HB974 is an insurance modernization bill that creates two major regulatory frameworks for Missouri. First, it adds the “Insurance Data Security Act,” which sets statewide cybersecurity and data-breach standards for insurers and other insurance licensees handling nonpublic information. The act requires covered entities to maintain written information security programs, conduct risk assessments, use safeguards such as encryption and multi-factor authentication where appropriate, oversee third-party service providers, maintain incident response plans, and notify the Department of Commerce and Insurance within specified timeframes after certain cybersecurity events. It also establishes confidentiality protections for materials submitted to the department, limits private causes of action, and gives the director rulemaking and enforcement authority.
Second, the bill creates the “Peer-to-Peer Car-Sharing Program Act,” regulating insurance coverage and liability for vehicle-sharing platforms. It defines key terms for shared vehicles, drivers, owners, and car-sharing periods, and requires peer-to-peer car-sharing programs to provide or ensure primary motor vehicle liability coverage during the sharing period. The bill addresses uninsured/underinsured motorist coverage, personal injury protection, indemnification, recordkeeping, disclosure obligations, driver eligibility, safety recall procedures, equipment installed by the platform, and recovery rights between insurers. It also clarifies that these provisions do not broadly alter other motor vehicle, airport, or tax laws.
The bill’s impact on state law is substantial in two areas: insurance cybersecurity compliance and peer-to-peer vehicle sharing. It amends chapters 375 and 379, gives the Department of Commerce and Insurance new oversight and enforcement responsibilities, and sets phased compliance dates, including delayed implementation for some cybersecurity requirements. It also creates new statutory duties for insurers, producers, and car-sharing platforms, while carving out exemptions for smaller entities and certain HIPAA-covered organizations. The bill is designed to standardize practices across the insurance industry and to clarify liability and coverage rules for a growing transportation-sharing market.
The general sentiment around the bill appears strongly favorable and largely noncontroversial. It passed the House and Senate with overwhelming support, including unanimous or near-unanimous votes in several stages and only two no votes on the House’s final consideration of Senate amendments. The absence of committee transcript debate in the provided materials also suggests limited recorded opposition or public controversy in the legislative record supplied.
The main points of contention, to the extent they can be inferred from the text, are likely to involve compliance burden, cybersecurity reporting deadlines, and the allocation of insurance responsibility among platforms, owners, drivers, and insurers. Smaller licensees and certain producers are exempted from some requirements, indicating concern about regulatory burden on smaller businesses. In the car-sharing provisions, potential friction points include when platform coverage becomes primary, how disputes over vehicle control are resolved, and the extent to which insurers may exclude coverage for shared-vehicle use. The bill also carefully limits private lawsuits and preserves existing underwriting and cancellation authority, which may reflect efforts to balance consumer protection with industry flexibility.
HB974 amends Missouri’s insurance code by adding new sections to chapters 375 and 379. It establishes statewide cybersecurity standards for insurance licensees, including mandatory information security programs, breach investigation and notice procedures, board oversight, third-party vendor controls, and enforcement authority for the Department of Commerce and Insurance. It also creates a new statutory scheme governing peer-to-peer car-sharing programs, including insurance coverage requirements, liability allocation, disclosure duties, record retention, and recall-related obligations. The bill includes exemptions for certain small entities and delayed effective dates for some provisions, especially the cybersecurity program requirements.
The bill appears to have broad bipartisan support and little visible opposition in the available record. It passed the House and Senate by large margins, with several unanimous votes and only two no votes on the House’s final action on Senate amendments. No committee transcript was provided, so there is no recorded floor or committee debate here indicating significant controversy.
The likely areas of contention are regulatory burden and liability allocation. On the cybersecurity side, insurers and other licensees may be concerned about the cost of implementing written security programs, vendor oversight, encryption, multi-factor authentication, and reporting obligations, which is why the bill exempts some smaller entities and gives delayed compliance dates. On the car-sharing side, the most sensitive issues are which party’s insurance is primary during a sharing period, how disputes over vehicle control are handled, what exclusions insurers may keep in place, and how much responsibility the platform assumes versus the vehicle owner or driver. The bill also limits private causes of action and preserves insurer underwriting/cancellation rights, which may have been important compromise points.