SB 1989 expands contribution options for Oklahoma's 529 College Savings Plan by explicitly permitting digital payments through peer-to-peer apps and digital networks, in addition to cash. This change directly affects anyone contributing to the plan, including parents, students, or others saving for qualified higher education expenses. The bill updates the statute (70 O.S. 2021, Section 3970.7) to clarify that contributions may now be made via these digital methods. The amendment does not alter savings limits, tax treatment, or other program rules, focusing solely on expanding how funds can be deposited.
SB 325 allows Oklahoma state employees and private vendors to choose Bitcoin as payment for salaries or transactions. Employees must agree in writing on whether Bitcoin payments use market value at pay period start or end, and payments must go to a secure digital wallet controlled by the recipient. The State Treasurer must select a payment processor by January 2026 and contract with them, while the Tax Commission must issue tax guidance on digital asset payments by the same date. The bill takes effect November 1, 2025.
SB 1083 requires digital asset kiosks (physical terminals for exchanging cryptocurrencies or digital assets for cash) to operate under a money transmitter license in Oklahoma. It mandates kiosk operators to report locations to the Banking Department quarterly, disclose clear warnings about irreversible transactions and scams (including specific fraud alerts), and display risk information like "losses are not recoverable." The law prohibits unlicensed operation, with fines up to $2,000 per violation or jail time, and allows customers harmed by unlicensed kiosks to sue for losses. It directly affects kiosk businesses and users engaging in digital asset transactions at these terminals.
SB 626, the Security Breach Notification Act, requires businesses to notify Oklahomans when specific personal data used to verify identity (like Social Security numbers or account credentials) is compromised in a security breach. This law directly affects businesses and organizations that collect or store such identifying information, including credit bureaus, healthcare providers, and financial institutions. The key provision clarifies that notifications are mandated only when data enabling authentication of an individual is breached, not for all types of data. The law became effective on May 28, 2025, without the Governor's signature.
HB 1179 requires Oklahoma public and charter school staff to include a student’s parent, legal guardian, or designated "alternate adult" (such as a homeless shelter case manager for homeless students) in all electronic or digital communications about the student, unless the communication occurs on a school-approved platform for academic purposes. Exceptions apply for emergencies, but schools must later notify the parent or guardian. Schools must train staff on these rules by July 2025, and staff who violate the policy face administrative leave during investigation, with possible discipline up to termination if misconduct is found. The bill directly affects school personnel, students, and families, particularly those supporting homeless youth.
SB 410 requires Oklahoma public high school students in grades 8-12 to complete a computer science unit to earn a standard diploma starting with the 2024-2025 school year. This replaces the previous requirement for two world language units with a new computer technology course requirement covering programming, hardware, and business applications like spreadsheets. The bill mandates that this unit must be approved for college admission and excludes basic keyboarding or typing courses. It directly affects all students pursuing standard diplomas in Oklahoma public high schools under the updated graduation requirements.
SB 567 allows patients in Oklahoma to request that healthcare providers or covered entities restrict the disclosure of certain protected health information, such as details about treatment, payment, or health care operations, and personal details like Social Security numbers or financial data. It applies to all healthcare providers, hospitals, and insurance companies covered under federal privacy rules (HIPAA). Patients can specifically ask for limits on sharing information with family members, other providers, or for billing purposes. The bill takes effect November 1, 2025.
SB 910, the Military Installation and Critical Infrastructure Protection Act of 2025, prohibits foreign principals from countries designated as "foreign adversaries" (by the U.S. Secretary of State) from owning, leasing, or controlling agricultural land or property near military bases. It requires companies accessing Oklahoma's critical infrastructure (like energy, water, or telecommunications systems) to certify foreign ownership status and bans certain foreign software from state infrastructure systems. The bill establishes registration requirements, mandates the Attorney General to enforce compliance through court actions, and creates whistleblower rewards for reporting violations, with proceeds from forfeited property funding enforcement efforts.
SB 1229 requires Oklahoma's Service Oklahoma to store specific personal information - including full name, date of birth, biometric photos, address, and license number - related to REAL ID Noncompliant driver license applications in a separate, secure database. The bill mandates that this data must be deleted after a specified period, with the definition of "personally identifiable information" explicitly excluding Social Security numbers. This law directly affects Oklahoma residents applying for driver licenses or identification cards, particularly those seeking non-REAL ID compliant options. The measure aims to enhance data privacy by creating strict storage and deletion protocols for sensitive applicant information.
HB 1915 establishes rules for using artificial intelligence (AI) in Oklahoma healthcare. It requires hospitals and healthcare facilities (deployers) to ensure AI devices used for diagnosis or treatment are only operated by licensed physicians (qualified end-users) who review all AI outputs for accuracy. Deployers must create quality assurance programs, document all AI use - including overrides of AI recommendations - and maintain an AI governance group with physician input. The law mandates compliance with federal FDA guidelines, tracks performance through national registries when possible, and authorizes the State Department of Health to enforce penalties for violations, effective November 2025.