Cybersecurity bills in Tennessee

Every bill in the Tennessee Legislature that falls inside the Cybersecurity Legislation Tracker's scope, with where each one currently stands.

5

Bills in Scope

0

Past Committee

5 February 2026

Most Recent Action

Cybersecurity bills in Tennessee

5Introduced or inactive

5 bills in scope

Introduced or inactive

5

HB 2312Criminal Offenses - As introduced, clarifies that the criminal offense of knowingly accessing a communication or computer system for the purpose of fraud or theft includes accessing a cloud computing service. - Amends TCA Title 4; Title 10; Title 35; Title 37; Title 38; Title 39; Title 40; Title 45; Title 47; Title 65; Title 66; Title 67 and Title 71.IntroducedHB 1033Civil Procedure - As introduced, creates an affirmative defense that may be utilized by a covered entity that is the subject of a data breach, if the covered entity’s cybersecurity program meets certain criteria at the time the breach occurs. - Amends TCA Title 20; Title 29 and Title 47, Chapter 18.In committeeHB 481State Government - As introduced, increases membership of the information systems council by adding a state employee with experience in the field of cybersecurity, to be appointed by the governor. - Amends TCA Title 4, Chapter 3.In committeeHB 511Insurance, Health, Accident - As introduced, requires a healthcare provider, healthcare group, practice, or clinic, healthcare facility, or other entity to provide notice to each health insurance entity with which it is under contract as soon as practicable if the healthcare provider, healthcare group, practice, or clinic, healthcare facility, or other entity is the subject of a cyber-attack. - Amends TCA Title 33; Title 56; Title 63; Title 68, Chapter 11 and Title 71.IntroducedHB 549State Government - As introduced, creates the "Tennessee Critical Infrastructure Act." - Amends TCA Title 4.In committee

Bill titles link to the Tennessee Legislature's own page.

Coverage depth varies by jurisdiction. How this is measured, and where it is thinner.

What's In Scope

How Cybersecurity Legislation bills are selected

In scope is any bill imposing security duties on an identifiable party: incident notification to a regulator or an affected person, written information security programs and reasonable security standards, ransomware payment restrictions and disclosure, vendor and supply chain requirements, and the treatment of industrial control systems and supervisory control and data acquisition systems.

Scope is defined by a written topic profile that every bill is measured against. The profiles are drafted by a model and validated by retrieval measurement against a judged set of bills, not reviewed by an attorney. LawSignals is a research tool and does not provide legal advice.

Tennessee is one of Cybersecurity Legislation's jurisdictions

The tracker follows this subject everywhere it is legislated, and publishes a monthly issue on what moved across all of them.