Florida’s cybersecurity laws sit in three main places: the Florida Information Protection Act (FIPA), which governs how businesses and agencies handle personal data; Chapter 282, which sets security standards for state agencies and local governments; and Chapter 815, which criminalizes unauthorized computer activity. Together they require reasonable data safeguards, breach notification within 30 days, and impose civil penalties up to $500,000 per breach along with felony charges for hacking that endangers lives or hits medical systems.
Who FIPA Covers and What Data It Protects
FIPA, codified at Florida Statutes section 501.171, reaches any entity that acquires, uses, stores, or maintains personal information belonging to Florida residents. Physical presence in the state is not required. Sole proprietorships, corporations, government entities, and third-party agents contracted to handle data are all covered.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
The law kicks in when someone’s first name (or first initial) and last name appear together with any unencrypted sensitive data element:
- Social Security numbers
- Driver’s license, passport, or military ID numbers
- Financial account or card numbers paired with the security code or password needed to access the account
- Medical information, including health history, diagnoses, or treatment records
- Health insurance policy numbers, subscriber IDs, or other unique insurer-assigned identifiers
- Biometric data
- Geolocation information
A username or email address combined with the password or security question that unlocks an online account also qualifies as personal information on its own, without a name attached.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Encrypted data is outside the definition. So is information a government entity has already made publicly available.
Security and Disposal Duties Under FIPA
Every covered entity, government entity, and third-party agent must take reasonable measures to protect electronic data containing personal information. The statute does not name a specific security framework, so what counts as reasonable scales with the volume and sensitivity of what you hold.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
When customer records are no longer needed, you must dispose of them by shredding, erasing, or otherwise modifying the personal information so it cannot be read or reconstructed. The same duty applies to third-party agents holding data on your behalf.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Breach Notification Timelines
Under FIPA, a breach is unauthorized access to electronic data containing personal information. Good-faith access by an employee or agent does not count, provided the information is not used for unrelated purposes or further disclosed without authorization.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Notifying Affected Residents
You must notify every affected Florida resident within 30 days after determining the breach occurred. The notice has to include the date or estimated date range of the breach, a description of the personal information involved, and contact information the person can use to reach you about it. If you can show good cause, you may request an additional 15 days by writing to the Department of Legal Affairs within the original 30-day window.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Notifying the State and Credit Bureaus
A breach affecting 500 or more Florida residents also requires written notice to the Florida Department of Legal Affairs within the same 30 days. At 1,000 or more individuals, you must additionally notify all nationwide consumer reporting agencies about the timing, distribution, and content of the individual notices.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Third-Party Agents
If the breach hits a system maintained by a third-party agent, that agent has 10 days from discovery to notify the covered entity. The tight window is meant to preserve enough time for the primary entity to meet its 30-day obligations.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Penalties and Enforcement
Late notification carries civil penalties calculated per breach, not per affected individual:
- $1,000 per day for the first 30 days past the deadline
- $50,000 for each 30-day period after that, up to 180 days
- A maximum of $500,000 per breach beyond 180 days
The $500,000 cap applies to notification-timing penalties. Other enforcement remedies are available on top of it.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
FIPA violations are treated as unfair or deceptive trade practices, and the Florida Department of Legal Affairs brings enforcement actions. The statute does not create a private cause of action, so individuals cannot sue a company under FIPA for mishandling their data. Enforcement runs exclusively through the state.1Online Sunshine. Florida Code 501.171 – Security of Confidential Personal Information
Rules for State Agencies
State agencies work under a more prescriptive regime at Florida Statutes section 282.318. The Florida Digital Service within the Department of Management Services sets the standards, and every state agency must develop and maintain a cybersecurity program aligned with those standards.2Florida Senate. Florida Code 282.318 – Cybersecurity
Incident reporting for state agencies runs on a severity-based timeline. Level 3, 4, or 5 cybersecurity incidents must be reported to the Cybersecurity Operations Center and the Cybercrime Office of the Department of Law Enforcement within 48 hours of discovery. Ransomware incidents must be reported within 12 hours. Reports must include a summary of the facts.2Florida Senate. Florida Code 282.318 – Cybersecurity
Rules for Local Governments
Counties and municipalities are governed by the Local Government Cybersecurity Act at section 282.3185. They must adopt cybersecurity standards consistent with generally accepted best practices, including the NIST Cybersecurity Framework. Deadlines were staggered: counties with 75,000 or more residents and municipalities with 25,000 or more had to comply by January 1, 2024, while smaller jurisdictions had until January 1, 2025.3Online Sunshine. Florida Code 282.3185 – Local Government Cybersecurity
The incident reporting deadlines mirror those for state agencies: 48 hours for Level 3, 4, or 5 incidents and 12 hours for ransomware. Local governments must also notify the sheriff with jurisdiction over the local government, in addition to the Cybersecurity Operations Center and the Cybercrime Office.3Online Sunshine. Florida Code 282.3185 – Local Government Cybersecurity
Training is mandatory. All local government employees with network access must complete basic cybersecurity training within 30 days of starting work and annually after that. Technology professionals and employees with access to highly sensitive information take an advanced curriculum on the same schedule.3Online Sunshine. Florida Code 282.3185 – Local Government Cybersecurity
Criminal Computer Offenses
Chapter 815 criminalizes unauthorized computer activity. These offenses target the people doing the hacking rather than the organizations that fail to prevent it.
Knowingly accessing a computer without authorization, disrupting data transmission, destroying equipment, introducing malware, or conducting unauthorized audio or video surveillance through a device’s built-in features is a third-degree felony. The charge rises to a second-degree felony when the offense causes damage of $5,000 or more, is committed as part of a fraud scheme, disrupts government operations or public services like water or transportation, or targets a public transit system.4Online Sunshine. Florida Code 815.06 – Offenses Against Users of Computers, Computer Systems, Computer Networks, and Electronic Devices
The top tier is a first-degree felony, reserved for unauthorized activity that endangers human life or disrupts systems tied to medical equipment used in direct patient care.4Online Sunshine. Florida Code 815.06 – Offenses Against Users of Computers, Computer Systems, Computer Networks, and Electronic Devices
Section 815.04 addresses intellectual property offenses. Knowingly introducing computer contaminants, destroying data, or disclosing trade secrets or legally confidential information stored in a computer system is a third-degree felony, rising to the second degree when done as part of a fraud scheme.5Online Sunshine. Florida Code Chapter 815 – Computer-Related Crimes
Healthcare Data Must Stay in North America
Florida imposes a geographic restriction on electronic health records that goes beyond HIPAA. Under the Florida Electronic Health Records Exchange Act at section 408.051, any healthcare provider using certified electronic health record technology must ensure patient information stored offsite, whether through a third-party data center or cloud service, is physically located in the continental United States, its territories, or Canada. The rule covers all qualified electronic health records stored using technology that allows electronic retrieval, access, or transmission.6Online Sunshine. Florida Code 408.051 – Florida Electronic Health Records Exchange Act
Overlap With Federal Requirements
Florida’s cybersecurity rules run alongside federal ones. Healthcare providers still owe HIPAA compliance in addition to FIPA and the section 408.051 storage restriction. Financial institutions covered by the Gramm-Leach-Bliley Act have their own federal data-security duties. FIPA accommodates the overlap by allowing federally regulated entities to follow their federal notification procedures, provided they still report the breach to the Florida Department of Legal Affairs.
Publicly traded companies face another timeline. SEC rules require filing a Form 8-K within four business days after determining a cybersecurity incident is material. That clock starts at materiality, not at the breach itself, so the SEC deadline and FIPA’s 30-day window can run on different schedules. A company can meet one and miss the other if it is not tracking both from the start.