Amends TCA Title 20; Title 29 and Title 47, Chapter 18.
Tennessee HB1033 establishes requirements for covered entities that access, store, or process personal information, personal health information, or restricted information to create and maintain a written cybersecurity program. This bill affects businesses operating in Tennessee that handle sensitive data and outlines key provisions, including the need for administrative, technical, and physical safeguards, as well as the establishment of an affirmative defense against data breach claims if the entity complies with recognized cybersecurity frameworks. Additionally, it mandates the appointment of a chief information officer or security officer to oversee the program and employee training.
Tennessee HB1033 establishes requirements for covered entities that access, store, or process personal information, personal health information, or restricted information to create and maintain a written cybersecurity program. This bill affects businesses operating in Tennessee that handle sensitive data and outlines key provisions, including the need for administrative, technical, and physical safeguards, as well as the establishment of an affirmative defense against data breach claims if the entity complies with recognized cybersecurity frameworks. Additionally, it mandates the appointment of a chief information officer or security officer to oversee the program and employee training.
Track Tennessee Legislation Like a Pro
Join hundreds of professionals using LegisGo to stay ahead of legislative changes.
Instant Alerts
Get notified when bills you track move through the legislature
AI Summaries
Understand complex legislation in seconds with AI-powered analysis
Full Access
All 132 legislators, committee schedules, and voting records