Maryland's product-security and cyber-resilience posture rests on one enacted state statute, the Maryland Personal Information Protection Act's safeguards and secure-disposal duty, Commercial Law sections 14-3502 and 14-3503 (Title 14, Subtitle 35, added by 2007 Md. Laws ch. 531 (S.B. 194), approved by Governor Martin O'Malley May 17, 2007 and effective January 1, 2008), which requires a business that owns, maintains, or licenses the personal information of a Maryland resident to implement and maintain reasonable security procedures and practices appropriate to the nature of that information and the size of the business, to take reasonable steps to protect personal information from unauthorized access when destroying records that contain it, and to require the same of a nonaffiliated third-party service provider by contract.
Commercial Law section 14-3507 deems a business already complying with the security, notification, or destruction rules of its own primary or functional federal or State regulator, or already subject to and in compliance with the Gramm-Leach-Bliley Act, the Fair and Accurate Credit Transactions Act's Red Flags Rule, the federal Interagency Guidelines Establishing Information Security Standards, or Health Insurance Portability and Accountability Act (HIPAA), to be in compliance with the whole subtitle.
No enacted Maryland statute sets security requirements a connected device or software product must meet before or after it reaches the market: bills closely modeled on California's connected-device statute, Senate Bill 443 and a House companion, House Bill 888, considered by the House Economic Matters Committee as recently as February 2020, were introduced and did not advance past committee, and no successor bill was located in a later session, so this is a researched absence rather than a gap in coverage.
Maryland has no general private-sector duty to report an exploited vulnerability or a security incident to an authority.
Chapter 242 of the Laws of 2022 (S.B. 812) made the Office of Security Management and the State Chief Information Security Officer permanent within the Department of Information Technology and requires each unit of the Executive Branch of State government and certain local government entities, not a private business, to report a cybersecurity incident, so it belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.
Chapter 243 of the Laws of 2022 (H.B. 1205, the Modernize Maryland Act of 2022) separately requires a public or private water or sewer system that serves 10,000 or more users and receives State financial assistance to assess its vulnerability to a cyber attack, develop a cybersecurity plan where appropriate, and report to the General Assembly; because the LexLint activity vocabulary cannot yet express a water or sewer utility operator as a bound role, it is deferred rather than flagged on a guess (#6740), and recorded here so a reader knows it exists.
The Maryland Insurance Administration separately administers the Maryland Insurance Data Security Act, Insurance Article Title 33 (Chapter 231 of the Laws of 2022, S.B. 207, based on the NAIC's Insurance Data Security Model Law), effective October 1, 2022, which requires a licensed insurance carrier to maintain a written information security program and notify the Insurance Commissioner of a cybersecurity event; because its bound party, an insurance licensee, is also a role the activity vocabulary cannot express, it too is deferred and recorded here rather than filed as an instrument.
Commercial Law section 14-3508 makes a violation of the safeguards and disposal duty an unfair or deceptive trade practice under Title 13 of the Commercial Law Article (the Maryland Consumer Protection Act) and subjects it to that title's enforcement and penalty provisions: the Attorney General's Consumer Protection Division may seek a civil penalty of up to $10,000 per violation and up to $25,000 for a repeat violation under Commercial Law section 13-410, and, unlike New York's SHIELD Act safeguards duty, Commercial Law section 13-408 also lets any person bring a private action to recover for an injury or loss the violation caused, plus attorney's fees.
Title 13's own criminal provision, section 13-411, makes a violation of that title a misdemeanor carrying a fine of up to $1,000 or imprisonment of up to one year; whether that reaches a safeguards or disposal violation through section 14-3508's incorporation of Title 13's penalty provisions, as distinct from the civil penalty alone, is not addressed in the Office of the Attorney General's own published compliance guidance and was not located in any other primary source.
Maryland's breach-notification duty, Commercial Law section 14-3504, the other half of the Maryland Personal Information Protection Act, is already this jurisdiction's privacy row rather than repeated here: it requires notice to an affected Maryland resident and, before that notice, to the Office of the Attorney General, once a business discovers or is notified of a breach of the security of a system.
The Maryland Online Data Privacy Act's own controller and processor obligations are this jurisdiction's comprehensive privacy regime and are researched there rather than duplicated here.