Showing 4 of 4
bills
All technology bills
This bill updates Maine state laws to modernize terminology and procedures related to information technology and cybersecurity. It directly affects state agencies, the Department of Administrative and Financial Services, and the Chief Information Officer by clarifying how technology purchases and security measures should be handled. Key changes include adjusting procurement thresholds for IT spending, defining cybersecurity terms more precisely, and expanding the Chief Information Officer's authority to approve technology acquisitions and oversee security training for state employees. The legislation also establishes clearer rules for purchasing cybersecurity services and using federal government procurement options when beneficial to the state.
This bill requires hospitals in Maine to create and submit an annual cybersecurity plan to the Department of Health and Human Services. The plan must outline procedures for notifying authorities and patients of security breaches, maintaining patient care during incidents, and providing cybersecurity training for staff and board members. Additionally, the bill adds cybersecurity intrusions that affect patient access to medical care to the list of sentinel events, which are serious incidents that must be reported. Hospitals must also conduct annual tests of their cybersecurity plans to ensure they work effectively.
LD 120 expands Maine's Homeland Security Advisory Council from 9 to 11 members by adding two specific positions: the Chief Information Officer (or designee) from the Department of Administrative and Financial Services, and the director of the Maine School Safety Center (or designee) from the Department of Education. The bill directly affects the council's composition and its ability to include expertise in cybersecurity and school safety. The key mechanism is a statutory amendment to the council's membership structure under Title 37-B MRSA §708. This procedural change does not alter the council's duties but broadens its membership to include these two new roles.
LD 224 expands Maine's legal definition of "terrorism" to include cyberattacks targeting critical infrastructure, such as information systems and telecommunications networks. It specifically defines "cyberattack" as actions intended to disrupt, disable, destroy, or steal data from state infrastructure. This change directly affects the Maine Emergency Management Agency's ability to classify and respond to incidents involving digital infrastructure disruptions. The bill updates existing laws without creating new criminal penalties, aligning the definition with modern threats to both physical and digital systems.