Relating To Critical Infrastructure.
HB1132 would create a new confidentiality rule for “critical infrastructure information” received or maintained by the Hawaii Office of Homeland Security in connection with the state’s critical infrastructure security and resilience program. The bill declares that such information must be kept confidential and not disclosed to the public, despite the general public records law, except when shared with federal, state, or county agencies for critical infrastructure security purposes. Any agency receiving the information must also keep it confidential.
The bill also adds a statutory definition of “critical infrastructure information,” covering non-public information about threats, attacks, compromises, vulnerabilities, security testing, risk assessments, recovery, reconstruction, insurance, continuity planning, and related operational problems or solutions involving critical infrastructure or protected systems. It expressly preserves existing public access rights to records held by agencies other than the Office of Homeland Security and the agencies that receive this protected information. The bill is set to take effect on July 1, 3000, which appears to function as a placeholder effective date rather than a near-term implementation date.
HB1132 would amend chapter 128A, Hawaii Revised Statutes, by adding a new confidentiality provision and a new definition tied to homeland security and critical infrastructure protection. In practice, it would narrow public access to certain security-related records held by the Office of Homeland Security, while allowing controlled sharing with government partners for security purposes. It would also interact with Hawaii’s Uniform Information Practices Act (chapter 92F) by creating a specific exception for these records, without changing access rights for records held by other agencies outside the protected sharing framework.
Based on the bill text and available context, the measure appears to be framed as a security and resilience initiative with a protective, administrative purpose rather than a controversial policy shift. The description emphasizes confidentiality and coordination among government agencies, suggesting support for safeguarding sensitive infrastructure information. No committee transcripts or recorded votes were provided, so there is no documented opposition or support beyond the bill’s stated intent.
The main potential point of contention is the tension between critical infrastructure secrecy and public records transparency. The bill overrides chapter 92F for information held by the Office of Homeland Security, which could raise concerns about reduced public oversight, but it limits the exception to non-public security information and preserves access to records held by other agencies. Another possible issue is the breadth of the definition, which includes vulnerability assessments, risk audits, recovery planning, and operational problems, potentially covering a wide range of documents that might otherwise be sought under open records laws.