Maryland 2025 Regular Session

Maryland Senate Bill SB691

Introduced
1/30/25  
Refer
1/30/25  
Report Pass
3/31/25  
Engrossed
4/1/25  
Refer
4/2/25  
Refer
4/2/25  
Report Pass
4/3/25  
Enrolled
4/7/25  

Caption

Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

Summary

SB691 establishes a new cybersecurity framework for Maryland’s “healthcare ecosystem,” which includes hospitals, freestanding medical facilities, health information exchanges, electronic data interchange clearinghouses, carriers, and pharmacy benefits managers, but excludes governmental payors. The bill requires the Maryland Health Care Commission and the Maryland Insurance Administration to each employ at least one cybersecurity expert, use that expertise to oversee regulated entities, and coordinate with the Office of Security Management on cybersecurity issues. It also directs the agencies to adopt regulations setting cybersecurity standards and procedures aimed at preventing disruptions, maintaining essential healthcare services, and supporting recovery after an incident. The bill imposes direct obligations on covered healthcare ecosystem entities. These entities must adopt cybersecurity standards at least as strong as those set by the relevant agency, implement a zero-trust approach for on-premises and cloud services, meet minimum security standards for operational and information technology devices, and undergo third-party cybersecurity audits every two years beginning January 1, 2026. They must also submit audit reports and, through the Commission or Administration, provide certifications of compliance. In addition, cybersecurity incidents must be reported to the State Security Operations Center, which must notify appropriate state and local agencies, and the Office of Security Management must provide annual reporting to the Governor, the Maryland Cybersecurity Coordinating Council, and the General Assembly on reported incidents. The bill also creates the Healthcare Ecosystem Stakeholder Cybersecurity Workgroup, a broad stakeholder group led by the Maryland Health Care Commission and the Maryland Insurance Commissioner. The workgroup includes legislators, state cybersecurity and emergency management officials, healthcare and insurance industry representatives, cybersecurity organizations, and patient advocates. Its charge is to identify essential healthcare capabilities, map ecosystem dependencies, assess threats and risks, review best practices such as NIST and HICP guidance, and make recommendations for cybersecurity standards and resilience. The workgroup must issue an interim report by January 1, 2026, and a final report by December 1, 2026, and the workgroup provisions are temporary and set to expire after a limited period. The bill’s impact on state law is significant because it adds new regulatory duties to the Health – General, Insurance, and State Finance and Procurement Articles, expanding state oversight of healthcare-related cybersecurity. It creates new reporting, audit, and compliance requirements for a wide range of healthcare and insurance entities, while also formalizing interagency coordination and incident reporting procedures. The legislation is designed to improve continuity of care and resilience against cyberattacks by tying cybersecurity requirements to patient safety and essential services. Overall sentiment appears strongly favorable. The Senate adopted the bill, and the recorded floor votes were overwhelmingly in support, with 39-7 in the Senate and 136-3 in the House. No committee transcript excerpts were provided, but the vote margins suggest broad bipartisan agreement that healthcare cybersecurity is a pressing issue and that the state should take a more structured, proactive role. The main points of contention likely concern the scope of regulated entities, the cost and burden of recurring third-party audits and compliance reporting, and the extent to which state standards should be imposed on private healthcare and insurance organizations versus allowing industry-led practices.

Impact

SB691 amends Maryland law to create new cybersecurity oversight, reporting, audit, and rulemaking requirements for healthcare ecosystem entities and the state agencies that regulate them. It adds provisions to the Health – General, Insurance, and State Finance and Procurement Articles, requires agency cybersecurity staffing and regulations, mandates incident reporting to the State Security Operations Center, and establishes a temporary stakeholder workgroup to study and recommend improvements to healthcare cybersecurity and resilience.

Sentiment

The bill appears to have broad support and little visible opposition in the recorded votes. It passed the Senate 39-7 and the House 136-3, indicating strong bipartisan approval for strengthening healthcare cybersecurity protections. The absence of committee transcript excerpts limits direct insight into debate, but the vote totals suggest consensus that the bill addresses an important public-safety and infrastructure issue.

Contention

The likely areas of contention are operational and economic rather than ideological: which entities should be covered, how stringent the required cybersecurity standards should be, how often audits should occur, and who bears the cost of compliance. Healthcare providers, insurers, clearinghouses, PBMs, and related stakeholders may differ on the practicality of zero-trust requirements, third-party audits, and incident reporting timelines. Another possible point of debate is the bill’s broad regulatory authority for the Commission and Administration to define standards and identify additional covered entities by regulation.

Companion Bills

MD HB333

Crossfiled Healthcare Ecosystem Stakeholder Cybersecurity Workgroup

Similar Bills

No similar bills found.