This bill creates a new Cybersecurity Coordination Board within the Pennsylvania Office of Administration to improve state cybersecurity efforts. The board will collect and share security information, advise the Governor on best practices, and coordinate with federal agencies, local governments, and private sector partners. Its membership includes representatives from key state offices, elected officials, local government leaders, and three appointed cybersecurity experts. The board will also invite federal agency representatives to serve in advisory roles and will elect its own leadership while appointing an executive director to manage its daily operations.
This Pennsylvania House resolution urges the U.S. Congress to pass the Enhanced Cybersecurity for SNAP Act of 2026 to protect Supplemental Nutrition Assistance Program benefits from theft and fraud. The bill proposes requiring all states to upgrade to more secure chip-enabled EBT cards and mandates that federal security regulations be updated at least every five years. It directly affects the millions of low-income individuals and families in Pennsylvania and across the country who rely on SNAP for food assistance. The measure aims to address rising instances of benefit theft through methods like card skimming and cloning, which have left many residents without food.
HB 2104 establishes Pennsylvania's Office of Information Technology and an Information Technology Fund to centralize and streamline state IT management. It requires all state agencies to submit detailed business cases for major IT projects and sets five-year budget limits to control costs, reduce redundancy, and improve cybersecurity. The bill also creates a Joint Cybersecurity Oversight Committee, mandates improved data protection for personal information, and assigns oversight for the Pennsylvania Statewide Radio Network. These changes directly affect all state agencies by requiring standardized IT procurement, budgeting, and security protocols.
HB 997 updates Pennsylvania's data breach notification law, requiring businesses to notify affected individuals more clearly and promptly after a security breach involving personal information. It directly affects businesses that collect or store personal data, such as healthcare providers, retailers, and financial institutions. Key changes include modernizing definitions of personal information, clarifying when notification is required, adding new security protections, and repealing outdated civil relief provisions. The bill also removes certain exemptions that previously allowed businesses to delay or avoid notifying individuals about breaches.
HB 1219 establishes a new Office of Information Technology and an Information Technology Fund to consolidate Pennsylvania state government IT operations. The bill requires all state agencies to follow new procurement rules, including business case reviews and five-year budget limits for significant IT projects, to reduce costs and improve efficiency. It also creates a Joint Cybersecurity Oversight Committee to strengthen data protection and mandates better cybersecurity practices for all state IT systems. The bill directly affects all Pennsylvania state agencies responsible for managing information technology and cybersecurity.
SB 415 creates new criminal penalties for ransomware attacks targeting Pennsylvania state government systems. It prohibits possessing, using, or threatening to use ransomware (defined as software blocking access or encrypting data for payment demands) with penalties ranging from misdemeanors to felonies based on the ransom amount ($10,000+ triggers felony charges). The law requires managed IT service providers to notify state agencies within one hour of detecting ransomware, and agencies to report attacks to police within two hours. These provisions aim to prevent, detect, and respond to cyberattacks on Commonwealth agencies while mandating public notification after incidents.
SB 373 establishes new statewide cybersecurity standards for Pennsylvania state agencies' information technology systems. It requires agencies to obtain "authorization to operate" for all IT systems using public funds, conduct annual security reviews, and perform risk assessments - including penetration testing - to identify vulnerabilities. The bill mandates biannual compliance checks of vendors and creates a Joint Cybersecurity Oversight Committee to monitor implementation. These requirements directly affect all state agencies and their IT vendors, focusing on proactive security management rather than reactive measures.
SB 374 creates a new Office of Information Technology within Pennsylvania's state government, led by a Chief Information Officer (CIO) appointed by the Governor with Senate confirmation. The CIO, who becomes part of the Governor's Cabinet, will manage all state agency IT systems and establish security protocols for data handled by those agencies. This bill directly affects all Pennsylvania state agencies operating under the Governor's authority, centralizing oversight of their technology infrastructure. The key change is replacing fragmented IT management with a single, accountable office responsible for both operations and cybersecurity across state agencies.
HB 655 requires Pennsylvania's Department of Education to create and annually update a model data security plan for all public and private schools (including charter and cyber charter schools) to protect student information. The plan must include guidelines for data access, privacy standards, breach response procedures, and data retention policies. School entities must follow this model, and the department will designate a chief data security officer to assist schools with implementation. The bill also mandates a working group to develop initial security measures and report on implementation costs by December 2026. (Based on Section 135 of the Public School Code amendment in HB 655.)