At a time when municipal water systems in seven states have suffered cyberattacks, the need to guard against malicious hacking has taken on greater urgency. Mississippi’s hospitals and other institutions have meanwhile been subjected to their own run of attacks, yet for years the state has not required the facilities to defend against them.
Against that backdrop, Lt. Gov. Delbert Hosemann has created a Senate Select Committee on Cybersecurity to study the security of state and local government computer systems and review how Mississippi prosecutes cybercrime.
Hosemann points to the most severe recent Mississippi case, in February 2026, when a ransomware group that security researchers link to Russia took the University of Mississippi Medical Center offline for more than a week, which resulted in the closure of its clinics, forced doctors to work with pen and paper, and demanded an $800,000 ransom. The FBI and the Department of Homeland Security joined the recovery in that case. UMMC houses the state’s only children’s hospital, its only Level I trauma center and its only organ transplant program. Hosemann said cybercrime costs the state hundreds of millions of dollars.
The medical center was the fourth Mississippi hospital system hit in three years. A 2023 ransomware attack on Singing River Health System in Ocean Springs exposed the health information of nearly a million people. North Mississippi Health Services and OCH Regional Medical Center in Starkville were struck the same year. UMMC had been breached before that. A decade ago, it paid $2.75 million in federal fines after the 2013 theft of a laptop exposed about 10,000 patients’ records, and federal investigators found the center had known of the vulnerability since 2005 and left it unaddressed.
Through all of this, Mississippi has had no state law requiring hospitals to guard against cyberattacks. Only the federal health-privacy law, HIPAA, imposes that duty, and the federal government enforces it. The select committee is the state’s move to close the gap.
The state Senate committee will be co-chaired by Bart Williams (R-Starkville) and Tyler McCaughn (R-Newton), with members Bradford Blackmon (D-Jackson), Scott DeLano (R-Gulfport), Jeremy England (R-Ocean Springs) and Rod Hickman (D-Macon).
Hosemann, a Republican who presides over the Senate, said state agencies protect their systems separately and without a shared standard. “Everybody has siloed their own security stuff, which is for self-protection,” he said in announcing the committee on his official website. “Now we want to be able to have those protections done on a universal basis.” The committee will hold hearings this fall and make recommendations to the 2027 legislative session.
This is the second cybersecurity effort that Hosemann has driven through the Senate this year. During the 2026 session, a Senate committee advanced two bills that would create a state Department of Cybersecurity and require the governor to appoint a cabinet-level chief information officer for data protection and cyber strategy. Lawmakers have said they plan to keep working on the measures, and the new committee’s recommendations are set to feed the coming session.
Hosemann is considering a run for governor in 2027 but has not yet entered the race. The Republican primary so far includes Attorney General Lynn Fitch, Agriculture Commissioner Andy Gipson, State Auditor Shad White and former House Speaker Philip Gunn, with businessman Tommy Duff also weighing a bid. Current governor Tate Reeves is term-limited.
All of which means the committee hearings this fall and any legislation that results will unfold in the months leading up to the election.
Image: Delbert Hosemann (R) meets with representatives of Mississippi State University’s Cyber and Technology Center on the Coast in July 2026 (via his official Facebook page)




