House Bill 215 would amend the Charlotte Firefighters' Retirement System’s governing law to add explicit protections for participants and beneficiaries against data breaches and other cybersecurity incidents. The bill requires the system to maintain data breach and cyber liability insurance, creates a reporting and grievance process for affected members, requires investigation of reported incidents, and directs the board to provide resources to help participants protect their funds and assets after an incident. It also requires the system to include cybersecurity incidents and their costs in the annual report to the Charlotte City Council.
The bill also revises several administrative and fiduciary provisions for the retirement system. It clarifies the roles of the board, actuary, medical board, legal counsel, auditor, administrator, treasurer, and investment fiduciaries, and it adds language allowing system funds to be used for cyber insurance and for making whole participants or beneficiaries harmed by a qualifying breach or cybersecurity incident. The bill applies only to the City of Charlotte and sets deadlines for the board to contract for an administrator, obtain cyber insurance, and establish the reporting mechanism within 60 days of enactment.
HB215 would amend the local act governing the Charlotte Firefighters' Retirement System, changing how the system must manage administration, reporting, insurance, and investment-related fiduciary duties. It would create a new statutory obligation to maintain cyber liability coverage and to compensate affected participants or beneficiaries for losses caused by covered data breaches or cybersecurity incidents occurring on or after the effective date. It also requires reporting of such incidents to the City Council and directs the board to investigate incidents reported within a year before or after enactment, with remedial resources provided if an incident is found.
The available record shows no committee transcript or recorded votes, so there is no documented floor or committee debate to gauge broad sentiment. Based on the bill text, the measure appears to be framed as a protective, remedial local bill intended to strengthen retirement-system security and participant protections. Its structure suggests a generally supportive policy goal centered on safeguarding firefighters' retirement assets and responding to cybersecurity risk.
No specific points of contention are documented in the provided materials. Potential areas of concern inherent in the bill include the cost of cyber insurance, the administrative burden of creating grievance and investigation procedures, and the open-ended obligation to make participants or beneficiaries whole after a qualifying incident. The bill also directs the board to assess whether the current administrator has failed to meet contractual obligations, which could raise questions about existing vendor performance and implementation.