Utah 2025 Regular Session

Utah House Bill HB0492

Introduced
2/13/25  
Refer
2/18/25  
Report Pass
2/21/25  
Engrossed
2/24/25  
Refer
2/26/25  
Report Pass
3/3/25  

Caption

Drinking Water Utilities Amendments

Summary

HB0492, the Drinking Water Utilities Amendments, establishes new cybersecurity and physical-security requirements for community water systems in Utah. It requires each community water system supplier to complete a security plan on a staggered schedule based on system size, with larger systems due first, and to update and certify completion annually. The required plan must address cybersecurity training, software maintenance, network protections, secure authentication, vulnerability assessments, access termination for departing employees, manual operation capability, and compliance with federal security requirements and directives from the Division of Drinking Water director. The bill also creates a rapid incident-reporting requirement: a community water system must report a security breach to the Utah Cyber Center within two hours of discovering it, and the Cyber Center must notify the Division of Drinking Water within one day. In addition, the Division of Drinking Water must provide technical resources to systems preparing plans and submit an annual report to two legislative committees on security incidents, security plans, and any recommendations for legislation or funding. The bill further classifies security plans, incident reports, and related records for drinking water and wastewater facilities as protected records under the Government Records Access and Management Act (GRAMA).

Impact

HB0492 amends Utah Code provisions governing the Division of Drinking Water and public records law, and it enacts a new section requiring community water systems to adopt formal security planning and breach-reporting procedures. It expands the director’s duties to include ensuring compliance with the new security-plan requirements and adds protected-record status for security-related water utility records, limiting public access to sensitive operational and cybersecurity information. The bill affects community water system suppliers, the Division of Drinking Water, and the Utah Cyber Center, while also creating annual reporting obligations to legislative committees.

Sentiment

The bill appears to have broad support. It received unanimous favorable recommendations in House committee, passed the House on third reading 68-0, and later received unanimous favorable and substitute recommendations in Senate committee. The available voting history suggests the legislation was viewed positively as a public-safety and infrastructure-security measure, with no recorded opposition in the provided materials.

Contention

No formal committee transcript is provided, and the recorded votes show no opposition, so there is little evidence of active controversy in the available record. The main policy tradeoff embedded in the bill is between transparency and security: it shields security plans, incident reports, and related facility records from public disclosure to reduce risk of misuse, while requiring annual legislative reporting and rapid breach notification to preserve oversight. Any potential concerns would likely center on compliance burdens for smaller water systems, the two-hour breach-reporting deadline, and the scope of records classified as protected.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.