Displaying 6 results for

Search Filters: Policy cancel California cancel Florida cancel Utah cancel

State Policy Trends in Cybersecurity and Public Health Preparedness

Blog,
Utah,

State Policy Trends in Cybersecurity and Public Health Preparedness Maggie Nilz Learn how states are including cybersecurity in their emergency preparedness work in this Health Policy Update. Cybersecurity is an increasingly important component of public health preparedness as state cybersecurity policy intersects with public health agency responsibilities. Public health agencies rely on interconnected digital systems and critical infrastructure for disease surveillance, laboratory reporting, emergency communications, and health data management, making cybersecurity critical to maintaining these functions. Beyond compromising sensitive data and potentially harming patients, cyber incidents can disrupt essential public health services, including emergency response operations. Health care data breaches have steadily increased over the last 15 years, highlighting growing risks for government and health systems. A recent report showed that more than 7,000 health care data breaches were reported to the Department of Health and Human Services since 2009, and reported HIPAA data breaches in 2023 were nearly double the number recorded in 2018. Meanwhile, preparedness capacity has lagged: as of 2022, only 13% of local health departments reported being prepared for cyber-related disruptions, and recent scans show cybersecurity is rarely included in emergency preparedness planning. In response at the federal level, HHS recently announced it is undoing a 2024 reorganization by returning department-wide technology responsibilities to the Office of the Chief Information Officer while refocusing the Office of the National Coordinator for Health Information Technology on improving nationwide health IT interoperability and data sharing. In recent years, state and territorial legislatures have begun to address these gaps by incorporating cybersecurity into preparedness, health care oversight, and statewide governance structures. These legislative trends signal a need to integrate cybersecurity into emergency operations plans, strengthen cross-sector coordination, and safeguard the continuity of public health services. Some of the most recent policies considered and enacted by legislatures treat cyber incidents as emergencies, expand reporting requirements, and strengthen cyber governance. Cyber Incidents Are Being Built into Emergency Preparedness Frameworks In response to these growing threats, jurisdictions have begun incorporating cyber response into emergency plans and strategies, reinforcing cybersecurity as essential to preparedness. These developments highlight growing awareness that cyber incidents can disrupt critical services, much like natural disasters. In 2025, New York enacted S 7672, which requires municipal entities and public authorities report cybersecurity incidents and demands for ransom to the state Division of Homeland Security and Emergency Services. In addition, it directs the Director of the Office of Information Services to establish cybersecurity training and protection standards for state systems as well as require cybersecurity training for state and local government employees. Virginia is currently considering HB 83, which would establish a volunteer Cyber Civilian Corps within the state IT agency to provide rapid assistance during cybersecurity incidents affecting municipalities, nonprofits, education, and critical infrastructure. Preparedness efforts also extend beyond legislation to executive action. In February 2026, Minnesota Governor Tim Walz authorized $1.2 million in state disaster assistance to support response efforts and restore critical systems in response to a cyber incident that disrupted digital services in Saint Paul on July 29, 2025. Additionally, the National Governors Association has included cybersecurity as a primary consideration for planning and preparedness in their latest edition of the Public Health Emergency Playbook. Health care and Public Health Critical Sectors Are Facing New Cyber Requirements Beyond emergency response frameworks, jurisdictions are also adopting cybersecurity reporting and planning requirements for health care and public health organizations. Companion bills in Tennessee (HB 511/SB 555) would require health care providers and facilities to notify their contracted health insurers of cybersecurity incidents. In Maine, LD 2103 would require hospitals to adopt cybersecurity plans to protect patient data and maintain operations, and must include cybersecurity training for employees and board members. New Jersey is looking to adopt and implement a more comprehensive cybersecurity plan across all sectors. This session, legislators have introduced at least two cyber security bills: A 3231 would require “sensitive businesses” (defined as those engaged in financial, essential infrastructure, or health care industries) to report cybersecurity incidents to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) when they are aware of their occurrence and would require NJCCIC to conduct a cybersecurity audit within 30 days of notification. A 3283 would require the same “sensitive businesses” to implement cybersecurity programs in accordance with standards adopted by NJCCIC and certify compliance annually. As states expand reporting and cybersecurity requirements, these obligations may intersect with public health reporting and continuity planning. States Are Strengthening Government Cyber Governance and Coordination In addition to sector-specific requirements, jurisdictions are also strengthening the governance structures responsible for coordinating cybersecurity, improving their ability to respond to large-scale incidents affecting public systems. Legislation enacted recently in Texas and California aim to improve coordination among state government by establishing a state agency centralizing cybersecurity incident prevention and response (Texas HB 150) and mandating the development of a cybersecurity playbook to strengthen information sharing (California AB 979). A 2024 bill enacted in Puerto Rico (PC 1530) requires commonwealth agencies to develop and implement a cybersecurity program, which must include a yearly risk assessment as well as vulnerability assessment. At least three jurisdictions are currently considering bills strengthening established cybersecurity programs, with two states recently passing legislation. Utah recently enacted a bill authorizing the Utah Cyber Center to conduct voluntary cybersecurity risk assessments for critical infrastructure and coordinate with government entities on infrastructure safety (HB 165). Utah also enacted legislation creating a specific funding stream for the Center to use for various activities, including implementing a statewide cybersecurity plan and conducting assessments for governmental entities (SB 123). Kansas enacted HB 2574, which would require chief information security officers for the executive, legislative, and judicial branches to adopt cybersecurity programs based on a nationally recognized standard for governmental entities. Finally, Florida recently passed SB 7024, which would expand the state’s public record exemption to include risk assessments, information related to cybersecurity breaches, and information related to data protection, ensuring the confidentiality of sensitive cybersecurity information held by state agencies; the bill is with the governor for final consideration. Key Takeaways for Preparedness Leaders Cybersecurity is critical for preparedness across multiple policy areas, and requires new planning, coordination, and oversight responsibilities. By including cyber incidents into disaster frameworks, standards for health care organizations, and governance, preparedness leaders may find themselves more directly engaged in integrating cybersecurity into emergency operations, exercises, and cross-sector partnerships. For state and territorial health agencies beginning to incorporate cybersecurity into their preparedness plans, agencies such as the Cybersecurity and Infrastructure Security Agency provide jurisdictional support and resources to guide this work. article yes

Shifting Legal Landscape of Public Health and Places of Worship

Blog,
Ohio,
Utah,

Reconciling the tension between public health and civil liberties is one of the most significant challenges of public health law and ethics. The Supreme Court of the United States historically upheld state authority to enact and enforce public health laws that temporarily limit a person’s civil liberties, such as quarantine and isolation powers that restrict a person’s freedom of assembly in order to prevent the spread of contagious disease. There have been many legal challenges to the public health orders issued to slow the spread of COVID-19—many of the claims asserting violations of First Amendment rights of assembly, association, and expression—but they’ve largely been rejected by the courts. However, courts have treated claims asserting violations of the free exercise of religion more favorably, which may indicate an impending shift in how courts analyze the impact state and territorial actions may have on religious organizations.

Domestic Holiday Travel Pandemic Restrictions and Recommendations

Blog,
Guam,
Iowa,
Ohio,
Utah,

The 2020 holiday season is coinciding with a nationwide surge of COVID-19 cases. With great concern that holiday travel to see loved ones may exacerbate community spread of the virus, many states are increasing public health measures before the winter holiday season. As of November 16, 2020, 13 states and D.C. had a quarantine requirement for out-of-state travelers. The U.S. territories also have instituted travel restrictions to limit the spread of COVID-19.

COVID-19 Pandemic Underscores Need for Tobacco Control Policies

Blog,
Utah,

The COVID-19 pandemic has further amplified the need for strong tobacco prevention and cessation policies. Research indicates that tobacco use is associated with increased rate of COVID-19 disease progression and increased likelihood of death among hospitalized patients, and that e-cigarette use is associated with a greatly increased risk of COVID-19 diagnosis in youth and young adults.

Do Cottage Foods Really Come from a Cottage?

Blog,
Iowa,
Ohio,
Utah,

Do Cottage Foods Really Come from a Cottage? Beth Giambrone Even if you're not familiar with the term "cottage foods," chances are you have purchased them—think getting a loaf of bread from your weekend farmers market or cookies from a friend's home-based baking business. In some cases, they can also be sold online. So, what exactly are they? Cottage foods are home-based, home-made food products prepared outside a commercial kitchen and sold to the public. Cottage food producers operate at a small scale, often from a home kitchen, selling goods in the jurisdiction where they are created. Cottage foods are exempt from many state food and safety regulations, with supporters of expanding cottage food laws asserting that existing laws burden small business and restrict competition and consumer freedom. Those opposing the expansion of cottage foods argue the need to ensure food safety and to protect consumers from food borne illness. Here's a primer on cottage foods and how they're regulated. What's the difference between a cottage food kitchen and a commercial kitchen? Commercial kitchens (sometimes known as shared use kitchens) are large, industrial spaces where food can be produced in high volumes; they can also be rented out for shared use. While every state subjects commercial kitchens to food safety inspection and regulations, a few states require inspection of microenterprise or home kitchens producing cottage foods. Does the government have a role in regulating cottage foods? While several federal agencies regulate commercial food products—such as USDA for meat processing and FDA for produce—cottage foods are not subject to federal regulation because they are typically only sold within a state and not across state lines. At the state level, cottage food producers are subject to the health and safety laws and regulations of the state in which they are operating. Some states require cottage food producers to register their business or to have training and/or certification in safe food handling. Currently, all 50 states and Washington D.C. have some sort of cottage food law in place. Under most state laws, cottage food producers are exempt from food safety laws that apply to food establishments. These exempt rules are usually based on the type of food product produced, the point of sale, and the labeling requirements associated with the food. Although cottage food producers are exempt from certain requirements, all states allow the Department of Health to investigate complaints related to foodborne illness and fine producers if there are violations. Since the 2020 legislative sessions, at least 17 states (Alabama, Arkansas, California, Connecticut, Florida, Iowa, Illinois, Maryland, Missouri, Mississippi, New Hampshire, New Jersey, Oklahoma, Tennessee, Utah, West Virginia, and Wyoming) considered bills related to cottage foods, often centering around product sales, food products, and labeling. An overview of the conditions and a snapshot of the laws passed in states are below. What are common cottage food products? Most state laws limit which food products can be produced and sold as cottage foods. And while specific allowable foods vary state to state, some common restrictions on the type of food sold include foods requiring temperature control (e.g., meat and dairy products) and fermented or pickled foods. Foods such as dairy-free baked goods (e.g., breads and biscuits), candies, and jams are popular cottage food products. Over the last few years, states have expanded the types of foods that qualify to be a cottage food. In 2021, Illinois enacted SB 2007, amending the types of foods permissible under the cottage food law from a delineated list of canned foods (e.g. jams and syrups) to a general standard that mirrors the FDA definition of "low-acid canned food." The New Jersey legislature passed A 3991 in 2022 to exempt raw, unprocessed honey from the state's cottage food regulations. The bill is currently awaiting action by the governor. Oklahoma enacted its "Homemade Food Freedom Act" (HB 1032) in 2021. This new law allows any packaged food or beverage (excluding alcoholic beverages, unpasteurized milk, or cannabis products) to be considered a cottage food rather than only baked goods made without meat or fresh fruits. Additionally, the law allows beekeepers who produce less than 500 gallons of honey per year to qualify for the state's food freedom exemptions if the honey is produced from hives located in the state and sold directly to the consumer. Similarly, the 2022 "Tennessee Food Freedom Act" (HB 813/SB 693) broadly expands the types of homemade foods eligible for sale under the cottage food law to include any non-time/temperature-controlled food item or non-alcoholic beverage. What limitations do states place on cottage food sales? Most states limit cottage food producers to direct-to-consumer sales, such as at a farmers market or roadside stand. More than half of states allow online and direct-to-consumer sales as long as they are to in-state consumers only. While the producer is usually required to deliver the products, at least five states allow delivery by a third party. Several states have considered allowing the sale of cottage food in retail settings. In 2020, Wyoming enacted HB 84, which increased the gross sales cap for producers and allowed producers of non-temperature controlled foods (e.g., jams, vegetables, dried soup mixes) to use third-party vendors like a retail shop rather than solely relying on gross sales. Furthermore, the Wyoming legislature expanded the use of third-party vendors to include the sale of eggs in 2021 by enacting HB 118. A 2021 Arkansas law (HB 248) also allows for the sale of cottage food products at retail stores. Additionally, many states define cottage foods based on the number of items sold or the annual gross sales. The gross sales cap limits vary greatly across states, ranging from $3,000 to $250,000. At least twenty states have no gross sales limit. At least one state (Ohio) places a limit on meals sold per week from home kitchens. What are common labeling requirements for cottage foods? Most states require cottage food producers label their goods. While specific labeling requirements vary state to state, producers generally must provide the name of the product, a list of ingredients, known allergens (e.g., nuts), contact information of the producer, and a statement declaring the product was made in a kitchen exempt from licensing and inspection regulations. In some states, cottage food producers are allowed to use an identification number in place of contact information on product labels. Maryland enacted HB 1017 in 2020, which allows cottage food producers to use a unique identification number issued by the Department of Health in lieu of the business name and address. Arkansas HB 248 (referenced above) also allows producers to use an identification number. What's next? State policy surrounding cottage foods is constantly evolving, with more foodstuffs exempt from state food and safety regulations increasing the risk of foodborne illness outbreaks necessitating a public health response. ASTHO will continue monitoring these changes and provide relevant updates. website yes