<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H440952F46FE14EF6BF2FBD67E443A07B" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>111 HR 3847 IH: Cyber Awareness and Recovery Enhancement Act of 2013</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-01-10</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress>113th CONGRESS</congress><session>2d Session</session><legis-num>H. R. 3847</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action><action-date date="20140110">January 10, 2014</action-date><action-desc><sponsor name-id="B001279">Mr. Barber</sponsor> (for himself, <cosponsor name-id="D000618">Mr. Daines</cosponsor>, and <cosponsor name-id="S001191">Ms. Sinema</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name>, and in addition to the Committee on <committee-name committee-id="HGO00">Oversight and Government Reform</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Homeland Security the responsibility to develop and provide to the Secretary of Health and Human Services risk-based, performance-based cybersecurity standards for the Federal information technology requirements under the Patient Protection and Affordable Care Act, including the healthcare.gov website, and for other purposes.</official-title></form><legis-body id="H6E89C55594124F1D8C2C86D858D1B7D2" style="OLC"><section id="H211314C24B76405FA4C0D8405C0A38E4" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Awareness and Recovery Enhancement Act of 2013</short-title></quote> or the <quote><short-title>CARE Act of 2013</short-title></quote>.</text></section><section id="H0377BB1B5F37413A9342F990FD3C586B"><enum>2.</enum><header>Cybersecurity for healthcare.gov website</header><subsection id="H79545C0E63C24629BA1FD29BBA529952"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Notwithstanding the requirements of the Federal Information Security Management Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/44/3531">44 U.S.C. 3531 et seq.</external-xref>) or any other provision of law, not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall develop and provide to the Secretary of Health and Human Services risk-based, performance-based cybersecurity standards for the Federal information technology requirements under the Patient Protection and Affordable Care Act (<external-xref legal-doc="public-law" parsable-cite="pl/111/148">Public Law 111–148</external-xref>), including the healthcare.gov website (or any successor website). Such standards shall be based on cybersecurity best practices, and on homeland security information that the Secretary of Homeland Security has collected, analyzed, and disseminated about cyber threats, vulnerabilities, and consequences.</text></subsection><subsection id="H3A6F94F5455549A7B2D85774746C07FD"><enum>(b)</enum><header>Consultation</header><text>In carrying out the cybersecurity standards described in subsection (a), the Secretary of Homeland Security shall consult with the Secretary of Health and Human Services.</text></subsection><subsection id="HEACE5E08B55248EDB5852E92CD5B037F"><enum>(c)</enum><header>Implementation and enforcement</header><text display-inline="yes-display-inline">Not later than 90 days after receiving the cybersecurity standards described in subsection (a), the Secretary of Health and Human Services shall adopt and implement such cybersecurity standards.</text></subsection><subsection commented="no" id="HA715F03DFC324016870156FAC7DCA779"><enum>(d)</enum><header>Enforcement</header><text display-inline="yes-display-inline">The Secretary of Health and Human Services shall submit to Congress an annual report on cyber incidents relating to the Federal information technology requirements under the Patient Protection and Affordable Care Act, including the healthcare.gov website (or any successor website).</text></subsection></section></legis-body></bill>


