Requires a local government, local service district or special government body to notify and submit a report to the State Chief Information Officer within 48 hours of an information security incident or ransomware incident.
HB 4055 creates a new statewide incident-reporting requirement for Oregon local public bodies. It requires local governments, local service districts, and special government bodies to notify the State Chief Information Officer within 48 hours after discovering an information security incident or ransomware incident, and to submit a report describing the incident and the steps taken or needed to prevent, mitigate, or recover from the damage. The bill defines covered incidents broadly enough to include substantial losses of confidentiality, integrity, or availability, operational disruption, compromise of safety and resilience, and certain third-party provider breaches affecting public bodies.
The measure also directs the State Chief Information Officer to build and maintain a secure reporting system and a public webpage with instructions on how to report incidents. The CIO must be able to track trends, identify threat indicators, and compile information for reporting, while also producing an annual report to the Governor and the Joint Legislative Committee on Information Management and Technology summarizing the number and types of incidents and the kinds of public bodies affected. The bill is set to become operative on July 1, 2026, but it declares an emergency so it would take effect immediately upon passage, allowing implementation work to begin beforehand.
HB 4055 would add a new compliance obligation for local public bodies in Oregon by requiring rapid cyber incident reporting to the State Chief Information Officer. It would also create a new state-level reporting infrastructure and establish confidentiality protections by exempting incident reports from public records disclosure. The bill would affect local governments, local service districts, special government bodies, the State Chief Information Officer, and potentially law enforcement and cybersecurity partners who may receive shared or anonymized information under the measure.
The available record suggests the bill was introduced as a cybersecurity and public-safety measure and was not accompanied by recorded committee testimony or votes in the materials provided. Its structure and emergency clause indicate a policy emphasis on prompt response, coordination, and information sharing for cyber incidents affecting public entities. Because there is no transcript or voting history here, there is no documented opposition or support to characterize beyond the bill’s apparent administrative and security-focused purpose.
No committee transcript or vote record is included, so specific points of contention are not documented in the provided materials. Based on the text, likely issues of debate would include the 48-hour reporting deadline, the scope of incidents that must be reported, confidentiality and public-records exemptions, and the administrative burden on smaller local public bodies. Another possible area of concern is the breadth of the State Chief Information Officer’s discretion to share incident information with law enforcement, the Oregon Cybersecurity Center of Excellence, or other entities deemed appropriate.