<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H55B1AD7B2646424D8C56CC00991CD4AA" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>111 HR 3795 IH: One Hour Notification Act of 2013</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2013-12-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress>113th CONGRESS</congress><session>1st Session</session><legis-num>H. R. 3795</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action><action-date date="20131219">December 19, 2013</action-date><action-desc><sponsor name-id="B001257">Mr. Bilirakis</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require notifications by the Secretary of Health and Human Services to Congress and to individuals of breaches of personally identifiable information of such individuals maintained, submitted to, or submitted by a system maintained by Exchanges under the Patient Protection and Affordable Care Act, and for other purposes.</official-title></form><legis-body id="H1DEFC74B1A9246A1B7A64581FB05DE96" style="OLC"><section id="HA834C84136EA4BD3AD32745FBB5FA2A2" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>One Hour Notification Act of 2013</short-title></quote> and as the <quote><short-title>OH No Act of 2013</short-title></quote>.</text></section><section id="H37FA7B69480344978A23BDDA3174E223"><enum>2.</enum><header>Notification and annual report relating to breaches of personally identifiable information by PPACA Exchanges</header><subsection id="H52FCEFE5F2A5447996D91FBE67932D7C"><enum>(a)</enum><header>Notification of data breaches</header><text display-inline="yes-display-inline">The Secretary of Health and Human Services, following the discovery of a breach of the personally identifiable information of an individual that is maintained, submitted to, or submitted by a system maintained by an Exchange established under title I of the Patient Protection and Affordable Care Act (<external-xref legal-doc="public-law" parsable-cite="pl/111/148">Public Law 111–148</external-xref>), shall—</text><paragraph id="HDF650357367A480F8D739C63539D36EB"><enum>(1)</enum><text>not more than one hour after the time at which the Secretary is notified of such breach, notify the individual that such information has been so breached; and</text></paragraph><paragraph id="H3104BBE60E204010A22B6179A76D3BE7"><enum>(2)</enum><text>in a timely manner, notify the Committees on Energy and Commerce, Ways and Means, and Education and Workforce of the House of Representatives and the Committees on Finance and Health, Education, Labor, and Pensions of the Senate that such information has been so breached.</text></paragraph></subsection><subsection id="HC28A30D626E84BBFBB6075C4F1646D62"><enum>(b)</enum><header>Annual report</header><text display-inline="yes-display-inline">Not later than January 1, 2015, and each year thereafter, the Secretary of Health and Human Services shall submit to Congress an annual report that identifies, with respect to the breaches of security described in subsection (a)—</text><paragraph id="H1FE0E68BFE9B48B6877B3D5E3EFFA929"><enum>(1)</enum><text>all such breaches that occurred within the past year; and</text></paragraph><paragraph id="HC84321962C094F35BF3769B29FBC2DEC"><enum>(2)</enum><text>the security rules, standards, and risk mitigation strategies implemented by the Secretary, as of the date of the submission of such report, for the purpose of preventing such breaches.</text></paragraph></subsection></section></legis-body></bill>


