<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-KEN24064-5GN-KM-P2F"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S3773 IS: Strengthening Cybersecurity in Health Care Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2024-02-08</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>2d Session</session><legis-num>S. 3773</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20240208" legis-day="20240207">February 8 (legislative day, February 7), 2024</action-date><action-desc><sponsor name-id="S350">Mr. Rubio</sponsor> (for himself, <cosponsor name-id="S363">Mr. King</cosponsor>, <cosponsor name-id="S384">Mr. Tillis</cosponsor>, and <cosponsor name-id="S388">Ms. Hassan</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSHR00">Committee on Health, Education, Labor, and Pensions</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Inspector General of the Department of Health and Human Services to evaluate the cybersecurity practices and protocols of the Department, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening Cybersecurity in Health Care Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="idc21ea30152f74c3f998c5143e00b95de"><enum>2.</enum><header>Evaluation of HHS cybersecurity</header><subsection commented="no" display-inline="no-display-inline" id="id905389ae6e394e80a7dede8f76384a98"><enum>(a)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Not later than 2 years after the date of enactment of this Act, and every 2 years thereafter, the Inspector General of the Department of Health and Human Services shall evaluate the cybersecurity practices and protocols of the Department through the conduct of penetration tests and other testing procedures to determine how systems processing, transmitting, or storing mission critical or sensitive data by, for, or on behalf of the Department is currently, or could be compromised and—</text><paragraph commented="no" display-inline="no-display-inline" id="idc455cf2cdeda43a38df4b7aa0d492f3d"><enum>(1)</enum><text display-inline="yes-display-inline">expose patient data, including Medicare numbers of individuals; or</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id07f5a5f9e1f14cc3a0951076e3783ed6"><enum>(2)</enum><text display-inline="yes-display-inline">impact patient safety. </text></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id93f9d3dc973d462c8b26f33d7a7b15b4"><enum>(b)</enum><header>Reports</header><text>Not later than 2 years after the date of enactment of this Act, and every 2 years thereafter—</text><paragraph commented="no" display-inline="no-display-inline" id="id7d85ce355930482bb91ac167a76a7fe2"><enum>(1)</enum><text display-inline="yes-display-inline">the Secretary of Health and Human Services shall submit to Congress a report that describes how the Secretary will update the cybersecurity practices and protocols of the Department of Health and Human Services to adapt to the latest cyberattack strategies; and</text></paragraph><paragraph id="idc43b7237c4ec4302aa18f4522b39195c"><enum>(2)</enum><text>the Inspector General of the Department of Health and Human Services shall submit to Congress a report that describes—</text><subparagraph commented="no" display-inline="no-display-inline" id="ida6d1c98110b948c4810bd33cca3e9e2c"><enum>(A)</enum><text display-inline="yes-display-inline">how the Inspector General is currently using Federal funds of the Inspector General to carry out subsection (a); and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idec4bb62894714739aa598fd17271c419"><enum>(B)</enum><text display-inline="yes-display-inline">additional funding or legislative changes required for the Inspector General to maintain the evaluation described in subsection (a).</text></subparagraph></paragraph></subsection></section></legis-body></bill> 

