HB 492 Utah House · 2025 General Session

Drinking Water Utilities Amendments

HB 492 requires community water systems serving 10,000 or more people to create security plans by December 2025 (and annually after), while smaller systems must do so by July 2026. It mandates reporting security breaches to the Utah Cyber Center within two hours and includes specific requirements for updating software, training staff, and conducting vulnerability assessments. The bill classifies security plans as protected records and requires annual reports to legislative committees on security practices. These changes apply directly to water utility providers, not the public, and involve no new state funding.
Bill status passed 3 of 4 stages cleared
Introduction
Feb 2025
Committee Review
Mar 2025
Senate Passage
Feb 2025
Governor
Introduced Feb 13, 2025 Last action Mar 8, 2025
Maddy AI version diff · 1 comparison

What changed between versions

Introduced Substitute #1 · 6 edits
MODERATE
This bill substitutes a new version of HB 492 that strengthens security requirements for drinking water systems in Utah. The main changes include clarifying definitions for security terms, establishing specific timelines for security plan completion based on population size, requiring breach reporting within two hours, and designating security plans as protected records. The bill also maintains the requirement for annual security reports to legislative committees.
Scope change
The bill's scope remains focused on drinking water facility security, but the substitute version clarifies the population thresholds (10,000 or greater vs. less than 10,000) for when security plans must be completed and adds specific cybersecurity requirements to the security plan.
DEFINITION

Added clear definitions for 'authorized employee,' 'control system,' 'operational technology,' and 'secure area' to establish what systems and personnel are covered by security requirements.

REQUIREMENT

Added specific cybersecurity requirements including software updates, secure passwords, annual cybersecurity training, internal vulnerability assessments, and procedures for removing access when employees leave.

TIMELINE

Established staggered deadlines for security plan completion: systems serving 10,000+ people must complete plans by July 1, 2025, while smaller systems have until July 1, 2026.

ENFORCEMENT

Added requirement to report security breaches to the Utah Cyber Center within two hours of discovery, with the center required to notify the Division of Drinking Water within one day.

TECHNICAL

Added Section 63G-2-305 to classify community water system security plans as protected records, preventing public disclosure of sensitive security information.

Removed a study requirement about water provider efficiencies that was in the original version, focusing instead on the security plan implementation.

Floor votes

How they voted

This bill passed the Senate by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
25
Key actions
3
Committee
4
Mar 1, 2025
Upper · Passed
Senate Comm - Favorable Recommendation
upper
Feb 26, 2025
Committee
Senate/ to standing committee
upper
Feb 24, 2025
Introduced
Senate/ 1st reading (Introduced)
upper
Feb 24, 2025
Upper · Passed
House/ passed 3rd reading
upper
Feb 20, 2025
Lower · Passed
House Comm - Favorable Recommendation
lower
Feb 18, 2025
Committee
House/ to standing committee
lower
Feb 13, 2025
Introduced
House/ 1st reading (Introduced)
lower
1 primary · 1 co-sponsor

Sponsors