Bill Text: MS HB1220 | 2026 | Regular Session | Engrossed


Bill Title: Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

Sponsorship: Partisan Bill (Republican 2)

Status: (Failed) 2026-03-03 - Died In Committee [HB1220 Detail]

Download: Mississippi-2026-HB1220-Engrossed.html

MISSISSIPPI LEGISLATURE

2026 Regular Session

To: Judiciary A

By: Representative Hood

House Bill 1220

(As Passed the House)

AN ACT TO PROVIDE THAT STATE AND LOCAL GOVERNMENTAL ENTITIES AND CERTAIN COVERED COMMERCIAL ENTITIES ARE NOT LIABLE IN CONNECTION WITH A CYBERSECURITY INCIDENT IF THE ENTITY INVOLVED HAS ADOPTED CERTAIN CYBERSECURITY STANDARDS; TO DEFINE CERTAIN TERMS; TO REQUIRE CYBERSECURITY STANDARDS TO ALIGN WITH NATIONALLY-RECOGNIZED STANDARDS AND THE REQUIREMENTS OF SPECIFIED FEDERAL LAWS; TO CREATE A REBUTTABLE PRESUMPTION AGAINST LIABILITY IN CONNECTION WITH A CYBERSECURITY INCIDENT FOR COMMERCIAL ENTITIES THAT HAVE ADOPTED A CYBERSECURITY PROGRAM THAT SUBSTANTIALLY ALIGNS WITH CERTAIN SPECIFIED CYBERSECURITY STANDARDS IN COMPLIANCE WITH THIS ACT; TO AMEND SECTION 83-5-803, MISSISSIPPI CODE OF 1972, TO CONFORM TO THE PROVISIONS OF THIS ACT; AND FOR RELATED PURPOSES.

     BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MISSISSIPPI:

     SECTION 1.  (1)  As used in this section, the following words and phrases have the meanings as defined in this subsection unless the context clearly requires otherwise:

          (a)  "Covered entity" means a sole proprietorship,

partnership, company, corporation, trust, estate, cooperative, association or other commercial entity, or a financial institution organized, chartered or holding a license authorizing operation under the laws of this state, another state, the United States or another country.

          (b)  "Third-party agent" means an entity that has

been contracted to maintain, store or process personal information on behalf of a covered entity.

          (c)  "Substantial compliance" or "substantially complies" means that the covered entity or third-party agent has implemented and maintains the technical cybersecurity requirements as outlined in the relevant standard, guideline or regulation listed in subsection (3)(a) of this section, and can demonstrate that such requirements have been implemented and maintained.

     (2)  (a)  The state, a county, municipality, county hospital or other political subdivision of the state is not liable in connection with a cybersecurity incident if the entity adopts cybersecurity standards that:

              (i)  Safeguard its data, information technology and information technology resources to ensure availability, confidentiality and integrity; and

              (ii)  Are consistent with generally accepted best practices for cybersecurity, including the National Institute of Standards and Technology Cybersecurity Framework.

          (b)  This statement of immunity may not be construed to waive any immunity granted to the state, a county, municipality or other political subdivision of the state under Title 11, Chapter 46, Mississippi Code of 1972.  Further, this section shall not apply to acquisitions of information technology governed by Section 25-53-1 et seq.

     (3)  There is a rebuttable presumption that a covered entity or third-party agent that acquires, maintains, stores or uses personal information is not liable in connection with a cybersecurity incident if the covered entity or third-party agent, in good faith, substantially complies with reasonable measures to protect and secure data in electronic form containing personal information and has:

          (a)  Adopted a cybersecurity program that substantially aligns with the current version of any standards, guidelines or regulations that implement any of the following:

              (i)  The National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and the implementing regulations or publications or its most current applicable update, revision or replacement;

              (ii)  NIST special publication 800-171 Revision 3 or its most current applicable update, revision or replacement;

              (iii)  NIST special publications 800-53 and 800-53A Release 5.2.0 or their most current applicable update, revision or replacement;

              (iv)  The Federal Risk and Authorization Management Program 20x/Revision 5 security assessment framework or its most current applicable update, revision or replacement;

              (v)  The Center for Internet Security (CIS) Critical Security Controls Version 8.1, or its most current applicable update, revision or replacement; or

              (vi)  The International Organization for Standardization/International Electrotechnical Commission 27000- series (ISO/IEC 27000) family of standards; or

          (b)  If regulated by the state or federal government, or both, or if otherwise subject to the requirements of any of the following laws and regulations, substantially aligned its cybersecurity program to the current version of the following, as applicable:

              (i)  The Health Insurance Portability and Accountability Act of 1996 security requirements in 45 CFR part 160 and part 164 subparts A and C;

              (ii)  Title V of the Gramm-Leach-Bliley Act of 1999, Public Law 57 No. 106-102, as amended, and the implementing regulations;

              (iii)  The Federal Information Security Modernization Act of 2014, Public Law No. 113-283; or

              (iv)  The Health Information Technology for Economic and Clinical Health Act requirements in 45 CFR parts 160 and 164.

     (4)  A covered entity's or third-party agent's alignment with a framework or standard under paragraph (a) or (b) of subsection (3) of this section may be demonstrated by providing documentation or other evidence of an assessment, conducted internally or by a third-party, reflecting that the covered entity's or third-party agent's cybersecurity program substantially is aligned with the relevant framework or standard or with the applicable state or federal law or regulation. 

     (5)  The scale and scope of substantial alignment with a standard, law or regulation under paragraph (a) or (b) of subsection (3) of this section by a covered entity or third-party agent, as applicable, is appropriate if it is based on all of the following factors:

          (a)  The size and complexity of the covered entity or third-party agent;

          (b)  The nature and scope of the activities of the covered entity or third-party agent;

          (c)  The sensitivity of the information to be protected;

          (d)  The cost and availability of tools to improve information security and reduce vulnerabilities; and

          (e)  The resources available to the covered entity.

     (6)  A commercial entity or third-party agent covered by subsection (3) of this section which substantially complies with a combination of industry-recognized cybersecurity frameworks or standards to gain the presumption against liability under subsection (3) must adopt, upon the revision of two (2) or more of the frameworks or standards with which the entity complies, the revised frameworks or standards within one (1) year after the latest publication date or latest compliance or effective date stated in the revisions and, if applicable, comply with the Payment Card Industry Data Security Standard (PCI DSS).

     (7)  In a civil action in connection with a cybersecurity incident, if the defendant is an entity covered by subsection (2) of this section, the plaintiff has the initial burden of demonstrating that the entity was not in substantial compliance with this section.

     (8)  In a civil action in connection with a cybersecurity incident, if the defendant is an entity under subsection (3) of this section, the defendant has the burden of proof to establish a prima facie case of compliance with industry-recognized cybersecurity frameworks or standards to gain the presumption against liability created under this section.  If a defendant meets its initial burden, the burden of proof then shifts to the plaintiff to overcome this presumption against liability by proving that the defendant failed to substantially comply with applicable industry-recognized cybersecurity frameworks or standards.

     (9)  This act does not establish a private cause of action, including a class action, nor does it preclude or diminish any previously established cause of action, if a covered entity or third-party agent fails to comply with this act.

     (10)  Failure of a county, municipality, county hospital, other political subdivision of the state, covered entity or third-party agent to substantially implement a cybersecurity program that is in compliance with this section is not evidence of negligence and does not constitute negligence per se.

     (11)  A choice of law provision in an agreement that designates this state as the governing law applies to this act, if applicable, to the fullest extent possible in a civil action brought against a person regardless of whether the civil action is brought in this state or another state.

     (12)  This section is applicable to any suit filed on or after January 1, 2026.

     (13)  Nothing in this section shall be construed to modify an insurance licensee's obligations under the Insurance Data Security Law, Section 83-5-801 et seq. or to affect the commissioner's power to enforce its provisions.

     SECTION 2.  Section 83-5-803, Mississippi Code of 1972, is amended as follows:

     83-5-803.  (1)  * * * Notwithstanding any other provision of law, Except for determining liability pursuant to a civil action in accordance with Section 1 of this act, this article establishes the exclusive state standards applicable to licensees for data security, the investigation of a cybersecurity event as defined in Section 83-5-805, and notification to the Commissioner of Insurance.

     (2)  This article may not be construed to create or imply a private cause of action for violation of its provisions nor may it be construed to curtail a private cause of action which would otherwise exist in the absence of this article.

     SECTION 3.  This act shall take effect and be in force from and after July 1, 2026.


feedback