Public Safety - Critical Infrastructure Protection
HB1239 establishes a new Critical Infrastructure Protection Branch within the Maryland Coordination and Analysis Center and creates a Chief Critical Infrastructure Officer to lead it. The bill defines “critical infrastructure” broadly to include assets, systems, and networks whose disruption would significantly affect security, economic security, public health, or safety, and expressly includes hospitals and health care facilities. The new branch is tasked with identifying threats, prioritizing critical infrastructure assets, coordinating with state, local, federal, military, and industry partners, and advising the Governor and homeland security officials on infrastructure security issues.
The bill also directs the branch to engage critical infrastructure providers in voluntary cyber and physical assessments, share best practices, and help connect priority assets to resources, grants, and remediation support. It requires the Department of Emergency Management to coordinate consequence management and response to cascading impacts from attacks on critical infrastructure, and requires the Department of Information Technology to allow critical infrastructure owners and operators to join the Maryland Information Sharing and Analysis Center and receive current cybersecurity reporting standards. The act takes effect July 1, 2026, and includes a savings clause stating it does not override existing federal, state, or sector-specific cybersecurity requirements.
HB1239 adds a new subtitle to the Public Safety Article creating a formal state structure for critical infrastructure protection and cybersecurity coordination. It expands the responsibilities of the Maryland Coordination and Analysis Center, the Department of Emergency Management, and the Department of Information Technology, while creating new coordination and information-sharing pathways with critical infrastructure owners and operators. The bill affects public safety, homeland security, cybersecurity, emergency management, and regulated infrastructure sectors, including hospitals and health care facilities, but it expressly preserves existing regulatory frameworks.
The bill appears to have been broadly supported and noncontroversial. It passed the House 120-0 and the Senate 43-0, indicating unanimous or near-unanimous approval in both chambers. The absence of committee transcript material suggests there was little recorded public debate or opposition, and the final status shows it was approved by the Governor.
There is little evidence of substantive contention in the available record. The main policy sensitivity is the bill’s interaction with existing cybersecurity authorities and sector-specific regulation, which the bill addresses directly by stating it does not supersede or limit current federal, state, or industry-specific requirements. Any potential concern would likely center on coordination burdens, information sharing, and the scope of state involvement in privately owned critical infrastructure, but no opposing arguments are reflected in the votes or transcripts provided.