Florida 2024 Regular Session Status: To Executive 4 R cosponsors

HB 473 — Cybersecurity Incident Liability

Last action — Veto Message received

  1. ✓
    Introduced
  2. ✓
    In Committee
  3. ✓
    Passed House
  4. ✓
    Passed Senate
  5. 5
    To Executive
  6. 6
    Enacted

This bill died with 2024 Regular Session. It reached “To Executive” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.

Signed by Governor Ron DeSantis (Republican) on June 17, 2024.

This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.

Summary

Cybersecurity Incident Liability; Provides county, municipality, other political subdivision of state, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to adopt revised frameworks, standards, laws, or regulations within specified time period; provides private cause of action is not established; provides certain failures are not evidence of negligence & do not constitute negligence per se; specifies defendant in certain actions has certain burden of proof.

Bill Text

What changed in the latest version

100 added · 130 removed

100 line(s) added, 130 removed.

→
Previous
Latest
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 A bill to be entitled An act relating to cybersecurity incident liability;
F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB473 2024 A bill to be entitled An act relating to cybersecurity incident liability;
providing definitions;
providing that a county, municipality, other political subdivision of the state, commercial entity, or third-party agent that complies with certain requirements is not liable in connection with a cybersecurity incident;
providing that a county, municipality, other political subdivision of the state, covered entity, or third- party agent that complies with certain requirements is not liable in connection with a cybersecurity incident;
requiring certain entities to adopt certain revised frameworks or standards within a specified time period;
requiring covered entities and third-party agents to adopt revised frameworks, standards, laws, or regulations within a specified time period;
providing applicability;
768.401 Limitation on liability for cybersecurity incidents.— (1) As used in this section, the term:
768.401 Limitation on liability for cybersecurity incidents.— (1) A county or municipality that substantially complies with s.
(a) "Covered entity" means a sole proprietorship, Page 1of 5 CODING:
Words strickenare deletions;
words underlined are additions.
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 partnership, corporation, trust, estate, cooperative, association, or other commercial entity.
(b) "Third-party agent" means an entity that has been contracted to maintain, store, or process personal information on behalf of a covered entity.
(2) A county or municipality that substantially complies with s.
282.3185 on a voluntary basis, is not liable in connection with a cybersecurity incident.
282.3185 on a voluntary basis, is not liable in connection with a Page 1of 4 CODING:
(3) A covered entity or third-party agent that acquires, maintains, stores, processes, or uses personal information is not liable in connection with a cybersecurity incident if the covered entity or third-party agent does all of the following, as applicable:
(a) Substantially complies with s.
501.171(3)-(6), as applicable.
(b)1.
Has adopted a cybersecurity program that substantially aligns with the current version of any standards, guidelines, or regulations that implement any of the following:
a.
The National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity;
b.
NIST special publication 800-171;
c.
NIST special publications 800-53 and 800-53A;
Page 2of 5 CODING:
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 d.
hb0473-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB473 2024 cybersecurity incident.
The Federal Risk and Authorization Management Program security assessment framework;
(2) A sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity or third-party agent that acquires, maintains, stores, or uses personal information is not liable in connection with a cybersecurity incident if the entity substantially complies with s.
e.
501.171, if applicable, and has:
The Center for Internet Security (CIS) Critical Security Controls;
(a) Adopted a cybersecurity program that substantially aligns with the current version of any standards, guidelines, or regulations that implement any of the following:
f.
1.
The National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity.
2.
NIST special publication 800-171.
3.
NIST special publications 800-53 and 800-53A.
4.
The Federal Risk and Authorization Management Program security assessment framework.
5.
The Center for Internet Security (CIS) Critical Security Controls.
6.
Show all 74 changed rows (34 more)
Previous
Latest
g.
or (b) If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, substantially aligned its Page 2of 4 CODING:
HITRUST Common Security Framework (CSF);
Words strickenare deletions;
h.
words underlined are additions.
Service Organization Control Type 2 (SOC 2) Framework;
hb0473-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB473 2024 cybersecurity program to the current version of the following, as applicable:
i.
1.
Secure Controls Framework;
or j.
Other similar industry frameworks or standards;
or 2.
If regulated by the state or Federal Government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, has adopted a cybersecurity program that substantially aligns with the current version of the following, as applicable:
a.
b.
2.
c.
3.
d.
4.
Page 3of 5 CODING:
(3) The scale and scope of substantial alignment with a standard, law, or regulation under paragraph (2)(a) or paragraph (2)(b) by a covered entity or third-party agent, as applicable, is appropriate if it is based on all of the following factors:
Words strickenare deletions;
words underlined are additions.
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 e.
The Criminal Justice Information Services (CJIS) Security Policy.
f.
Other similar requirements mandated by state or federal law or regulation.
(4) A covered entity's or third-party agent's substantial alignment with a framework or standard under subparagraph (3)(b)1.
or with a law or regulation under subparagraph (3)(b)2.
may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program is substantially aligned with the relevant framework or standard or with the applicable state or federal law or regulation.
In determining whether a covered entity's or third-party agent's cybersecurity program is in substantial alignment, all of the following factors must be considered:
(5) Any covered entity or third-party agent must substantially align its cybersecurity program with any revisions of relevant frameworks or standards or of applicable state or federal laws or regulations within 1 year after the latest publication date stated in any such revisions in order to retain Page 4of 5 CODING:
(4) Any commercial entity or third-party agent covered by subsection (2) that substantially complies with a combination of industry-recognized cybersecurity frameworks or standards to gain the presumption against liability pursuant to subsection (2) must, upon the revision of two or more of the frameworks or Page 3of 4 CODING:
hb0473-02-c2 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/CS/HB473 2024 protection from liability.
hb0473-01-c1 F L O R I D A H O U S E O F R E P R E S E N T A T I V E S CS/HB473 2024 standards with which the entity complies, adopt the revised frameworks or standards within 1 year after the latest publication date stated in the revisions and, if applicable, comply with the Payment Card Industry Data Security Standard (PCI DSS).
(6) This section does not establish a private cause of action.
(5) This section does not establish a private cause of action.
(7) Failure of a county, municipality, other political subdivision of the state, covered entity, or third-party agent to substantially implement a cybersecurity program that is in compliance with this section is not evidence of negligence and does not constitute negligence per se.
Failure of a county, municipality, other political subdivision of the state, or commercial entity to substantially implement a cybersecurity program that is in compliance with this section is not evidence of negligence and does not constitute negligence per se.
(8) In an action relating to a cybersecurity incident, if the defendant is a county, municipality, or political subdivision covered by subsection (2) or a covered entity or third-party agent covered by subsection (3), the defendant has the burden of proof to establish substantial compliance.
(6) In an action in connection with a cybersecurity incident, if the defendant is an entity covered by subsection (1) or subsection (2), the defendant has the burden of proof to establish substantial compliance.
The amendments made by this act apply to any suit filed on or after the effective date of this act and to any putative class action not certified on or before the effective date of this act.
Section 3.
Page 5of 5 CODING:
Page 4of 4 CODING:
hb0473-02-c2
hb0473-01-c1
View plain text versions (4)

Action History

  1. Veto Message received

  2. Vetoed by Governor

  3. Signed by Officers and presented to Governor

  4. Ordered enrolled

  5. In Messages

  6. CS passed; YEAS 32 NAYS 8

  7. Read 3rd time

  8. Read 2nd time

  9. Substituted for CS/SB 658

  10. Placed on Calendar, on 2nd reading

  11. Withdrawn from Rules

  12. Received

  13. Referred to Rules

  14. In Messages

  15. CS passed; YEAS 81, NAYS 28

  16. Read 3rd time

  17. Added to Third Reading Calendar

  18. Placed on 3rd reading

  19. Read 2nd time

  20. Bill added to Special Order Calendar (2/29/2024)

  21. Added to Second Reading Calendar

  22. Bill referred to House Calendar

  23. 1st Reading (Committee Substitute 2)

  24. CS Filed

  25. Laid on Table under Rule 7.18(a)

  26. Reported out of Judiciary Committee

  27. Favorable with CS by Judiciary Committee

  28. PCS added to Judiciary Committee agenda

  29. Now in Judiciary Committee

  30. Reported out of State Administration & Technology Appropriations Subcommittee

  31. Favorable by State Administration & Technology Appropriations Subcommittee

  32. Added to State Administration & Technology Appropriations Subcommittee agenda

  33. Now in State Administration & Technology Appropriations Subcommittee

  34. Referred to Judiciary Committee

  35. Referred to State Administration & Technology Appropriations Subcommittee

  36. 1st Reading (Committee Substitute 1)

  37. CS Filed

  38. Laid on Table under Rule 7.18(a)

  39. Reported out of Commerce Committee

  40. Favorable with CS by Commerce Committee

  41. Added to Commerce Committee agenda

  42. 1st Reading (Original Filed Version)

  43. Now in Commerce Committee

  44. Referred to Judiciary Committee

  45. Referred to State Administration & Technology Appropriations Subcommittee

  46. Referred to Commerce Committee

  47. Filed

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

4 sponsors · 2 co-sponsors · 158 not signed on · 29 voted No

Sponsors (4)

Co-sponsors (2)

Not signed on (158)

158 members have not signed on to this bill.

Show all 158 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Votes

Third Reading

Passed 32 Yea · 8 Nay
Party YeaNayPresentNot Voting
Republican 22000
Unaffiliated 8300
Democrat 2400
No Party Affiliation 0100
Total 32800
% of votes cast 80%20%0%0%
How each member voted (40)
Member Party Vote
Stewart — Yea
Hutson — Yea
Ingoglia — Yea
Torres — Nay
Broxson — Yea
Collins — Yea
Perry — Yea
Powell — Yea
Baxley — Yea
Book — Nay
Thompson, Geraldine F. "Geri" — Nay
Berman, Lori Democrat Yea
Davis, Tracie Democrat Nay
Jones, Shevrin D. "Shev" Democrat Nay
Osgood, Rosalind Democrat Nay
Polsky, Tina Scott Democrat Yea
Rouson, Darryl Ervin Democrat Nay
Pizzo, Jason W. B. No Party Affiliation Nay
Albritton, Ben Republican Yea
Boyd, Jim Republican Yea
Bradley, Jennifer Republican Yea
Brodeur, Jason Republican Yea
Burgess, Danny Republican Yea
Burton, Colleen Republican Yea
Calatayud, Alexis Republican Yea
DiCeglie, Nick Republican Yea
Garcia, Ileana Republican Yea
Grall, Erin Republican Yea
Gruters, Joe Republican Yea
Harrell, Gayle Republican Yea
Hooper, Ed Republican Yea
Martin, Jonathan Republican Yea
Mayfield, Debbie Republican Yea
Passidomo, Kathleen Republican Yea
Rodriguez, Ana Maria Republican Yea
Simon, Corey Republican Yea
Trumbull, Jay Republican Yea
Vacant Republican Yea
Wright, Tom A. Republican Yea
Yarborough, Clay Republican Yea

Official roll call →

Passage, Third Reading

Passed 81 Yea · 28 Nay · 11 Other
Party YeaNayPresentNot Voting
Republican 60204
Democrat 22106
Unaffiliated 19501
Total 8128011
% of votes cast 68%23%0%9%
How each member voted (120)
Member Party Vote
Altman — Yea
Payne — Yea
Amesty — Yea
Fine — Yea
Renner — Yea
Roach — Yea
Bell — Yea
Grant — Yea
Beltran — Yea
Rommel — Yea
Benjamin — Nay
Roth — Yea
Rudman — Yea
Silvers — Nay
Keen — Nay
Killebrew — Yea
Stevenson — Yea
Caruso — Yea
Temple — Yea
Tomkow — Yea
Clemons — Yea
Waldron — Nay
Williams — Nay
Casello — Not Voting
Lopez, V. — Yea
Antone, Bruce Hadley Democrat Nay
Arrington, Kristen Aston Democrat Nay
Bartleman, Robin Democrat Nay
Bracy Davis, LaVon Democrat Nay
Campbell, Daryl Democrat Nay
Chambliss, Kevin D. Democrat Not Voting
Cross, Lindsay Democrat Nay
Daley, Dan Democrat Not Voting
Daniels, Kimberly Democrat Nay
Driskell, Fentrice Democrat Nay
Dunkley, Lisa Democrat Nay
Edmonds, Jervonte "Tae" Democrat Nay
Eskamani, Dr. Anna V. Democrat Nay
Franklin II, Gallop Democrat Nay
Gantt, Ashley Viola Democrat Nay
Gottlieb, Michael "Mike" Democrat Nay
Gregory, Emily Democrat Yea
Harris, Jennifer "Rita" Democrat Nay
Hart-Lowman, Dianne "Ms Dee" Democrat Not Voting
Hinson, Yvonne Hayes Democrat Not Voting
Hunschofsky, Christine Democrat Nay
Joseph, Dotie Democrat Nay
López, Johanna Democrat Nay
Nixon, Angela "Angie" Democrat Not Voting
Rayner, Michele K. Democrat Nay
Robinson, Felicia Simone Democrat Not Voting
Skidmore, Kelly Democrat Nay
Tant, Allison Democrat Yea
Woodson, Marie Paule Democrat Nay
Abbott, Shane G. Republican Yea
Alvarez, Daniel Antonio "Danny" Republican Yea
Anderson, Adam Republican Yea
Andrade, Robert Alexander "Alex" Republican Yea
Baker, Jessica Republican Yea
Bankson, Douglas Michael "Doug" Republican Yea
Barnaby, Webster Republican Not Voting
Basabe, Fabián Republican Yea
Berfield, Kimberly Republican Yea
Black, Dean Republican Yea
Borrero, David Republican Yea
Botana, Adam Republican Yea
Brackett, Robert A. "Robbie" Republican Yea
Brannan III, Robert Charles "Chuck" Republican Yea
Buchanan, James Republican Yea
Busatta, Demi Republican Yea
Canady, Jennifer Republican Yea
Cassel, Hillary Republican Nay
Chamberlin, Ryan Republican Yea
Chaney, Linda Republican Yea
Duggan, Wyman Republican Yea
Esposito, Tiffany Republican Yea
Fabricio, Tom Republican Yea
Garcia, Ileana Republican Yea
Garrison, Sam Republican Yea
Giallombardo, Mike Republican Yea
Gonzalez Pittman, Karen Republican Yea
Gossett-Seidman, Peggy Republican Yea
Griffitts Jr., Philip Wayne "Griff" Republican Yea
Holcomb, Jeff Republican Yea
Jacques, Berny Republican Yea
Koster, Traci Republican Yea
LaMarca, Chip Republican Yea
Leek, Thomas J. "Tom" Republican Yea
Maggard, Randall Scott "Randy" Republican Not Voting
Maney, Patt Republican Yea
Massullo, Ralph E., Jr. Republican Yea
McClain, Stan Republican Yea
McClure, Lawrence Republican Yea
McFarland, Fiona Republican Not Voting
Melo, Lauren Republican Yea
Michael, Kiyan Republican Yea
Mooney Jr., James Vernon "Jim" Republican Yea
Overdorf, Tobin Rogers "Toby" Republican Yea
Perez, Daniel Republican Yea
Persons-Mulicka, Jenna Republican Yea
Plakon, Rachel Saunders Republican Yea
Plasencia, Susan Republican Yea
Porras, Juan Carlos Republican Yea
Redondo, Mike Republican Yea
Rizo, Alex Republican Yea
Robinson Jr., William Cloud "Will" Republican Yea
Salzman, Michelle Republican Not Voting
Shoaf, Jason Republican Yea
Sirois, Tyler I. Republican Yea
Smith, David Republican Yea
Snyder, John Republican Yea
Stark, Paula A. Republican Yea
Steele, Kevin M. Republican Yea
Trabulsy, Dana Republican Yea
Tramont, Chase Republican Yea
Truenow, Keith L. Republican Yea
Tuck, Kaylee Republican Yea
Valdés, Susan L. Republican Nay
Yarkosky, Taylor Michael Republican Yea
Yeager, Bradford Troy "Brad" Republican Yea

Official roll call →

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

What does HB 473 do?
Cybersecurity Incident Liability; Provides county, municipality, other political subdivision of state, covered entity, or third-party agent that complies with certain requirements is not liable in connection with cybersecurity incident; requires covered entities & third-party agents to adopt revised frameworks, standards, laws, or regulations within specified time period; provides private cause of action is not established; provides certain failures are not evidence of negligence & do not constitute negligence per se; specifies defendant in certain actions has certain burden of proof.
Who sponsors HB 473?
HB 473 is sponsored by Judiciary Committee, Commerce Committee, Giallombardo, Mike (Republican), Steele, Kevin M. (Republican), Barnaby, Webster (Republican), and Trabulsy, Dana (Republican).
What is the current status of HB 473?
This bill died with 2024 Regular Session. It reached “To Executive” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
Where can I track HB 473?
Track HB 473 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HB 473

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HB 473

Last checked for changes 2 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →