Cybersecurity of Mortgage Brokers and Lenders and Money Services Businesses:
SB 1216 would create new cybersecurity requirements for two categories of Florida financial licensees: mortgage brokers and lenders under chapter 494, and money services businesses under chapter 560. For each group, the bill requires a written information security program with administrative, technical, and physical safeguards to protect customer information and information systems, along with a written incident response plan for responding to cybersecurity events. The bill also defines key terms such as customer information, nonpublic personal information, cybersecurity event, third-party service provider, and information system.
The bill sets minimum standards for those security programs, including periodic testing and monitoring, retention and destruction schedules for sensitive data, and ongoing updates to address changes in technology, business arrangements, and threats. It also requires prompt investigation of suspected cybersecurity events, documentation of those investigations, retention of records for five years, and notice to the Office of Financial Regulation when a breach affects 500 or more persons in Florida. The bill allows the Financial Services Commission to adopt implementing rules and provides that compliance with the FTC’s Safeguards Rule may be deemed compliance with the new mortgage-broker/lender cybersecurity section.
The bill would add new sections to the Florida Statutes, creating section 494.00170 for mortgage brokers and lenders and section 560.1215 for money services businesses. It would also amend the disciplinary provisions in sections 494.00255 and 560.114 so that failure to comply with the new breach-notification requirements becomes an explicit ground for administrative action, including penalties, cease and desist orders, removal orders, and license denial, suspension, or revocation. The Office of Financial Regulation would gain a clearer enforcement role, and affected licensees would need to build or update cybersecurity compliance programs, incident response procedures, and reporting practices.
The available context suggests the bill was generally treated as a regulatory and consumer-protection measure rather than a controversial policy change. There are no recorded committee transcripts or votes in the provided material, and the bill ultimately died in the Senate Banking and Insurance Committee. The structure of the bill, including an exemption for smaller licensees and a compliance safe harbor tied to the FTC Safeguards Rule, suggests an effort to balance stronger cybersecurity standards with operational flexibility for regulated businesses.
No specific points of contention are documented in the provided committee materials, but the bill’s likely pressure points are clear from its text. Affected mortgage and money services firms may have been concerned about the cost and administrative burden of creating formal security programs, incident response plans, investigations, recordkeeping, and breach reporting. Smaller licensees are partially shielded by an exemption for firms with fewer than 20 workers or fewer than 500 customers a year, which indicates that scope and compliance burden were important issues. Another possible area of debate is the interaction with existing Florida breach-notification law in section 501.171 and whether the new chapter-specific requirements duplicate or expand existing obligations.