Loading chat...

OR HB4055

Bill

Status

Failed

3/6/2026

Primary Sponsor

Unknown

Origin

House of Representatives

2026 Legislative Measures

AI Summary

  • Local governments, local service districts, and special government bodies must notify the State Chief Information Officer and submit a report within 48 hours of discovering an information security incident or ransomware incident

  • Reports must describe actions taken or planned to prevent, mitigate, or recover from damage, unauthorized access, or impairments to the public body's information system

  • The State Chief Information Officer must establish a secure, confidential reporting system and maintain a webpage with reporting instructions within 90 days of the act's effective date

  • Incident reports are exempt from public records disclosure but may be shared with the Oregon Cybersecurity Center of Excellence, law enforcement, and other entities deemed appropriate

  • The State Chief Information Officer must provide annual reports to the Governor and Joint Legislative Committee on Information Management and Technology summarizing incident notifications received; becomes operative July 1, 2026

Legislative Description

Relating to information security; declaring an emergency.

Last Action

In committee upon adjournment.

3/6/2026

Committee Referrals

Information Management and Technology2/2/2026

Full Bill Text

No bill text available