HB 1355, the Maryland Stablecoin Act, creates a new regulatory framework for entities providing payment stablecoin services in Maryland. It directly affects nondepository trust companies (financial institutions not covered by FDIC insurance) that wish to offer stablecoin-related services, such as issuing or facilitating transactions with stablecoins (digital currencies pegged to assets like the US dollar). The bill establishes licensing requirements, capital stock rules, and disclosure obligations for these providers under the Commissioner of Financial Regulation, while exempting certain existing nondepository trust companies from unrelated regulations. It adds new sections (14-101 through 14-603) to Maryland’s Financial Institutions code to define terms like "permitted payment stablecoin issuer" and "state issuer," and modifies existing fee structures for new bank charters. The law aims to provide legal clarity and oversight for this emerging financial service within the state.
SB 85 clarifies how Maryland's Information Technology Investment Fund can be used to support state IT systems. The bill requires fund money to directly support the state's telecommunication network and the Maryland First public safety radio system (used by first responders), while giving the Secretary of Information Technology discretion to allocate funds for other state-owned communication sites and equipment related to IT agreements. It does not create new programs but specifies existing fund usage for these concrete purposes. The law takes effect July 1, 2026, and primarily affects state agencies managing IT infrastructure and public safety communications.
HB 266 clarifies how Maryland's Information Technology Investment Fund can be used to support specific state IT systems. It authorizes the Secretary of Information Technology to allocate fund money - paid into the fund under existing rules - to maintain the state's telecommunication network and Maryland First (the public safety radio system for first responders). The bill also allows the Secretary to use fund resources at their discretion for state-owned communication sites, facilities, and equipment related to IT agreements. This bill does not create new funding but specifies existing fund usage for core state IT infrastructure, effective July 1, 2026.
SB 8 prohibits using personal identifying information (like Social Security numbers or bank details) or AI-generated deepfakes - defined as computer images indistinguishable from real people - to cause harm, such as physical injury, emotional distress, or financial loss. It bans maliciously disclosing personal details via online services, assuming another’s identity for fraud (e.g., accessing healthcare or avoiding debt), and using devices that copy payment card data without consent. The law directly affects individuals or entities exploiting personal data or deepfakes for fraudulent gain, harassment, or harm. Victims may pursue civil lawsuits against violators, and the bill updates Maryland’s criminal law to address emerging threats from AI and deepfake technology.
HB 487 amends Maryland law to give the Maryland Technology Development Corporation (MTDC) more flexibility regarding investments in businesses that no longer qualify under program rules. Specifically, it changes the requirement that MTDC must divest such investments to an authorization allowing it to choose whether to divest or pursue other remedies (like repayment) when a business no longer meets "qualified business" criteria. The bill also updates procedures for the MTDC's investment committee to consider these remedies. This directly affects MTDC and businesses that previously received MTDC equity investments but no longer qualify under the program.
HB 264, the Maryland Data Privacy and Protection Act of 2026, sets new rules for how Maryland state government agencies collect, store, and handle personal information. It requires agencies to only collect personal data that is necessary for a legitimate government purpose, delete or remove identifying details when no longer needed, and post clear privacy notices on their websites. The bill specifically defines "sensitive data" (like racial origin, health information, biometric data, and location tracking) and mandates that agencies designate a Privacy Officer to oversee compliance. This law directly affects all Maryland state government units, including departments and agencies, by requiring them to update their data practices to protect residents' privacy.
SB 482 makes it a crime to intentionally access or interfere with computer systems supporting critical infrastructure (like emergency services, utilities, or public safety answering points) with the intent to disrupt operations. It prohibits unauthorized access, ransomware attacks, or sharing access codes to such systems, specifically targeting acts meant to impair public safety services. The law applies to individuals who disrupt or deny access to systems vital for public security, health, transportation, or utilities. It amends Maryland’s criminal code to clarify penalties for these specific cyber-related interferences.
HB 593 amends Maryland's criminal law to specifically prohibit unauthorized actions intended to disrupt critical infrastructure or public safety answering points. It makes it a crime to intentionally access, copy data from, or possess access codes for systems like power grids, emergency call centers, or transportation networks with the intent to impair their function. The bill defines "critical infrastructure" as systems vital to public security, health, safety, or utilities, and explicitly includes ransomware attacks as a prohibited act. This law directly affects individuals who interfere with these essential systems, imposing criminal penalties for intentional disruption.
SB 601 requires all Maryland local school systems to designate a cybersecurity point of contact by 2027 and comply with state minimum cybersecurity standards established by the Department of Information Technology. Schools must conduct a cybersecurity maturity assessment every two years and certify compliance annually by June 30, starting in 2027. The bill repeals a previous requirement that county boards prioritize purchasing digital devices with certain funds and instead mandates annual reporting on cybersecurity expenditures. It also directs the Department of Information Technology to annually review and update the state cybersecurity standards. This bill directly affects all public school systems in Maryland, focusing on strengthening cybersecurity practices rather than device procurement.
HB 957 requires all Maryland local school systems to designate a cybersecurity point of contact, comply with state minimum cybersecurity standards set by the Department of Information Technology (DOIT), and conduct a cybersecurity maturity assessment every two years starting in 2027. It repeals a prior requirement that county boards prioritize purchasing digital devices with certain funds, shifting focus toward cybersecurity compliance. Schools must annually certify compliance with DOIT’s standards by June 30 and report cybersecurity spending details by August 15 each year. The bill also mandates DOIT to annually review and update the state cybersecurity standards. This directly affects all local school systems and their technology budgeting and reporting practices.