Loading chat...

ME LD2103

Bill

Status

Introduced

1/7/2026

Primary Sponsor

Julia McCabe

Click for details

Origin

House of Representatives

132nd Legislature

AI Summary

  • Licensed hospitals must adopt and annually update a cybersecurity plan and submit it to the Department of Health and Human Services

  • Cybersecurity plans must include timely notification procedures for intrusions to law enforcement, patients, health care providers, municipalities, and state regulators

  • Plans must address backup communications, patient triage, diversion of services, regional hospital partnerships, and patient complaint processes to ensure continuity of care during cyber incidents

  • Hospitals must provide cybersecurity training for employees, board members, and affiliated organizations, and conduct annual test runs of their cybersecurity plans

  • Cybersecurity intrusions that impact patients' access to medical care are added to the definition of "sentinel event," requiring mandatory reporting

Legislative Description

An Act Requiring Hospitals to Adopt Cybersecurity Plans

Health Care Services

Last Action

Voted: OTP-AM

3/11/2026

Committee Referrals

Health And Human Services1/7/2026

Full Bill Text

No bill text available