Nonpartisan civic infrastructure
AllCiv·Legis1
·

HB 4055

BillStateORHouse
Relating to information security; declaring an emergency.
About This Bill
Latest Action · Mar 7, 2026
In committee upon adjournment.
Session
2026R1
Introduced
Feb 2, 2026

Summary

Highlight any text to annotate
Requires a local government, local service district or special government body to notify and submit a report to the State Chief Information Officer within 48 hours of an information security incident or ransomware incident. Prescribes the information that a public body is required to report. Directs the State Chief Information Officer to establish a reporting system that allows a public body to submit a notification or report in a timely, secure and confidential manner. Directs the State Chief Information Officer to create a webpage to provide instructions on how to provide notification and submit a report. Requires the State Chief Information Officer to provide an annual report to the Governor and the Joint Legislative Committee on Information Management and Technology on the information security incidents and ransomware incidents reported for the preceding year. Exempts information security incident or ransomware incident reports from disclosure under public records laws and allows for the sharing of information under certain circumstances. Becomes operative July 1, 2026. Declares an emergency, effective on passage.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight the summary on the Overview tab to attach a note. Annotations appear on the Annotations tab.