HB 473 — Cybersecurity Incident Liability
Last action — Veto Message received
-
✓Introduced
-
✓In Committee
-
✓Passed House
-
✓Passed Senate
-
5To Executive
-
6Enacted
This bill died with 2024 Regular Session. It reached “To Executive” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
Signed by Governor Ron DeSantis (Republican) on June 17, 2024.
This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.
Summary
Cybersecurity Incident Liability; Provides county, municipality, other political subdivision of state, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to adopt revised frameworks, standards, laws, or regulations within specified time period; provides private cause of action is not established; provides certain failures are not evidence of negligence & do not constitute negligence per se; specifies defendant in certain actions has certain burden of proof.
Bill Text
What changed in the latest version
100 added · 130 removed100 line(s) added, 130 removed.
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473CS/HB473 2024 A bill to be entitled An act relating to cybersecurity incident liability;
providing definitions;that a county, municipality, other political subdivision of the state, commercial entity, or third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident;
providingrequiring thatcertain aentities county,to municipality,adopt othercertain politicalrevised subdivisionframeworks of the state, covered entity, or third-standards partywithin agent that complies with certain requirements is not liable in connection with a cybersecurityspecified incident;time period;
requiring covered entities and third-party agents to adopt revised frameworks, standards, laws, or regulations within a specified time period;
providing applicability;
768.401 Limitation on liability for cybersecurity incidents.— (1) AsA usedcounty inor thismunicipality section,that thesubstantially term:complies with s.
(a) "Covered entity" means a sole proprietorship, Page 1of 5 CODING:
Words strickenare deletions;
words underlined are additions.
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 partnership, corporation, trust, estate, cooperative, association, or other commercial entity.
(b) "Third-party agent" means an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity.
(2) A county or municipality that substantially complies with s.
282.3185 on a voluntary basis, is not liable in connection with a cybersecurityPage incident.1of 4 CODING:
(3) A covered entity or third-party agent that acquires, maintains, stores, processes, or uses personal information is not liable in connection with a cybersecurity incident if the covered entity or third-party agent does all of the following, as applicable:
(a) Substantially complies with s.
501.171(3)-(6), as applicable.
(b)1.
Has adopted a cybersecurity program that substantially aligns with the current version of any standards, guidelines, or regulations that implement any of the following:
a.
The National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity;
b.
NIST special publication 800-171;
c.
NIST special publications 800-53 and 800-53A;
Page 2of 5 CODING:
hb0473-02-c2hb0473-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473CS/HB473 2024 d.cybersecurity incident.
The(2) FederalA Risksole andproprietorship, Authorizationpartnership, Managementcorporation, Programtrust, securityestate, assessmentcooperative, framework;association, or other commercial entity or third-party agent that acquires, maintains, stores, or uses personal information is not liable in connection with a cybersecurity incident if the entity substantially complies with s.
e.501.171, if applicable, and has:
The(a) CenterAdopted fora Internetcybersecurity Securityprogram (CIS)that Criticalsubstantially Securityaligns Controls;with the current version of any standards, guidelines, or regulations that implement any of the following:
f.1.
The National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity.
2.
NIST special publication 800-171.
3.
NIST special publications 800-53 and 800-53A.
4.
The Federal Risk and Authorization Management Program security assessment framework.
5.
The Center for Internet Security (CIS) Critical Security Controls.
6.
Show all 74 changed lines (34 more)
g.or (b) If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, substantially aligned its Page 2of 4 CODING:
HITRUSTWords Commonstrickenare Securitydeletions; Framework (CSF);
h.words underlined are additions.
Servicehb0473-01-c1 OrganizationF ControlL TypeO 2R (SOCI 2)D Framework;A H O U S E O F R E P R E S E N T A T I V E S CS/HB473 2024 cybersecurity program to the current version of the following, as applicable:
i.1.
Secure Controls Framework;
or j.
Other similar industry frameworks or standards;
or 2.
If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, has adopted a cybersecurity program that substantially aligns with the current version of the following, as applicable:
a.
b.2.
c.3.
d.4.
Page(3) 3ofThe 5scale CODING:and scope of substantial alignment with a standard, law, or regulation under paragraph (2)(a) or paragraph (2)(b) by a covered entity or third-party agent, as applicable, is appropriate if it is based on all of the following factors:
Words strickenare deletions;
words underlined are additions.
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 e.
The Criminal Justice Information Services (CJIS) Security Policy.
f.
Other similar requirements mandated by state or federal law or regulation.
(4) A covered entity's or third-party agent's substantial alignment with a framework or standard under subparagraph (3)(b)1.
or with a law or regulation under subparagraph (3)(b)2.
may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program is substantially aligned with the relevant framework or standard or with the applicable state or federal law or regulation.
In determining whether a covered entity's or third-party agent's cybersecurity program is in substantial alignment, all of the following factors must be considered:
(5)(4) Any coveredcommercial entity or third-party agent mustcovered substantiallyby alignsubsection its(2) cybersecuritythat programsubstantially complies with anya revisionscombination of relevantindustry-recognized cybersecurity frameworks or standards orto ofgain applicablethe statepresumption oragainst federalliability lawspursuant orto regulationssubsection within(2) 1must, yearupon after the latestrevision publicationof datetwo statedor inmore anyof suchthe revisionsframeworks inor order to retain Page 4of3of 54 CODING:
hb0473-02-c2hb0473-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473CS/HB473 2024 protectionstandards fromwith liability.which the entity complies, adopt the revised frameworks or standards within 1 year after the latest publication date stated in the revisions and, if applicable, comply with the Payment Card Industry Data Security Standard (PCI DSS).
(6)(5) This section does not establish a private cause of action.
(7) Failure of a county, municipality, other political subdivision of the state, covered entity, or third-partycommercial agententity to substantially implement a cybersecurity program that is in compliance with this section is not evidence of negligence and does not constitute negligence per se.
(8)(6) In an action relatingin toconnection with a cybersecurity incident, if the defendant is aan county,entity municipality, or political subdivision covered by subsection (2)(1) or a covered entity or third-party agent covered by subsection (3),(2), the defendant has the burden of proof to establish substantial compliance.
The amendments made by this act apply to any suit filed on or after the effective date of this act and to any putative class action not certified on or before the effective date of this act.
Section 3.
Page 5of4of 54 CODING:
hb0473-02-c2hb0473-01-c1
Show all 74 changed rows (34 more)
View plain text versions (4)
- H 473 c1 View text pdf
- H 473 c2 View text pdf
- H 473 er View text Current pdf
- Introduced H 473 Filed pdf
Action History
-
Veto Message received
-
Vetoed by Governor
-
Signed by Officers and presented to Governor
-
Ordered enrolled
-
In Messages
-
CS passed; YEAS 32 NAYS 8
-
Read 3rd time
-
Read 2nd time
-
Substituted for CS/SB 658
-
Placed on Calendar, on 2nd reading
-
Withdrawn from Rules
-
Received
-
Referred to Rules
-
In Messages
-
CS passed; YEAS 81, NAYS 28
-
Read 3rd time
-
Added to Third Reading Calendar
-
Placed on 3rd reading
-
Read 2nd time
-
Bill added to Special Order Calendar (2/29/2024)
-
Added to Second Reading Calendar
-
Bill referred to House Calendar
-
1st Reading (Committee Substitute 2)
-
CS Filed
-
Laid on Table under Rule 7.18(a)
-
Reported out of Judiciary Committee
-
Favorable with CS by Judiciary Committee
-
PCS added to Judiciary Committee agenda
-
Now in Judiciary Committee
-
Reported out of State Administration & Technology Appropriations Subcommittee
-
Favorable by State Administration & Technology Appropriations Subcommittee
-
Added to State Administration & Technology Appropriations Subcommittee agenda
-
Now in State Administration & Technology Appropriations Subcommittee
-
Referred to Judiciary Committee
-
Referred to State Administration & Technology Appropriations Subcommittee
-
1st Reading (Committee Substitute 1)
-
CS Filed
-
Laid on Table under Rule 7.18(a)
-
Reported out of Commerce Committee
-
Favorable with CS by Commerce Committee
-
Added to Commerce Committee agenda
-
1st Reading (Original Filed Version)
-
Now in Commerce Committee
-
Referred to Judiciary Committee
-
Referred to State Administration & Technology Appropriations Subcommittee
-
Referred to Commerce Committee
-
Filed
Sponsors
- Judiciary Committee · Primary
- Commerce Committee · Primary
- Mike Giallombardo · Primary
- Kevin M. Steele · Primary
- Webster Barnaby · Cosponsor
- Dana Trabulsy · Cosponsor
Sponsorship breakdown
Export CSV (upgrade) →4 sponsors · 2 co-sponsors · 158 not signed on · 29 voted No
Sponsors (4)
- Judiciary Committee
- Commerce Committee
- Giallombardo, Mike Republican
- Steele, Kevin M. Republican
Co-sponsors (2)
- Barnaby, Webster Republican
- Trabulsy, Dana Republican
Not signed on (158)
158 members have not signed on to this bill.
Show all 158 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Votes
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Republican | 22 | 0 | 0 | 0 |
| Unaffiliated | 8 | 3 | 0 | 0 |
| Democrat | 2 | 4 | 0 | 0 |
| No Party Affiliation | 0 | 1 | 0 | 0 |
| Total | 32 | 8 | 0 | 0 |
| % of votes cast | 80% | 20% | 0% | 0% |
How each member voted (40)
| Member | Party | Vote |
|---|---|---|
| Stewart | — | Yea |
| Hutson | — | Yea |
| Ingoglia | — | Yea |
| Torres | — | Nay |
| Broxson | — | Yea |
| Collins | — | Yea |
| Perry | — | Yea |
| Powell | — | Yea |
| Baxley | — | Yea |
| Book | — | Nay |
| Thompson, Geraldine F. "Geri" | — | Nay |
| Berman, Lori | Democrat | Yea |
| Davis, Tracie | Democrat | Nay |
| Jones, Shevrin D. "Shev" | Democrat | Nay |
| Osgood, Rosalind | Democrat | Nay |
| Polsky, Tina Scott | Democrat | Yea |
| Rouson, Darryl Ervin | Democrat | Nay |
| Pizzo, Jason W. B. | No Party Affiliation | Nay |
| Albritton, Ben | Republican | Yea |
| Boyd, Jim | Republican | Yea |
| Bradley, Jennifer | Republican | Yea |
| Brodeur, Jason | Republican | Yea |
| Burgess, Danny | Republican | Yea |
| Burton, Colleen | Republican | Yea |
| Calatayud, Alexis | Republican | Yea |
| DiCeglie, Nick | Republican | Yea |
| Garcia, Ileana | Republican | Yea |
| Grall, Erin | Republican | Yea |
| Gruters, Joe | Republican | Yea |
| Harrell, Gayle | Republican | Yea |
| Hooper, Ed | Republican | Yea |
| Martin, Jonathan | Republican | Yea |
| Mayfield, Debbie | Republican | Yea |
| Passidomo, Kathleen | Republican | Yea |
| Rodriguez, Ana Maria | Republican | Yea |
| Simon, Corey | Republican | Yea |
| Trumbull, Jay | Republican | Yea |
| Vacant | Republican | Yea |
| Wright, Tom A. | Republican | Yea |
| Yarborough, Clay | Republican | Yea |
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Republican | 60 | 2 | 0 | 4 |
| Democrat | 2 | 21 | 0 | 6 |
| Unaffiliated | 19 | 5 | 0 | 1 |
| Total | 81 | 28 | 0 | 11 |
| % of votes cast | 68% | 23% | 0% | 9% |
How each member voted (120)
| Member | Party | Vote |
|---|---|---|
| Altman | — | Yea |
| Payne | — | Yea |
| Amesty | — | Yea |
| Fine | — | Yea |
| Renner | — | Yea |
| Roach | — | Yea |
| Bell | — | Yea |
| Grant | — | Yea |
| Beltran | — | Yea |
| Rommel | — | Yea |
| Benjamin | — | Nay |
| Roth | — | Yea |
| Rudman | — | Yea |
| Silvers | — | Nay |
| Keen | — | Nay |
| Killebrew | — | Yea |
| Stevenson | — | Yea |
| Caruso | — | Yea |
| Temple | — | Yea |
| Tomkow | — | Yea |
| Clemons | — | Yea |
| Waldron | — | Nay |
| Williams | — | Nay |
| Casello | — | Not Voting |
| Lopez, V. | — | Yea |
| Antone, Bruce Hadley | Democrat | Nay |
| Arrington, Kristen Aston | Democrat | Nay |
| Bartleman, Robin | Democrat | Nay |
| Bracy Davis, LaVon | Democrat | Nay |
| Campbell, Daryl | Democrat | Nay |
| Chambliss, Kevin D. | Democrat | Not Voting |
| Cross, Lindsay | Democrat | Nay |
| Daley, Dan | Democrat | Not Voting |
| Daniels, Kimberly | Democrat | Nay |
| Driskell, Fentrice | Democrat | Nay |
| Dunkley, Lisa | Democrat | Nay |
| Edmonds, Jervonte "Tae" | Democrat | Nay |
| Eskamani, Dr. Anna V. | Democrat | Nay |
| Franklin II, Gallop | Democrat | Nay |
| Gantt, Ashley Viola | Democrat | Nay |
| Gottlieb, Michael "Mike" | Democrat | Nay |
| Gregory, Emily | Democrat | Yea |
| Harris, Jennifer "Rita" | Democrat | Nay |
| Hart-Lowman, Dianne "Ms Dee" | Democrat | Not Voting |
| Hinson, Yvonne Hayes | Democrat | Not Voting |
| Hunschofsky, Christine | Democrat | Nay |
| Joseph, Dotie | Democrat | Nay |
| López, Johanna | Democrat | Nay |
| Nixon, Angela "Angie" | Democrat | Not Voting |
| Rayner, Michele K. | Democrat | Nay |
| Robinson, Felicia Simone | Democrat | Not Voting |
| Skidmore, Kelly | Democrat | Nay |
| Tant, Allison | Democrat | Yea |
| Woodson, Marie Paule | Democrat | Nay |
| Abbott, Shane G. | Republican | Yea |
| Alvarez, Daniel Antonio "Danny" | Republican | Yea |
| Anderson, Adam | Republican | Yea |
| Andrade, Robert Alexander "Alex" | Republican | Yea |
| Baker, Jessica | Republican | Yea |
| Bankson, Douglas Michael "Doug" | Republican | Yea |
| Barnaby, Webster | Republican | Not Voting |
| Basabe, Fabián | Republican | Yea |
| Berfield, Kimberly | Republican | Yea |
| Black, Dean | Republican | Yea |
| Borrero, David | Republican | Yea |
| Botana, Adam | Republican | Yea |
| Brackett, Robert A. "Robbie" | Republican | Yea |
| Brannan III, Robert Charles "Chuck" | Republican | Yea |
| Buchanan, James | Republican | Yea |
| Busatta, Demi | Republican | Yea |
| Canady, Jennifer | Republican | Yea |
| Cassel, Hillary | Republican | Nay |
| Chamberlin, Ryan | Republican | Yea |
| Chaney, Linda | Republican | Yea |
| Duggan, Wyman | Republican | Yea |
| Esposito, Tiffany | Republican | Yea |
| Fabricio, Tom | Republican | Yea |
| Garcia, Ileana | Republican | Yea |
| Garrison, Sam | Republican | Yea |
| Giallombardo, Mike | Republican | Yea |
| Gonzalez Pittman, Karen | Republican | Yea |
| Gossett-Seidman, Peggy | Republican | Yea |
| Griffitts Jr., Philip Wayne "Griff" | Republican | Yea |
| Holcomb, Jeff | Republican | Yea |
| Jacques, Berny | Republican | Yea |
| Koster, Traci | Republican | Yea |
| LaMarca, Chip | Republican | Yea |
| Leek, Thomas J. "Tom" | Republican | Yea |
| Maggard, Randall Scott "Randy" | Republican | Not Voting |
| Maney, Patt | Republican | Yea |
| Massullo, Ralph E., Jr. | Republican | Yea |
| McClain, Stan | Republican | Yea |
| McClure, Lawrence | Republican | Yea |
| McFarland, Fiona | Republican | Not Voting |
| Melo, Lauren | Republican | Yea |
| Michael, Kiyan | Republican | Yea |
| Mooney Jr., James Vernon "Jim" | Republican | Yea |
| Overdorf, Tobin Rogers "Toby" | Republican | Yea |
| Perez, Daniel | Republican | Yea |
| Persons-Mulicka, Jenna | Republican | Yea |
| Plakon, Rachel Saunders | Republican | Yea |
| Plasencia, Susan | Republican | Yea |
| Porras, Juan Carlos | Republican | Yea |
| Redondo, Mike | Republican | Yea |
| Rizo, Alex | Republican | Yea |
| Robinson Jr., William Cloud "Will" | Republican | Yea |
| Salzman, Michelle | Republican | Not Voting |
| Shoaf, Jason | Republican | Yea |
| Sirois, Tyler I. | Republican | Yea |
| Smith, David | Republican | Yea |
| Snyder, John | Republican | Yea |
| Stark, Paula A. | Republican | Yea |
| Steele, Kevin M. | Republican | Yea |
| Trabulsy, Dana | Republican | Yea |
| Tramont, Chase | Republican | Yea |
| Truenow, Keith L. | Republican | Yea |
| Tuck, Kaylee | Republican | Yea |
| Valdés, Susan L. | Republican | Nay |
| Yarkosky, Taylor Michael | Republican | Yea |
| Yeager, Bradford Troy "Brad" | Republican | Yea |
Subjects
Frequently asked questions
- What does HB 473 do?
- Cybersecurity Incident Liability; Provides county, municipality, other political subdivision of state, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to adopt revised frameworks, standards, laws, or regulations within specified time period; provides private cause of action is not established; provides certain failures are not evidence of negligence & do not constitute negligence per se; specifies defendant in certain actions has certain burden of proof.
- Who sponsors HB 473?
- HB 473 is sponsored by Judiciary Committee, Commerce Committee, Giallombardo, Mike (Republican), Steele, Kevin M. (Republican), Barnaby, Webster (Republican), and Trabulsy, Dana (Republican).
- What is the current status of HB 473?
- This bill died with 2024 Regular Session. It reached “To Executive” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
- Where can I track HB 473?
- Track HB 473 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HB 473
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HB 473
Last checked for changes 2 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →