Establishes cybersecurity and informational security standards to safeguard insurance company customer information
HB 436 establishes mandatory cybersecurity standards for insurance companies licensed to operate in Missouri, directly affecting all such insurers handling customer data. The bill requires insurers to develop written security programs based on risk assessments, including specific safeguards for sensitive customer information like Social Security numbers, health records, financial account details, and biometric data. Key provisions mandate multi-factor authentication for access, regular threat assessments, and protocols for responding to cybersecurity incidents. Insurers must also define data retention and secure destruction practices, with no private legal claims allowed for violations. The law sets the exclusive state standard for data security, overriding conflicting local rules but not impacting existing private lawsuits.
Bill status
in committee
1 of 4 stages cleared
Introduction
Dec 2024
Committee Review
Floor Vote
Governor
Introduced Dec 6, 2024
Last action May 6, 2025
Maddy AI version diff · 1 comparison
What changed between versions
Introduced
→
House Committee Substitute
·
2 edits
MINOR
The bill was amended from its original introduction to a House Committee Substitute version, primarily updating administrative details and refining the definition of a cybersecurity event. The Chief Clerk's name was changed from Dana Rademan Miller to Joseph Engler, and the bill identifier was updated to reflect its committee substitute status. Most notably, the definition of a 'cybersecurity event' was narrowed by adding the word 'malicious' before 'disruption', which limits the scope of the definition to intentional attacks rather than accidental system failures.
Scope change
The scope of the bill was narrowed by requiring that a cybersecurity event involve 'malicious' disruption, excluding accidental or non-malicious system disruptions from the definition.
DEFINITION
The definition of 'cybersecurity event' was modified to specify that the disruption must be 'malicious', narrowing the definition to exclude accidental or non-malicious system disruptions.
TECHNICAL
Administrative details were updated, including changing the Chief Clerk's name from Dana Rademan Miller to Joseph Engler and updating the bill identifier to HCS HB 436 to reflect its status as a House Committee Substitute.
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
18
Key actions
4
Committee
6
Mar 12, 2025
Lower · Passed
Reported Do Pass (H) - AYES: 10 NOES: 0 PRESENT: 0
lower
Mar 12, 2025
Lower · Passed
Voted Do Pass (H)
lower
Mar 5, 2025
Committee
Referred: Rules - Legislative(H)
lower
Feb 25, 2025
Lower · Passed
HCS Reported Do Pass (H) - AYES: 12 NOES: 0 PRESENT: 0
lower
Feb 24, 2025
Lower · Passed
HCS Voted Do Pass (H)
lower
Feb 6, 2025
Committee
Referred: Insurance(H)
lower
Dec 6, 2024
Introduced
Prefiled (H)
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Bill Hardwick
RRepublican
Ask Maddy
·
AI policy assistant
Ask Maddy about HB 436
Scope: MO
Hi! I can help you understand HB 436. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline