Florida 2025 Regular Session

Florida House Bill H1183

Introduced
2/26/25  
Refer
3/5/25  
Refer
3/5/25  
Refer
3/5/25  
Refer
3/26/25  
Refer
3/26/25  
Refer
4/4/25  

Caption

Cybersecurity Incident Liability

Summary

H1183 creates a new section of Florida law limiting liability for cybersecurity incidents when a county, municipality, other political subdivision, covered entity, or third-party agent has adopted and maintained specified cybersecurity safeguards. For public entities, the bill provides that they are not liable for a cybersecurity incident if they have policies that substantially comply with recognized cybersecurity standards or frameworks, along with disaster recovery planning and multi-factor authentication. For private covered entities and third-party agents handling personal information, the bill creates a presumption against liability in class actions if they maintain a qualifying cybersecurity program. The bill defines qualifying frameworks broadly, including NIST, CIS, ISO/IEC, HITRUST, SOC 2, and similar standards, and it also recognizes compliance with certain existing federal or state regimes such as HIPAA, GLBA, FISMA, HITECH, and CJIS. To retain the liability protection, entities must update their cybersecurity programs within one year of revisions to the applicable standards or laws. The bill also states that it does not create a private cause of action and bars plaintiffs from using the mere availability of the liability shield as evidence of negligence or fault.

Impact

The bill would add a new liability-defense framework to Florida’s civil code, specifically section 768.401, and would affect litigation arising from cybersecurity incidents involving public bodies and private entities that collect, store, process, or use personal information. It shifts the legal focus toward whether an entity substantially complied with recognized cybersecurity practices, and it places the burden on the defendant to prove substantial compliance when invoking the protection. The bill applies to putative class actions filed before, on, or after the effective date, which gives it broad retroactive reach in class-action litigation.

Sentiment

The available vote history suggests generally favorable sentiment toward the bill in committee, with strong majority support in both the House Information Technology Budget & Policy Subcommittee and the House Civil Justice & Claims Subcommittee. The absence of committee transcripts limits insight into detailed debate, but the vote margins indicate the measure was viewed positively by most members. Overall, the bill appears to have been treated as a pro-cybersecurity, pro-liability-limitation measure.

Contention

The main policy tension is between encouraging adoption of cybersecurity best practices and preserving remedies for people or entities harmed by data breaches. Supporters are likely to favor the bill because it rewards compliance with recognized security standards and may reduce litigation exposure for entities that invest in cybersecurity. Potential opponents may object that the bill makes it harder for plaintiffs to recover after a breach, especially because it creates a presumption against liability in class actions and prevents plaintiffs from arguing that failure to qualify for the shield itself is evidence of negligence. Another point of contention is the bill’s broad applicability to both public entities and private third-party processors, as well as its retroactive application to pending class actions.

Companion Bills

FL S1576

Same As Cybersecurity Incident Liability

Similar Bills

No similar bills found.