updated, including changing the Chief Clerk's name from Dana Rademan Miller to Joseph Engler and updating the bill identifier to HCS HB 436 to reflect its status as a House Committee Substitute.

Floor votes

How they voted

No floor votes recorded yet.
Full legislative history

Actions timeline

Total actions
18
Key actions
4
Committee
6
Mar 12, 2025
Lower · Passed
Reported Do Pass (H) - AYES: 10 NOES: 0 PRESENT: 0
lower
Mar 12, 2025
Lower · Passed
Voted Do Pass (H)
lower
Mar 5, 2025
Committee
Referred: Rules - Legislative(H)
lower
Feb 25, 2025
Lower · Passed
HCS Reported Do Pass (H) - AYES: 12 NOES: 0 PRESENT: 0
lower
Feb 24, 2025
Lower · Passed
HCS Voted Do Pass (H)
lower
Feb 6, 2025
Committee
Referred: Insurance(H)
lower
Dec 6, 2024
Introduced
Prefiled (H)
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Bill Hardwick
Bill Hardwick
RRepublican
MO
121